HIPAA-compliant storage of paper records means keeping any document containing protected health information behind physical barriers that block unauthorized access, under written policies, with access limited to the staff who actually need it, from the moment the record is created until it is securely destroyed. The governing rule is the Privacy Rule at 45 CFR 164.530(c), which requires “appropriate administrative, technical, and physical safeguards to protect the privacy of protected health information” in any form.1eCFR. 45 CFR 164.530 – Administrative Requirements That standard covers printed charts, intake forms, prescription records, and billing documents sitting in a file cabinet, and it applies whether you are a solo practice or a hospital system.
Which HIPAA Rule Actually Governs Paper
A lot of confusion comes from the assumption that the HIPAA Security Rule applies here. It does not. The Security Rule covers only electronic protected health information; paper and verbal communications fall outside its scope.2U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule Paper records are governed by the Privacy Rule instead.
The practical difference is that the Privacy Rule’s safeguard standard asks for “reasonable” measures rather than prescribing exact methods like encryption or audit logs. That flexibility gives you room to fit safeguards to the size and layout of your operation, but regulators will judge whether your chosen measures were reasonable under the circumstances. Documented policies and real physical controls are the baseline either way.
Physical Storage Controls
At a minimum, paper records containing PHI need to be stored behind a physical barrier that prevents unauthorized access. HHS guidance specifically mentions “securing medical records with lock and key or pass code, and limiting access to keys or pass codes” as examples of appropriate safeguards.3U.S. Department of Health and Human Services. Summary of the HIPAA Privacy Rule In practice that means locked file cabinets, a dedicated records room with restricted entry, or both.
Larger organizations layer on additional controls: alarm systems, surveillance cameras, and visitor sign-in logs. HHS guidance on incidental disclosures recommends “isolating or locking file cabinets or records rooms” and controlling who enters storage areas.4U.S. Department of Health and Human Services. Incidental Uses and Disclosures The Security Rule’s facility access controls at 45 CFR 164.310, though technically aimed at systems housing ePHI, offer a useful framework you can borrow for paper: maintain a facility security plan, validate access based on role, control visitors, and document repairs and modifications to security hardware.5eCFR. 45 CFR 164.310 – Physical Safeguards
Environmental Conditions
Keeping people out is only part of the job. Paper also needs protection from water, mold, and heat. Federal records storage standards under 36 CFR Part 1234 require that paper records be kept in conditions that prevent mold growth, meaning relative humidity should not exceed 70% and temperature and humidity should not spike together.6eCFR. 36 CFR Part 1234 – Facility Standards for Records Storage Facilities Those standards apply directly to federal records facilities rather than private health care offices, but they are the recognized benchmark. Records stored in a damp basement or an un-climate-controlled warehouse can become unreadable, which creates its own compliance problem if the records are still within a required retention period.
Access Control and the Minimum Necessary Standard
Not everyone in your office needs access to every file. The Privacy Rule requires covered entities to make “reasonable efforts to use, disclose, and request only the minimum amount of protected health information needed to accomplish the intended purpose.”3U.S. Department of Health and Human Services. Summary of the HIPAA Privacy Rule For paper storage, that means role-based access.
A billing clerk may need insurance and payment records but has no reason to read detailed clinical notes. A front-desk receptionist may need to pull a chart but should not have unrestricted access to files for patients not on the day’s schedule. Your policies should identify which categories of employees can access which types of records and limit physical access accordingly. That might mean separate locked cabinets for clinical versus billing records, or different keys or codes for different areas of a records room.
Access rights need active management. When someone is hired, they get only the access their role requires. When someone changes roles, access is updated. When someone leaves, keys and codes are collected or changed immediately. The failure to revoke access from departed employees is one of the most common gaps auditors find. Document every access grant, change, and revocation.
Handling Records During the Workday
Storage security is only half the equation. Most paper PHI exposures happen during routine use, not because someone broke into a records room. A chart left face-up on a check-in counter, a stack of lab results in a printer tray, an intake form visible through a window at a nurse’s station: these are the scenarios HHS worries about.
