How Long to Keep Medical Records Under HIPAA: Requirements Explained
HIPAA Medical Records Retention
What HIPAA actually requires
HIPAA focuses on protecting patient health information (PHI) rather than setting a universal medical record retention period. It does not tell you how long to keep patient charts. Instead, HIPAA requires you to retain HIPAA compliance documentation—such as policies, procedures, Notices of Privacy Practices, authorizations, training records, risk analyses, breach logs, and business associate agreements—for six years from the date of creation or the date last in effect, whichever is later.
The designated record set
Your patients have a right to access PHI in the “designated record set,” which includes medical and billing records used to make decisions about them. While HIPAA does not impose a specific timeline for keeping those records, destroying them too soon can undermine access rights and conflict with state retention regulations or payer obligations. Align your record keeping policies to ensure you can respond to requests and audits throughout the applicable retention window.
EHRs, logs, and metadata
Electronic systems add context you may need later—audit trails, patient portal messages, e-signatures, and metadata. HIPAA expects safeguards that support security and accountability, so retain such content long enough to meet state law, healthcare audits, and litigation needs, even though HIPAA sets no fixed timeline for EHR data itself.
State Laws Influence
State statutes and licensing board guidelines establish the minimum time you must keep medical records, and they often differ by provider type (hospital vs. physician), patient age (adult vs. minor), and record category (behavioral health, imaging, reproductive health). If multiple rules apply, follow the longest requirement to maintain HIPAA compliance and reduce risk.
State retention regulations also interact with statutes of limitations for malpractice, contract disputes, and billing appeals. Many practices extend retention beyond the bare minimum to ensure records are available for payer reviews, healthcare audits, and potential legal holds.
- Provider type: Hospitals commonly have longer requirements than office-based practices.
- Patient age: Minor records are usually kept until the age of majority plus additional years.
- Specialty rules: Behavioral health, oncology, and obstetrics may require longer retention.
- Payer/program terms: Medicare, Medicaid, and managed care contracts often add their own timelines.
- Board and facility licensing: Follow your state’s licensing board guidelines and facility rules.
Common Retention Periodss
The following ranges reflect common industry practice, not legal mandates. Always verify your state rule, payer contracts, and licensing conditions, then choose the longest applicable period.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
- Adult records (physician practices): Commonly 7 years after the last encounter.
- Adult records (hospitals): Commonly 10 years after discharge.
- Minors: Often until the patient reaches the age of majority plus 5–10 years; many organizations use age 21–25 as a conservative default.
- Deceased patients: Frequently retained for the same period as living adults or for 5–10 years after the date of death.
- Imaging and diagnostics: Reports and images are often kept 5–10 years; some programs (for example, mammography) require longer retention if no subsequent study occurs.
- Laboratory materials: Labs commonly retain test reports and certain materials for 2–10 years, depending on test type and program rules.
- Payer/contract records: Medicare Advantage and some Medicaid managed care contracts often specify 10 years.
- HIPAA documentation (policies, procedures, BAAs, training): 6 years from creation or last effective date.
Medical Records Types
Your retention schedule should clearly define what you keep. Include all PHI that forms part of the designated record set and supports clinical decisions and billing integrity.
- Clinical documentation: histories, exam notes, assessments, care plans, problem lists, medications, allergies, growth charts, and immunizations.
- Diagnostic content: lab reports, pathology reports, imaging studies and interpretations, waveforms, and photographs.
- Authorizations and consents: treatment consents, releases of information, advance directives, and research consents where applicable.
- Communications: referral letters, patient portal messages, secure emails, telehealth notes, and after-visit summaries.
- Billing and claims materials that are part of the designated record set: superbills, coding justifications, and claim attachments.
- Supporting data: device uploads, e-signatures, timestamps, and relevant EHR audit trails.
Purpose of Retention
Thoughtful retention balances patient care, privacy, and operational risk. You keep records to ensure continuity, demonstrate compliance, and protect your organization if questions arise years later.
- Clinical continuity: Prior notes and diagnostics inform safer, more efficient care.
- Regulatory and HIPAA compliance: Retained PHI and documentation support privacy rights and security expectations.
- Healthcare audits and payer reviews: Records substantiate medical necessity and coding.
- Licensing board guidelines and accreditation: Surveyors often request historical records and policies.
- Legal defensibility: Adequate retention supports responses to subpoenas, discovery, and claims.
- Quality improvement and research: Longitudinal data enables outcomes tracking and approved studies.
Recommendations for Providers
Build a defensible retention program
- Inventory all applicable rules: state retention regulations, licensing board guidelines, federal program terms, and payer contracts.
- Set category-specific timelines and triggers (last encounter, discharge date, age of majority, or contract end date).
- Default to the longest requirement that applies to a record type to minimize risk and support HIPAA compliance.
- Address minors explicitly: calculate destruction dates based on your state’s age of majority plus the chosen retention buffer.
- Define what is in the designated record set and ensure your EHR, imaging, and portal systems archive it consistently.
- Implement secure destruction with documented workflows and logs for paper and electronic media.
- Include litigation holds: pause destruction immediately when a dispute, investigation, or audit is reasonably anticipated.
- Manage third parties: ensure business associate agreements specify retention, return, and secure destruction of PHI.
- Train staff annually and audit compliance; adjust policies when laws or contracts change.
- Plan for practice transitions or closure so patients can access records throughout the retention period.
Conclusion
HIPAA sets a six-year requirement for compliance documentation, but state laws and contracts drive how long you keep patient medical records. Build clear record keeping policies, follow the longest applicable rule, and document secure destruction. This approach protects patients, supports audits, and reduces organizational risk.
FAQs.
What is the minimum retention period for medical records under HIPAA?
HIPAA does not impose a universal medical record retention period. It requires you to keep HIPAA compliance documentation—policies, procedures, authorizations, training, risk analyses, breach logs, and business associate agreements—for six years from creation or last effective date. For patient records, follow state retention regulations and payer or program terms, using the longest applicable rule.
How do state laws affect medical record retention?
State laws set the baseline for how long you must keep patient records, often varying by provider type, specialty, and whether the patient is a minor. They also interact with statutes of limitations and licensing board guidelines. When several rules apply, retain records for the longest required period to ensure compliance and audit readiness.
When should medical records for minors be destroyed?
Destroy minor records only after the patient reaches your state’s age of majority and the additional retention buffer has elapsed. Many organizations retain until age 21–25 to cover statutes of limitations and payer lookbacks. Verify your state’s rule and malpractice carrier guidance, and always document destruction.
What types of medical records must be retained?
Retain all PHI that forms the designated record set: clinical notes, diagnostics and images, consents, referrals, patient communications, and billing materials used to make decisions about the patient. Also keep HIPAA documentation for six years, and maintain EHR audit trails and related metadata long enough to meet security, audit, and legal needs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.