PII: What It Is and How to Protect It

Most people picture a breach as a break-in. Someone cracks a password, slips past a firewall, walks off with a database. Oftentimes in reality it’s slower and quieter than that. A name here, a birthdate there, an old address off a form that went into a dumpster intact — and eventually there’s enough to open a credit line or call a bank and sound convincing.

Consumers reported losing about $16 billion to fraud in 2025, the highest annual total the Federal Trade Commission has on record and roughly 25% above the year before. Imposter scams led every other category, turning up in nearly one in three fraud reports. People posing as banks accounted for close to $1 billion of the losses on their own.

Impersonation works because the caller already sounds like they know you. Some of what they know was bought out of a breached database. Some of it never required hacking at all, because it was sitting in a file drawer, a mailbox, or a curbside recycling bin.

So this page is about the information itself: what personally identifiable information (PII) actually is, which pieces of it carry real risk, where it quietly piles up in paper and digital files, and what you can do about it.

What Is PII?

Personally identifiable information (PII) is any information that can be used to distinguish or trace someone’s identity, either on its own or when combined with other data. That’s the framing the National Institute of Standards and Technology works from, and it splits into two halves.

The first half is the obvious material: name, Social Security number, date and place of birth, mother’s maiden name, biometric records. Each of these points at one person without help.

The second half is broader and easier to underestimate: anything linked or linkable to an individual, including medical, educational, financial, and employment information. A patient chart, a transcript, a loan file, an old performance review. Once any of it is attached to a name, it qualifies.

Examples of PII by Risk Level

Not every field carries the same weight, and guarding them all identically spends effort you could put toward the paperwork that genuinely needs it. A rough tiering:

Risk levelExamples of personally identifiable information
LowerName, work phone number, business email, ZIP code, license plate
ModerateHome address, personal phone number, date of birth, employment history
HigherSocial Security number, driver’s license or passport number, bank and card account numbers, medical records, biometric data, login credentials

The bottom row is the most sensitive personal information. It can be used to open accounts, file fraudulent tax returns, fill prescriptions, or take over a login, and is the category most likely to trigger a breach notification obligation if it escapes. Sorting documents by risk before building controls around them is the same logic behind most secure document management programs.

How Small PII Details Add Up

The tiers are useful, and also a little misleading, because attackers don’t work one field at a time. They aggregate and compound.

Healthcare has thought about this more carefully than most industries. Under the Safe Harbor de-identification standard in the Health Insurance Portability and Accountability Act (HIPAA), a record isn’t treated as de-identified until 18 separate categories of identifiers come out of it and nothing left behind could still point at a person. That list reaches items most people would call harmless. ZIP code detail. Any date more specific than a year. Device serial numbers. Web addresses. The standard exists because researchers kept demonstrating that a handful of ordinary details could be re-linked to one specific human being.

Fraud follows the same math. A name and a birthdate get someone partway through a security questionnaire. Add a former street address pulled off an old utility bill and a mother’s maiden name mentioned in a social post, and now they can reset a password or clear a phone verification. None of those facts is secret on its own. Assembled, they’re a key.

It also explains why a single exposed file escalates the way it does, as the damage rarely stops with the people named in it.

Where PII Piles Up

Most advice about protecting personal information aims at the device and the connection: the router, the antivirus software, the password on the Wi-Fi. Those controls do real work on traffic moving through your home or office. They do nothing at all for the four banker’s boxes in the garage.

For households, PII collects in predictable spots:

  • tax returns going back a decade
  • closed-account statements
  • medical explanations of benefits
  • expired insurance policies
  • folders of old school and employment paperwork

The digital equivalents pile up alongside them, from scanned attachments buried in an email archive to a retired laptop in a closet and a drawer of old phones. Every one of those was worth keeping at some point, and safe record keeping is largely about noticing when that stopped being true.

Businesses have the same problem at scale, with regulators watching. Human resources departments hold I-9s, payroll files, benefits enrollments, and background check results, and HR document management has to account for all of it. Medical practices hold charts, imaging, and billing records. Financial firms hold loan files, account applications, and audit trails. A good share of it sits in offsite boxes or a legacy shared drive nobody has inventoried in years, which is exactly where forgotten paperwork turns into exposure.

Identifying and Safeguarding PII

The goal is to make this routine. A one-time cleanup buys you about a year. Four steps, roughly in order.

Take Inventory First

You can’t protect what you haven’t found. Your first step should be taking an inventory of what PII you have.

Walk the physical spaces — filing cabinets, storage rooms, offsite boxes, desk drawers — and then the digital ones, including shared drives, email archives, backup media, and retired hardware.

