What Shred Size Does HIPAA Require? A Straight Answer
Share
HIPAA does not require a specific shred size. There is no particle dimension, no millimetre figure and no DIN security level anywhere in the Privacy Rule or the Security Rule. What HIPAA requires is an outcome: protected health information must be rendered “essentially unreadable, indecipherable, and otherwise cannot be reconstructed.”
If a vendor tells you that HIPAA mandates a particular level, they are either mistaken or selling. That said, “no specific size” is not the same as “anything goes”, and there is a defensible answer to the practical question of what to buy. This article gives you both: what the regulation says, and what a reasonable covered entity actually does.
What HHS actually says
The Department of Health and Human Services addresses disposal directly in its published HIPAA guidance. The relevant passages are short and worth reading in the original wording.
On the general obligation:
“The HIPAA Privacy Rule requires that covered entities apply appropriate administrative, technical, and physical safeguards to protect the privacy of protected health information (PHI), in any form.”
On method:
“However, the Privacy and Security Rules do not require a particular disposal method.”
On paper specifically, HHS gives examples of proper disposal:
“shredding, burning, pulping, or pulverizing the records so that PHI is rendered essentially unreadable, indecipherable, and otherwise cannot be reconstructed.”
And on what is definitely not acceptable:
Covered entities “are not permitted to simply abandon PHI or dispose of it in dumpsters or other containers that are accessible by the public or other unauthorized persons.”
That is the whole of it. Four sentences, no numbers.
Why the rule is written this way
HIPAA is deliberately technology-neutral. A rule that named a particle size in 2003 would have been obsolete within a decade, and it would have applied identically to a two-person dental practice and a thousand-bed hospital system. Instead the Privacy Rule and the Security Rule use a reasonableness standard: covered entities and business associates must assess their own circumstances — the sensitivity of the information, the volume, the physical environment, the cost and availability of controls — and implement safeguards that are appropriate to that assessment.
The practical consequence for you is that the burden of judgement sits with your organisation, and you should be able to show your work. An auditor is not going to ask “is this machine P-5?” They are going to ask “how did you decide this was adequate, and can you demonstrate it is being used?”
What vendors claim, and why it is wrong
Three claims recur across the shredder market. All three are false as stated.
“HIPAA requires a Level 3 / Level 4 / Level 5 shredder”
No level appears anywhere in HIPAA. This claim usually originates as someone's reasonable recommendation and then loses its qualifier as it gets copied between websites.
“HIPAA requires cross-cut shredding”
HIPAA does not name a cut type. It names four example methods — shredding, burning, pulping, pulverizing — and does not privilege any of them. In practice a strip-cut machine will struggle to satisfy the “cannot be reconstructed” test for a page containing a patient name and diagnosis, which is a good argument against strip-cut. It is not a citation.
“This shredder is HIPAA certified”
There is no such certification. HHS does not certify, approve or endorse equipment, and no accredited body issues a HIPAA mark for shredders. A machine can be suitable for a HIPAA-compliant process. It cannot be compliant on its own, because compliance is a property of your process, not of your hardware.
So what level should you actually buy?
Here is our recommendation, stated as a recommendation rather than a legal requirement.
Use DIN 66399 P-4 as your minimum and P-5 as your default for anything containing patient identifiers.
The reasoning:
- P-3 (max 320 mm²) is thin cover. A 320 mm² particle is roughly the size of a postage stamp. On a typical clinical document that is large enough to carry a legible name fragment alongside a legible diagnosis code. You can argue it satisfies “essentially unreadable”; you would rather not have to.
- P-4 (max 160 mm²) is the practical floor. Half the particle area of P-3. Reconstruction stops being an opportunistic act and becomes a project. P-4 machines are fast enough and cheap enough to be deployed at the point where documents are generated, which matters more than the specification does. Browse P-4 shredders.
- P-5 (max 30 mm²) is the defensible default. Five times finer again. At 30 mm² the “cannot be reconstructed” question stops being arguable. If you are writing a policy that has to survive a breach investigation, this is the level that ends the conversation. See P-5 shredders and the broader micro-cut range.
- P-6 and P-7 are over-specified for PHI. They exist for classified national security material. They are slower, more expensive and more maintenance-hungry, and buying one for a medical records room usually means the records queue up beside it. That is a net loss for patient privacy.
One useful external anchor: NIST Special Publication 800-88 Rev. 1, which HHS references in its own disposal guidance for electronic media, tells federal organisations to destroy paper using cross-cut shredders producing particles of 1 mm by 5 mm or smaller. That is a national-security-grade figure and it is not a HIPAA requirement, but it establishes the ceiling of what “thorough” means. P-5 sits comfortably in the range between a token effort and that ceiling.
