HIPAA Documentation Retention: Which Records to Keep and for How Long

As the year closes, many organizations tidy their files. Before anyone shreds or deletes, it helps to know what HIPAA expects you to keep. The rules require covered entities and business associates to maintain written or electronic documentation of policies, procedures and certain actions, and to retain it for six years from the date it was created or the date it was last in effect, whichever is later. This is general information, and your counsel can advise on state requirements.

Two different retention questions

People often confuse two separate topics.

HIPAA compliance documentation

This is the paperwork that proves you follow the rules. HIPAA specifies a six-year retention period for it.

Medical records

HIPAA does not set how long a provider must retain medical records. Those periods come from state law, Medicare and Medicaid conditions of participation, licensing rules and your own policies, and they vary by record type and resident status. Check with your state licensing agency and counsel for your requirements.

This article focuses on the first category.

What to keep for six years

The following records are commonly included in HIPAA documentation requirements.

Policies and procedures

Privacy, security and breach notification policies, including every version. When a policy is revised, keep the old version too, with the dates it was in effect.

Risk analysis and risk management records

Your security risk analyses, risk management plans and evidence showing how you addressed findings.

Notice of Privacy Practices

All versions of your notice, and records of acknowledgment of receipt where required.

Training records

Materials, attendance lists, dates and completion records for workforce training.

Business associate agreements

Signed agreements and related vendor documentation.

Authorizations and resident requests

Signed authorizations, requests for access, amendments, restrictions or accounting of disclosures, and your responses.

Breach and incident documentation

Incident reports, risk assessments, notification letters, logs of breaches affecting fewer than 500 individuals and records of decisions that an event was not a reportable breach.

Sanction documentation

Records of disciplinary actions taken for policy violations.

Designations

Records naming your privacy officer, security officer and contact person for complaints.

Security records

Audit and review records, documentation of maintenance and repairs to physical security components, contingency plan documents and test results, and access authorizations.

Organize so you can find it

Retention is only useful if you can produce records when asked. A simple structure helps:

One main folder for HIPAA compliance, with subfolders for policies, risk analysis, training, vendors, incidents and complaints

Consistent file names that include a date, such as policy name and effective date

A master index listing each document, its owner, its location and the date it can be retired

Restricted access, since many of these records are sensitive themselves

Store it safely

Records should be protected from loss and unauthorized access.

Keep electronic copies on secured, backed-up storage with access controls.

If paper copies are retained, store them in locked cabinets.

Make sure the records survive staff turnover, and do not rely on one person's personal drive or email.

Include documentation in your backup and disaster recovery plan.

Disposal

When records pass the retention period and no other rule requires keeping them, dispose of them securely: cross-cut shredding or certified destruction for paper, and proper media sanitization for electronic files. Document the disposal, including what was destroyed and when. Never discard anything that may be relevant to a pending investigation, audit or legal matter.

A year-end checklist

Confirm that this year's risk analysis and management plan are saved.

Collect training records for every workforce member.

Save current versions of all policies with approval dates.

Update your business associate list and signed agreements.

File incident and breach logs for the year.

Back up the compliance folder and test access.

Getting help

UnityCare IT helps healthcare organizations organize and secure their compliance documentation as part of broader security programs. If you would like help building a retention structure, we are glad to assist.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172