
A definitive HIPAA records compliance checklist for healthcare compliance and facilities leaders: the Security Rule controls that protect records (access, audit, integrity), how HIPAA, CMS, and Pennsylvania retention rules stack, the economics of a breach, defensible destruction, the ROT and dark-data problem, and a working audit-readiness checklist.
Guide briefing
HIPAA sets no fixed retention period for patient medical records — state law does — but it requires covered entities to keep compliance documentation for six years. In Pennsylvania, hospitals and physicians must retain records at least seven years, and minors' records until age 25. A defensible program pairs those rules with access, audit, and integrity controls and documented destruction.
More from the Compliance & Regulations category.
Next step
Share the framework, records condition, workflow, capacity issue, or implementation risk. Reynolds routes it to the discipline that owns the work — from Emmaus, with same-day response.
Guide deliverables
Need help applying this guide?
Talk to a specialistHealthcare organizations consistently get one thing wrong about HIPAA and records: they assume the law tells them how long to keep patient charts. It does not. The HIPAA Privacy Rule sets no retention period for medical records at all — that question is answered by state law and by program-specific rules from the Centers for Medicare & Medicaid Services (CMS). What HIPAA does require is a six-year retention period for the compliance documentation that proves your program works, plus a set of Security Rule controls that govern who can touch a record, how that access is logged, and how the record's integrity is protected over its lifetime.
So a defensible healthcare records program answers two separate questions. How long must each record be kept? That comes from your state retention statutes and any CMS rules tied to your reimbursement model. How must records be protected, accessed, and eventually destroyed? That comes from the HIPAA Security and Breach Notification Rules. Conflating the two is the most common reason an otherwise diligent organization fails an audit — and the stakes are not theoretical.
Healthcare has had the most expensive data breaches of any industry for 14 straight years. The average U.S. healthcare breach cost $7.42 million in 2025, and these incidents take an industry-worst 279 days to identify and contain. In 2024 alone, reported breaches exposed the protected health information of nearly 85% of the U.S. population. This guide lays out the controls, the retention math, the breach economics, defensible destruction, and a working audit-readiness checklist — with specific attention to Pennsylvania providers across the Lehigh Valley, the region Reynolds Business Systems has served for decades.
HIPAA is three rules working together. The Privacy Rule governs how protected health information (PHI) may be used and disclosed and gives patients the right to access their own records. The Security Rule sets the safeguards for electronic PHI (ePHI). The Breach Notification Rule dictates what happens when protected information is exposed. None of the three imposes a fixed lifespan on a patient's medical record.
This surprises most compliance teams. The U.S. Department of Health and Human Services is explicit that the Privacy Rule does not include medical-record retention requirements; how long records must be kept is left to the states. HIPAA's only hard retention number applies to your compliance paperwork: covered entities must retain required documentation — policies, procedures, risk analyses, training logs, business associate agreements, and the like — for six years from the date it was created or last in effect, whichever is later, under 45 CFR 164.316(b)(2)(i).
Read that distinction carefully, because it defines the whole program. A hospital can be perfectly compliant with HIPAA's six-year documentation rule and still be in violation of a state statute that requires patient charts to be kept far longer. Your retention schedule has to satisfy the longest applicable rule for every record type you hold — and applying the six-year figure to clinical records is a common way to under-retain and create malpractice and audit exposure.
HIPAA sets a six-year retention period for compliance documentation — not for medical records. Patient-record retention is governed by state law and CMS program rules. Always retain a record for the longest period any applicable rule demands.
The HIPAA Security Rule organizes its requirements into administrative, physical, and technical safeguards. For a records program — whether the records are paper in a warehouse or images in a content system — three technical controls do the heaviest lifting: access control, audit controls, and integrity. Together they answer the questions an auditor will ask first: who can reach this record, what did they do with it, and can we prove it has not been altered.
Access control means only authorized people can reach a record, and only the records their role requires. In practice that is role-based permissions, unique user identification so every action ties to a named individual, automatic logoff, and a documented process for granting and revoking access when staff join, change roles, or leave. For physical files, the equivalent is a locked, access-logged storage environment and chain-of-custody tracking on every box and retrieval.
Audit controls require mechanisms that record and examine activity in systems that contain ePHI. The point is accountability: if a record is viewed, copied, altered, or printed, the system should capture who did it and when. Audit logs are also your evidence in an investigation — without them, you cannot demonstrate that access was appropriate, and you cannot detect the insider snooping that drives a meaningful share of healthcare incidents. Logs need to be retained and periodically reviewed, not merely generated.
Integrity controls protect records from improper alteration or destruction. A medical record that can be silently changed has limited evidentiary or clinical value. Version history, controlled edits, tamper-evidence on stored images, and reliable backups together ensure a record is the same trustworthy document years later that it was the day it was created. Integrity is where retention and security meet: a record you are legally required to keep for seven years must remain readable and unaltered for that entire period.
Underpinning all three is documentation. The Security Rule requires that the policies and procedures implementing these safeguards be written down and — like all HIPAA compliance documentation — retained for six years. A control you cannot evidence is, for audit purposes, a control you do not have.
Why a retention schedule matters
| Category | Value |
|---|---|
| Redundant / obsolete / trivial | 33% |
| Dark (unclassified) data | 52% |
Because HIPAA defers to the states, your retention schedule is assembled from several overlapping authorities. Federal CMS rules attach to your participation in Medicare and Medicaid. State statutes set baseline minimums for hospitals and licensed professionals. And HIPAA's six-year documentation rule sits alongside all of it. The governing principle is simple to state and easy to get wrong: for any given record, you keep it for the longest period any applicable rule requires.
The CMS rules alone span a wide range. Hospitals participating in Medicare must retain medical records for at least five years after discharge under 42 CFR 482.24. Medicare providers more broadly must keep records and documentation for seven years from the date of service under 42 CFR 424.516. Providers that submit cost reports must hold supporting records for at least five years after the cost report is closed. And Medicare managed-care organizations face the longest federal baseline — ten years.
| Record type / obligation | Minimum retention | Authority |
|---|---|---|
| HIPAA compliance documentation | 6 years from creation or last in effect | 45 CFR 164.316(b)(2)(i) |
| Patient medical records under HIPAA | Not set by HIPAA — governed by state law | HHS OCR guidance (FAQ 580) |
| Pennsylvania hospital records (adult) | 7 years after discharge | 28 Pa. Code 115.23 |
| Pennsylvania hospital records (minors) | Until the patient turns 25 | 28 Pa. Code 115.23 |
| Pennsylvania physician records | 7 years from last service | 49 Pa. Code 16.95 |
| Medicare hospital records | 5 years after discharge | 42 CFR 482.24 |
| Medicare provider records | 7 years from date of service | 42 CFR 424.516 |
| Medicare managed-care records | 10 years | CMS MLN guidance |
| Medicare cost-report records | 5 years after cost report closure | CMS MLN guidance |
Pennsylvania's baselines are stricter than the federal hospital minimum. Pennsylvania hospitals must keep medical records for at least seven years following a patient's discharge, and the State Board of Medicine requires physicians to retain a patient's record for at least seven years from the date of the last service. For minor patients, Pennsylvania hospitals must hold records until the patient turns 25 — the age of majority plus seven years. A Pennsylvania hospital treating a Medicare managed-care patient therefore has to reconcile the state's seven-year rule against the federal ten-year rule and keep the record for ten.
The figures below combine cited unit costs and rates with clearly-illustrative volumes to show the method. Substitute your own box counts and contract rates.
Consider a mid-sized Lehigh Valley community hospital with roughly 8,000 boxes of inactive paper records in offsite storage. Offsite document storage typically runs about 50 to 95 cents per box per month before retrieval, indexing, and destruction fees. At that rate, 8,000 boxes cost between $4,000 and $7,600 per month — $48,000 to $91,200 a year — just to sit on a shelf.
Now apply the retention schedule. Industry studies find that roughly 33% of the data organizations store is redundant, obsolete, or trivial — material known to be useless. If a defensible review confirms that a comparable share of those boxes has passed every applicable retention trigger, that is about 2,640 boxes (8,000 multiplied by 0.33) eligible for certified destruction.
