The Filing Cabinet That Cost a Practice $150,000

A few years ago, I consulted with a mid-sized orthopedic group that had just moved offices. During the move, someone made the decision to shred six years' worth of HIPAA policies, risk assessments, and training logs. "We don't need that old stuff," the office manager told me. Three months later, OCR came knocking after a patient complaint.

They had nothing to show. No proof of prior risk analyses, no signed Business Associate Agreements from former vendors, no documentation that staff had ever received training. The investigation stretched across years they couldn't account for. What could have been a corrective action plan turned into a drawn-out compliance review with significant financial exposure — all because they didn't understand HIPAA retention requirements.

This scenario plays out more often than you'd think. Most covered entities and business associates know they need to protect PHI. Far fewer understand what records they must retain, and for exactly how long.

What HIPAA Actually Says About Retention — And What It Doesn't

Here's where confusion starts: HIPAA doesn't have a single, blanket retention period for all records. The retention rules live in different parts of the regulation, and they apply to different types of documents.

The HIPAA Privacy Rule and the HIPAA Security Rule each contain their own retention provisions. Under 45 CFR § 164.530(j), covered entities must retain specific documentation for six years from the date of creation or the date when the document was last in effect — whichever is later. This applies to Privacy Rule policies, procedures, and related documentation.

The Security Rule mirrors this under 45 CFR § 164.316(b)(2)(i), requiring that security policies, procedures, and documentation of actions, activities, or assessments be retained for six years.

Six years is the HIPAA floor. It's not the ceiling.

Documents Subject to the Six-Year Retention Rule

  • Privacy and security policies and procedures
  • Risk assessments and risk management plans
  • Business Associate Agreements (BAAs)
  • Workforce training records and acknowledgments
  • Notices of Privacy Practices (NPPs) and all revisions
  • Complaint logs and investigation documentation
  • Breach notification records
  • Authorization forms signed by patients
  • Sanctions applied to workforce members for violations
  • Any required accounting of disclosures

If you can't produce these documents during an OCR investigation, you're functionally non-compliant — regardless of whether you actually had them at some point.

HIPAA Retention Requirements Don't Cover Medical Records Directly

This trips up almost everyone I work with. HIPAA itself does not set a retention period for medical records or patient health information. The Privacy Rule governs how you use and disclose PHI, not how long you store the underlying clinical chart.

Medical record retention is governed by state law. And those laws vary wildly. Some states require five years from the last date of service. Others require ten. Pediatric records often have different rules tied to the age of majority. If you operate across state lines — telehealth, anyone? — you may need to comply with the strictest applicable state requirement.

My advice: always check your state's medical record retention statute and then apply HIPAA's six-year rule on top for any compliance documentation tied to how that PHI was handled.

What Happens When You Fail to Retain Records: Real Enforcement

OCR doesn't investigate retention failures in isolation. They come up during breach investigations, complaint reviews, and compliance audits. But when they surface, they compound penalties fast.

In 2018, Filefax, Inc. paid $100,000 to settle with OCR after medical records were found dumped in an unlocked vehicle accessible to the public. The case highlighted not just the improper disposal, but the lack of documentation around retention and destruction policies.

In the landmark Cignet Health case, OCR imposed a $4.3 million civil money penalty — the largest at the time — in part because the entity failed to cooperate and couldn't produce required compliance documentation. You can review OCR's full enforcement results on the HHS enforcement results page.

The pattern I've seen in over a decade of consulting: organizations that can't produce records during an investigation face steeper penalties, longer corrective action plans, and greater reputational damage. Retention isn't glamorous. It's protective.

How Long Must You Keep HIPAA Records? A Quick-Reference Answer

HIPAA requires covered entities and business associates to retain all policies, procedures, and compliance documentation for a minimum of six years from the date of creation or the date the document was last in effect, whichever is later. This applies to privacy policies, security policies, risk assessments, BAAs, training records, and breach documentation. Medical record retention is governed by state law, not HIPAA directly.

