Six-Year HIPAA Documentation Index Checklist for Closing a Medical Practice

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Six-Year HIPAA Documentation Index Checklist for Closing a Medical Practice

Kevin Henry

HIPAA

August 15, 2026

7 minutes read
Share this article
Six-Year HIPAA Documentation Index Checklist for Closing a Medical Practice

Six-Year HIPAA Documentation Retention Requirements

Your documentation retention policy must preserve required HIPAA records for six years from the date each item was created or last in effect, whichever is later. This six-year window applies to both covered entities and business associates and includes documentation required by the HIPAA privacy rule and the HIPAA security rule.

HIPAA’s six-year rule governs compliance documentation, not the clinical medical record itself. State law and payer contracts often set longer timelines for patient charts; align your medical record closure procedures with those requirements while still keeping HIPAA documentation for the full six years.

Index checklist

  • All HIPAA policies and procedures (privacy and security), including version history and approvals.
  • Risk analyses, risk management plans, and security evaluations.
  • Workforce training materials, schedules, and completion attestations.
  • Sanctions, complaints, investigations, and resolutions.
  • Breach and security incident logs, risk assessments, and notifications.
  • Notices of Privacy Practices (all versions), distribution/acknowledgment records.
  • Business Associate Agreements and amendments, plus PHI disposition confirmations.
  • Authorizations, access/amendment requests, and accounting of disclosures.

How to index each item

  • Document title and description.
  • Owner/custodian and contact method during and after closure.
  • Effective date, last revision date, and sunset/retention end date.
  • Repository/location (e.g., secure drive, archive box ID, vault).
  • Access controls (who may retrieve, how, and under what approvals).

Documentation for Closing a Medical Practice

Closing a practice concentrates risk. Use a written, dated closure plan that lists each compliance task, the owner, and the storage location for resulting records. Embed business associate compliance checks and protected health information safeguards into every step.

Closure documentation checklist

  • Closure plan and timeline with designated privacy and security officers for the wind-down period.
  • Inventory of all repositories containing PHI (EHR, email, backups, paper, imaging, third-party apps).
  • Medical record closure procedures: patient notifications, record custodian selection, and access methods post-closure.
  • Change-management log for decommissioning systems and revoking user access.
  • Chain-of-custody logs for records transferred to a custodian or storage vendor.
  • Certificates of destruction for media and files that are lawfully disposed.
  • Vendor offboarding records, including BAA termination letters and PHI return/destroy attestations.
  • Communication templates used for patients, payers, and partners regarding the closure.
  • Forwarding contact details and request-handling procedures for the six-year documentation window.

Index pro tips

  • Assign a single index ID to each document set (e.g., “SEC-RA-2026-01” for risk analysis).
  • Record specific retention end dates to avoid premature deletion.
  • Store a master index in two secure locations with read-only permissions.

Privacy Policies and Procedures

Maintain complete, approved privacy policies and procedures that match your actual workflows and reflect the HIPAA privacy rule. Retain every version and the effective dates so you can demonstrate what was in force at any point before and after closure.

Privacy documentation checklist

  • Uses and disclosures of PHI, including minimum necessary standards.
  • Authorizations, revocations, and verification of identity.
  • Patient rights: access, amendment, and accounting of disclosures.
  • Restriction and confidential communication requests.
  • Complaint intake, investigation, and resolution procedures.
  • Workforce sanctions and mitigation steps.

Index fields to capture

  • Policy title, code, and scope (who/what it covers).
  • Approver, effective date, and superseded date.
  • Linked forms/templates and where they are stored.
  • Cross-references to related security policies and training modules.

Security Policies and Safeguards

Preserve the documents that prove you implemented administrative, physical, and technical safeguards under the HIPAA security rule. Closing a practice requires extra care to secure ePHI during decommissioning, archival, and destruction.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Security documentation checklist

  • Risk analysis and risk management plan, plus periodic security evaluations.
  • Access management: role definitions, provisioning/deprovisioning, and termination checklists.
  • Authentication, encryption, and key management records.
  • Audit controls: system logs retention, review procedures, and sampling evidence.
  • Integrity controls and change management documentation.
  • Transmission security settings and secure messaging configurations.
  • Contingency planning: data backups, disaster recovery tests, and restoration logs.
  • Device and media controls, including inventory and destruction attestations.