Removing 2,640 boxes at the same 50-to-95-cent rate saves roughly $1,320 to $2,508 per month — about $15,840 to $30,096 a year — while simultaneously shrinking the volume of PHI exposed in any future breach. The retention schedule is not just a compliance artifact; it is the instrument that turns standing storage cost and standing risk into a controlled, recurring reduction. These amounts are illustrative example math, not a quote.
The cost of under-protecting records is well documented, and it is the single most persuasive argument for funding a disciplined program. Healthcare has recorded the most expensive data breaches of any industry for 14 consecutive years. In 2025 the average U.S. healthcare breach cost $7.42 million — down $2.35 million from the prior year's $9.77 million, but still far above the $4.44 million global all-industry average.
Healthcare breaches are also the slowest to contain, averaging 279 days from identification to resolution — roughly nine months in which exposed records remain a live liability. The volume is staggering: 772 large breaches of 500 or more records were reported to the HHS Office for Civil Rights in 2025, up from 741 in 2024, and 2024's incidents collectively exposed the PHI of nearly 85% of the U.S. population. The 2024 Change Healthcare ransomware attack alone affected an estimated 192.7 million individuals — the largest healthcare data breach in history.
| Metric | Figure |
|---|---|
| Average U.S. healthcare breach cost (2025) | $7.42 million |
| Prior-year average (2024) | $9.77 million |
| Year-over-year change | Down $2.35 million |
| Global all-industry average (2025) | $4.44 million |
| Average days to identify and contain (healthcare) | 279 days |
| Years healthcare has led all industries on breach cost | 14 consecutive years |
| Large breaches reported to OCR (2025) | 772 |
| Large breaches reported to OCR (2024) | 741 |
| Largest breach to date (Change Healthcare, 2024) | 192.7 million individuals |
| HIPAA civil penalty range | $145 to $2,190,294 per violation |
On top of breach-response costs sit regulatory penalties. HIPAA civil monetary penalties run from $145 to as much as $2,190,294 per violation, with the top of the range reserved for violations attributable to willful neglect that are not corrected. Because penalties are assessed per violation and per year, a systemic failure — say, missing audit logs across an entire records system — can compound quickly.
Healthcare has had the most expensive data breaches of any industry for fourteen straight years — and they take the longest of any industry to contain.
The instinct to keep everything 'just in case' is itself a compliance and security liability. Veritas's Global Databerg research found that only about 15% of stored information is business-critical. Roughly 33% is redundant, obsolete, or trivial — known to be useless — and about 52% is 'dark' data whose value the organization cannot even identify.
For a healthcare records holder, that dark and redundant material is not free. Every box and every file past its required retention period is storage you pay for, PHI an attacker can steal, and discoverable material a plaintiff's attorney can demand. Over-retention quietly inflates the blast radius of any breach: a record that should have been destroyed two years ago but still sits in a system becomes someone else's exposure statistic. Disposing of records on schedule is therefore a security control, not just a housekeeping task.
Over-retention is a risk, not a safe default. Records kept past their required life add storage cost, expand breach exposure, and become discoverable in litigation. Keeping everything is not the conservative choice — a defensible schedule is.
Destruction is the step most programs neglect, and it is where 'defensible' earns its name. Defensible destruction means you can prove — to a regulator, an auditor, or a court — that a record was destroyed in the ordinary course of business according to a consistent, documented retention policy, and not to make evidence disappear. The proof is as important as the act.
Two failures recur in audits. The first is destroying records inconsistently or off-schedule, which can look like spoliation if litigation later arises. The second is destroying records without a certificate, leaving no evidence the disposal was authorized and complete. A records partner that issues certificates of destruction and maintains chain-of-custody documentation closes both gaps.
Auditors do not grade intentions; they grade evidence. The HIPAA documentation requirement at the center of this is concrete: every policy and procedure implementing the Privacy and Security Rules must be maintained in writing, and that documentation — along with risk analyses, training records, business associate agreements, and incident logs — must be kept for six years from creation or last effective date. If a control is not documented, an auditor treats it as absent.
Patient access is the other obligation that shows up in complaints and investigations. Under the Privacy Rule's right of access, a provider must act on a patient's request for their records within 30 days, with a single 30-day extension permitted if the patient is notified. A records program that cannot locate and produce a chart within that window — because retention, indexing, or retrieval is disorganized — creates both a service failure and a compliance exposure.
