What Evidence to Keep for Six Years to Prove HIPAA Compliance

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

What Evidence to Keep for Six Years to Prove HIPAA Compliance

Kevin Henry

HIPAA

June 08, 2026

7 minutes read
Share this article
What Evidence to Keep for Six Years to Prove HIPAA Compliance

You need clear, retrievable evidence to demonstrate HIPAA compliance over time. This guide explains precisely what to retain for six years, how to organize HIPAA compliance documentation, and the proof auditors expect to see.

HIPAA Record Retention Requirements

HIPAA requires you to keep all required documentation for six years from the date it was created or last in effect. This applies to the Privacy, Security, and Breach Notification Rules and covers both covered entities and business associates.

What counts as “documentation”

  • Policies and procedures (current and superseded versions) and related approvals.
  • Workforce training records, acknowledgments, and sanctions.
  • Risk analyses, risk management plans, reports, and remediation evidence.
  • Patient authorization forms, notices, requests, denials, and accounting of disclosures.
  • Business associate agreements and vendor due diligence artifacts.
  • Breach notification records, incident investigations, and audit logs.
  • Complaint and resolution logs, contingency and testing records.

The six‑year clock and acceptable formats

  • Retain each item for six years after creation or the last date it was in effect, whichever is later.
  • Paper or electronic formats are acceptable if records are complete, readable, and readily producible.
  • Protect integrity and access (e.g., write‑once storage, audit trails, and documented retrieval procedures).

Practical retention controls

  • Use privacy policies version control with clear effective and superseded dates.
  • Maintain a centralized index of HIPAA compliance documentation and owners.
  • Apply a written retention schedule and automated alerts for review and archival.

Policies and Procedures Documentation

Your written policies prove intent; your version history proves consistent execution. Keep everything needed to show what was required, when, and by whom.

What to retain

  • All privacy and security policies and procedures with version numbers and effective dates.
  • Change logs showing edits, rationale, approvers, and implementation dates.
  • Publication evidence: where policies live, who can access them, and when they were communicated.
  • Related tools and forms (templates, checklists, standard operating procedures).

How to evidence adoption

  • Leadership approvals and attestations acknowledging responsibility.
  • Distribution records and employee attestations that policies were read.
  • Mappings between policies and applicable HIPAA requirements to show coverage.

Organization tips

  • Implement privacy policies version control with immutable archives of superseded versions.
  • Use consistent naming: title, version, effective date, owner, next review date.
  • Restrict edit rights; retain read‑only copies for audit readiness.

Training Records and Workforce Compliance

Training demonstrates that your workforce knows how to apply policies. Retain comprehensive workforce training records to prove completion, competency, and accountability.

What to retain

  • Curricula, modules, slide decks, and learning objectives in effect at the time.
  • Attendance logs, completion certificates, quiz scores, and time‑stamped attestations.
  • Role‑based training (e.g., clinicians, billing, IT, privacy and security officers).
  • Sanctions logs tied to policy violations and corrective actions taken.
  • Ongoing awareness items (security reminders, phishing exercises, posters, emails).

Lifecycle checkpoints

  • Onboarding: initial HIPAA and security orientation with signed acknowledgments.
  • Periodic: annual refreshers and ad hoc updates when policies change.
  • Transitions: documentation of re‑training upon role changes or technology rollouts.
  • Separation: attestations on data return/destruction and access termination proof.

Risk Assessments and Mitigation Plans

Risk analysis and risk management plans are cornerstone evidence for the Security Rule. Retain artifacts that show how you identified, prioritized, and reduced risk over time.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

What to retain

  • Formal security risk analyses, scope definitions, data‑flow diagrams, and asset inventories.
  • Vulnerability scans, penetration tests, configuration baselines, and encryption status reports.
  • Risk registers with likelihood/impact, owners, target dates, and residual‑risk decisions.
  • Change management, patch logs, and evidence of technical safeguards implementation.

