How Long Must HIPAA Compliance Records Be Retained for Providers
HIPAA compliance records must be retained for six years from the date the record was created or the date it was last in effect, whichever is later. That six-year rule applies to compliance documentation: policies, procedures, risk analyses, training records, authorizations, breach documentation, and business associate agreements.
Patient medical records follow a separate rule, and the separation is where most providers go wrong. HIPAA sets no retention period for patient charts or clinical notes. State law does, along with federal program rules like the Medicare Conditions of Participation, and those periods usually run longer than six years.
Every practice therefore runs two retention clocks at once. Below we cover what the six-year rule actually covers, what state law requires for clinical records, where the seven-year belief comes from, which federal programs add their own periods, how to resolve overlapping rules into a single schedule, what changed in 2026, and how to store and destroy records without creating a new problem.
How Long Must HIPAA Compliance Records Be Retained?
HIPAA compliance records must be retained for a minimum of six years from the date of creation or from the date the document was last in effect, whichever date is later. Two sections of the regulations set that standard. The Security Rule states it at 45 CFR 164.316(b)(2)(i), and the Privacy Rule repeats it at 45 CFR 164.530(j)(2). Both apply to covered entities and business associates alike.
The "last in effect" half of that sentence carries more weight than the creation date. A document that sits in force for years does not start its six-year clock on the day it was written. It starts on the day it stopped being current, which means long-standing documents accumulate retention time quietly. That mechanic trips up more practices than the six-year figure itself, and it is worth working into any HIPAA rules refresher your staff receives.
What Is the HIPAA 6-Year Rule for Record Retention?
The HIPAA 6-year rule for record retention is the requirement that documented policies, procedures, and records of actions, activities, and assessments be kept for six years from creation or from the date last in effect. The rule exists so that the Office for Civil Rights can verify compliance after the fact, and so an organization can meet the burden of proof the Breach Notification Rule places on it.
Arithmetic makes the rule concrete. A privacy policy written in 2014 and replaced in 2024 was in effect for ten years, so the original version must be kept until 2030, sixteen years after it was created. A risk analysis performed once and never superseded starts its clock on the date it was completed. A current risk analysis is also the single document the Office for Civil Rights cites most often in enforcement actions, which makes a documented risk assessment both a retention item and a compliance anchor.
What Records Need to Be Kept for 6 Years?
The records that need to be kept for six years are the documents proving compliance rather than the records of patient care. The exact list depends on what an organization does, since a clearinghouse issues no Notice of Privacy Practices and a small practice may hold no subcontractor agreements. The common categories are:
- Privacy, security, and information handling policies and procedures, including every superseded version
- Security risk analyses and risk management plans
- Notices of Privacy Practices and each revision of them
- Patient authorizations for uses and disclosures of PHI
- Workforce training records, completion dates, and attestations
- Employee sanction policies and records of sanctions applied
- Complaint records and documentation of how each complaint was resolved
- Incident and breach notification documentation, including risk assessments of non-notifiable incidents
- Business associate agreements and subcontractor agreements
- Contingency, backup, and disaster recovery plans
- Audit logs and access reports supporting information system activity reviews
- IT security system reviews, including new technologies and procedures put in place
One related obligation sits outside that list and catches practices off guard. Under 45 CFR 164.528, a patient can request an accounting of disclosures covering the six years before the request, which means the underlying disclosure records have to survive that long whether or not they feel like compliance documents.
Are HIPAA Training Records and Audit Logs Included?
Yes, HIPAA training records and audit logs are included in the six-year requirement. Training documentation covers completion records, timestamps, quiz results, the content of the course itself, and any workforce attestations, because all of them evidence a policy that was in effect on a given date.
Audit logs follow the same logic through a different route. The Security Rule requires regular review of information system activity, and that review rests on access reports and audit logs. Since the logs support a documented review, they inherit the six-year clock from the review they informed. Any log, note, or record tied to a HIPAA policy or procedure is retained for six years from the date the content was last used or last effective.
