- Services ServicesServices --
-
- Digital Solutions
- Document Scanning and Indexing
- Digital Contract Management
- Digital Invoice Processing
- Digital Mailroom
- Employee Management System (HRDMS)
- Visitor Management System (VIZIO)
- Enterprise Content Management (ECM)
- Information Consulting
- Employee Onboarding
- Central Know Your Customer Automation (CKYC)
- Digital Signatures
- Fixed Asset Management
- Digital file tracking (DART)
- Industries
- Case Studies
- Insight
- Resources
- Customer Centre
How dangerous are improperly stored physical records? The Kaiser case shows us the answer
For all the attention on digital transformation, some records are still physical for good reasons. Signed documents still matter. Paper files still sit inside healthcare, legal, HR, finance, and public-sector workflows. Some are waiting to be digitized. Some need to be retained in original form. Some live in offsite storage because the business still needs them. Physical records management isn’t just a leftover from a pre-digital era.
The department of Health and Human Services (HHS) in the U.S. own guidance states that that health information privacy rules apply to records “whether electronic, written, or oral,” and NHS England’s records code says records obligations apply across all media.
The compliance rules are stricter than many people realize
A lot of organizations have matured their cyber controls but have not given the same attention to physical storage, retrieval, and disposal. That gap can be expensive. In the U.K., the Information Commissioner’s Office (ICO) has said that security under U.K. GDPR includes physical and organizational measures. In other words, not just cyber controls. Of more pertinence if you have physical records is that the higher maximum fine can reach £17.5 million or 4% of worldwide turnover.
In the U.S., HHS says organizations are not allowed to “simply abandon personal health information” in publicly accessible dumpsters, and gives clear examples of compliant paper disposal such as shredding, pulping, burning, or pulverizing records so they cannot be reconstructed. Singapore’s Personal Data Protection Act (PDPC) makes the same broader point from another jurisdiction, saying data protection duties apply to personal data in “electronic or other form” and that retention must stop once there is no continuing legal or business purpose.
This is also more than a theoretical risk. One clear example is the ICO’s 2022/23 annual report, which said paperwork left insecure or stolen still accounted for just over 7% of the incident types generating the most personal data breaches. Physical records are not the biggest line item in every breach dashboard, but they are very clearly still a live source of exposure.
What the Kaiser case shows: Mishandled physical records = Big fines
One of the clearest recent examples came from California, but with increasingly harmonized rules around PPI the lessons are applicable anywhere. In 2023, the California Attorney General announced a $49 million settlement with Kaiser Permanente over allegations that it unlawfully disposed of hazardous waste, medical waste, and protected health information. According to the Attorney General’s office, inspectors reviewed dumpsters from 16 Kaiser facilities and found hundreds of items of hazardous and medical waste along with more than 10,000 paper records containing information on more than 7,700 patients. The state said those dumpsters were headed to publicly accessible landfills.
The timeline matters here. AP reported that the investigation started in 2015. So, this was not a one-off afternoon mistake. It turned into a long-running enforcement matter that ended with a court judgment, public scrutiny, a large payment, and years of required oversight. The final judgment requires an independent auditor, at least 520 trash audits, and at least 40 field audits each year for five years. That is what compliance remediation looks like when weak physical records controls become a public case.
The Attorney General put it plainly. Healthcare providers have “specific legal obligations” to dispose of medical waste correctly and safeguard patient information. That line lands because it gets to the heart of the issue.
Why do physical storage and disposal fail then?
When physical records management goes wrong, the root cause is usually a chain of what can be termed “small misses” rather than one big mistake. As one example we’ve seen: records go offsite before they are properly indexed. Retention dates being unclear are another such example. Disposal rules sit in a policy but not in day-to-day workflow that anyone is aware of. Vendors are appointed but rarely audited. Staff know where the shred bins are, but not what should and should not go into them. Eventually, something ends up in the wrong container, the wrong truck, or the wrong room and the results can be seen from the Kaiser case above.
These days, official guidance is consistent on what good practice looks like regardless of where you sit in the world. NHS England says offsite records management should include a full inventory, retention periods for each record, a disposal log, and evidence of secure disposal. The U.K. National Archives says no records should be sent offsite without an active disposal schedule, warning that poor disposal management can create unnecessary storage costs and legal risk. HHS says any workforce members involved in disposing of records should be trained. That is not glamorous work, but it is exactly where real risk gets reduced.
How to reduce physical records storage risk
First things first: If you do not know what is in storage, where it sits, who owns it, and when it is due for review or destruction, you do not have a records program.
Then tighten disposal governance. Paper destruction should be documented, authorized, and evidenced. If a third party is involved, due diligence needs to go beyond a contract. To expand the scope: Singapore’s PDPC states clearly that outsourcing does not remove the organization’s accountability.
Finally, audit the physical world with the same seriousness you apply to digital controls. Walk the process. Check collection points, archive rooms, transport handoffs, and destruction certificates. Review what staff actually do, not just what policy says. The Kaiser case is a reminder that physical records failures are often discovered through inspection of what ends up in the waste stream. If your organization never tests that path, you are trusting rather than verifying.
Records management still needs a physical plan
We’re not saying digitization is going to slow down. Quite the opposite (that is obvious to anyone). What we are saying is that the compliance burden has not stopped at digital. Physical records, firstly, still exist in abundance and still carry personal data, legal significance, retention obligations and reputational exposure.
The organizations that treat paper storage, retrieval, and destruction as a mature control area are in a better position to avoid the kind of consequences Kaiser faced. For records managers, that is the real message. Physical records may be a smaller share of the information estate than they once were, but when they fail, the fallout is still very current.
If you have physical or digital records, and want to get started on a holistic plan to manage either (or both) then get in touch with one of our experts today.