As the year closes, many organizations tidy their files. Before anyone shreds or deletes, it helps to know what HIPAA expects you to keep. The rules require covered entities and business associates to maintain written or electronic documentation of policies, procedures and certain actions, and to retain it for six years from the date it was created or the date it was last in effect, whichever is later. This is general information, and your counsel can advise on state requirements.
People often confuse two separate topics.
This is the paperwork that proves you follow the rules. HIPAA specifies a six-year retention period for it.
HIPAA does not set how long a provider must retain medical records. Those periods come from state law, Medicare and Medicaid conditions of participation, licensing rules and your own policies, and they vary by record type and resident status. Check with your state licensing agency and counsel for your requirements.
This article focuses on the first category.
The following records are commonly included in HIPAA documentation requirements.
Privacy, security and breach notification policies, including every version. When a policy is revised, keep the old version too, with the dates it was in effect.
Your security risk analyses, risk management plans and evidence showing how you addressed findings.
All versions of your notice, and records of acknowledgment of receipt where required.
Materials, attendance lists, dates and completion records for workforce training.
Signed agreements and related vendor documentation.
Signed authorizations, requests for access, amendments, restrictions or accounting of disclosures, and your responses.
Incident reports, risk assessments, notification letters, logs of breaches affecting fewer than 500 individuals and records of decisions that an event was not a reportable breach.
Records of disciplinary actions taken for policy violations.
Records naming your privacy officer, security officer and contact person for complaints.
Audit and review records, documentation of maintenance and repairs to physical security components, contingency plan documents and test results, and access authorizations.
Retention is only useful if you can produce records when asked. A simple structure helps:
One main folder for HIPAA compliance, with subfolders for policies, risk analysis, training, vendors, incidents and complaints
Consistent file names that include a date, such as policy name and effective date
A master index listing each document, its owner, its location and the date it can be retired
Restricted access, since many of these records are sensitive themselves
Records should be protected from loss and unauthorized access.
Keep electronic copies on secured, backed-up storage with access controls.
If paper copies are retained, store them in locked cabinets.
Make sure the records survive staff turnover, and do not rely on one person's personal drive or email.
Include documentation in your backup and disaster recovery plan.
When records pass the retention period and no other rule requires keeping them, dispose of them securely: cross-cut shredding or certified destruction for paper, and proper media sanitization for electronic files. Document the disposal, including what was destroyed and when. Never discard anything that may be relevant to a pending investigation, audit or legal matter.
Confirm that this year's risk analysis and management plan are saved.
Collect training records for every workforce member.
Save current versions of all policies with approval dates.
Update your business associate list and signed agreements.
File incident and breach logs for the year.
Back up the compliance folder and test access.
UnityCare IT helps healthcare organizations organize and secure their compliance documentation as part of broader security programs. If you would like help building a retention structure, we are glad to assist.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172