Does HIPAA Set a Retention Period for Patient Medical Records?
No, HIPAA does not set a retention period for patient medical records. There is no federal HIPAA medical record retention period, and state law governs how long patient charts and clinical notes must be kept. HIPAA does not preempt state retention law, so the state period controls for clinical records.
Confusion on this point is widespread enough that some published guidance states, incorrectly, that 45 CFR 164.316 requires six years of retention for all PHI. That section governs Security Rule documentation. A patient chart is not Security Rule documentation, and treating six years as the ceiling for clinical records is how practices destroy charts years before their state allows it.
HIPAA still governs those records in other ways. Patients can access and amend PHI for as long as it is maintained in a designated record set, retained records must be protected to the same standard as active ones, and when the state clock finally runs out, HIPAA dictates how the records are destroyed. Those safeguards sit alongside the day-to-day work of protecting patient data in a live clinical environment.
How Long Do State Laws Require Medical Records to Be Kept?
State laws require medical records to be kept for periods ranging from five years to permanently, with most falling between six and ten years. Periods differ by provider type, by patient age, and by the event that starts the clock, which may be discharge, last professional contact, or the date the record was created. The figures below come from each state's medical practice rules and hospital licensure codes, and they illustrate the spread rather than covering all fifty states.
StatePhysician RecordsHospital RecordsMinor Patient RecordsAlabama7 years from last professional contactAt least 5 years after dischargeLonger of 7 years from last contact or 2 years past age 19Florida5 years from last patient contact7 yearsStandard period appliesNew York6 years from last visit6 years from dischargeAge 21, or 6 years, whichever is longerTexas7 years from last treatment10 years from last treatmentAge 21, or 7 years, whichever is longerNorth Carolina7 years from last service11 years after dischargeUntil age 30Washington10 years from last contact26 years from the date created26 years from the date createdNew MexicoNo specific statutePermanentPermanent
State rules also move. Washington replaced a ten-year hospital standard with a twenty-six-year requirement effective July 27, 2025, which reshaped storage planning for every hospital in the state overnight. Because periods change and vary by record type, confirm your current requirements with your state licensing board or your attorney rather than relying on a general reference.
How Long Do You Have to Keep Medical Records in Alabama?
In Alabama, physicians have to keep patient medical records for at least seven years from the date of last professional contact with the patient, under the Alabama Board of Medical Examiners rule at Ala. Admin. Code 540-X-9-.10. Hospitals licensed in the state work to a separate standard, retaining records for at least five years after discharge under Alabama Department of Public Health licensure requirements.
Minor patients extend both clocks. For records of minors, Alabama physicians retain for the longer of seven years from last professional contact or two years after the patient reaches the age of majority, which the state sets at nineteen. Imaging carries its own periods, with mammograms held for ten years. A practice in Huntsville that follows the federal six-year documentation rule alone would be years short on every one of those categories.
How Long Must Minor Patient Records Be Kept?
Minor patient records must be kept until the patient reaches the age of majority plus an additional period, with thresholds across the states ranging from age eighteen to age twenty-eight. The reasoning is legal rather than clinical. A minor's right to bring a claim generally does not begin running until majority, so the record has to outlast that window.
Thresholds cluster at recognizable points. Colorado, Nebraska, and Pennsylvania require retention to age twenty-eight, with Pennsylvania reaching that figure because it defines majority as twenty-one. Maryland, Michigan, and Mississippi reach age twenty-five. Several states, including the District of Columbia, Idaho, Illinois, Indiana, and Rhode Island, use age twenty-three. Pediatric practices and family medicine offices carry the longest archives in healthcare for this reason.
How Long Must Records of Deceased Patients Be Kept?
Records of deceased patients must be kept for the full state retention period, which does not stop running at death. Texas measures retention from the date of death rather than from last treatment, and other states apply their standard periods without modification.
