
Does HIPAA Require Medical Record Retention? Federal Rules Explained
TL;DR: Does HIPAA Require Medical Record Retention? Federal Rules Explained
HIPAA does not establish a general retention period for patient medical records.
The HIPAA six-year rule applies to specified privacy and security documentation, not every medical record.
State law commonly determines medical-record retention and may vary by provider type and patient status.
Other federal programs and requirements may impose additional retention obligations.
Retention schedules should map record types, jurisdictions, triggering events, holds, and disposal methods.
Secure, documented destruction should occur only after every applicable period and preservation duty ends.
Does HIPAA require a medical record retention period? The HIPAA Privacy Rule does not establish a general period for retaining patient medical records. State laws generally govern how long healthcare organizations must retain those records, while other federal and program-specific rules may impose additional requirements.
Confusion often arises because HIPAA does require certain privacy and security documentation to be retained for six years. That six-year rule applies to specified HIPAA documentation, not automatically to every patient's medical record.
Healthcare organizations need a retention schedule that maps each record type to all applicable requirements. This article provides general educational information and not legal advice. Retention decisions should be reviewed with qualified counsel for the relevant organization, jurisdiction, population, and record type.
Need structured support for secure healthcare workflows? Explore AMI's healthcare services.
Does HIPAA Set a Medical Record Retention Period?
No. HHS states directly that the HIPAA Privacy Rule does not include medical-record retention requirements and that state laws generally determine how long medical records must be kept. See the official HHS medical-record retention FAQ.
HIPAA still affects records throughout their lifecycle. If protected health information is maintained, covered entities and business associates must apply applicable privacy and security safeguards. Individuals may also retain access rights to information in a designated record set even when the information is old or archived.
The absence of one HIPAA medical-record period does not mean an organization can choose any retention period. Other federal rules, state laws, professional requirements, contracts, litigation holds, and payer programs may apply.
What Does HIPAA Require Organizations to Retain for Six Years?
HIPAA requires specified documentation created or maintained under the Privacy and Security Rules to be retained for six years from the date of creation or the date when it last was in effect, whichever is later.
Examples may include:
- Privacy and security policies and procedures
- Required risk-analysis and risk-management documentation
- Notices of privacy practices and related versions
- Authorizations and certain individual-rights documentation
- Business associate documentation
- Security incident and response documentation
- Training, sanctions, and complaint documentation when required
This is not an exhaustive list. The critical distinction is that HIPAA compliance documentation and patient medical records are different record classes. A retention schedule should label and manage them separately.
Which Federal Rules Can Affect Medical Record Retention?
Federal requirements may apply based on provider type, program participation, service, research activity, employment, or record content. Medicare Conditions of Participation, federal grant or program rules, laboratory requirements, substance-use-disorder confidentiality rules, occupational requirements, and other authorities may create distinct obligations.
For example, CMS hospital guidance has required medical records to be retained in original or legally reproduced form for at least five years, while noting that federal, state, or local rules may require longer periods. See the applicable CMS hospital medical-record guidance.
Organizations should not apply one federal period to every entity or record. Confirm whether the rule covers the facility, provider type, program, patient population, and record category in question.
How Do State Medical Record Retention Laws Apply?
State laws commonly establish medical-record retention periods and may distinguish hospitals, physicians, clinics, behavioral-health providers, pharmacies, laboratories, or other licensed entities. Requirements can differ for adults, minors, deceased patients, closed practices, and specific record types.
Some states set a fixed number of years after the last encounter. Others tie retention to the age of majority, a patient's age, facility closure, or another event. State professional boards and health departments may impose additional record-management obligations.
Organizations operating in multiple states should maintain jurisdiction-specific requirements rather than using an undocumented national default. Legal counsel should resolve conflicts and determine which period governs a particular record.
How Should Organizations Handle Overlapping Requirements?
When several rules apply, the retention schedule should identify each source and use the period required by the controlling authority. In practice, organizations often retain a record for the longest applicable period, but that decision should be legally validated rather than assumed.
| Retention Factor | Question to Resolve |
|---|---|
| Entity type | Is the organization a hospital, physician practice, health plan, laboratory, or another regulated entity? |
| Jurisdiction | Which state and local requirements apply? |
| Program | Do Medicare, Medicaid, grant, research, or other program rules apply? |
| Patient status | Is the record for an adult, minor, or deceased individual? |
| Record type | Is it a clinical record, billing record, image, authorization, policy, or audit document? |
| Legal status | Is there litigation, an investigation, an audit, or a preservation hold? |
Do not destroy information solely because one schedule period has expired. First confirm that no longer requirement, contractual obligation, investigation, or hold applies.

