HIPAA documentation retention
What HIPAA requires you to keep and for how long — six years for compliance documentation — and why medical record retention is a state-law question.
HIPAA documentation retention at a glance
HIPAA requires covered entities and business associates to keep required documentation — policies and procedures, risk analyses, training records, BAAs, breach assessments and similar records — for six years from when it was created or last in effect, whichever is later (45 CFR 164.316(b)(2) and 164.530(j)). HIPAA does not set how long medical records themselves must be kept; that is governed by state law and other rules.
| Rule | 45 CFR 164.316(b)(2) and 164.530(j) |
|---|---|
| Period | 6 years from creation or last effective date, whichever is later |
| Covers | Policies, procedures, risk analyses, training records, BAAs, breach assessments, notices, acknowledgments |
| Medical records | Retention period set by state law, not HIPAA |
| During retention | Records must still be safeguarded under HIPAA |
Six years for compliance documentation
The Security Rule requires written policies and records of required actions and assessments, kept for 6 years from the date of creation or the date last in effect, whichever is later (164.316(b)(2)). The Privacy Rule has a matching requirement (164.530(j)).
| Keep for 6 years | Examples |
|---|---|
| Policies and procedures | Every version, with dates |
| Risk analysis and risk management | Each assessment and plan |
| Training | Who, what, when; acknowledgments |
| BAAs | Signed agreements, including expired ones |
| Breach records | Four-factor assessments, notices, HHS logs |
| Patient notices and requests | Notice of Privacy Practices versions, acknowledgments, access and amendment requests |
Medical records are different
HIPAA does not say how long to keep medical records. State laws — and sometimes Medicare and professional rules — set those periods, and they vary. HIPAA does require you to protect records for as long as you keep them, and to dispose of them securely.
In practice
Keep compliance documentation in one place with version dates. When you replace a policy or vendor, keep the old version and agreement for the full six years after it stopped being in effect.
Related requirements
- Security risk analysis →§ 164.308(a)(1)(ii)(A)
- HIPAA training requirements →§ 164.530(b)
- Business associate agreements (BAAs) →§ 164.502(e)
Frequently asked questions
How long does HIPAA require medical records to be kept?
HIPAA doesn't set a retention period for medical records. State laws do, and they vary. HIPAA requires that records be protected for as long as you keep them.
How long must HIPAA policies and training records be kept?
Six years from when they were created or last in effect, whichever is later.
Do business associates have the same retention requirement?
Yes, for documentation the Security Rule requires them to keep, such as policies, risk analyses and records of security activities.