Although the Privacy Rule does not specify a specific method of disposal, covered institutions should consider the risks to patient confidentiality when deciding what protocols to implement when getting rid of PHI.
Paper records containing PHI may be destroyed by shredding, burning, or pulverizing the records such that the PHI cannot be read, identified, or even reconstructed to protect patient privacy.
Records cannot be disposed of by covered entities in trash cans or other areas where the general public or unauthorized individuals can access them.