Record Retention Policy Requirements Under HIPAA and State Law: What to Keep and How Long

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Record Retention Policy Requirements Under HIPAA and State Law: What to Keep and How Long

Kevin Henry

HIPAA

June 19, 2026

8 minutes read
Share this article
Record Retention Policy Requirements Under HIPAA and State Law: What to Keep and How Long

Overview of HIPAA Record Retention Guidelines

What HIPAA does—and does not—require

HIPAA focuses on Patient Health Information Confidentiality and the safeguards around it. It does not set a nationwide timeframe for how long you must keep a patient’s clinical medical record. Instead, HIPAA requires you to retain specific compliance documentation for at least six years from the date it was created or last in effect, whichever is later. This six-year rule applies to both the HIPAA Privacy Rule and Security Rule documentation.

Who must comply

The requirements apply to Covered Entities—health plans, health care clearinghouses, and most health care providers—and to their Business Associates. Your organization’s policy should also recognize other obligations (for example, payor contracts or accreditation standards) that may extend retention beyond HIPAA’s baseline.

Implications for your retention schedule

Because HIPAA defers clinical record retention to other laws, you should anchor your schedule in State-Specific Retention Regulations and overlay any federal program or contractual requirements. Keep HIPAA compliance documents at least six years, and set medical-record timeframes based on state law and operational risk.

State Law Medical Record Retention Periods

Common state patterns

  • Adult records: often 7–10 years from the last encounter or discharge.
  • Minor records: typically until the age of majority plus an additional period (commonly 2–10 years).
  • Hospitals vs. physician practices: hospitals frequently have longer minimums than ambulatory settings.
  • Specialty content: imaging, pathology slides/blocks, and obstetric or surgical records may carry longer retention windows.
  • Immunization histories: many jurisdictions recommend very long or indefinite retention to support lifetime access.

Multi-state operations and conflicts

If you operate in multiple states, adopt the longest applicable retention period for a record category unless operationally necessary to manage state-specific schedules. Document the legal basis for each retention rule and define the event that starts the clock (for example, last treatment date, discharge, or case closure).

When in doubt

Use conservative default periods that reflect common state requirements, then refine them as you validate statutes and board-of-medicine rules. Always pause destruction if litigation, audit, or investigation is reasonably anticipated or active.

Retention of HIPAA Compliance Documentation

Core records to keep at least six years

  • Policies and procedures required by the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, including all prior versions and effective dates.
  • Notices of Privacy Practices and any acknowledgments or distribution records.
  • Risk analyses, risk management plans, and security evaluations.
  • Business Associate Agreements and due-diligence records.
  • Workforce training content, completion logs, and sanctions/disciplinary documentation.
  • Complaints, investigations, and resolutions related to HIPAA.
  • Breach assessments, incident reports, notifications, and mitigation steps.
  • Authorizations, access requests, restrictions, and confidential communication requests.
  • Accounting of disclosures logs and responses.
  • Device and media control logs, backup/restoration tests, and contingency/DR plans.

Practical tips for Compliance Documentation Retention

  • Centralize records in a controlled repository with versioning and immutable audit trails.
  • Index each document with retention codes, trigger events, and legal citations.
  • Encrypt stored documentation and restrict access by role.
  • Automate lifecycle workflows to notify owners when review or disposition is due.

Procedures for Secure Disposal of Medical Records

Pre-destruction controls

  • Verify the retention period has elapsed and no legal hold applies.
  • Obtain documented approval identifying record categories, volumes, and destruction method.
  • Log destruction details to demonstrate Medical Records Disposal diligence.

Destruction methods

  • Paper: cross-cut shredding, pulping, or incineration that renders PHI unreadable and irretrievable.
  • Electronic media: use a recognized standard (e.g., NIST SP 800-88) to clear, purge, or destroy media—cryptographic erasure, secure wipe, shredding, or degaussing. Do not rely on simple file deletion or basic reformatting.
  • Backups: define how long PHI persists in backups and how it will be expired; document exceptions when technical constraints delay media disposal.

Working with vendors

  • Execute a Business Associate Agreement when vendors handle PHI.
  • Use locked consoles, screened staff, and documented chain-of-custody.
  • Obtain certificates of destruction detailing date, method, and material scope.