For providers in Allentown, Bethlehem, Easton, and the surrounding Lehigh Valley, Pennsylvania's rules set the practical floor. The seven-year hospital and physician baselines, the age-25 minimum for minors, and the interaction with CMS's longer managed-care rule mean most Pennsylvania records carry multi-year — sometimes decades-long — obligations that have to survive system migrations, mergers, and storage-vendor changes without a gap.
That continuity is where storage strategy matters. Inactive records can sit in-house, with a national vendor, or with a regional partner. National vendors offer scale — Iron Mountain, for example, reports serving more than 240,000 organizations and 95% of the Fortune 1000 across more than 1,400 facilities in over 50 countries — while a regional partner offers local pickup, faster in-person retrieval, and a single point of contact. The right answer depends on retrieval frequency, audit posture, and how much PHI is involved.
| Model | Profile | Indicative cost |
|---|---|---|
| In-house storage | On-site space, staff time, climate control, internal chain of custody | Opportunity cost of clinical or administrative floor space |
| National vendor | Large scale (Iron Mountain reports 240,000+ organizations, 95% of the Fortune 1000, 1,400+ facilities, 50+ countries) |
Reynolds Business Systems approaches this as a Pennsylvania problem first: retention schedules mapped to PA and CMS rules, secure local storage and retrieval across the Lehigh Valley, scanning to bring active records into a searchable system, and certified destruction with documentation when records reach end of life.
The corollary — when not to keep a record — follows directly. Once a record has satisfied every applicable retention trigger and is under no litigation hold, continuing to store it is the riskier choice. The defensible move is to destroy it on schedule, with documentation. The only records that should outlive their statutory minimums are those subject to a legal hold or a deliberate, documented best-practice decision to retain longer.
It depends on the record and the jurisdiction. HIPAA sets no retention period for medical records; state law and CMS program rules do. In Pennsylvania, hospitals must keep records at least seven years after discharge and physicians at least seven years from the last service. Medicare managed-care records run ten years. Always apply the longest rule that fits the record.
Not for patient medical records. HIPAA's only fixed retention requirement is six years for compliance documentation — policies, procedures, risk analyses, training logs, and similar evidence — measured from the date created or last in effect. The U.S. Department of Health and Human Services leaves medical-record retention to the states, which is why Pennsylvania's seven-year rules, not HIPAA, set the floor for charts.
Possibly, but it is not guaranteed. Pennsylvania requires hospitals and physicians to keep records for a minimum of seven years, so a ten-year-old adult record may already have been lawfully destroyed. Records tied to Medicare managed care are kept ten years, and minors' records run until age 25, so availability depends entirely on which retention rule applied to that specific record.
In Pennsylvania, hospital records (seven years after discharge) and physician records (seven years from the last service) carry seven-year minimums. Federally, Medicare providers must retain records and documentation for seven years from the date of service. Note that HIPAA compliance documentation is a separate six-year rule, and some records — minors' and managed-care — must be kept longer.
Records held by Medicare managed-care organizations carry a ten-year federal retention requirement from CMS — the longest standard federal baseline. Because you must apply the longest applicable rule, a Pennsylvania provider handling a managed-care patient keeps that record for ten years even though the state hospital and physician minimums are seven.
Usually not for an adult patient. Pennsylvania's seven-year hospital minimum means a twenty-year-old record has typically passed its required retention period and may have been destroyed under a defensible schedule. The main exceptions are records for patients who were minors — which Pennsylvania hospitals must keep until the patient turns 25 — and any record placed under a legal hold.
Billing and cost-report records follow CMS rules: Medicare providers retain documentation for seven years from the date of service, and cost-report supporting records must be kept at least five years after the cost report closes. Because billing records can be tied to clinical records, the safe practice is to align their disposal with the longest retention rule covering the underlying care.
HIPAA and Pennsylvania set minimum retention periods, not maximums, so no law requires records to be kept forever. In practice, some providers choose to retain certain records — such as immunization histories or implant and operative records — well beyond the legal minimum as a clinical best practice. Those are documented policy decisions, not statutory mandates.
