A family practice that had been in the same building since 1998 called us about a storage unit. It held roughly 140 boxes of paper charts from before the EHR conversion in 2011, plus banker's boxes of explanation of benefits printouts, deposit slips and superbills going back to the early 2000s. The unit cost $240 a month. Nobody had opened it in years. The practice manager wanted to know whether she could shred all of it, and the senior physician wanted to know whether she could shred any of it. Both had been told different things by different consultants.
The honest answer is that several clocks run at once, they start on different dates, and the longest one wins for each record. The paper charts were subject to the state medical board's retention rule. The billing records were subject to payer contracts and Medicare Advantage rules. The HIPAA documentation (policies, training logs, the old notice of privacy practices) was subject to HIPAA's own six-year rule, which is the one rule HIPAA actually has about retention. A good part of that storage unit could go; a smaller part had to stay; and the unit itself, with no access log, was a compliance problem regardless.
This article sorts out medical records retention for an independent practice: which rule governs which record, how long each clock runs and when it starts, how to write a schedule you can defend, and how to destroy records so that the destruction is not itself a breach.
Key takeaways
- HIPAA does not set a retention period for medical records; it requires HIPAA documentation (policies, procedures, notices, authorizations, risk analyses, training and breach records) to be kept for six years from creation or last effective date.
- Medical record retention is set by state law and medical board rules, most often 5 to 10 years from the last visit, with longer periods for minors, and the state period is a floor, not a target.
- Medicare Advantage contracts require records supporting claims to be kept for 10 years; the False Claims Act can reach back as far as 10 years; and Medicare fee-for-service claims can be reopened for four years for good cause and indefinitely for fraud, which is why 10 years is a common practical standard for anything tied to a claim.
- Employee exposure and medical records under OSHA rules are kept for the duration of employment plus 30 years, which surprises most practices.
- Destruction must render PHI unreadable and unreconstructable, be documented, and be performed by staff or a vendor under a business associate agreement with a certificate of destruction.
Which rule governs which record
Start by sorting what the practice holds into four piles, because each pile has a different rulebook. Clinical records (the chart, results, images, consents) answer to state law. Billing and claims records (superbills, claim files, remittances, payer correspondence, refund records) answer to payer contracts, Medicare rules and federal fraud statutes. HIPAA compliance documentation answers to HIPAA. Employment records answer to OSHA, the IRS and state labor law. A record can sit in two piles: a signed Advance Beneficiary Notice is both a clinical consent and a billing document, and it follows the longer clock.
| Record type | Governing rule | Period | Clock starts |
|---|---|---|---|
| Adult medical record | State medical board or statute | Commonly 5 to 10 years (Florida physicians 5, New York 6, California and Texas 7) | Last date of service or discharge |
| Minor's medical record | State law | Longer of the adult period or a set time after majority (Texas: until age 21 or 7 years, whichever is longer) | Last date of service, or the 18th birthday |
| Records supporting Medicare Advantage claims | 42 CFR 422.504(d), flowed down through the MA contract | 10 years | End of the contract period or completion of an audit |
| Records supporting Medicare fee-for-service claims | Reopening rules and the False Claims Act | No fixed provider rule; 4 years for good-cause reopening, up to 10 years under the False Claims Act | Date of payment or claim |
| Medicaid claim records | State Medicaid rules and provider agreement | Commonly 5 to 10 years, set by the state | Date of service or payment |
| Commercial payer claim records | Participation agreement | Commonly 5 to 7 years for audit access | Date of service or contract end |
| HIPAA policies, notices, BAAs, authorizations, risk analyses, training logs, breach files | 45 CFR 164.316 and 164.530(j) | 6 years | Creation date or the date the document was last in effect |
| Employee exposure and medical records | OSHA 29 CFR 1910.1020 | Duration of employment plus 30 years | Separation date |
| Payroll and employment tax records | IRS | At least 4 years | Date the tax was due or paid |
Three things about that table trip people up. State periods are minimums; a board rule that says seven years does not require destruction at seven, and malpractice counsel often recommend longer. The clocks start on different events: last visit for the chart, payment date for the claim, separation for the employee. And the Medicare Advantage 10-year requirement reaches any practice that participates with an MA plan, whether or not anyone read the contract's flow-down clause.
HIPAA's six years, and what it covers
HIPAA is silent on how long to keep the chart, and OCR says so plainly in its guidance. What the Privacy and Security Rules require is that the practice keep its compliance documentation for six years: the written policies and procedures, every version of the notice of privacy practices and the acknowledgments, signed authorizations, business associate agreements, the security risk analysis and risk management plan, training records, sanction records, accounting of disclosures logs, complaint files and breach documentation including the risk assessments that concluded an incident was not a breach.
The six years run from the date the document was created or, for a policy or agreement, from the date it stopped being in effect. A business associate agreement signed in 2015 and replaced in 2022 must be kept until 2028. When OCR investigates a breach, its data request routinely asks for policies and risk analyses covering the six years before the incident, and a practice that cannot produce the 2021 risk analysis in 2026 has a documentation finding on top of whatever caused the breach.
