hipaa.systems
General provisions · 45 CFR 164.316(b)(2), 164.530(j)

HIPAA documentation retention

What HIPAA requires you to keep and for how long — six years for compliance documentation — and why medical record retention is a state-law question.

Checked 2026-10-06Sources 2

HIPAA documentation retention at a glance

HIPAA requires covered entities and business associates to keep required documentation — policies and procedures, risk analyses, training records, BAAs, breach assessments and similar records — for six years from when it was created or last in effect, whichever is later (45 CFR 164.316(b)(2) and 164.530(j)). HIPAA does not set how long medical records themselves must be kept; that is governed by state law and other rules.

Rule45 CFR 164.316(b)(2) and 164.530(j)
Period6 years from creation or last effective date, whichever is later
CoversPolicies, procedures, risk analyses, training records, BAAs, breach assessments, notices, acknowledgments
Medical recordsRetention period set by state law, not HIPAA
During retentionRecords must still be safeguarded under HIPAA

Six years for compliance documentation

The Security Rule requires written policies and records of required actions and assessments, kept for 6 years from the date of creation or the date last in effect, whichever is later (164.316(b)(2)). The Privacy Rule has a matching requirement (164.530(j)).

Keep for 6 years Examples
Policies and procedures Every version, with dates
Risk analysis and risk management Each assessment and plan
Training Who, what, when; acknowledgments
BAAs Signed agreements, including expired ones
Breach records Four-factor assessments, notices, HHS logs
Patient notices and requests Notice of Privacy Practices versions, acknowledgments, access and amendment requests

Medical records are different

HIPAA does not say how long to keep medical records. State laws — and sometimes Medicare and professional rules — set those periods, and they vary. HIPAA does require you to protect records for as long as you keep them, and to dispose of them securely.

In practice

Keep compliance documentation in one place with version dates. When you replace a policy or vendor, keep the old version and agreement for the full six years after it stopped being in effect.

Frequently asked questions

How long does HIPAA require medical records to be kept?

HIPAA doesn't set a retention period for medical records. State laws do, and they vary. HIPAA requires that records be protected for as long as you keep them.

How long must HIPAA policies and training records be kept?

Six years from when they were created or last in effect, whichever is later.

Do business associates have the same retention requirement?

Yes, for documentation the Security Rule requires them to keep, such as policies, risk analyses and records of security activities.