They are two different obligations. HIPAA documentation retention is the six-year requirement to keep the paperwork that proves your compliance program exists — policies, risk analyses, training logs, and the like. Medical-record retention is how long patient charts must be kept, which HIPAA does not specify and which state and CMS rules govern. A compliant program satisfies both.
Under HIPAA's right of access, a covered entity must act on a patient's request within 30 days. A single 30-day extension is permitted if the provider notifies the patient in writing of the reason and the expected completion date. A disorganized retention or retrieval system that cannot meet this window is both a service failure and a compliance exposure.
Defensible destruction is disposing of records in a way you can prove was proper: on schedule, under a consistent documented retention policy, using a secure irreversible method, and with a certificate of destruction recording what was destroyed, when, how, and by whom. The documentation matters as much as the act, because it shows the disposal was routine and authorized — not an attempt to destroy evidence.
It depends on the record and the jurisdiction. HIPAA sets no retention period for medical records; state law and CMS program rules do. In Pennsylvania, hospitals must keep records at least seven years after discharge and physicians at least seven years from the last service. Medicare managed-care records run ten years. Always apply the longest rule that fits the record.
Not for patient medical records. HIPAA's only fixed retention requirement is six years for compliance documentation — policies, procedures, risk analyses, training logs, and similar evidence — measured from the date created or last in effect. The U.S. Department of Health and Human Services leaves medical-record retention to the states, which is why Pennsylvania's seven-year rules, not HIPAA, set the floor for charts.
Possibly, but it is not guaranteed. Pennsylvania requires hospitals and physicians to keep records for a minimum of seven years, so a ten-year-old adult record may already have been lawfully destroyed. Records tied to Medicare managed care are kept ten years, and minors' records run until age 25, so availability depends entirely on which retention rule applied to that specific record.
In Pennsylvania, hospital records (seven years after discharge) and physician records (seven years from the last service) carry seven-year minimums. Federally, Medicare providers must retain records and documentation for seven years from the date of service. Note that HIPAA compliance documentation is a separate six-year rule, and some records — minors' and managed-care — must be kept longer.
Records held by Medicare managed-care organizations carry a ten-year federal retention requirement from CMS — the longest standard federal baseline. Because you must apply the longest applicable rule, a Pennsylvania provider handling a managed-care patient keeps that record for ten years even though the state hospital and physician minimums are seven.
Usually not for an adult patient. Pennsylvania's seven-year hospital minimum means a twenty-year-old record has typically passed its required retention period and may have been destroyed under a defensible schedule. The main exceptions are records for patients who were minors — which Pennsylvania hospitals must keep until the patient turns 25 — and any record placed under a legal hold.
Billing and cost-report records follow CMS rules: Medicare providers retain documentation for seven years from the date of service, and cost-report supporting records must be kept at least five years after the cost report closes. Because billing records can be tied to clinical records, the safe practice is to align their disposal with the longest retention rule covering the underlying care.
HIPAA and Pennsylvania set minimum retention periods, not maximums, so no law requires records to be kept forever. In practice, some providers choose to retain certain records — such as immunization histories or implant and operative records — well beyond the legal minimum as a clinical best practice. Those are documented policy decisions, not statutory mandates.
They are two different obligations. HIPAA documentation retention is the six-year requirement to keep the paperwork that proves your compliance program exists — policies, risk analyses, training logs, and the like. Medical-record retention is how long patient charts must be kept, which HIPAA does not specify and which state and CMS rules govern. A compliant program satisfies both.
Under HIPAA's right of access, a covered entity must act on a patient's request within 30 days. A single 30-day extension is permitted if the provider notifies the patient in writing of the reason and the expected completion date. A disorganized retention or retrieval system that cannot meet this window is both a service failure and a compliance exposure.
Defensible destruction is disposing of records in a way you can prove was proper: on schedule, under a consistent documented retention policy, using a secure irreversible method, and with a certificate of destruction recording what was destroyed, when, how, and by whom. The documentation matters as much as the act, because it shows the disposal was routine and authorized — not an attempt to destroy evidence.
| ~$0.50–$0.95 per box per month plus retrieval, indexing, and destruction fees |
| Regional partner | Local pickup and retrieval, single point of contact, market familiarity | Comparable per-box rates with local, same-region service |
|---|