Records management may be the most important business service that you've never heard of. In an era of increasing identify theft and more stringent regulations, however, it's time to get the facts on this important industry.
If your company handles or stores customer information like names, addresses, medical records, Social Security or bank account numbers, then finding a safe, secure way to both manage and dispose your office's paperwork isn't optional—it's mandated by law. Depending on your industry, your business may be subject to federal laws like HIPAA or the Gramm-Leach-Bliley Act, but state regulations often also apply. Some regs, like Massachusetts General Laws 93H and 93I, require companies to have written procedures that outline how paper and electronic files are secured on a day-to-day basis, as well as how they will be destroyed once they are no longer needed. When companies fail to meet these basic standards, they can be subject to prosecution and end up paying significant fines—sometimes per record.
Here's where a Records Management System (RMS) comes in. These services come in a variety of shapes and sizes, but their purpose is essentially the same: to help companies manage their paper and electronic records in such a way that sensitive information is secured and properly stored, and remains accessible if needed in the future. A typical Records Management vendor will offer some (if not all) of the following services:
- Site analysis and compliance documentation
- Secure, off-site record storage for paper files
- Online access to storage inventory
- Scheduled document destruction services, one-time or ongoing
- Document imaging for digital storage and retrieval
- Disaster recovery planning
Of course, not all Records Management vendors are created equal. There are any number of companies to choose from—not all of whom can handle the job successfully. Take the time to evaluate each vendor carefully, and consider the following:
The National Association for Information Destruction (NAID) offers training and certification for Records Management professionals. Records Management vendors with this credential have completed extensive training and have pledged to follow the standards and ethical practices of the NAID organization.
A reputable Records Management vendor should know immediately what procedures your business needs to follow to be in compliance with federal and state laws. Educate yourself ahead of time regarding your particular industry so that you know whether their recommendations are on-target.
Learn how the vendor you are considering secures its own facilities. Ask what safeguards are in place for physical files, as well as digitally stored information. Be sure that the company has a definite policy regarding employee background checks. Every employee, but especially those with direct contact with sensitive information, should be thoroughly checked before gaining access to your company's files.
The Records Management vendor you choose should provide evidence of their commitment to customer service. Consider how responsive and flexible the vendor has been during the sales process: Were they easy to reach? Able to offer scalable solutions to your particular company? Was their pricing competitive? Next, ask for references and determine whether or not existing customers are satisfied with their level of service. Finally, determine what procedures are in place to ensure that the vendor is accessible when needed. 24/7 online access to your records is an absolute requirement.
A reputable, service-oriented Records Management vendor will lower your company's risk exposure, reduce document storage costs and allow you to focus on growing your business. Take the time to evaluate your current and future records management needs—and then find the vendor who is right for the job.