HIPAA Records Management Checklist for Healthcare Facilities
HIPAA records management means retaining, securing, and disposing of protected health information under the HIPAA Security Rule and right of access, alongside CMS and Pennsylvania retention law. HIPAA sets a six-year minimum for compliance documentation; CMS requires five to ten years for Medicare records. This checklist covers retention schedules, audit-ready access controls, patient access requests, and certified destruction.
HIPAA records management is the disciplined practice of capturing, storing, securing, retaining, and disposing of protected health information (PHI) in line with the HIPAA Privacy and Security Rules and the federal and state retention laws that sit alongside them. The most common misconception is that HIPAA prescribes a single number of years to keep a medical record. It does not. HIPAA's explicit retention requirement applies to compliance documentation, while the records themselves answer to CMS rules and state law.
Getting this right is a measurable risk control, not paperwork. The average cost of a healthcare data breach in the United States reached $7.42 million in 2025 — the costliest of any industry IBM studied, a distinction healthcare has held for 14 consecutive years. Healthcare breaches also take the longest to identify and contain, averaging 279 days. A records program that limits who can reach PHI, logs every access, and disposes of records securely directly reduces that exposure.
This guide gives healthcare HIM and compliance leaders a working checklist: how to build a defensible retention schedule across HIPAA, CMS, and Pennsylvania requirements; how the five technical safeguards translate into an audit trail; how to handle patient access requests on the legal clock; how to destroy records with certificates of destruction; and how to bring legacy paper into the EHR. Reynolds Business Systems applies these same controls for healthcare clients across the Lehigh Valley.
What HIPAA actually requires for records management
Three distinct obligations govern healthcare records, and conflating them is where most programs go wrong. The first is documentation retention. HIPAA requires covered entities to keep required compliance documentation — risk analyses, written policies and procedures, business associate agreements, training logs, and breach records — for at least six years. That six-year clock is the one explicit retention period HIPAA names.
The second is the Security Rule's protection standards. For electronic PHI, 45 CFR 164.312 sets five technical-safeguard standards — access control, audit controls, integrity, person or entity authentication, and transmission security — that define how records must be protected at rest and in transit. The third is the individual right of access under 45 CFR 164.524, which dictates how quickly a patient or their representative must receive a copy of their record.
HIPAA does not set a single retention period for the medical record itself. The six-year requirement applies to HIPAA compliance documentation. How long you keep the actual chart is governed by CMS program rules and your state's medical-record law — in Reynolds' market, Pennsylvania.
HIPAA sets a six-year floor for compliance documentation. The medical record itself answers to CMS and Pennsylvania law, not to a single federal number.
How HIPAA-compliant records management works: the lifecycle
A defensible program treats every record as moving through a fixed lifecycle. Each stage carries its own HIPAA obligation, and the audit trail that ties the stages together is what turns a pile of charts into a system an auditor can verify.
- Capture and classify — Records enter the system through intake, scanning, or an EHR feed and are categorized so a retention rule and access level can be applied.
- Store and secure — Records are protected with access control, authentication, and encryption where appropriate, so only authorized staff can reach them.
- Provide access — Patient requests and internal use are served within the legal timeframe, with every view and export logged.
- Retain — Records are held for the longest applicable period across HIPAA, CMS, and Pennsylvania rules.
- Destroy and document — Once retention is satisfied, records are disposed of securely and a certificate of destruction is filed.
- Audit — Activity logs and disposal records are kept so the program can prove what happened to any record at any point.
The thread running through all six stages is the audit trail. Because healthcare breaches average a 279-day lifecycle to identify and contain, the ability to see exactly who touched a record and when is not a convenience — it is the difference between a contained incident and an open-ended investigation.
Building a retention schedule across HIPAA, CMS, and Pennsylvania
A retention schedule is the master document that assigns a keep-until rule to every record category. The governing principle is straightforward: when multiple authorities apply to the same record, retain for the longest required period. HIPAA's six-year documentation minimum is a floor, not a ceiling — CMS and state law frequently require longer.
| Record category | Governing authority | Minimum retention |
|---|---|---|
| HIPAA compliance documentation (policies, risk analyses, BAAs, training, breach logs) | HIPAA Privacy/Security Rule | 6 years |
| Medicare hospital medical records | CMS Conditions of Participation | 5 years |
| Medicare managed-care (Medicare Advantage) records | CMS | 10 years |
| Pennsylvania medical records | Pennsylvania state regulation | Set by state law — verify the current requirement; often exceeds the HIPAA documentation floor |
| Minor / pediatric patient records | State law | Typically runs from the age of majority — confirm the applicable period |
Pennsylvania sets its own medical-record retention periods under state regulation, and records for minor patients generally must be kept beyond the patient reaching the age of majority. Because those specific periods are set by state law and can change, HIM teams should confirm the current Pennsylvania requirement with legal counsel rather than relying on the HIPAA documentation minimum alone.