A separate federal clock governs privacy rather than retention. Under 45 CFR 164.502(f), a covered entity must protect a decedent's PHI for fifty years following death. After that window, the information is no longer treated as protected health information, though any state record that still exists remains subject to its own rules.
What Is the 7 Year Retention Policy?
The 7 year retention policy is a state medical record requirement, not a HIPAA requirement. Articles asserting that HIPAA mandates seven years are confusing the federal documentation rule with the medical record period set by a particular state. Alabama, California, Indiana, Pennsylvania, and Texas are among the states requiring physicians or hospitals to hold records for seven years, which is why the figure circulates so widely.
The federal number never changes with the state. For HIPAA compliance purposes, documentation is always six years from the date a document was created or last in force. A practice operating in a seven-year state runs both: seven years on the charts under state law, six years on the compliance file under federal law, with the clocks starting on different events.
What Records Need to Be Kept for 7 Years?
The records that need to be kept for seven years are patient medical records in states whose law sets that period. In Alabama that covers the physician's full patient record measured from last professional contact. In Texas it covers physician records from last treatment, while hospitals in the same state hold theirs for ten years.
Supporting clinical documentation generally follows the record it belongs to. Charts, clinical notes, diagnostic reports, consent forms filed in the chart, and correspondence about care are retained with the medical record rather than on the federal six-year schedule. A patient authorization is the interesting edge case, because it is subject to the six-year documentation rule and, if it has been filed into the patient's record, to the state medical record period as well. The longer period wins.
How Long Do Records Have to Be Kept Under Other Federal Rules?
Records have to be kept for three, five, six, seven, ten, or thirty years depending on which federal program generated the obligation. Federal retention periods stack on top of HIPAA rather than replacing it, and several of them reach well past six years:
- Medicare Conditions of Participation: participating hospitals retain medical records for at least five years, under 42 CFR 482.24(b)(1).
- Critical access hospitals: six years, under 42 CFR 485.638(c).
- Medicare managed care program providers: ten years, unless a longer state period applies.
- Medicare cost report documentation: at least five years after the cost report closes.
- OSHA employee medical and exposure records: thirty years plus the duration of employment, under 29 CFR 1910.1020.
- CLIA laboratory records: two years minimum, under 42 CFR 493.1105.
- Medicaid records under audit or litigation: held until the action resolves, under 42 CFR 431.17(c).
Employer-side rules add further layers for organizations that sponsor health plans, since the Employee Retirement Income Security Act and the Fair Labor Standards Act carry their own schedules. Those obligations sit beside HIPAA in the same way other compliance regulations do, governing the same filing cabinet from different directions.
Which Retention Period Applies When the Rules Conflict?
When retention rules conflict, the longest applicable period controls for that specific record type. The rules rarely conflict in the way providers assume, because each one governs a different category of information. A six-year federal documentation requirement and a ten-year state medical record requirement are not in conflict at all; they apply to different records and both must be satisfied.
Genuine overlap resolves in HIPAA's favor only in one direction. Where a state requires policy documentation to be kept for five years and HIPAA requires six, the federal six-year floor preempts the shorter state period. HIPAA never shortens a longer state requirement, so a state demanding ten years on clinical records keeps its ten years regardless of what the federal documentation rule says. Working that logic record type by record type is the part of a compliance program that turns a pile of regulations into one usable schedule.
Does Pending Litigation Change the Retention Clock?
Yes, pending litigation changes the retention clock by suspending destruction entirely. Records relevant to an open investigation, audit, or pending or anticipated claim must be preserved until the matter closes, even when the normal retention period has already expired. Illinois states this directly in its hospital record statute, and federal Medicaid regulations require retention until an action resolves.
Destroying records under a legal hold is treated far more seriously than keeping them too long. Routine destruction on schedule is defensible; destruction after a claim surfaces can support a spoliation finding. Statutes of limitation are the quieter version of the same problem, since many run longer than any retention period and a destroyed record cannot defend a practice that did nothing wrong.
