Standards for Certified Data Destruction Organizations
ClearChain is an independent, non-government auditor of information security, controls and risk management.
HIPAA | GLBA | PCI | NIST 800 | FACTA | FINRA
Our Certification for Your Risk Management
A Certificate of Destruction from a third-party vendor does not transfer liability!
Your organization remains legally responsible and liable for the protection of consumer and patient information long after giving up custody of paper and digital media. Healthcare providers should be very familar with HIPAA & HITECH regarding these rules.
Our Certified requirements
ClearChain conducts a comprehensive review of documentation, policies and procedures, operational protocols, and other supporting materials submitted by data destruction service providers. The objective is to independently validate that the vendor possesses the experience, infrastructure, and controls necessary to securely destroy information in accordance with applicable data privacy regulations.
A ClearChain Certification confirms that a vendor has implemented reasonable and appropriate safeguards, as required under data protection laws such as HIPAA, HITECH, GLBA, and FACTA. Engaging a ClearChain Certified vendor satisfies an organization’s due diligence obligation when selecting third-party data destruction and information security providers.

Your third party due diligence
Organizations may either perform vendor due dilience inhouse, by reviewing policies & procedures, employee background, etc., or hire a company Certified for data destruction.
Requirements for Certification
ClearChain Certified data destruction vendors are required to comply with standard policies & procedures (“P&P”). Â These P&Ps were develped based on guidelines of NIST 800-88 Guidelines, ISO 27001 & the Department of Defense.
A well-vetted vendor not only maintains compliance but minimizes financial and reputation risk exposure.
Policies and Procedures
- Media control & handling
- Destruction type & size
- Compliance reports
- Certificate of Destruction
- Equipment capatability
Administrative
- Breach notification & response
- Insurance requirements
- Business licenses & permits
- Reporting & documentation
Employees
- Background checks
- Travel ining
- Substance abuse screening
- Non-disclosure agreements