Executive summary. Policies, notices, authorizations, complaint records, and other required documentation each need an owner, a version, and a retention approach.
Definition
HIPAA documentation retention is the practice of maintaining required policies, procedures, communications, and actions for the applicable period.
Organize by purpose and version
Keep a controlled copy of policies and forms, with effective dates and superseded versions. Staff should be able to identify which instruction applied at the time of an event.
A working approach assigns ownership, preservation expectations, and a way to retrieve records for a real question. A storage folder does none of that on its own.
Review records before they are needed
Periodically test whether the common records can be found: a signed authorization, a training completion, a complaint response, the notice in effect on a given date.
When a record is updated, preserve the history needed to explain the change. That answers day-to-day questions and formal review alike.
Frequently asked questions
How long must HIPAA documentation be retained?
HIPAA includes a six-year documentation retention requirement in specified provisions. Apply the regulation, along with any longer state, contractual, or record-specific requirement.
Referenced standards and further reading
- 45 CFR 164.530, Administrative Requirements ↗U.S. Department of Health and Human Services
Related articles
HIPAA Security Rule risk analysis: scope, evidence, decisions →
The minimum necessary standard in operational design →
Business associate relationships: map the work, not the logo →