Building a Retention Policy That Actually Works

Having a retention requirement and operationalizing it are two different things. Here's the framework I walk clients through.

1. Inventory Every Document Type

Map every document your organization creates or receives that falls under HIPAA. Include policies, procedures, workforce training acknowledgments, BAAs, risk assessments, incident reports, access logs, and breach notification letters. If you use electronic health records, include system audit logs and access reports tied to ePHI.

2. Assign Retention Periods by Category

Apply the six-year HIPAA minimum to all compliance documentation. Then layer on state requirements for medical records, which may be longer. For employment records that contain health information (like accommodation requests or drug test results), consider EEOC and state employment law requirements too.

3. Define Destruction Procedures

HIPAA requires that when you do dispose of PHI, you must render it unreadable and indiscernible. For paper, that means cross-cut shredding or incineration. For ePHI, it means degaussing, overwriting, or physical destruction of media. Document your destruction process — and keep those destruction logs for six years.

4. Train Your Workforce on Retention

Your staff can't follow a retention policy they've never seen. Every member of your workforce who handles PHI or compliance documentation needs to know what to keep, where to store it, and when (and how) to destroy it. Our Annual HIPAA Refresher course covers retention obligations as part of a comprehensive compliance curriculum — the kind of training OCR expects to see documented in your files.

5. Audit Retention Compliance Annually

At least once a year, verify that your retention schedule is being followed. Spot-check document storage locations — both physical and electronic. Confirm that departed employees' training records haven't been purged from your system. I've seen organizations lose years of training documentation simply because an IT administrator cleaned up old user accounts.

Electronic Records, Cloud Storage, and the Retention Trap

Moving to cloud-based systems doesn't eliminate your retention obligations. It complicates them. When your ePHI or compliance documents live on a vendor's platform, your BAA with that vendor should explicitly address data retention and return-of-data provisions.

What happens if you switch EHR vendors? Your old system might archive records in a proprietary format you can no longer access. I've seen practices pay tens of thousands of dollars for data migration — or worse, lose access entirely when a vendor goes out of business.

Build data portability and retention into every vendor contract. Require exportable formats. Specify what happens to your data at contract termination. And keep a copy of that BAA for six years after the relationship ends.

State Law Can Extend Your Obligations Significantly

Remember: HIPAA's six-year rule is a federal floor. Several states impose longer requirements for specific record types. For example, many states require medical records for minor patients to be retained until the patient reaches the age of majority plus an additional period — sometimes extending to 10 or even 21 years from treatment.

If you operate as a covered entity in multiple states, your retention policy needs to account for the most conservative requirement. The Code of Federal Regulations, Title 45, Part 164 provides the federal baseline, but state health departments publish supplementary requirements that you must integrate.

Retention Is a Training Problem, Not Just a Policy Problem

I can write you a flawless retention policy in an afternoon. But if your front desk staff shreds authorization forms after 90 days, or your IT team purges audit logs quarterly, that policy is worthless.

Retention compliance lives or dies with workforce training. Every person in your organization who touches records — clinical, administrative, technical — needs to understand their role in the retention chain. This isn't a one-time orientation checkbox. It's an ongoing competency that should be reinforced through regular HIPAA training tied to your specific policies.

OCR has made it clear through enforcement actions that "we had a policy" isn't a defense if your workforce wasn't trained on it and your organization can't produce the documentation to prove otherwise.

The Bottom Line on HIPAA Retention Requirements

Six years. That's the number you need to remember for HIPAA compliance documentation. But the real work is building systems, training your workforce, and auditing your practices to make sure those records actually survive for six years — intact, accessible, and organized.

Every document you can't produce during an OCR investigation is a gap in your defense. Every training log you shredded too early is a missed opportunity to demonstrate good faith. In my experience, the organizations that treat retention as a core compliance function — not an afterthought — are the ones that survive investigations with their budgets and reputations intact.

Start with an inventory. Build a schedule. Train your people. And whatever you do, don't let the office manager decide what's "old stuff."