Throughout disposal activities, apply minimum necessary principles and physical/technical safeguards to protect Patient Health Information Confidentiality.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Handling of Decedent's Health Information under HIPAA

The 50-year rule

PHI remains protected for 50 years after an individual’s death. Your retention schedule should not presume that a patient’s death shortens record-keeping obligations; follow your standard timeframes unless another law requires longer retention.

Access and disclosures

  • Personal representatives: treat a legally authorized personal representative as the decedent for access decisions, subject to applicable limits.
  • Individuals involved in care: you may disclose relevant PHI to family or others involved in care or payment prior to death unless doing so conflicts with known preferences.
  • Coroners, medical examiners, and funeral directors: disclosures are permitted as necessary to carry out their duties.
  • Organ procurement and research on decedents: permissible under HIPAA conditions.

Document identity and authority checks, apply minimum-necessary where required, and record disclosures consistent with your policy on Decedent Health Data Protection.

Establishing an Effective Record Retention Policy

Build your retention schedule

  • Assign ownership (privacy officer, HIM lead, or compliance) and define governance.
  • Inventory record types across clinical, billing, imaging, labs, and administrative sources.
  • Map laws and rules: State-Specific Retention Regulations, federal program rules, contracts, and accreditation standards.
  • Define retention periods, triggers (for example, last encounter), and authorized destruction methods.
  • Integrate legal holds and eDiscovery procedures that override normal destruction.
  • For multi-state entities, either standardize to the longest period or implement location-specific codes.

Operationalize and secure

  • Configure EHR and content systems with retention codes, automated disposition, and audit logs.
  • Encrypt archives, manage keys, and segment high-sensitivity content.
  • Train workforce on policy, emphasizing HIPAA Privacy Rule principles and role-based responsibilities.
  • Align with contingency planning so required records remain available during outages or disasters.
  • Embed vendor oversight and BAA reviews into the lifecycle.

Compliance Monitoring and Auditing

What to monitor

  • Coverage: percentage of record types assigned a retention rule and legal citation.
  • Timeliness: destruction events completed vs. scheduled; backlog trends.
  • Quality: exceptions due to misclassification, retrieval failures, or policy deviations.
  • Security: access anomalies for archived PHI and integrity of disposal chains.

Audit cadence and improvement

  • Perform periodic sampling of retention decisions, legal-hold compliance, and vendor certificates of destruction.
  • Reassess laws and contracts at least annually and after major regulatory changes.
  • Capture findings in corrective action plans and update your policy, training, and systems accordingly.

Conclusion

HIPAA sets a six-year baseline for compliance documentation, while state law drives how long you keep clinical records. Build a clear, defensible schedule; protect PHI throughout its lifecycle; and document every decision from creation to destruction. With disciplined monitoring and auditing, you can meet legal duties, reduce storage risk, and uphold patient trust.

FAQs.

What are the minimum HIPAA record retention requirements?

HIPAA requires you to retain required privacy, security, and breach-notification documentation for at least six years from the date of creation or the date last in effect, whichever is later. This includes policies and procedures, Notices of Privacy Practices, risk analyses, training records, complaints and investigations, Business Associate Agreements, incident and breach files, authorizations, and accounting-of-disclosures logs. HIPAA does not set a nationwide period for retaining clinical medical records.

How do state laws affect medical record retention?

States set the minimum timeframes for keeping medical records, and they vary by setting (hospital vs. clinic), patient type (adult vs. minor), and content (for example, imaging or pathology). Many states require 7–10 years for adults and “age of majority plus” for minors. If you operate in more than one state, apply the longest applicable period or manage location-specific schedules, and always suspend destruction when a legal hold applies.

What documents must be retained for HIPAA compliance?

Retain policies and procedures for the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule; all versions of your Notice of Privacy Practices; risk analyses and risk management plans; workforce training logs and sanctions; complaints and investigation records; Business Associate Agreements and vendor due diligence; breach assessments and notifications; device/media control logs; contingency and disaster recovery plans; authorizations, access requests, restrictions, and accounting-of-disclosures logs. Keep each for at least six years from creation or last effective date.

How should medical records be securely destroyed?

Confirm the retention period has elapsed and no legal hold exists, authorize destruction, and maintain a detailed log. For paper, use cross-cut shredding, pulping, or incineration. For electronic media, follow a recognized standard (such as NIST SP 800-88) to clear, purge, or destroy—cryptographic erasure, secure wipe, shredding, or degaussing—and address backups in your policy. If a vendor performs destruction, ensure a Business Associate Agreement, documented chain-of-custody, and a certificate of destruction.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles