As a general rule, keep your protected health information for at least three to ten years, with a small core of documents held for life and workplace exposure records held for 30 years or more. There is no single federal law telling you, the patient, how long to retain protected health information, but your copies often outlast your provider’s, and they are what you will reach for during a disability claim, an insurance appeal, or an emergency room visit.
The right retention window depends on the document. A vaccination record and a routine billing statement do not deserve the same treatment. Below is what to keep, for how long, and why.
Records to Keep for Life
Some documents never lose their usefulness and belong in permanent storage:
- Immunization records, which are required for school enrollment, international travel, and sometimes employment, and are difficult to reconstruct years later.
- Major surgical reports and discharge summaries, since future surgeons need to know about prior procedures, implants, and complications.
- Records of chronic conditions such as diabetes, heart disease, and autoimmune disorders, which provide continuity across providers over your lifetime.
- Allergy and adverse drug reaction records, which can prevent a life-threatening prescribing error in an emergency.
- Family medical history, which informs screening recommendations for genetic risk factors like cancer and heart disease.
- Advance directives, including living wills and healthcare power of attorney documents, kept current and accessible to family and providers.
These records take little space, especially in digital form. The cost of not having them when you need them is far higher than the effort of keeping them.
Records to Keep for 7 to 10 Years
Documents with medium-term relevance fit here. That includes routine checkup notes, general lab results not tied to a chronic condition, imaging reports such as X-rays and MRIs, dental records, and prescription histories for medications you no longer take. Seven to ten years gives a new provider enough history to spot trends, and it covers the window during which most insurance disputes or malpractice questions typically arise.
This range also lines up with the retention windows that most state laws impose on healthcare providers. Hospitals typically must keep records for seven to ten years, while physician offices generally face requirements of five to ten years after the last visit. Once those windows close, your provider may destroy their copies. If you do not have yours, that history is gone.
Medical Records You Keep for Tax Purposes
If you deducted medical expenses on a federal tax return, the IRS requires you to keep the supporting records until the period of limitations for that return expires. For most people that means at least three years from the date the return was filed or its due date, whichever is later.1Internal Revenue Service. How Long Should I Keep Records If you underreport income by more than 25 percent, the IRS has six years to assess additional tax, so keep those records for at least six years.2Internal Revenue Service. Topic No. 305 – Recordkeeping
Save receipts for prescriptions, copays, premiums, medical devices, and any out-of-pocket costs you claimed. If you received advance premium tax credits through the Health Insurance Marketplace, keep documentation of both the credits and the premiums you paid.2Internal Revenue Service. Topic No. 305 – Recordkeeping Billing statements and appointment confirmations with no tax implications can go once payment is confirmed and the insurance dispute window, usually one to three years, has passed.
Workplace Exposure and Injury Records
If you have ever worked around toxic chemicals, radiation, loud noise, or other harmful agents, your medical and exposure records need a much longer retention window than typical health documents. Federal OSHA rules require employers to preserve employee medical records for the duration of employment plus 30 years, and exposure records for at least 30 years.3Occupational Safety and Health Administration. 1910.1020 – Access to Employee Exposure and Medical Records Occupational diseases like mesothelioma and chemical-induced cancers can take decades to surface, which is why the window is that long.
Do not count on your employer to hang onto those files for three decades. Companies change ownership, go bankrupt, or simply lose track of old records. Request copies of any workplace medical exams, biological monitoring results, and exposure assessments while you are still employed. If an occupational illness surfaces later, those records become the foundation for workers’ compensation or disability claims.
Why Your Own Copies Matter
Retention only pays off if the records show up when you need them. A few situations put that to the test.
Social Security disability claims lean heavily on medical documentation. The Social Security Administration develops a complete medical history covering at least the 12 months before you file, and it may look further back if there is reason to think your disability started earlier.4Social Security Administration. Code of Federal Regulations 404.1512 – Evidence Applicants who rely entirely on providers to forward records often face gaps that delay or weaken their cases.
Switching doctors or moving is another pressure point. A new provider starts with a blank slate unless you bring your history along, and older records from a practice you left years ago may no longer exist. When an insurer denies a claim, documentation of prior diagnoses, failed treatments, and physician recommendations is what turns an appeal into an overturned denial. And in an emergency, a short summary of your allergies, current medications, and major conditions, kept in your wallet or a mobile app, gives paramedics and ER staff what they need when you cannot speak for yourself.
Health Apps Are Not Covered by HIPAA
One boundary worth knowing before you decide where to store records: HIPAA’s protections apply to covered entities like hospitals, insurers, and pharmacies, not to most of the health apps on your phone.5Federal Trade Commission. Complying with FTC’s Health Breach Notification Rule Fitness trackers, period trackers, diet logs, and mental health apps sit largely outside HIPAA.
Many of these apps fall under the FTC’s Health Breach Notification Rule instead, which requires vendors of personal health records to notify users after a breach. It does not stop an app from sharing your data with advertisers in the first place. The FTC has penalized companies for doing exactly that: GoodRx paid $1.5 million for sharing user health data with advertising platforms including Facebook and Google, and the maker of the Premom ovulation-tracking app paid $100,000 for similar violations.6Federal Register. Health Breach Notification Rule Before storing sensitive health data in a consumer app, read the privacy policy for third-party sharing. A patient portal from your provider carries HIPAA protections; a free wellness app generally does not.
How to Store and Safeguard Records
For paper, a simple filing system organized by category (lab results, imaging, prescriptions, billing) kept in chronological order works well. Store them somewhere secure, and fireproof if you can manage it.
For digital files, scanning paper documents creates a searchable backup. Patient portals are a good primary storage location because those systems are HIPAA-protected. If you add cloud storage on top, enable two-factor authentication and encryption, and back up regularly. Avoid sending sensitive health records through unencrypted email or text messages.
Keep a one- to two-page summary listing your current medications, allergies, chronic conditions, emergency contacts, and the location of your advance directives. Update it at least once a year or after any significant medical event. It is the single most useful document you can hand to a first responder.
Disposing of Records Safely
When a document has outlived its retention period, do not just drop it in the recycling. Medical records carry the personal information that fuels identity theft. The FTC recommends shredding paper medical documents before discarding them, and community shred events are a convenient option. For items that resist shredding, like prescription bottles or medical device packaging, black out all personal and medical information with a permanent marker before throwing them out.7Federal Trade Commission. What To Know About Medical Identity Theft
Deleting a digital file from your computer does not fully remove the data. Use a secure-delete utility that overwrites the file, or encrypt files before deletion so any recoverable fragments stay unreadable. When disposing of an old hard drive or USB drive that held health data, physical destruction is the most reliable approach.