Steps to build the schedule
- Inventory every record type your organization creates or receives, including hybrid paper-and-electronic charts.
- Map each record type to all applicable authorities — HIPAA documentation rules, CMS program requirements, and Pennsylvania law.
- Assign the longest required retention period to each category as the controlling rule.
- Flag special cases — minors, behavioral health, and litigation holds — that extend or suspend the standard clock.
- Document the legal basis for each retention decision; that documentation is itself subject to the six-year HIPAA requirement.
- Assign an owner, review the schedule at least annually, and version every change.
Access controls and the audit trail: the five technical safeguards
For electronic PHI, the HIPAA Security Rule at 45 CFR 164.312 defines five technical-safeguard standards. Each maps directly to a records-management control. Treating them as a checklist of system capabilities — rather than abstract policy language — is what makes a records repository defensible.
| Standard | What it requires | Records-management application |
|---|---|---|
| Access control | Limit ePHI to authorized persons and software | Unique user IDs and role-based permissions on every chart |
| Audit controls | Record and examine activity in systems containing ePHI | Tamper-evident logs of every view, edit, print, and export |
| Integrity | Protect ePHI from improper alteration or destruction | Version control and image-quality validation on scanned records |
| Person or entity authentication | Verify identity before granting access | Strong passwords and multi-factor authentication |
| Transmission security | Guard ePHI moving across networks | Encryption of records sent between systems or partners |
One nuance trips up many programs: under 45 CFR 164.312, encryption and decryption of electronic PHI is an addressable implementation specification, not a flat requirement. Addressable means you must implement it where it is reasonable and appropriate, or document why it is not and adopt an equivalent measure. The decision must be recorded — silence is not an option. Given the stakes, encryption of records at rest and in transit is the defensible default for most healthcare organizations.
The audit trail is the single highest-leverage control in this list. A complete, tamper-evident log of who accessed each record is what compresses a breach investigation and demonstrates compliance during an OCR review.
Handling patient access requests on the legal clock
The HIPAA right of access under 45 CFR 164.524 is one of the most heavily enforced provisions in the rule. A covered entity must act on an individual's request for their records no later than 30 days, with one permitted extension of no more than 30 additional days when the entity notifies the individual in writing of the reason and the new completion date.
- Log the request the day it arrives and start the 30-day clock immediately.
- Verify the identity of the requester or their personal representative before releasing anything.
- Locate the record across all systems, including hybrid paper and any back-file archive.
- Provide the copy in the form and format the individual requests when readily producible, including electronic copies of electronic records.
- Charge only a reasonable, cost-based fee where one is permitted, and never use fees to discourage access.
- If an extension is needed, notify the individual in writing within the first 30 days and complete the request within the second 30-day window.
- Record the fulfillment in the audit trail as proof the deadline was met.
A records system that cannot quickly locate a complete record — because the chart is split between an EHR and an off-site paper file — is the most common cause of missed access deadlines. Consolidating legacy paper into the EHR is therefore both an efficiency measure and a compliance one.
Secure destruction and certificates of destruction
Records do not become safe simply because their retention period has passed. Until they are destroyed, every retained record is exposure. Over-retention enlarges the volume of PHI that can be breached without adding any operational value — a meaningful concern when the average U.S. healthcare data breach costs $7.42 million. Disciplined, documented destruction shrinks that surface.
- Confirm the record has satisfied every applicable retention period — HIPAA, CMS, and Pennsylvania — before any disposal.
- Check for active litigation holds, which suspend destruction regardless of the schedule.
- Destroy paper by cross-cut shredding or pulping, and sanitize electronic media so PHI cannot be reconstructed.
- Obtain a certificate of destruction documenting what was destroyed, when, by whom, and by what method.
- Retain the certificate itself; as compliance documentation, it falls under the six-year HIPAA retention requirement.
Destruction performed without a certificate is, from an auditor's perspective, indistinguishable from a missing record. The certificate of destruction is the evidence that disposal was authorized, complete, and compliant.
Managing paper in the EHR era: back-file conversion
Electronic records are now the norm, but paper has not disappeared. Office-based physician adoption of any EHR more than doubled from 42% in 2008 to 88% in 2021, and reached just 18% as recently as 2001 — meaning two decades of charts were created on paper and still need to be reconciled with modern systems. Among office-based physicians, 78% had adopted a certified EHR by 2021, and nearly all non-federal acute care hospitals — 96% — had done so, up from only 9% in 2008.
