Medical records retention looks simple until one rule overlaps another. For health systems, the right answer depends on the organization, record class, care setting, jurisdiction, contract terms, and preservation duties.
A sound program connects legal validation with technology and daily operations. This guide explains a practical framework for CIOs, HIM leaders, privacy teams, compliance officers, legal counsel, and records owners.
This article provides educational information, not legal advice. Obtain qualified legal counsel and state-specific validation before setting or changing a medical records retention schedule.
How Long to Keep Medical Records in a Health System
There is no single universal U.S. answer for how long to keep medical records. A health system needs a validated schedule that layers applicable federal rules, state requirements, contracts, and preservation obligations for each record class.
A retention schedule is a written control that defines what must be kept, for how long, from which trigger date, and under whose authority. A strong healthcare compliance framework also defines access, holds, exceptions, review dates, and final disposition.
Before relying on one number, ask: Does every record class have a current rule that legal counsel has validated?
A Quick-Reference View of Verified Federal Layers
Federal requirements have different scopes. The table below is a quick reference, not a complete national schedule or a substitute for state-specific review.
| Federal Layer | Covered Material | Verified Duration or Trigger | Operational Requirement | Scope Warning |
|---|---|---|---|---|
| HIPAA Privacy Rule documentation | Specified policies, communications, actions, and designations required by the Privacy Rule | Six years from creation or the date last in effect, whichever is later | Keep the required compliance documentation available | This is not a universal patient-chart retention rule |
| CMS hospital Condition of Participation | Inpatient and outpatient medical records for hospitals subject to 42 CFR 482.24 | At least five years | Keep records in original or legally reproduced form, properly filed, retained, and accessible | Other federal or state requirements may require longer retention |
| Medicare Part A/B documentation | Defined supporting documentation for covered ordered, certified, referred, or prescribed services, items, and drugs | Seven years from the date of service | Maintain the covered documentation and provide access when CMS or its contractor requests it | This does not apply to every medical record |
| HIPAA individual access | PHI in a designated record set | For as long as the PHI is maintained | Support access subject to the regulation’s exceptions | This access rule does not set a universal retention duration |
| Federal civil litigation preservation under Rule 37(e) | Relevant electronically stored information, or ESI, that should be preserved for federal civil litigation | When the ESI should be preserved in anticipation or conduct of federal civil litigation | Take reasonable preservation steps and follow counsel-directed hold procedures | This row is limited to relevant ESI under Rule 37(e); counsel must determine scope and release |
CMS hospital record rule: “Medical records must be retained in their original or legally reproduced form for a period of at least 5 years.”
The Medicare documentation access requirement says, “Maintain documentation … for 7 years from the date of service.” It covers only the defined Part A/B documentation within its scope.
What HIPAA’s Six-Year Rule Actually Covers
HIPAA’s six-year period is often misapplied to patient charts. HIPAA documentation rule: “retain the documentation … for six years from the date of its creation or the date when it last was in effect, whichever is later.”
That section covers specified Privacy Rule compliance materials, including required policies, written communications, actions, and designations. It does not create one six-year retention period for every patient’s medical record.
Does your schedule separate HIPAA compliance documentation from patient-chart retention requirements?
Why Medical Record Retention Periods Vary
Medical record retention requirements change because the rules apply to different organizations, programs, records, and events. A useful analysis starts by classifying the entity and information before assigning a duration.
HHS explains state-law preemption rules: “Where the more stringent State law and Privacy Rule are not contrary, covered entities must comply with both laws.” This supports state-specific validation, not a 50-state retention schedule.
When rules overlap, has your organization documented which requirement controls each record class?
Federal Rules Are Floors or Category-Specific Requirements
A federal minimum may be only one layer in the final decision. For each authority, identify who and what it covers, the trigger, duration, access duty, and exceptions.
Hospital records, HIPAA compliance documents, and defined Medicare supporting documents sit in separate categories. The HIPAA access duration applies “for as long as the protected health information is maintained in the designated record set,” subject to exceptions.
State, Minor, Deceased, and Specialty Records Need Validation
Because this guide does not establish state-specific retention rules, obtain current legal review before assigning a retention period or disposition process for minor, deceased, behavioral health, substance-use, occupational, research, or other specialty records.
A Data Retention Roadmap can help teams organize the operational plan after counsel validates the requirements. Use a clear escalation list for any category that lacks a current, approved authority.
- Jurisdiction: Identify every state connected to the provider, patient, service, record, and business entity.
- Record category: Separate clinical, billing, imaging, laboratory, research, employee, and specialty information.
- Patient status: Flag minor and deceased patient records for specific review.
- Program obligations: Check Medicare, Medicaid, grants, research, contracts, and other program terms.
- Preservation status: Confirm whether litigation, investigation, audit, or another applicable duty stops routine disposition.
Which record categories still need state-specific validation in your organization?
How to Build a Defensible Medical Records Retention Schedule
A defensible schedule turns validated requirements into repeatable controls. It requires HIM, privacy, compliance, legal, IT, security, clinical operations, finance, and business records owners to work from the same inventory.
Use a data archiving roadmap to connect policy decisions with extraction, retention, access, and legacy-system retirement. The result should show what the organization keeps, where it lives, who owns it, and how it reaches final disposition.
Could your team trace any retained record from its legal authority to its system, owner, hold status, and approved disposition?
Inventory and Classify Records Across Active and Legacy Systems
Start with an enterprise inventory of applications, repositories, databases, interfaces, vendors, and physical media. Include active platforms, acquired systems, systems marked for retirement, and data already moved to an archive.
Map each record class to its business use, designated record set status, owner, format, and location. An enterprise active archive can centralize secure, searchable access to legacy clinical, financial, and ERP data after source systems retire.
Assign Rules, Triggers, Owners, and Exceptions
Build a rule-to-record matrix instead of placing every detail in a long policy document. For each class, capture the authority, trigger date, approved period, access need, owner, hold status, final disposition, and next review date.
Federal civil rules address ESI “that should have been preserved in the anticipation or conduct of litigation.” Use litigation hold preservation procedures when an applicable duty arises. Counsel should direct the trigger, scope, and release.
- Authority: Name the law, regulation, contract, policy, or approved legal analysis.
- Trigger: Define the event that starts the retention period.
- Owner: Assign a person or role accountable for the record class.
- Access: State who needs the record and how quickly it must be available.
- Exception: Record holds, investigations, audits, disputes, and approved extensions.
- Disposition: Define the authorized action after all requirements are cleared.
Approve, Implement, and Review the Schedule
Legal counsel should validate the schedule before executive approval. Then IT and records teams can configure controls, train staff, document exceptions, and test whether policy matches actual system behavior.
Review the schedule on a set cycle and whenever laws, services, contracts, systems, or jurisdictions change. Date-stamp each review, record the approvers, and preserve the prior version so decisions remain traceable.
Is your current schedule approved, implemented, and ready for its next review cycle?
Keep Retained Records Accessible After Legacy Systems Retire
Retention without reliable retrieval can create new compliance and operational risk. Passive storage may preserve bits, while active archiving keeps authorized information searchable, readable, auditable, and available within real workflows.
This distinction matters during EHR transitions, acquisitions, audits, patient requests, and clinical follow-up. It also lets CIOs reduce technical debt without treating continued access as an afterthought.
Before retiring a source system, can users retrieve a complete, readable record under realistic conditions?
Design Access Around Real HIM and Clinical Workflows
Define access by the work people must complete. Plan for patient matching, role-based permissions, search, export, legal record management, audit trails, and access from the go-forward EHR or other approved workflow.
HIM teams also need tested release of information workflows for records held outside the current EHR. The archive should support governed access without requiring users to keep unsupported applications running.
Test Retrieval, Security, and Audit Evidence
Set clear service expectations for common record requests. Test sample retrievals by record type, age, source system, user role, and output format before the source application is decommissioned.
Validate permissions, audit logs, patient matching, readable formats, and export quality. Document defects and complete remediation before final retirement approval.
- Retrieval: Confirm that authorized users can find the right record within the expected time.
- Security: Verify role-based access and remove unnecessary privileges.
- Usability: Check that records remain readable and useful outside the old application.
- Evidence: Preserve test results, approvals, defects, and remediation records.
Test your archive before decommissioning any source system. Can users retrieve complete records under expected security and service levels?
Use a Controlled, Defensible Destruction Workflow
As a control practice, do not treat schedule expiration as an automatic deletion instruction. Before disposition, confirm the organization’s approved schedule and whether any applicable legal, regulatory, contractual, or preservation obligation remains; use documented sanitization and disposition controls appropriate to the record or media involved.
MediQuant’s governance and security controls guidance can help connect access controls, audit evidence, and purge governance. Destruction should be the last governed stage of stewardship, not a background storage task.
If an auditor asked today, could your team prove what was destroyed, why it was eligible, who approved it, and how completion was validated?