HHS guidance recommends placing patient charts in holders with identifying information facing the wall rather than visible to passersby, limiting access to areas where records are used, supervising those areas, and escorting non-employees.4U.S. Department of Health and Human Services. Incidental Uses and Disclosures In public-facing spots like a pharmacy counter, even asking waiting customers to step back counts as a reasonable safeguard. Cubicle dividers, curtains, and privacy shields can reduce visibility where multiple patients are present.
Shared printers, fax machines, and copiers deserve particular attention. Any device that routinely outputs paper PHI should be located in a non-public area rather than a hallway, waiting room, or conference room. Staff should retrieve printed documents promptly. Faxed documents should be routed to the intended recipient or the patient’s record immediately, and if a fax goes to the wrong number, the sender should contact the recipient and confirm destruction. Copy machines need an operator present when copying PHI, so their placement rules are slightly more flexible, but any copier with fax or print capability should follow the same restrictions as a standalone fax machine.
Written Policies, a Security Official, and Training
Safeguards without written policies behind them are hard to enforce and nearly impossible to defend during an HHS investigation. The Privacy Rule requires covered entities to maintain written policies and procedures for protecting PHI, and many organizations extend the Security Rule’s administrative requirements to their paper programs as well.
Every covered entity must designate a security official responsible for developing and implementing its security policies.7eCFR. 45 CFR 164.308 – Administrative Safeguards In a small practice that might be the office manager. In a hospital it is usually a dedicated compliance officer. Someone specific has to own the program.
That official must implement a security awareness and training program for the entire workforce, including management. Training should cover how to handle paper records, where to store them, what to do if records are found in an unsecured area, and the consequences for violating the policies. Training happens at onboarding and periodically thereafter. Document it every time: who attended, what was covered, and when.
Organizations must also establish contingency plans for emergencies that could damage records, such as fires, floods, or natural disasters.7eCFR. 45 CFR 164.308 – Administrative Safeguards For paper, this means knowing where backup copies exist if any, planning to secure or relocate records during an emergency, and having procedures to continue critical operations while records are inaccessible.
All HIPAA compliance documentation, including your policies, training records, BAAs, and access logs, must be retained for at least six years from the date of creation or the date last in effect, whichever is later.1eCFR. 45 CFR 164.530 – Administrative Requirements This six-year rule is often confused with a requirement to keep patient medical records for six years. It is not. Medical record retention is a separate question, covered below.
Off-Site Storage, Business Associate Agreements, and Transport
Many organizations eventually outgrow their on-site storage capacity and send older records to a third-party vendor. Under HIPAA, any outside vendor that stores, handles, or has access to PHI qualifies as a business associate, and the covered entity must have a written Business Associate Agreement (BAA) in place before handing over any records.8U.S. Department of Health and Human Services. Business Associates
The BAA is not a formality. Federal regulation at 45 CFR 164.504(e) specifies what the contract must contain:9eCFR. 45 CFR 164.504 – Uses and Disclosures
- The contract must spell out exactly what the vendor is allowed to do with the PHI and prohibit any other use or disclosure.
- The vendor must agree to use appropriate safeguards to prevent unauthorized access.
- The vendor must report any unauthorized use or disclosure it becomes aware of, including breaches of unsecured PHI.
- If the vendor uses subcontractors who will also handle the PHI, those subcontractors must agree to the same restrictions.
- At the end of the contract, the vendor must return or destroy all PHI it still holds. If that is not feasible, the contract must explain why and extend protection indefinitely.
Signing a BAA does not end your responsibility. You are expected to perform due diligence before selecting a vendor, which means verifying physical security measures, asking about their track record, and confirming they can actually deliver what the contract requires. If you learn the vendor has violated the agreement, you are obligated to take steps to fix the problem or terminate the relationship.8U.S. Department of Health and Human Services. Business Associates
Moving records between locations introduces its own risks. Records should travel in sealed, opaque containers that prevent anyone from viewing PHI in transit. Logging or numbering boxes helps track them and prevents shipments from being misplaced. If records move on carts within a facility, they should be covered and placed in secure containers rather than stacked openly.
How Long to Keep the Records
HIPAA does not tell you how long to keep patient records. The Privacy Rule requires you to protect PHI for as long as you maintain it, but it sets no minimum or maximum retention period for the records themselves.3U.S. Department of Health and Human Services. Summary of the HIPAA Privacy Rule The six-year rule above applies to compliance documentation, not patient charts.
Retention periods come from other sources. Hospitals participating in Medicare must retain medical records for at least five years under CMS conditions of participation.10eCFR. 42 CFR 482.24 – Condition of Participation: Medical Record Services State laws set their own retention requirements and they vary significantly, from as short as five years in some states to permanent retention in others. Records for minor patients often must be kept until the child reaches the age of majority plus several additional years, which can mean retaining charts until the patient is in their mid-to-late twenties depending on the state. The safest approach is to identify the longest applicable retention period among federal rules, state statutes, accreditation requirements, and malpractice insurance guidelines, and use that as your floor.
Disposal When Retention Ends
Once a paper record has passed its required retention period, you cannot just toss it in a recycling bin. HHS is blunt: “covered entities are not permitted to simply abandon PHI or dispose of it in dumpsters or other containers that are accessible by the public or other unauthorized persons.”11U.S. Department of Health and Human Services. Frequently Asked Questions About the Disposal of Protected Health Information
Acceptable disposal methods must render the information “essentially unreadable, indecipherable, and otherwise cannot be reconstructed.” HHS lists several options:12U.S. Department of Health and Human Services. What Do the HIPAA Privacy and Security Rules Require of Covered Entities When They Dispose of Protected Health Information
- Shredding, most commonly with cross-cut shredders that produce smaller fragments than strip-cut, though HHS does not mandate a specific shredder type.
- Burning through incineration in a controlled environment.
- Pulping or pulverizing, which breaks the paper into a slurry or unrecognizable fragments.
If you hire an outside destruction vendor, that vendor is a business associate and needs a BAA, just like a storage vendor. The BAA must require the vendor to safeguard the PHI throughout the destruction process.11U.S. Department of Health and Human Services. Frequently Asked Questions About the Disposal of Protected Health Information HIPAA does not explicitly require a Certificate of Destruction, but obtaining one is widely recommended. It documents the date, method, and scope of destruction, giving you a paper trail if your practices are ever questioned during an audit.
If Paper Records Are Lost or Stolen
If paper PHI is lost, stolen, or accessed without authorization, the Breach Notification Rule applies. Paper records that have not been shredded or otherwise destroyed are considered unsecured, so nearly any breach involving intact paper documents requires notification.13U.S. Department of Health and Human Services. Breach Notification Rule
The covered entity must notify each affected individual no later than 60 days after discovering the breach. The notification must describe what happened, what types of information were involved, what steps individuals should take to protect themselves, and what the organization is doing to investigate and prevent future breaches. Breaches affecting 500 or more people in a single state or jurisdiction trigger additional notifications to prominent local media within the same 60-day window and immediate reporting to HHS. Smaller breaches can be reported to HHS annually, no later than 60 days after the end of the calendar year in which they were discovered.13U.S. Department of Health and Human Services. Breach Notification Rule If the breach happens at your storage vendor, that business associate must notify you within 60 days of discovering it, and you then handle notifications to individuals and HHS.
Penalties for Getting It Wrong
HIPAA enforcement has real teeth, and paper record violations are not treated as minor. The Office for Civil Rights at HHS handles civil enforcement. Civil monetary penalties are organized into four tiers based on culpability. As of January 2026, the inflation-adjusted amounts are:14Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
- Did not know, and could not have known with reasonable diligence: $145 to $73,011 per violation.
- Reasonable cause, not willful neglect: $1,461 to $73,011 per violation.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation.
- Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation.
Each tier carries a calendar-year cap of $2,190,294 for all violations of the same provision.14Federal Register. Annual Civil Monetary Penalties Inflation Adjustment HHS counts each record affected as a separate violation. A box of 500 patient files left in an unlocked storage unit is not one violation; it could be 500. Knowingly obtaining or disclosing PHI without authorization can also carry federal criminal charges under 42 U.S.C. § 1320d-6, with fines and prison terms that scale up when the act is done under false pretenses or for personal gain.15Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information