Decommissioning focus areas

  • Document final backups, storage media identifiers, and retrieval procedures.
  • Record steps to disable integrations and API connections that exchange PHI.
  • Capture evidence that residual data on retired systems was sanitized or destroyed.

Notices of Privacy Practices Retention

Keep every Notice of Privacy Practices (NPP) version, the dates it was in effect, and how it was distributed. Retain acknowledgments or good-faith efforts to obtain them, along with evidence of posting (e.g., office signage and website postings while active).

NPP index checklist

  • All NPP versions with effective dates and revision reasons.
  • Distribution logs and acknowledgment records.
  • Public posting evidence and the date postings were removed at closure.
  • Contact information listed in the NPP and how patients can still reach the custodian.

Business Associate Agreements Management

Compile a complete file of Business Associate Agreements to demonstrate business associate compliance. At closure, document each vendor’s PHI disposition and the termination or transition of services.

BAA management checklist

  • Executed BAAs and all amendments, plus services descriptions.
  • Points of contact, allowed uses/disclosures, and PHI categories involved.
  • Termination notices and attestations of PHI return or destruction.
  • Certificates of destruction or return receipts, where applicable.
  • Security questionnaires, due diligence notes, and incident history.

Index fields to capture

  • Vendor name, services, and data flows touching protected health information.
  • Agreement dates, renewal/termination dates, and retention end date.
  • Repository location and retrieval instructions for audits or patient requests.

HIPAA Training and Breach Notification Records

Training and incident records prove ongoing compliance. Preserve the curriculum, attendance logs, and attestations for all workforce members. For incidents, maintain a complete file from initial report through risk assessment and any notifications required by breach notification requirements.

Training records checklist

  • Annual and role-based training content, schedules, and delivery method.
  • Attendance logs, test results, and signed attestations.
  • Remediation steps for failed assessments and related sanctions.

Incident and breach documentation checklist

  • Incident reports, investigation notes, and risk assessment outcomes.
  • Decision rationale on whether notification was required.
  • Copies of all notifications (individuals, regulators, and media if applicable).
  • Mailing/email proofs, call logs, and FAQs used for patient inquiries.
  • Corrective action plans and lessons learned.

Summary: Build and maintain a master index, map each HIPAA record to a secure repository, and assign clear retention end dates. With disciplined indexing and documented handoffs, you can close the practice confidently while meeting the six-year HIPAA documentation requirement.

FAQs.

What HIPAA documents must be retained when closing a medical practice?

Retain all required HIPAA documentation: privacy and security policies and procedures (with versions), risk analyses and management plans, workforce training and sanctions records, complaints and resolutions, Notices of Privacy Practices and acknowledgments, Business Associate Agreements and PHI disposition attestations, incident and breach files, plus patient rights records (authorizations, access/amendment requests, and accounting of disclosures).

How long must HIPAA documentation be retained after practice closure?

Keep HIPAA documentation for six years from the date each document was created or last effective, whichever is later. This six-year retention period applies even after the practice has closed, so maintain secure access to the index and repositories throughout that timeframe.

Which records are essential for HIPAA compliance upon medical practice closure?

Essential records include the closure plan and master index, all versions of privacy and security policies, risk assessments, training logs, sanctions and complaint files, BAAs with termination and PHI disposition records, NPP versions and distribution logs, incident/breach documentation, and patient rights activity logs. These demonstrate adherence to the HIPAA privacy rule and HIPAA security rule during and after the wind-down.

How should breach notification records be handled in closing procedures?

Preserve a complete incident file: initial report, investigation notes, risk assessment, decision rationale, and copies of all notifications with proof of delivery. Store these alongside corrective actions and timelines, and ensure they remain retrievable for the full six-year period consistent with your documentation retention policy.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles