HIPAA Medical Records Storage and Retention: Requirements by State
The most common misconception about medical-record retention is that HIPAA sets the clock. It does not. What is distinct about this topic is that two different timelines get confused: HIPAA governs how long you keep your compliance documentation and how securely you store PHI, while state law and CMS rules govern how long you keep the medical record itself. Getting this wrong leads organizations either to purge records too early or to hoard PHI they should have securely destroyed.
The six-year rule is about documentation, not records
HIPAA’s one explicit retention requirement is 45 CFR § 164.316(b)(2): covered entities must retain required HIPAA documentation for six years from the date of creation or the date it was last in effect, whichever is later. That covers your policies and procedures, Security Risk Analyses, business associate agreements, notices of privacy practices, and breach records. It says nothing about the patient chart. Confusing the two is why so many practices either over-retain or under-retain.
State law sets the medical-record clock — and it varies
Actual medical-record retention is set by the state in which you practice, layered with federal program rules. Adult records are commonly retained somewhere in the range of five to ten years from the last date of service, but the specific number is a state-by-state question. Records for minors almost always run longer — typically until the patient reaches the age of majority plus a set number of additional years — because the statute of limitations does not start until adulthood. Medicare Conditions of Participation, payer contracts, and litigation holds can extend any of these. The practical takeaway: identify the longest applicable requirement for each record type and retain to that, in every state where you operate.
Storage and disposal are HIPAA’s domain
While HIPAA does not dictate how long you keep records, it absolutely dictates how you store and destroy them. Stored electronic PHI needs Security Rule safeguards — access controls, encryption where reasonable and appropriate, audit logging, and backup and disaster-recovery planning so records survive a ransomware event or hardware failure. Paper archives need physical safeguards: locked, access-limited rooms or cabinets. When a retention period ends, disposal must render PHI unreadable and unrecoverable; discarded drives and unshredded paper are recurring breach sources.
Risk analysis ties it together
Knowing where every record lives — which servers, which archive boxes, which cloud buckets, which legacy systems — is exactly what the Security Rule’s risk analysis requirement under 45 CFR § 164.308(a)(1)(ii)(A) forces you to document. A Security Risk Analysis that inventories all storage locations is what prevents forgotten ePHI sitting unprotected on a decommissioned system. The proposed 2026 Security Rule update reinforces this: HHS’s Notice of Proposed Rulemaking, published in December 2024, would require a written technology asset inventory and more rigorous, regularly updated risk analyses. It is a proposal, not yet final, with a 240-day compliance window once a final rule is published — but mapping your storage now positions you for it.
How Medcurity helps
Medcurity’s guided Security Risk Analysis walks you through inventorying every place PHI is stored — active systems, backups, archives, and cloud storage — and documents the safeguards on each, so retention and disposal decisions rest on a complete map rather than guesswork. The platform is $499/year (about $42/month) for most practices; larger or multi-location organizations can request a quote. For related topics, see our HIPAA right of access guide and the HIPAA compliance checklist.
Frequently asked questions
How long does HIPAA require us to keep medical records?
HIPAA itself sets no retention period for medical records. The six-year rule people cite is 45 CFR § 164.316(b)(2), which applies to HIPAA documentation — policies, procedures, risk analyses, business associate agreements, and breach records — not to the clinical record. How long you keep the actual medical record is governed by state law and, for many providers, CMS Conditions of Participation.
What do state retention laws typically require?
It varies widely. Many states require adult medical records to be retained roughly five to ten years from the last date of service, while records for minors often must be kept until the patient reaches the age of majority plus additional years. Specialty rules, payer contracts, and Medicare requirements can extend these periods. Because the periods differ by state and record type, you should map your specific obligations rather than assume a single number.
Does HIPAA say how records must be stored?
Yes, indirectly. The Security Rule requires you to protect electronic PHI at rest with appropriate administrative, physical, and technical safeguards — access controls, encryption where reasonable, audit controls, and backup and contingency planning. Paper records require physical safeguards such as locked, access-limited storage. Storage method is flexible; the safeguards are not.
How should we dispose of records once the retention period ends?
Disposal must render PHI unreadable and unrecoverable. For paper, that means shredding, burning, or pulping; for electronic media, secure wiping or destruction. Simply deleting files or discarding drives is a frequent source of breaches. Keep documentation of what was destroyed and when, since that record supports your compliance position.