Debt collection agencies record a high volume of calls for debt collection purposes, but these recordings often contain personally identifiable information (PII), personal health information (PHI), and payment card information (PCI), all of which must be securely protected and retained to prevent exposure and ensure compliance.
This checklist outlines steps and processes for debt collection agencies to adhere to laws such as the Gramm-Leach-Bliley Act (GLBA), Payment Card Industry Data Security Standards (PCI-DSS), the Fair Debt Collection Practices Act (FDCPA) Regulation F, and Health Insurance Portability and Accountability Act (HIPAA) for medical debt.
By following this checklist, debt collection agencies can effectively safeguard sensitive information across call recordings, whether it is stored or shared, through key practices outlined in the following sections: