What Is Record Retention in Healthcare? HIPAA, Medicare, and ERISA

Record retention in healthcare is the practice of keeping patient charts, billing files, and compliance paperwork for legally required time periods, and no single federal law sets one universal deadline. HIPAA governs how long you keep your compliance documentation (six years), but the retention period for the patient chart itself comes from state law and from program-specific federal rules that can run anywhere from five years to more than three decades.

What HIPAA Actually Requires

One of the most common misconceptions in healthcare compliance is that HIPAA dictates how long providers must keep patient medical records. It does not. HIPAA’s retention rules apply to the organization’s own compliance documentation, not to the clinical chart.

Under the HIPAA Security Rule, covered entities must retain their security policies, procedures, and any required written assessments for six years from the date of creation or the date the document was last in effect, whichever comes later.1eCFR. 45 CFR 164.316 – Policies and Procedures and Documentation Requirements The Privacy Rule imposes a parallel six-year requirement for privacy policies, written communications, and documentation of any action or designation the Privacy Rule requires.2eCFR. 45 CFR 164.530 – Administrative Requirements That covers your Notice of Privacy Practices, business associate agreements, breach notification logs, and training records.

The retention period for a patient’s chart comes from somewhere else. Organizations that assume HIPAA handles everything routinely fall short of the longer timelines their state medical board or CMS requires.

How Long Patient Charts Must Be Kept

For the chart itself, state law is usually the controlling authority. Every state sets its own minimum, and the range across the country typically falls between five and ten years after the patient’s last encounter. Providers operating in multiple states have to track each one independently: a seven-year floor in one state offers no cover if a neighboring state requires ten.

Records for Minors

Most states extend retention timelines for pediatric records. The common approach is to require retention until the minor reaches the age of majority (usually 18) plus an additional period that often ranges from three to ten years depending on the state. A record created for a newborn can end up needing to be kept for more than two decades. Because these rules vary widely, pediatric practices should verify their state medical board’s specific requirement.

Deceased Patients

HIPAA’s privacy protections for individually identifiable health information continue for 50 years following a patient’s death.3U.S. Department of Health and Human Services. Health Information of Deceased Individuals That does not mean the chart must be stored for 50 years. It means that while the record exists, HIPAA’s privacy and security rules still apply to it. The actual retention period for a deceased patient’s record is set by state law, which commonly requires seven to ten years from the date of death or discharge.

Federal Programs That Add Their Own Deadlines

Several federal programs impose retention periods that sit on top of state law, and they vary significantly by activity.

Hospitals Participating in Medicare

Hospitals participating in Medicare must meet the CMS Conditions of Participation, which require medical records to be retained in their original or legally reproduced form for at least five years.4eCFR. 42 CFR 482.24 – Condition of Participation: Medical Record Services This is a floor, not a ceiling. State law frequently requires longer, and hospitals must comply with whichever rule is stricter.

Medicare Advantage Organizations

Medicare Advantage (Part C) plans face a much longer timeline. Organizations contracting with CMS under Part C must maintain books, records, and documents related to their financial operations, quality of services, and bid preparation for ten years. That period can extend further if CMS identifies a special need, or if there has been a termination, dispute, or allegation of fraud, in which case records must be kept for six years from the final resolution of the matter.5eCFR. 42 CFR 422.504 – Contract Provisions

Employee Exposure and Medical Records

OSHA’s Access to Employee Exposure and Medical Records standard applies to healthcare employers whose workers face toxic substance exposure or harmful physical agents. Employers must retain employee medical records for the duration of employment plus 30 years. Exposure records must be kept for at least 30 years. Limited exceptions exist for first aid records of minor incidents and for employees who worked less than one year, provided the records are given to the employee at termination.6eCFR. 29 CFR 1910.1020 – Access to Employee Exposure and Medical Records

When the retention period ends, the employer cannot simply shred everything. If a specific OSHA standard requires it, the records must be transferred to the National Institute for Occupational Safety and Health. Otherwise, the employer must notify NIOSH in writing at least three months before disposal and wait for a response.

Clinical Trial Records

Investigators conducting FDA-regulated clinical trials must retain records for two years after the marketing application for the drug is approved for the relevant indication, or, if no application is filed or approved, for two years after the investigation is discontinued and the FDA has been notified.7eCFR. 21 CFR 312.62 – Investigator Recordkeeping and Record Retention Sponsors face a similar timeline under the companion sponsor recordkeeping regulation.8eCFR. 21 CFR 312.57 – Recordkeeping and Record Retention

ERISA Health Benefit Plans

Organizations that administer employee health benefit plans subject to ERISA must keep plan reports and the underlying records for at least six years after the filing date of the documents based on that information.

Litigation Holds Override the Schedule

A retention schedule tells you when you can destroy records. A litigation hold tells you when you cannot, regardless of what the schedule says. When litigation is reasonably anticipated or already underway, the organization must suspend its normal destruction process for any records that could be relevant.9U.S. Department of Health and Human Services. Department of Health and Human Services Policy for Litigation Holds

Destroying records subject to a hold, even inadvertently, is spoliation of evidence. Courts take this seriously. Sanctions range from monetary fines to adverse inference instructions, where the jury is told to presume the destroyed information was unfavorable to the party that destroyed it. Beyond formal sanctions, losing key evidence can cripple a defense to a malpractice claim or a billing dispute.

The hold stays in effect until formally lifted, and during that time the relevant records must stay in their original format and cannot be altered or deleted.9U.S. Department of Health and Human Services. Department of Health and Human Services Policy for Litigation Holds Litigation hold protocols belong in the retention policy from the start. Waiting until a lawsuit arrives is how records end up destroyed by staff who were following routine procedures and never got the memo.

Destroying Records the Right Way

Once the retention period has expired and no litigation hold applies, the organization must destroy records in a way that makes the information permanently unrecoverable. The HIPAA Security Rule requires covered entities to implement policies and procedures for the final disposition of electronic protected health information and the hardware or media it is stored on, and for removing protected health information from electronic media before that media is reused.10eCFR. 45 CFR 164.310 – Physical Safeguards

For paper records, acceptable methods include cross-cut shredding, incineration, and pulping. Standard strip-cut shredding is generally considered inadequate for protected health information because strips can be reconstructed. For electronic records, the options include overwriting the data multiple times, degaussing magnetic media with a strong magnetic field, or physically destroying the storage device. Simply deleting files or reformatting a drive does not meet the standard, because the underlying data remains recoverable with readily available tools.

Document every destruction event: what was destroyed, the method, the date, and who authorized and performed the work. That documentation is itself part of the organization’s compliance records under the six-year HIPAA requirement.

Penalties for Non-Compliance

Failing to meet retention and privacy obligations carries real financial consequences. The HHS Office for Civil Rights enforces HIPAA through a tiered civil penalty structure, with amounts adjusted annually for inflation. The current tiers are:

  • Tier 1, no knowledge: the organization did not know and could not reasonably have known about the violation. Penalties range from $145 to $73,011 per violation.
  • Tier 2, reasonable cause: the violation resulted from reasonable cause rather than willful neglect. Penalties range from $1,461 to $73,011 per violation.
  • Tier 3, willful neglect corrected within 30 days of discovery. Penalties range from $14,602 to $73,011 per violation.
  • Tier 4, willful neglect not corrected within 30 days. Penalties range from $73,011 to $2,190,294 per violation.

Each tier carries a calendar-year cap of $2,190,294 for identical violations.11Federal Register. Annual Civil Monetary Penalties Inflation Adjustment Because a single incident can involve thousands of individual records, the per-violation structure means totals escalate fast.

State medical boards can impose their own discipline for records violations on top of federal fines, including license suspension or revocation. And destroying records during pending litigation can bring court sanctions entirely separate from any regulatory penalty. A written retention schedule that reflects every rule that applies to your organization, paired with a working litigation-hold process, costs far less than defending against any of these outcomes.