Do Retention Rules Differ for Minors?
Yes. State rules often require records for minors to be retained beyond the period used for adults, frequently by connecting the deadline to the age of majority plus an additional number of years.
The exact calculation varies. Teams should record the patient's date of birth, applicable jurisdiction, triggering event, and required period so systems do not apply an adult schedule automatically.
Special rules may also apply to newborn, pediatric, genetic, behavioral-health, or other records. Confirm those requirements separately.
What Happens When a Practice Closes or Changes Ownership?
Closure, merger, acquisition, relocation, or provider retirement does not automatically eliminate record-retention and access obligations. State rules may require patient notice, transfer arrangements, custodianship, board notification, or continued availability for a defined period.
Contracts should identify responsibility for custody, storage, access requests, amendments, legal holds, breaches, and final disposition. Organizations should verify that legacy systems and archived records remain searchable and readable after migration.
Patients may still request access to old or archived information that remains in a designated record set. A system transition should not make retrievable information operationally inaccessible.
Teams should also understand who can access PHI records when assigning custodianship and responding to requests after ownership or system changes.
How Should Records Be Destroyed After Retention Ends?
Destruction should be authorized, documented, consistent, and appropriate to the medium. Paper records may require secure shredding or destruction. Electronic information may require validated deletion across active systems, archives, removable media, and vendor environments.
Before destruction, confirm that the retention period has expired and that no legal hold, investigation, audit, complaint, contract, or patient-access activity requires preservation. Record what was destroyed, when, under which policy, by whom, and through what method.
HIPAA requires reasonable safeguards for protected health information through final disposition. Vendor destruction should be supported by appropriate agreements, controls, and evidence.
How Should Business Associates and Vendors Be Managed?
Business associates, cloud providers, storage vendors, destruction vendors, and other service providers may hold protected information on behalf of a healthcare organization. Contracts and procedures should define retention, access, security, return, destruction, legal holds, and evidence requirements.
The organization's schedule should account for every copy and repository within scope. Data may remain in backup systems, exports, scanned-document platforms, analytics environments, or legacy applications after it disappears from the primary EHR.
Periodic vendor reviews should test whether records can be retrieved, protected, placed on hold, and destroyed according to documented instructions. Related guidance explains third-party HIPAA compliance for vendors and business associates.
Inline CTA 2: Need stronger operational controls for protected health information? Explore AM Infoweb.

Why do healthcare security gaps persist despite strong policies?
Because patient data moves across teams, systems, and vendors where access, disclosure, and documentation controls can fail. AMI brings PHI-aware workflows, trained teams, QA, and operational visibility together to strengthen security across every handoff.
What Should a Medical Record Retention Schedule Include?
A defensible schedule should list the record category, description, owner, system, legal authority, triggering event, retention period, hold conditions, disposal method, and evidence requirement.
Use version control and record when requirements were reviewed. Link the schedule to operational procedures so departments know when the retention clock begins and who authorizes destruction.
Schedules should cover clinical records, billing information, diagnostic images, authorizations, release logs, complaints, audit evidence, policies, contracts, and other required documentation without treating them as one category.
Which Medical Record Retention Mistakes Should Teams Avoid?
Common mistakes include:
- Treating HIPAA's six-year documentation rule as a universal medical-record period
- Applying one state requirement across every jurisdiction
- Ignoring special rules for minors or specific provider types
- Destroying records while a legal hold or investigation is active
- Leaving legacy data unreadable after a system migration
- Failing to include vendor and backup copies in the schedule
- Keeping information indefinitely without a documented purpose
- Destroying records without approval or evidence
Retention should be long enough to meet requirements and operational needs, but not indefinite by default. Unnecessary retention can increase storage, discovery, privacy, and security exposure.
How AM Infoweb Supports Secure Record Lifecycle Workflows
AM Infoweb supports healthcare organizations with structured, PHI-aware workflows for record handling, information requests, quality assurance, documentation, and operational reporting.
With two decades of experience in the U.S. healthcare industry, AM Infoweb uses a co-managed model that brings AI agents and skilled human agents together to eliminate process bottlenecks and execute secure healthcare workflows.
AMI can support:
- Record inventory and workflow documentation
- Request intake and retrieval coordination
- Legacy and archived-record indexing
- Retention-schedule execution support
- Legal-hold routing and escalation
- Vendor workflow monitoring
- Quality assurance and audit evidence
- Secure disposition tracking
The organization retains authority over legal interpretation, retention policy, holds, and destruction approval while co-managed teams support consistent execution. See how EMR and HIPAA compliance connects electronic records with privacy and operational controls.
What Is the Correct Retention Approach?
Do not begin with the assumption that HIPAA requires all medical records to be kept for six years. Begin by identifying the entity, jurisdiction, program, patient population, record type, triggering event, and any active hold.
Document the applicable authorities, select the legally validated retention period, preserve access and security throughout the lifecycle, and retain evidence of authorized destruction.
Medical record retention is a multi-rule governance problem. A current schedule, clear ownership, searchable systems, vendor controls, and qualified legal review help organizations retain records for the right period and dispose of them responsibly.
Need stronger control over healthcare record lifecycle workflows? AMI combines PHI-aware teams, structured processes, QA, escalation controls, and operational visibility across record handling and disposition activities.
Get in TouchFrequently Asked Questions
About the Author

Written by
Urza Dey
Urza Dey is a content and copywriter with over five years of experience across marketing, B2B SaaS, HealthTech, EdTech, and related industries. At AMI, they contribute to content strategy, blog development, and marketing communication focused on healthcare operations, business process management, and AI-enabled service delivery.