Confirm Eligibility and Clear Preservation Obligations
Confirm the approved retention period and trigger for the exact record population. Then check legal or regulatory holds, litigation, investigations, audits, contracts, patient disputes, and other approved exceptions.
Require named approval before releasing records for disposition. If an exception remains open, keep the affected records and document why routine destruction was suspended.
Document Sanitization, Validation, and Final Disposition
The disposition log should identify the record scope, method, operator, date, tool and version, result, exception, and approving authority. It should also reconcile the approved population with the completed population.
NIST SP 800-88 Rev. 2 offers useful sanitization documentation controls. Its fields include “Sanitization Method,” “Tools Used,” “Verification/Status,” “Validation,” and “MEDIA DESTINATION/DISPOSITION.” These fields are a control model, not a HIPAA-specific legal mandate.
- Define the population: Identify the records, systems, media, dates, and exclusions covered by the event.
- Approve the action: Record the authority, eligibility review, hold clearance, and named approvers.
- Perform the work: Use the approved destruction or sanitization method and controlled tools.
- Verify the result: Confirm the method completed as intended and investigate failures or exceptions.
- Preserve evidence: Store the log, validation, reconciliation, and vendor documentation under an approved schedule.
Can your team document every destruction event from eligibility through validation?
Common Retention Mistakes to Avoid
Most retention failures begin with an overbroad shortcut or a gap between policy and systems. Pair each common mistake with a control that an owner can test.
- One number for every record: Classify records and apply validated rules to each class.
- HIPAA’s six years treated as a chart rule: Limit the six-year statement to specified Privacy Rule documentation.
- Medicare’s seven years extended to every chart: Apply it only to the defined Part A/B supporting documentation.
- State validation skipped: Obtain current counsel review for each applicable jurisdiction and special category.
- Legacy systems left running by default: Move retained data to a secure, accessible archive through an approved process.
- Expiration treated as automatic deletion: Require hold clearance, approval, controlled disposition, and evidence.
Which of these mistakes could your CIO, HIM, privacy, legal, or security team find in current practice?
Medical Records Retention FAQs
These answers provide a starting point, not a universal schedule. Apply them through current legal review and your organization’s approved retention controls.
How Long Do Providers Legally Need to Keep Medical Records?
The period varies by provider, record type, program, state, contract, and applicable hold. Use a counsel-validated schedule rather than one universal number.
Does HIPAA Require Medical Records to Be Kept Six or Seven Years?
No. HIPAA’s six-year provision covers specified compliance documentation, while a separate Medicare rule covers defined Part A/B documentation for seven years.
What Is the CMS Hospital Minimum?
Hospitals subject to 42 CFR 482.24 must keep inpatient and outpatient records at least five years. Records must remain accessible in original or legally reproduced form, and other rules may require longer retention.
How Long Should Minor Patient Records Be Kept?
There is no national duration established by this guide. Validate state law, record category, claim considerations, and organization policy with qualified counsel.
Do Deceased Patients’ Records Have to Be Retained 50 Years?
Do not assume a national 50-year rule. Validate applicable state, estate, privacy, program, and organizational requirements before assigning a period.
Can Records Be Destroyed After the Scheduled Period?
Treat expiration as a review trigger, not an automatic deletion instruction. Confirm applicable obligations with counsel, then use documented sanitization controls appropriate to the record or media.
Can Patients Get Medical Records From 20 Years Ago?
Availability depends on whether the organization still maintains the PHI and whether an access exception applies. An older record may no longer exist if it was lawfully disposed of under an approved schedule.
Should Every Health System Have a Retention Schedule?
Yes, health systems should maintain a written, approved, implemented, and regularly reviewed schedule. It should map record classes to validated requirements, owners, systems, holds, access needs, and disposition.
Next Steps for a Sustainable Retention Program
Review your schedule to confirm every record class has an owner, trigger, access plan, and approved disposition path.
Start with classification, validate each legal layer, and map the approved rules to real systems and owners. When leaders ask how long to keep medical records, answer with a validated schedule instead of one number.
Then test access, holds, exceptions, and disposition evidence as connected parts of one health data stewardship program. This guide is educational and is not legal advice.
Obtain qualified legal counsel and state-specific validation before setting or changing your schedule. This step is critical for minor, deceased, specialty, and multistate records.
MediQuant reports 1.1B+ accounts archived, 500M+ patient records archived, and 500+ health system customers. Are your records governed, accessible, and ready for defensible disposition? Learn More.