The parts of HIPAA disposal that are not about the machine
Most HIPAA disposal failures that reach enforcement have nothing to do with particle size. They are process failures. The common ones:
Documents waiting to be shredded
An unlocked box of records beside the shredder is unsecured PHI, and it is PHI in its original readable form. Use lockable consoles or bins for anything held between generation and destruction. This is the single most common gap we see.
Disposal in public-facing waste
HHS calls this out explicitly. Records in a dumpster, in an unsecured recycling stream, or in a bag left in a corridor are a reportable problem regardless of what your policy says.
Business associate agreements
If you use an outside shredding service, that service is a business associate. You need a business associate agreement in place, and you should conduct and document due diligence on them. Off-site destruction also means PHI leaves your control in readable form during transport, which is a risk you have accepted and should have assessed.
Electronic media
PHI on hard drives, USB sticks, backup tapes and multifunction printer drives is subject to the same disposal obligation. HHS points to NIST SP 800-88 for media sanitization, which distinguishes between clearing, purging and destroying. Note that degaussing does nothing to solid-state media — SSDs and flash drives must be purged cryptographically or physically destroyed. Digital media shredders handle the physical route.
Written policy and training
The Privacy Rule requires policies and procedures and workforce training. “We have a shredder” is not a disposal policy. A one-page document that states what gets destroyed, at what level, by whom, on what schedule, and how exceptions are handled is both easy to write and materially useful in an investigation.
What enforcement looks like
Disposal failures are enforced by the HHS Office for Civil Rights. Civil monetary penalties are structured in four tiers based on culpability, running from a violation the entity did not know about and could not reasonably have known about, through reasonable cause, through wilful neglect corrected within 30 days, to wilful neglect not corrected. The dollar amounts attached to each tier are adjusted for inflation and change periodically, so check the current figures on hhs.gov rather than relying on any number quoted on a vendor site — including this one.
The pattern worth noting is that the tiers key off whether you had reasonable safeguards and whether you fixed the problem, not off the technical specification of your equipment. A documented decision to shred at P-5, a lockable console and an annual training record are worth more in that framework than an expensive machine with no policy around it.
A workable standard to adopt
If you want a single sentence for your policy document:
All paper containing protected health information is destroyed on site to DIN 66399 level P-5 or finer, is held in a locked console from the point of generation until destruction, and is never placed in general or recycling waste in readable form.
That statement exceeds anything HIPAA specifically demands, is inexpensive to meet, and is easy to evidence.
Frequently Asked Questions
Does HIPAA require cross-cut or micro-cut shredding?
Neither is named in the regulation. HIPAA lists shredding, burning, pulping and pulverizing as examples of proper disposal, and requires only that the result be essentially unreadable and non-reconstructable. In practice cross-cut at P-4 is a sensible minimum and micro-cut at P-5 is a stronger position, but that is a risk judgement, not a citation.
Is a strip-cut shredder ever acceptable for PHI?
It is difficult to defend. Strip-cut output at P-1 or P-2 leaves ribbons up to 12 mm wide with full lines of text intact, which is hard to reconcile with “cannot be reconstructed” for a document carrying a name and a clinical detail. We would not recommend it for any material containing patient identifiers.
Can a shredder be “HIPAA compliant”?
No. Compliance attaches to your organisation's safeguards, policies and practices, not to a device. HHS does not certify equipment and no HIPAA certification exists for shredders. A machine can be appropriate for a compliant process; it cannot supply compliance by itself.
Do we have to shred on site, or can we use a service?
Either is permitted. If you use a service, it is a business associate: you need a business associate agreement, and you should document your due diligence on their handling, transport and destruction practices. On-site destruction removes the transport risk entirely, which is why many practices prefer it for small volumes.
How long do we have to keep records before we can destroy them?
HIPAA itself does not set a medical record retention period — that is governed by state law and by other federal requirements, and it varies considerably. HIPAA does require covered entities to retain certain HIPAA-specific documentation, such as policies and notices, for six years. Confirm your retention obligations before destroying anything; the disposal standard only tells you how, not when.
Does HIPAA cover shredding of electronic media too?
Yes. The disposal obligation applies to PHI “in any form”. HHS points to NIST SP 800-88 for media sanitization guidance, which covers clearing, purging and destroying. Note that magnetic degaussing is ineffective on solid-state drives and flash media, which must be cryptographically erased or physically destroyed.
This article is general guidance for facilities and compliance staff and is not legal advice. Quoted language is from HHS HIPAA guidance published at hhs.gov. Verify current requirements and penalty amounts against the primary sources, and consult counsel on your specific obligations.