Billing records: why ten years is the practical answer
The billing pile is where practices under-retain, because remits and superbills feel like clutter. They are the evidence that a claim was supported. Medicare fee-for-service can reopen a paid claim within one year for any reason, within four years for good cause, and at any time for fraud or similar fault. The False Claims Act allows the government to sue up to six years after a violation, or up to three years after it should have known, capped at ten years. Medicare Advantage plans and their downstream providers must retain records for ten years. Commercial contracts typically give the payer audit access for five to seven years after the service or the end of the agreement.
Put together, a ten-year retention period for anything that supports a claim (the encounter note, the charge, the claim, the remittance, the appeal, the refund) covers every clock that a small practice is realistically exposed to. That is longer than most state chart rules, which means the billing rule, not the medical board rule, usually decides when a chart can go. The 2011 paper charts in our opening practice were past the state's seven-year period, but any chart with a Medicare Advantage visit in 2016 or later had a claim clock still running.
Electronic remittance files deserve a mention. The 835 file is often kept only in the clearinghouse portal, which retains it for a period the practice never checked, sometimes as little as 18 or 24 months. Download and archive the files, or confirm the practice management system stores the full remittance detail. Our billing team archives remits monthly for this reason.
A worked example: emptying the storage unit
The practice inventoried the 140 boxes over two Saturdays. Ninety-one boxes held paper charts with no visit after 2011; for adult patients that was past the state's seven-year rule and past every claim clock, so they were eligible for destruction. Six boxes held charts of patients who were minors at the last visit; the manager pulled the youngest birth dates, found two patients who would not reach the state's minor threshold until 2027, and set those charts aside. Twenty-eight boxes held EOBs and superbills from 2003 to 2010: eligible. Fifteen boxes held EOBs and deposit records from 2012 to 2017 that included Medicare Advantage payments, which the 10-year rule still covered for 2016 and 2017; those stayed.
The practice also checked for litigation holds. One former patient had a pending malpractice claim; her chart, in the 2011 group, was pulled and kept regardless of the schedule, because a hold overrides every retention period. The result: 117 boxes to a shredding vendor under a business associate agreement, with an itemized certificate of destruction listing box numbers and dates; 23 boxes back to a locked cabinet in the office with a destruction date written on each; the storage unit closed. Annual savings of $2,880 was the least of it. The unit had been the practice's largest unmanaged repository of PHI.
Destroying records properly
HIPAA does not prescribe a method, but OCR guidance says PHI must be rendered unreadable, indecipherable and otherwise unable to be reconstructed. For paper that means shredding, pulping or burning; tossing charts in a dumpster or a recycling bin is a breach, and OCR has settled cases over exactly that. For electronic media the reference is NIST Special Publication 800-88 on media sanitization: overwrite, degauss or physically destroy drives, and do not forget copiers, fax machines and old servers that hold images of everything that passed through them. Affinity Health Plan paid $1,215,780 to OCR in 2013 after returning leased copiers with patient data still on the hard drives.
A destruction vendor is a business associate and needs a signed agreement before the first box leaves. Ask for a certificate of destruction for each pickup that lists what was destroyed, when, how and by whom, and keep the certificates for six years as HIPAA documentation. Keep a destruction log of your own too, with the record type, date range, authorization and method; if a patient or payer later asks for a record you destroyed under the schedule, the log is your answer.
When a practice closes or a physician leaves, state medical board rules usually require notice to patients and a named custodian for the records, and the payer clocks follow the records to the custodian.
Questions we hear
Our EHR stores everything. Do we need a retention schedule at all?
Yes. Records in the EHR are only part of what you hold; scanned documents, remits, emails, texts and the storage unit are elsewhere. And "keep everything forever" is itself a risk, because every record you hold is one you must protect and could have to produce. A schedule lets you destroy what you may, on a documented basis, and keep what you must.
How long do we keep the records of a deceased patient?
The same clocks apply. Most state rules run from the last date of service regardless of death, some set a shorter period after death, and the claim-related clocks are unchanged. Ask counsel about your state; there is no federal shortcut.
Can we keep records in the cloud and shred the paper?
Generally yes, if the scanned copy is complete, legible, retrievable for the whole retention period and protected as electronic PHI, and if your state does not require originals for a specific record type. Test that a ten-year-old scanned chart can actually be found and opened before you shred the paper, and include the scanning vendor under a business associate agreement. A practice audit is a reasonable time to check.
What to do this week
- List every place records live: EHR, practice management system, scanned document store, clearinghouse portal, email, storage unit, old servers and copiers.
- Look up your state's medical record retention rule for physicians and for minors, and write both periods into a one-page schedule.
- Set 10 years for anything supporting a claim and 6 years for HIPAA documentation, and add the OSHA and tax rows.
- Check for litigation holds and open payer audits before destroying anything.
- Sign a business associate agreement with a shredding and media destruction vendor and require itemized certificates.
- Download the last two years of 835 remittance files from your clearinghouse and archive them where the practice controls retention.
