
How Long to Retain HIPAA Records? Key Rules
An audit request rarely arrives with a warning. It may ask for a signed authorization, a risk analysis, a training record, or proof that a former employee’s access was removed. That is why the question of how long retain HIPAA records is not just about clearing storage space. It is about being able to produce credible evidence that your practice followed its own compliance process.
For most HIPAA compliance documentation, the federal baseline is six years. But that answer has a critical limitation: HIPAA’s six-year rule does not establish a universal retention period for patient medical records. Small practices need to separate those two record categories, then apply the longer requirement when state law, payer rules, a contract, or litigation demands it.
The HIPAA six-year documentation rule
HIPAA requires covered entities to retain required documentation for six years from the date it was created or the date it was last in effect, whichever is later. This requirement appears in both the HIPAA Privacy Rule and Security Rule.
In practical terms, the six-year period applies to documentation that shows how your practice administers privacy and security. It includes written policies and procedures, required notices, authorizations, workforce training records, complaint documentation, sanctions, access-related records, and evidence of actions taken to comply with HIPAA.
The phrase “last in effect” matters. If your practice updates a security policy in 2026, do not calculate retention from the policy’s original 2022 publication date. Retain the applicable documentation for at least six years after the policy was replaced or ceased being effective. Version history can be just as valuable as the current policy because it demonstrates what rules were in place at a specific point in time.
Records commonly subject to the six-year rule
Your compliance file should preserve the documentation behind daily HIPAA operations. That can include risk assessments and remediation plans, security incident reports, breach investigation files, business associate agreements, employee HIPAA training acknowledgments, access authorization records, privacy notices, patient authorization forms, complaint records, and documentation of workforce sanctions.
Keep evidence, not just a final document. A policy alone does not prove your practice implemented it. If your policy requires annual training, retain the training assignment, completion status, employee acknowledgment, and any follow-up for overdue staff. If your policy requires periodic access reviews, retain the review log and the actions taken when access was changed or terminated.
This is where scattered folders and spreadsheets create avoidable exposure. A practice may know it completed training or removed access, yet still struggle to prove it months later. Centralized, time-stamped documentation makes the compliance process far more defensible.
HIPAA does not set a standard medical-record retention period
A common mistake is assuming that six years applies to every patient chart. It does not. HIPAA governs the retention of HIPAA-required documentation, but it does not prescribe how long physicians, clinics, or other providers must retain medical records.
Medical-record retention is primarily driven by state law. Requirements vary by state, provider type, and patient age. Many states require adult records to be retained for several years after the last treatment date, while records for minors may need to be kept until the patient reaches the age of majority plus an additional period. Certain specialty services can create additional obligations.
Federal programs, payer agreements, malpractice considerations, and accreditation standards may also affect retention. A Medicare or Medicaid participation requirement, for example, may require records to be available for a defined period. Your practice should not rely on HIPAA alone when setting a patient-chart destruction date.
The safest operational rule is straightforward: identify every retention requirement that applies to each record category and retain the record for the longest applicable period. Confirm the schedule with healthcare counsel or a qualified compliance professional who understands your state and practice type.
How long to retain HIPAA records when rules overlap
Retention becomes complicated when a document fits more than one category. A patient authorization is both a HIPAA-required document and part of the patient’s administrative record. A breach file may include incident evidence, patient communications, and legal analysis. An employee access log may support HIPAA security obligations while also being relevant to an employment dispute.
Do not create separate destruction dates without considering the full context. Instead, assign a record owner, classify the record, document the governing retention requirements, and apply the latest required destruction date. This approach prevents a well-intentioned cleanup project from deleting information your practice later needs.
A few examples show why this matters:
A former employee’s HIPAA training acknowledgment should generally remain available for at least six years under HIPAA documentation requirements, even after the employee leaves.
A business associate agreement should be retained for at least six years after it was last effective, not merely six years after it was first signed.
A patient chart may need to be retained longer than six years because state law or a payer contract requires it.
A record connected to an active lawsuit, investigation, audit, or insurance claim should not be destroyed under a routine schedule.
That last point is essential. A legal hold pauses normal destruction. Once your practice reasonably anticipates litigation, receives an investigation request, or becomes aware of a dispute, preserve relevant records until the hold is formally lifted. Routine retention schedules are not a defense for destroying documents that should have been preserved.
Build a retention schedule your team can actually follow
A retention schedule only works if staff can use it without guessing. For a small practice, the goal is not a complex records-management program. The goal is a clear operating standard that identifies what to keep, where it belongs, who owns it, and when it can be securely destroyed.
Start by separating records into practical groups: patient clinical records, HIPAA privacy documentation, HIPAA security documentation, workforce records, vendor and business associate records, financial and payer records, and incident or breach records. For each group, document the retention period, the source of the requirement, the event that starts the retention clock, and the approved disposal method.
Then connect the schedule to real workflows. When onboarding a new employee, capture training and access approvals in the same controlled system. When terminating an employee, document account removal but preserve the termination and access evidence according to the schedule. When a policy is revised, archive the prior version and record its effective end date.
Veri-Hub helps practices bring these recurring compliance records into one organized workspace, so the proof behind training, access management, policy updates, and incidents does not disappear into individual inboxes or disconnected drives.
Set ownership and review dates
Assign one person, often the HIPAA Security Officer, Privacy Officer, or practice administrator, to maintain the retention schedule. That person does not need to personally manage every record. They do need to ensure responsibilities are assigned and that the schedule is reviewed at least annually.
An annual review should check for changes in state law, payer contracts, services offered, software vendors, and internal policies. It should also identify records approaching their destruction date and confirm that no legal hold, audit, complaint, or ongoing investigation requires continued preservation.
Secure disposal is part of compliance
Keeping records too long can create risk as well. The more unnecessary protected health information your practice stores, the more information could be exposed in an incident. Once the retention period ends and no hold applies, dispose of records in a way that makes PHI unreadable and unrecoverable.
For paper, that usually means cross-cut shredding or a documented secure destruction service. For electronic records, deletion must account for shared drives, cloud storage, archived systems, backup media, and retired devices. Simply moving files to a recycle bin is not a defensible disposal process.
Document the destruction event, including the record category, date range, method, approval, and date of disposal. You do not need to retain the destroyed records themselves, but you should retain evidence that the destruction followed your approved policy.
A clear retention process gives your practice control at both ends: records are available when an auditor, payer, patient, or regulator needs them, and they are securely removed when keeping them no longer serves a legal or operational purpose. Start with the six-year HIPAA documentation baseline, verify the longer rules that apply to your patient records, and make the process simple enough that your team can follow it every time.



Comments