That widespread adoption concentrates records in a handful of platforms, which shapes how scanned paper must be indexed for import. In 2024, Epic held 42.3% of U.S. acute care hospitals by market share — and 54.9% measured by hospital beds — while Oracle Health, formerly Cerner, held 22.9% of acute care hospitals.
| EHR vendor | U.S. acute care hospital share (2024) |
|---|---|
| Epic | 42.3% |
| Oracle Health (formerly Cerner) | 22.9% |
Back-file conversion is the work of digitizing legacy paper and indexing it so it lands cleanly in the EHR under the right patient and document type. Done well, it ends the split-chart problem behind missed access deadlines and lets the organization apply its retention schedule and audit controls uniformly. Done poorly — scanned without indexing or quality validation — it simply moves the problem to a new medium.
What HIPAA-compliant records digitization costs
Medical records scanning typically costs 7 to 12 cents per page before indexing and HIPAA-specific handling. For most medical practices, 10 cents per page or above is the typical quoted rate once HIPAA controls and indexing are included. The variation reflects how much preparation each chart needs: production scanners process hundreds of pages per hour, but staples, clips, and fasteners must be removed during chart prep or paper jams slow the run.
| Page volume | At $0.07/page | At $0.10/page (typical medical floor) | At $0.12/page |
|---|---|---|---|
| 1,000 pages | $70 | $100 | $120 |
| 50,000 pages | $3,500 | $5,000 | $6,000 |
| 600,000 pages | $42,000 | $60,000 | $72,000 |
Worked example (illustrative): a multi-site Lehigh Valley practice closing out a records room holding roughly 600,000 pages would budget about $42,000 at the 7-cent rate, $60,000 at the 10-cent medical floor, and $72,000 at 12 cents — each figure simply the cited per-page rate multiplied by the page count. Indexing, chart preparation, and HIPAA chain-of-custody handling are additional and are why medical scanning tends toward the upper end of the range.
When evaluating quotes, the per-page number is only the starting point. Indexing to the correct patient and document type, image-quality validation, and a documented chain of custody under a business associate agreement are what make the scan defensible — and what separate a healthcare-grade provider from a commercial copy service.
The HIPAA records-management implementation checklist
Use the following as a working checklist. It consolidates the obligations above into actions an HIM or compliance lead can assign, track, and audit.
- Inventory all record types across paper and electronic systems, including hybrid charts.
- Build a retention schedule mapping each record to HIPAA, CMS, and Pennsylvania requirements, controlled by the longest period.
- Retain HIPAA compliance documentation — policies, risk analyses, BAAs, training, breach logs — for at least six years.
- Implement all five technical safeguards from 45 CFR 164.312: access control, audit controls, integrity, authentication, and transmission security.
- Make an encryption decision for ePHI at rest and in transit, and document it as required for an addressable specification.
- Enable tamper-evident audit logging on every system containing PHI.
- Apply unique user IDs and role-based access so staff see only the records their role requires.
- Define a right-of-access workflow that fulfills requests within 30 days, with the one permitted 30-day extension handled in writing.
- Charge only reasonable, cost-based fees for record copies, never as a barrier to access.
- Establish a destruction process with cross-cut shredding or media sanitization and a certificate of destruction for every disposal.
- Honor litigation holds that suspend the retention and destruction schedule.
- Plan back-file conversion of legacy paper, indexed for clean import into your EHR.
- Require a signed business associate agreement and documented chain of custody from any scanning or storage vendor.
- Review the entire program and retention schedule at least annually and version every change.
Common mistakes and when not to digitize everything
Most records-management failures are not exotic. They are predictable lapses that a checklist prevents.
- Assuming HIPAA sets the medical-record retention period — it sets six years for documentation, not for the chart itself.
- Retaining everything forever, which enlarges the breach surface without adding value.
- Treating encryption as optional because it is addressable, without documenting the decision.
- Scanning paper without indexing or quality validation, which recreates the split-chart problem electronically.
- Destroying records without a certificate of destruction, leaving no proof disposal was compliant.
- Using a retail or free scanning option for PHI; such services generally cannot sign a business associate agreement or provide a documented chain of custody.
- Missing the 30-day access deadline because the complete record cannot be located across systems.
Digitization is not always the right answer for every box. Records already past their retention period should be destroyed, not scanned — paying to digitize a record you are legally clear to dispose of is wasted spend and added exposure. The disciplined sequence is to apply the retention schedule first, destroy what has aged out, and digitize only what must be kept and actively used.
The Pennsylvania and Lehigh Valley angle
Healthcare organizations in Pennsylvania carry the federal HIPAA obligations plus state-specific medical-record retention rules, and those state periods can exceed the HIPAA documentation floor. For HIM teams in Allentown, Bethlehem, Easton, and the wider Lehigh Valley, that means a retention schedule built only around HIPAA's six-year documentation minimum is incomplete — CMS program rules and Pennsylvania law govern the records themselves and must be confirmed with counsel.