Write down what’s in each location, roughly how much of it there is, and which risk tier it falls into. For a household, that’s an afternoon. For a business, it’s a project, and one that gets skipped most often.

Set Retention Limits

Keeping everything forever feels like the cautious choice, but it isn’t. Every extra year a document sits in a box is another year it can be stolen, and old files are rarely the ones anyone is watching.

The IRS advises keeping records for three years in most situations, six years if income was underreported by more than 25%, and seven years for a worthless securities or bad debt claim. Employment tax records run at least four years from the date the tax comes due or gets paid, whichever is later. Employers also have to keep each Form I-9 for three years after the hire date or one year after employment ends, whichever comes later.

Industry and state rules layer on top of all that, which is why most organizations end up committing a written retention schedule to paper and following it. Households can run a simpler version — personal records retention usually comes down to tax years, warranty periods, and anything tied to property.

Secure What You Keep

Whatever survives the retention cut needs a better home than a cardboard box. For paper, that means locked storage with controlled access and a record of who pulled what and when. Digitizing the files removes the physical copy from circulation entirely and swaps casual browsing for permissioned search. Where documents have to be shared but not fully exposed, redaction pulls the identifying fields before anyone sees the page. A document management system adds user-level permissions and an audit trail on top, so you can show who opened what, and when. Combining physical, digital, and access controls is what closes the gaps any single measure might leave open.

Destroy the Rest

Recycling bins and household trash are not “disposal.” Federal rules are specific about the difference. Under the FTC’s Disposal Rule, anyone holding consumer report information for a business purpose has to take reasonable measures against unauthorized access at disposal, and the rule names burning, pulverizing, or shredding paper so the information can’t practicably be read or reconstructed. Electronic media has to be destroyed or erased to that same standard.

Hiring the work out is contemplated directly in the rule, which points to due diligence on the disposal company: reviewing its audits, checking references, and requiring certification by a recognized trade association. Secure destruction practices extend to the media people forget about — hard drives, solid-state drives, and backup tapes. That drawer of old phones counts, too.

Compliance Duties for Businesses

Hold other people’s PII in a business capacity and the exposure changes character. A household that loses a file might face fraud and a rough few months. An organization that loses a file faces notification deadlines, regulator questions, and liability on the balance sheet.

Which rules apply depends on what you hold. Health information brings HIPAA, where the most common violations still trace back to unsecured storage and sloppy disposal. Financial institutions answer to the Gramm-Leach-Bliley Act (GLBA) and its Safeguards Rule. Twenty states currently have comprehensive consumer privacy laws in effect, and four more — Louisiana, Oklahoma, Alabama, and Vermont — phase in across 2027 and 2028, most of them carrying data minimization and secure disposal requirements of their own. That tally grows nearly every legislative session, so it’s worth confirming where your state stands rather than assuming last year’s answer still holds.

Questions worth asking any provider that touches your records: 

  • Who has access, and is it logged? 
  • How is material transported and tracked in transit?
  • What certifications does the facility hold, and are they current? 
  • What does the chain of custody look like from pickup through final disposition, and can you get documentation of it afterward?

That last question does a lot of work. i-SIGMA sets the standards behind PRISM Privacy+ certification for information management and NAID AAA certification for destruction, and holding either one means submitting to ongoing unannounced audits as a condition of keeping it. Record Nations is an i-SIGMA member, and we work closely with the association so the providers we connect you with meet those specifications. A provider whose certification standing lapses stops receiving certification-level work through our network. Sorting out identity theft and breach prevention at the vendor level costs considerably less than proving diligence after an incident.

Protect PII With Record Nations

Sorting through a lifetime of paperwork isn’t something most people want to work out alone, and the right answer depends on what you’re holding and which rules attach to it.

Record Nations connects you with local scanning and storage companies matched to your volume, your industry, and the certifications your situation calls for. For material you have to keep but don’t need within arm’s reach, providers in our network offer offsite records storage in licensed facilities with indexed retrieval and access logging. For anything past its retention date, they handle secure destruction and issue documentation on the other end. The full range of services covers the ground in between.

That network reaches well past the biggest metros. Document scanning in Boise, records storage in Madison, and shredding in Knoxville all draw on providers carrying the same certifications, so a smaller market doesn’t mean a thinner bench.

Tell us what you’re working with and we’ll help find competitive quotes from providers who can actually do the job. Fill out our form or give us a call at (866) 385-3706, and we’ll scope it out with you.

Table of Contents