Cybersecurity: 24/7/365

Blog

HIPAA Record Retention: How Long to Keep Records
by 4MEDNET Team
May 5, 2026
HIPAA Compliance

A practice manager clearing out a storage unit calls to ask a simple question: the charts down here are eleven years old, can we shred them?

The answer she has usually been given is "HIPAA says six years." That answer is wrong, and it is wrong in the direction that gets practices sued.

HIPAA's six-year rule is real. It just does not apply to medical records.

What the HIPAA 6-year rule actually covers

Ask what the rule requires and you get two different answers depending on which records you mean. Start with the documentation side, because that is where the six years comes from.

The HIPAA Privacy Rule does require covered entities to retain HIPAA compliance documentation for six years from the date it was created, or from the date it was last in effect — whichever is later. Those records must be produced on request, so records retention is not a filing preference.

That means the paperwork proving you run a compliance program:

  • Written policies and procedures, including superseded versions
  • Your Notice of Privacy Practices, every revision of it
  • Business associate agreements, including expired ones
  • Risk analyses and risk management plans
  • Staff training records and signed acknowledgements
  • Breach investigations, notifications, and the reasoning behind them
  • Patient authorizations, access requests, complaints, and how you resolved them
  • Sanctions applied to workforce members

Note the "last in effect" half. A policy you used for nine years and retired in 2024 must be kept until 2030 — six years past retirement, not six years past creation. Practices that purge on a creation-date clock throw away documents they still need.

HIPAA does not set a medical record retention period

This is the part that surprises people. Nothing in HIPAA tells you how long medical records must be kept. HHS says so directly in its own guidance: HIPAA does not include medical record retention requirements.

Patient records are governed by state law, and the periods vary widely. Some states set six years from last treatment. Others use seven or ten. Several tie the clock to the patient rather than the chart.

So how long you retain medical records is decided elsewhere. Three rules settle how long health records stay in your custody:

  • State medical record retention law — the primary answer, and it differs by state and sometimes by provider type
  • Minors — most states extend retention until some years past the age of majority, so a paediatric chart can need keeping for two decades
  • Payer and program rules — Medicare requires providers to retain records for five years, and managed care arrangements commonly require ten

None of these require covered entities to keep everything forever, and several set a floor rather than a ceiling. Malpractice exposure sits on top of all of it. Your professional liability carrier may want records held past the statutory minimum, because a destroyed chart is an indefensible claim. Ask them in writing.

Practical rule: find your state's period, compare it to the payer requirements you are bound by, and retain for the longest one. Never the shortest.

Is there a new HIPAA rule this year?

Not one that is in effect. The proposed Security Rule overhaul published in January 2025 is still a proposal, and the current Unified Agenda puts the final rule around July 2027 — a date that has already slipped once.

It matters for retention because the proposal would add documentation duties, including a written asset inventory and network map reviewed annually. Those become records you must keep. Our summary of the proposed Security Rule changes covers what is coming and what is still speculative.

Do not restructure your retention policies around a rule that has not been finalised. Do make sure the documentation you already produce is being kept for the full six years.

Paper records, electronic records, and the ones people forget

The retention period is the same regardless of format. What changes is how easy each one is to lose track of.

Paper records are the visible problem — the storage unit, the basement, the boxes behind the break room. They are also the easiest to inventory, because you can see them.

Electronic records are the harder case. Protected health information accumulates in places nobody lists: the old practice management system nobody logs into but nobody decommissioned, backup tapes in a drawer, an archived mailbox, the scanner's hard drive, the copier's hard drive. If a system holds patient information, it is inside your retention obligation and inside your risk analysis — see our risk assessment checklist for how to capture it.

Departing vendors deserve a specific mention. When you switch EHRs, the old vendor's copy of your data is governed by your business associate agreement, which should say what happens to it at termination. Our BAA guide covers the return-or-destroy clause most practices never read.

Record destruction: doing it so it counts

Keeping records too long is a risk of its own. Every chart you hold past its required period is a chart that can be breached, and there is no compliance benefit to holding it.

HIPAA requires that protected health information be rendered unreadable and unable to be reconstructed. In practice:

  • Paper: cross-cut shredding, pulping, or incineration. Not the recycling bin, and not an intact dumpster.
  • Electronic media: secure wiping to a recognised standard, degaussing, or physical destruction of the drive.
  • Devices leaving the building: copiers, scanners, and multifunction printers store images internally. Wipe or remove those drives before the lease ends.

Use a vendor that issues a certificate of destruction, and keep those certificates — they are themselves compliance documentation subject to the six-year rule. A shredding company handling PHI is a business associate and needs an agreement in place.

The failure mode here is well documented. Improper disposal, from charts in an open dumpster to unwiped devices, has produced repeated enforcement actions, and HIPAA penalties run from $145 to $2.19 million per violation.

Write a retention schedule

One page, reviewed annually. For each record type, list the retention period, the legal source, where it lives, who owns it, and how it gets destroyed. A written records retention schedule is what turns scattered practice into something you can show an auditor.

Start with the categories: medical records, HIPAA compliance documentation, billing records, employment files, and business associate agreements. They have different clocks and different owners, and conflating them is how practices end up either shredding too early or paying to store boxes for thirty years.

Then set a date each year to actually run it. A retention policy nobody executes produces the same outcome as no policy — with the added problem that you documented the standard you failed to meet. An auditor will ask for both the schedule and the evidence you followed it, which is exactly the ground our OCR audit preparation guide covers.

Back to the storage unit

Retention has a mirror image worth reading next: while records are in your custody, patients can ask for them. Our guide to the HIPAA right of access covers that obligation, and records from a substance use disorder programme carry extra restrictions under 42 CFR Part 2.

Eleven-year-old charts might be destroyable. It depends on your state's period, whether any of those patients were minors, what your payer contracts require, and what your malpractice carrier advises.

Look up those four answers before anything goes in the shredder. "HIPAA says six years" is the one answer you can be sure is wrong.

Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.

Tags:
Share:
HIPAACybersecurityManaged ITRansomwareComplianceEHRData BreachAI AutomationBackup & DR
4MEDNET
Contact Us
Ready to secure your practice?
Schedule a free IT assessment today
Book Your Free IT Assessment