What Is the New HIPAA Rule in 2026?
The new HIPAA rule in 2026 is the substance use disorder records rule, which reached its compliance deadline on February 16, 2026 and is now being enforced. That final rule aligns the confidentiality regulations at 42 CFR Part 2 more closely with HIPAA while preserving the protection that substance use disorder records cannot be used against a patient in civil, criminal, administrative, or legislative proceedings without written consent or a court order. Practices had to update their Notices of Privacy Practices to address how that information is used and disclosed, and each version of that notice then falls under the six-year documentation rule.
Two larger rules remain unfinished. A final rule implementing proposed HIPAA Privacy Rule changes has been pencilled in for August 2026 on the federal regulatory agenda. The Security Rule overhaul, published as a proposed rule on January 6, 2025, drew more than 4,700 public comments, missed its original spring 2026 target, and now sits pencilled for July 2027. Neither is enforceable until a final rule publishes, and the current Security Rule remains the law in force.
The proposed Security Rule still matters for retention planning. It would require written documentation of every Security Rule policy, procedure, plan, and analysis, kept current and available for review, making documentation a requirement in its own right rather than evidence of some other requirement. Healthcare providers with sound security practices and thin paperwork would feel that change first, and every new document it created would start its own six-year clock.
How Should Retained Records Be Stored and Protected?
Retained records must be stored and protected to the same standard as active records, with the full set of administrative, physical, and technical safeguards applied for the entire retention period. An archive is not a lower-risk category. A record held for twenty-six years is exposed for twenty-six years, and breach notification obligations attach to old records exactly as they do to current ones.
Four practical issues decide whether an archive holds up. Access control has to narrow over time rather than widen, since few staff need routine access to records from a decade ago. Encryption applies to archived media and backups as well as to live systems, which is one reason file encryption shows up in nearly every HIPAA remediation plan we see. Physical media degrades, and consumer-grade drives can become unreadable within a few years, which quietly converts a retained record into a missing one.
The fourth issue is recoverability. A record that exists but cannot be produced within the thirty days HIPAA allows for a patient access request has failed its purpose, and long-term archives are exactly where retrieval testing gets skipped. Verified backup with periodic restoration testing is the difference between a record you have and a record you can prove you have.
This is where retention stops being a legal question and becomes an operating one. Policies, risk analyses, training records, and audit logs have to be produced on demand years after anyone remembers creating them, and reactive technology support cannot deliver that. We built our managed cybersecurity model around continuous maintenance for that reason, with documentation and evidence kept current rather than assembled when someone asks.
How Should Records Be Destroyed When the Retention Period Ends?
Records must be destroyed so that protected health information is rendered essentially unreadable, indecipherable, and unable to be reconstructed. HIPAA does not mandate a single method, only that result. The Office for Civil Rights recognizes shredding, burning, pulping, or pulverizing for paper, and clearing, purging, or physical destruction by disintegration, pulverization, melting, incineration, or shredding for electronic media.
Two shortcuts fail the standard outright. Strip-cut shredding leaves strips that can be reassembled, so cross-cut or micro-cut shredding is the working minimum for paper. Deleting files or reformatting a drive leaves data recoverable, so electronic media needs overwriting, degaussing, or physical destruction. Business associates face a related obligation at the end of a contract, returning or destroying the PHI they hold rather than retaining it by default.
Outside help does not transfer the obligation, whether the work is destruction or broader compliance support. A destruction vendor that handles PHI is a business associate, and a signed business associate agreement has to be in place before any records change hands. Documentation of what was destroyed, when, by what method, and under whose authority is itself a compliance record, which means it joins the six-year file.
How Do You Build a Retention Schedule That Holds Up?
A retention schedule holds up when it resolves every applicable rule into one controlling period per record type and records the decisions behind it. Build it in this order:
- Inventory your record types separately, splitting compliance documentation from clinical records and noting where a record belongs to both categories.
- Identify every rule that applies to each type, including HIPAA, your state medical board, hospital licensure, Medicare or Medicaid participation, OSHA, CLIA, and any payer contract.
- Assign the longest applicable period to each type, and write down which rule produced it so the figure can be defended later.
- Define the triggering event precisely, since discharge, last professional contact, and date of creation produce different destruction dates for the same chart.
- Set a legal hold procedure that suspends destruction the moment a claim, audit, or investigation becomes known or reasonably anticipated.
- Document each destruction event, retain that documentation for six years, and review the whole schedule annually against current state and federal rules.
Annual review is the step that gets dropped and the one that matters most, because a schedule built on last decade's rules fails quietly. Washington's jump from ten years to twenty-six is the obvious example, and a practice that reviews its schedule only when preparing for a compliance audit will find out late.
Frequently Asked Questions
What Is 45 CFR 164.316?
45 CFR 164.316 is the Security Rule section covering policies, procedures, and documentation. It requires covered entities and business associates to maintain written policies and procedures implementing the Security Rule, document any action, activity, or assessment the rule requires, and retain that documentation for six years from creation or from the date last in effect. The Privacy Rule carries a parallel requirement at 45 CFR 164.530(j)(2).
How Long Do You Keep Business Associate Agreements?
Business associate agreements are kept for six years from the date the agreement was last in effect, not six years from signing. An agreement active for eight years before termination is therefore retained for fourteen years in total. Keeping agreements with subcontractors on the same schedule matters too, since a covered entity can be held responsible for a business associate's violation where it knew or should have known of the pattern.
What Happens If a Provider Destroys Records Too Early?
A provider that destroys records too early faces enforcement exposure and loses the ability to defend itself. If a patient requests access to a record that was destroyed before its period expired, the Office for Civil Rights can penalize the covered entity for failing to provide access, and the practice also loses the documentation it would need in a malpractice or contract dispute. Early destruction after a claim arises can support a spoliation finding on top of the compliance problem.
How Long Are Records Kept When a Practice Closes?
Records are kept for the remainder of the applicable retention period when a practice closes, because closure does not end the obligation. Providers typically transfer records to a successor practice or appoint a custodian to hold them and respond to requests. Several states require advance notice to patients before closure, by direct letter, newspaper publication, or both, so they can obtain copies or arrange a transfer.
How Quickly Must a Provider Respond to a Request for Records?
A provider must act on a request for access no later than thirty calendar days after receiving it, under 45 CFR 164.524. One extension of up to thirty additional days is permitted, but only with written notice of the reason and a completion date given inside the original thirty-day window. Records stored offsite or held by a records vendor do not excuse the deadline.
Does HIPAA or State Law Take Precedence on Retention?
Neither takes precedence across the board, because the two govern different records. HIPAA's six-year rule controls compliance documentation and preempts any state rule requiring a shorter period for those same documents. State law controls patient medical records, and HIPAA does not shorten or override it. The practical answer for any single record is the longest period that applies to it.
The Bottom Line
HIPAA record retention comes down to running two clocks without confusing them. Compliance documentation is kept six years from creation or from the date last in effect, whichever is later, and that federal floor never moves. Patient medical records are kept for whatever period state law and your federal program participation require, which for most practices means seven to ten years and considerably longer for minors. Where periods overlap, the longest one applicable to that record type is the one to follow.
The work that makes a schedule real is unglamorous: a written inventory, one defended period per record type, precise triggering events, a legal hold procedure, archives protected as carefully as live systems, and destruction documented when the time comes. Practices across Huntsville and North Alabama tend to have the policies and miss the proof, which is the same gap we see in manufacturing, finance, and government contracting work.
If you are sorting out what your practice actually has to keep and whether your archives would survive a request, the team at Interweave Technologies is glad to take a look with you. Give us a call at 256.837.2300 and we will walk through where things stand.
.webp)
.webp)



.webp)





Share Post