The Filing Cabinet That Cost a Hospital $2.3 Million

In 2018, Cottage Health in California settled with the Office for Civil Rights (OCR) for $3 million after repeated failures in security management — including poor documentation practices that made it impossible to prove policies had ever been followed. I've seen variations of this scenario play out at organizations of every size. They assumed keeping medical charts was enough. They were wrong.

A solid HIPAA retention policy isn't just about storing patient records. It governs how long you keep policies, risk assessments, training logs, business associate agreements, and every scrap of documentation that proves your compliance. Most organizations I work with don't realize how many categories of records HIPAA actually requires them to retain — or that the retention clock doesn't always start when you think it does.

This post breaks down exactly what a HIPAA retention policy must cover, how long each type of record needs to stay on file, and the mistakes I see organizations make that turn routine audits into enforcement actions.

What a HIPAA Retention Policy Actually Covers

Here's where most covered entities stumble: they conflate medical records retention with HIPAA documentation retention. These are two entirely different things.

HIPAA itself — specifically the Privacy Rule at 45 CFR Part 164, Subpart E — requires covered entities and business associates to retain certain administrative documentation for six years from the date it was created, or six years from the date it was last in effect, whichever is later. This includes:

  • Privacy policies and procedures
  • Security policies and procedures
  • Risk assessments and risk management plans
  • Workforce training records
  • Business associate agreements (BAAs)
  • Notices of privacy practices
  • Breach notification documentation
  • Complaint logs and disposition records
  • Authorizations for use and disclosure of PHI
  • Accounting of disclosures

That six-year window is the HIPAA floor. State law often extends it further. And medical records? HIPAA doesn't set a specific retention period for them at all. That's governed by state law, which varies wildly from five years in some states to thirty years — or permanently — in others.

The Six-Year Rule: When the Clock Actually Starts

Creation Date vs. Last-in-Effect Date

This distinction trips up more compliance officers than I can count. If your organization writes a breach notification policy in 2020 and retires it in 2024 after adopting a new version, you must keep that old policy until 2030 — six years from when it was last in effect, not from when it was created.

The same logic applies to BAAs. If you terminate a business associate relationship in March 2026, you hold onto that agreement until at least March 2032. Tossing it because the relationship ended is one of the fastest ways to fail an OCR investigation.

Training Records Deserve Special Attention

Every workforce member who handles PHI or ePHI must receive HIPAA training, and you must document it. If OCR comes knocking after a breach, the first thing investigators ask for is proof that your staff completed training — and when they completed it. Our HIPAA Introduction Training 2026 course generates completion certificates your organization can archive for exactly this purpose.

Retain those records for six years. If someone leaves the organization, keep their training documentation anyway. OCR doesn't care that they left. They care that training happened while the person had access.

What About Medical Records? HIPAA Doesn't Say What You Think

I get this question constantly: "How long does HIPAA require us to keep patient records?" The answer surprises people. HIPAA's retention requirements apply to administrative and compliance documentation, not to medical records themselves.

Medical records retention is governed by state law, and sometimes by CMS Conditions of Participation for Medicare/Medicaid providers. Most states require five to ten years from the date of last treatment, with pediatric records often extending to a set number of years past the age of majority.

Texas, for example, layers additional requirements through the Texas Medical Records Privacy Act (HB 300), which imposes stricter standards on how organizations handle health information beyond federal HIPAA minimums. If your organization operates in Texas, our Texas Medical Records Privacy Act (HB 300) Training walks through those state-specific obligations in detail.

The safe move? Apply your state's medical records retention period and HIPAA's six-year administrative retention period, then follow whichever is longer for records that overlap both categories.

The $1.5 Million Mistake: Poor Documentation During an OCR Investigation

In 2017, Memorial Healthcare System agreed to a $5.5 million settlement with OCR after employees accessed the ePHI of over 115,000 individuals without authorization. One of OCR's findings? The organization couldn't produce adequate documentation of its access control policies and monitoring procedures.

This is what a missing HIPAA retention policy leads to. When an investigator asks for your 2019 risk assessment, your 2021 BAA amendments, or your 2023 training logs, "we didn't keep those" is an answer that opens your organization to maximum penalties.

How to Build a HIPAA Retention Policy That Actually Works

Step 1: Inventory Every Document Category

Start by listing every type of document HIPAA requires you to maintain. Use the list above as a starting point, then add categories specific to your organization — incident response reports, access logs, encryption documentation, device inventories.

Step 2: Map Each Category to Its Retention Period

Apply the six-year HIPAA minimum. Then check your state law for longer requirements. If you're a home health agency operating across state lines, this step gets complicated fast. Our HIPAA Training for Home Health Care Agencies addresses multi-state compliance challenges that home health organizations face when serving patients in different jurisdictions.

Step 3: Define Storage, Access, and Destruction Procedures

Your HIPAA retention policy must specify how records are stored (encrypted drives, locked storage, cloud repositories with access controls), who can access them, and how they're destroyed when the retention period expires. Shredding paper is obvious. But what about backup tapes? Decommissioned laptops? Database archives?

Document your destruction methods. OCR wants to see that you didn't just delete files — they want proof that destruction was thorough and auditable.

Step 4: Assign Ownership and Audit the Policy Annually

Someone in your organization must own the retention policy. Not "the compliance team." A named person. That person should audit the policy annually, verify that records scheduled for destruction actually get destroyed, and confirm that new document categories (like updated BAAs or new risk assessments) are entering the retention workflow.

How Long Must You Keep HIPAA Compliance Documents?

HIPAA requires covered entities and business associates to retain all administrative compliance documentation — including policies, procedures, risk assessments, training records, BAAs, and breach notification logs — for a minimum of six years from the date of creation or the date the document was last in effect, whichever is later. Medical records retention is governed by state law, not HIPAA, and varies by state.

Electronic vs. Paper Records: The ePHI Wrinkle

The Security Rule requires you to protect ePHI throughout its lifecycle — including during the retention period. That means your HIPAA retention policy can't just say "keep electronic records for six years." It must also address ongoing encryption, access controls, backup integrity, and media sanitization.

I've audited organizations that faithfully retained electronic records on servers that no one had patched in three years. The records were technically retained. They were also completely vulnerable. Retention without security is just a breach waiting to happen.

Common Mistakes I See Every Quarter

  • Destroying records too early. Organizations purge files during office moves, system migrations, or leadership changes without checking retention schedules. This is preventable with a written policy and a calendar.
  • Keeping everything forever. The opposite problem. Retaining PHI longer than required increases your attack surface and breach exposure. A retention policy should include destruction timelines, not just preservation timelines.
  • Ignoring business associate documentation. Your vendors' BAAs, subcontractor agreements, and breach notifications are your responsibility to retain. If your business associate has a breach, OCR will ask you for the signed agreement.
  • No proof of training. Training happened, but nobody kept the sign-in sheets or completion certificates. Six years from now, that training effectively never happened as far as OCR is concerned.

Your HIPAA Retention Policy Is Your Defense

When OCR investigates, the organization with meticulous documentation wins. Not "wins" as in walks away clean — but wins as in demonstrates good faith, reduces penalty tiers, and avoids the highest fines. The organization that can't produce records? They're the cautionary tale in the next HHS press release.

A HIPAA retention policy isn't a filing exercise. It's your organization's legal memory. Build it deliberately. Review it annually. And never, ever assume that because something is old, it's safe to throw away.

Need to get your workforce trained — and documented? Browse our full HIPAA training catalog for courses that generate the completion records your retention policy demands.