
HIPAA, PHMC, DoD, NJSA — guides and checklists for regulated industries.

Featured field guide
A definitive HIPAA records compliance checklist for healthcare compliance and facilities leaders: the Security Rule controls that protect records (access, audit, integrity), how HIPAA, CMS, and Pennsylvania retention rules stack, the economics of a breach, defensible destruction, the ROT and dark-data problem, and a working audit-readiness checklist.
Read the guideA source-cited retention guide for Pennsylvania hospitals, ambulatory surgical facilities, and physician practices — covering the 7-year state rule, the HIPAA documentation floor most organizations mistake for chart retention, and the diverging minor-patient rules between hospitals and physician practices.
A source-cited walkthrough of how Pennsylvania's PHMC municipal and county records schedule system actually operates — schedule adoption, the 5-step disposition process, the permanent-vs-non-permanent distinction, and PHMC's own scanning standards for digital surrogates.
A source-cited guide to Pennsylvania K-12 student records retention — what FERPA actually governs (privacy, not retention duration), why PHMC's county/municipal schedules don't cover school districts, the IDEA special-education destruction rule, and the specific questions that have no statewide answer.
A source-cited retention-schedule reference for Pennsylvania organizations — PA municipal records, hospital medical records, HIPAA documentation, IRS tax records, FLSA payroll records, and OSHA exposure/medical records — with every period traced to its primary regulatory source.
A cited walkthrough of the ISO 14644-1 particle-count classification table, how ISO 5/7/8 map to EU GMP grades, and how to choose and build the right class for a life sciences facility.
A compliance-grade guide to financial-services records management: SEC Rule 17a-4 and FINRA Rule 4511 retention periods, the 2023 WORM-or-audit-trail amendments, GLBA secure disposal, PCI DSS logging, SOC 2 attestation, and the enforcement context that makes the program matter.
A deep reference for records managers, evidence custodians, and IT staff in law enforcement: what FBI CJIS Security Policy v6.0 requires, how to build a defensible digital chain of custody, how long body-worn camera footage must be retained, and how to prepare for the triennial CJIS audit.
A definitive reference for pharma and biotech QA, RA, and IT on document management under FDA 21 CFR Part 11 and GMP — covering the predicate rules, the electronic record and electronic signature controls in 11.10 through 11.300, ALCOA+ data integrity, computer system validation, audit trails, GxP retention periods, and the recurring failures behind FDA Form 483 observations and warning letters.
A definitive FERPA reference for registrars, IT, and records officers: education-record definitions, the four core rights, consent and disclosure rules, the disclosure log, retention schedules, IDEA special-education records, digitization, and enforcement.
A working quick-reference for Pennsylvania county officials: how the PHMC County Records Manual sets retention by record series, which series are permanent, the Right-to-Know Law clocks and fee caps, how to run defensible destruction, electronic PDF/A records, and how the County Records Improvement Fund pays for it.
A definitive guide for Pennsylvania healthcare compliance and facilities leaders: the retention rules that never change (HIPAA, CMS, and PA state law), the real tradeoffs between a regional partner and a national vendor across response time, breach liability, and cost, the economics of storage versus digitization, and how to evaluate a vendor.
A definitive HIPAA records-management checklist for healthcare HIM and compliance teams: how to build a retention schedule across HIPAA, CMS, and Pennsylvania law; the five technical safeguards and the audit trail; handling patient access requests; certified destruction; and converting EHR-era paper.
A working DoD 5015.02 compliance program for defense contractors: run a gap assessment, select a records system after the JITC certification program ended in 2025, build file plans and NARA-approved disposition, stand up a defensible audit trail, and handle CUI under DFARS 252.204-7012, NIST SP 800-171, and CMMC.
A definitive guide to Pennsylvania county records compliance: the PHMC County Records Manual and County Records Committee, Right-to-Know Law deadlines, defensible destruction, electronic and microfilm standards, and the County Records Improvement Fund.
Subscribe to receive newly published compliance guides and checklists from Reynolds.
Review the Privacy Policy for details about form-data handling.
Our team can help you apply these guides to your specific situation — same-day response.