Proof of remediation

  • Tickets, before/after screenshots, and validation results for closed gaps.
  • Leadership sign‑offs for risk acceptance with documented justifications.
  • Third‑party assessments and follow‑up actions tracked to completion.

Contingency and resilience

  • Contingency plans, backup schedules, restore tests, and disaster recovery exercises.
  • Downtime procedures, communication plans, and post‑exercise after‑action reports.

Authorizations and Disclosures Documentation

Keep patient authorization forms and all records that demonstrate lawful uses and disclosures of PHI, plus how you honored individuals’ rights.

What to retain

  • Signed authorizations and revocations, scopes of PHI, expiration terms, and identity verification.
  • Notice of Privacy Practices versions and acknowledgment or good‑faith attempt documentation.
  • Requests for access, amendments, restrictions, and confidential communications, including responses.
  • Accounting of disclosures logs for disclosures that require accounting.
  • Research approvals or waivers, subpoenas/court orders, and minimum‑necessary determinations.
  • Data use agreements for limited data sets and related disclosure records.

Accounting of disclosures essentials

  • Record who received PHI, dates, description of PHI, purpose/legal basis, and responsible staff.
  • Track method of disclosure (mail, portal, secure email) and verification steps taken.

Business Associate Agreements Management

Business associate agreements define responsibilities for safeguarding PHI. Keep complete contractual and oversight evidence for the entire vendor lifecycle.

What to retain

  • Executed business associate agreements, amendments, and renewal histories.
  • Statements of work, service descriptions, and PHI data‑flow summaries.
  • Subcontractor disclosures and confirmation of downstream BAAs where applicable.
  • Breach notification obligations, timelines, and contact protocols established in the contract.

Due diligence and monitoring

  • Security questionnaires, risk ratings, and remediation commitments.
  • Evidence of periodic reviews, meeting notes, and issue trackers.
  • Termination letters, return/secure destruction certificates, and offboarding confirmations.

Breach Notification and Audit Logs

Retain breach notification records and audit trails that show ongoing monitoring and timely incident response—even when an event is ultimately deemed not a breach.

Breach file contents

  • Incident description, timeline, systems and PHI involved, and containment steps.
  • Four‑factor risk assessment, determination memo, and legal/privacy review.
  • Copies of individual notices, media notices (if required), and notices to authorities.
  • Mailing lists, proof of delivery or substitute notice, and final closure summaries.
  • Corrective actions, root cause analysis, and lessons learned.

Audit and monitoring records

  • EHR and system access logs, “break‑glass” events, export/print/download activity.
  • Authentication, privilege changes, and terminated‑user access revocation logs.
  • Security alerts, DLP/SIEM records, endpoint encryption status, and backup/restore logs.
  • Documented periodic audit reviews and follow‑up actions.

In summary

Build a centralized, indexed repository; preserve current and superseded versions; and keep complete, tamper‑evident records for six years. Focus on policies, workforce training, risk management, authorizations and disclosures, BAAs, and robust incident and audit logging.

FAQs.

What specific documents must be retained for six years under HIPAA?

Keep all HIPAA compliance documentation: policies and procedures (with version history); workforce training records and sanctions; risk analyses and risk management plans; patient authorization forms, NPP versions, requests and responses, and accounting of disclosures; executed business associate agreements and vendor due diligence; breach notification records and full incident files; complaint logs; contingency plans and test results; and system audit logs that evidence monitoring.

How should breach notification records be maintained for compliance?

Maintain a complete, time‑stamped breach file for each event: incident narrative, scope of PHI, containment steps, four‑factor risk assessment and determination, approval trail, copies of all notices, mailing or substitute‑notice proof, hotline scripts/FAQs used, reports to authorities if required, and corrective actions. Store files in an access‑controlled, immutable repository with clear indexing and a six‑year retention timer.

Are there federal requirements for medical record retention under HIPAA?

HIPAA does not set a general retention period for medical records themselves. Its six‑year rule applies to documentation required by the HIPAA Privacy, Security, and Breach Notification Rules. Retention of clinical records is driven by state law, payer contracts, and other federal program rules outside HIPAA.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles