Skip to main content

Lone Star Document Management Solutions

Ready to protect what matters? 

Get in touch with us today.

FACTA

FACTA was enacted to help protect consumers from identity theft and to improve the accuracy of credit reporting. It amended the Fair Credit Reporting Act (FCRA) and grants consumers the right to obtain one free credit report per year from each of the major credit reporting agencies. It also introduced requirements for businesses to properly dispose of consumer information, implement identity theft prevention programs (Red Flags Rule), and provide notifications of data breaches. While the law strengthened federal protections, it also preempted stronger state-level laws in many areas, limiting state power to impose stricter regulations.

HIPAA

HIPAA established national standards to protect individuals’ medical records and other personal health information. The Privacy Rule provides individuals with rights over their health data, including the ability to access and request corrections. The Security Rule mandates that covered entities implement safeguards—technical, physical, and administrative—to protect electronic protected health information (ePHI). HIPAA applies to healthcare providers, health plans, and healthcare clearinghouses, and violations can result in significant civil and criminal penalties. It also governs how information is shared for treatment, payment, and healthcare operations.

Privacy Act of 1974​

The Privacy Act of 1974 limits how federal agencies collect, use, and share personal information stored in systems of records. It gives individuals the right to access records about themselves, request amendments, and be protected from unauthorized disclosure. Each agency must publish notices of its systems of records and how the data is used in the Federal Register. The Act includes provisions for enforcement and legal recourse if rights are violated. Agencies such as the FTC use the Act to manage employee files, consumer complaint data, and other personally identifiable information (PII).

Sarbanes-Oxley Act​

The Sarbanes-Oxley Act was passed in response to major corporate scandals (e.g., Enron, WorldCom) to restore investor confidence. It requires public companies to improve financial transparency, accuracy in reporting, and internal controls. Key provisions include mandatory CEO/CFO certification of financial statements, auditor independence, stricter penalties for fraud, and the creation of the Public Company Accounting Oversight Board (PCAOB). While originally aimed at publicly traded companies, many private and nonprofit organizations have adopted SOX-compliant practices to strengthen governance and accountability.

Patriot Act​

The USA Patriot Act, passed after 9/11, expanded government surveillance and placed new compliance requirements on businesses—particularly in preventing terrorism and financial crimes. One provision, along with laws like the Gramm-Leach-Bliley Act and FACTA, mandates that businesses protect sensitive data and securely destroy documents containing personal or financial information. Improper disposal, like placing intact records in public trash, can lead to identity theft and legal liability. Partnering with certified document destruction services like Lone Star Shredding helps ensure compliance with these regulations and protects businesses from litigation.

Gramm-Leach-Bailey Act

The Financial Modernization Act of 1999, also known as the “Gramm-Leach-Bliley Act” or GLB Act, includes provisions to protect consumers’ personal financial information held by financial institutions. There are three principal parts to the privacy requirements the Financial Privacy Rule, Safeguards Rule and pretexting provisions.

The GLB Act gives authority to eight federal agencies and the states to administer and enforce the Financial Privacy Rule and the Safeguards Rule. These regulations apply to “financial institutions”, including companies providing other types of financial products and services to consumers.