Reynolds Business Systems has supported records-intensive organizations across eastern Pennsylvania for more than five decades, applying the same retention, access-control, and certified-destruction discipline described here. Local presence matters in records work: chain of custody, on-site chart preparation, and same-region response are easier to verify and document when the provider is in the same market as the records.
Frequently asked questions
How long are you legally required to keep medical records?
There is no single federal answer. HIPAA requires keeping compliance documentation for at least six years, but not the medical record itself. The record is governed by CMS — five years for Medicare hospital records and ten years for Medicare managed care — and by state law. Pennsylvania sets its own periods, which can exceed the HIPAA documentation minimum, so confirm the current state requirement with counsel.
Does HIPAA require a specific retention period for medical records?
No. HIPAA's six-year retention requirement applies to compliance documentation such as policies, risk analyses, business associate agreements, and training logs. The retention of the medical record itself is set by CMS program rules and each state's medical-record law. Treating the six-year HIPAA documentation rule as the chart's retention period is one of the most common compliance errors.
How much does it cost to have documents scanned?
Medical records scanning typically runs 7 to 12 cents per page before indexing and HIPAA-specific handling. For most medical practices, 10 cents per page or above is the typical quoted rate once HIPAA controls and indexing are included. Chart preparation — removing staples, clips, and fasteners so production scanners do not jam — and indexing to the right patient drive the variation.
How much does it cost to scan 1,000 pages?
At the cited 7-to-12-cent-per-page range, 1,000 pages works out to roughly $70 to $120 before indexing and HIPAA handling — about $100 at the 10-cent medical floor. That is example math from published per-page rates; the final figure depends on chart preparation, indexing requirements, and the chain-of-custody controls a healthcare-grade provider builds in.
What does a medical records scanner do?
A production scanner converts paper charts into searchable digital images at high speed — hundreds of pages per hour. In a HIPAA workflow it is paired with chart preparation to remove staples and fasteners, indexing to file each document under the correct patient and record type, and image-quality validation, so the scanned record imports cleanly into the EHR and remains complete and legible.
How quickly must we respond to a patient's request for their records?
Under the HIPAA right of access at 45 CFR 164.524, a covered entity must act on a request no later than 30 days. One extension of up to 30 additional days is permitted if you notify the individual in writing within the first 30 days, explaining the delay and giving a completion date. Missing this deadline is among the most heavily enforced HIPAA violations.
What are the HIPAA technical safeguards for stored records?
The Security Rule at 45 CFR 164.312 sets five technical-safeguard standards for electronic PHI: access control, audit controls, integrity, person or entity authentication, and transmission security. Encryption is an addressable specification — required where reasonable and appropriate, with the decision documented. Together these standards make role-based access and a tamper-evident audit trail the core of compliant records storage.
Do we still need records management if we are fully on an EHR?
Yes. Even with 88% of office-based physicians and 96% of non-federal acute care hospitals on EHRs by 2021, the obligations remain: six-year retention of HIPAA documentation, the five technical safeguards, audit logging, right-of-access fulfillment, and certified destruction. Most organizations also hold legacy paper that predates the EHR and still must be retained, converted, or destroyed under the schedule.
What is a certificate of destruction and why does it matter?
A certificate of destruction documents what records were destroyed, when, by whom, and by what method. It is the evidence that disposal was authorized, complete, and compliant. Without it, destruction is indistinguishable from a missing record during an audit. Because it is compliance documentation, the certificate itself falls under HIPAA's six-year retention requirement.
Can we destroy paper records after scanning them?
Often, but only after two conditions are met: the record has satisfied every applicable retention period — HIPAA, CMS, and Pennsylvania — and the scanned image has passed quality validation so the digital copy is complete and legible. Confirm no litigation hold applies, destroy the paper securely, and keep the certificate of destruction as proof.
Can we scan HIPAA records at a retail store or free service?
For protected health information, retail or free scanning options are generally not appropriate. HIPAA requires a signed business associate agreement and a documented chain of custody from any party that handles PHI, which commercial copy and free consumer services typically cannot provide. Healthcare records should be digitized by a provider that operates under a BAA with healthcare-grade controls.
Why does healthcare have the highest data breach costs?
Healthcare has had the most expensive breaches of any industry for 14 consecutive years, averaging $7.42 million in the U.S. in 2025 — even after a $2.35 million year-over-year decline — against an all-industry U.S. record of $10.22 million. Sensitive PHI, regulatory exposure, and a 279-day average detection-and-containment lifecycle combine to drive the cost, which is why access control and secure destruction matter.
Sources Cited
20 REFS- Office of the National Coordinator for Health IT / ASTP (HealthIT.gov)
- Office of the National Coordinator for Health IT / ASTP (HealthIT.gov)
- The HIPAA Journal (reporting IBM 2025 Cost of a Data Breach Report)
- IBM (with Ponemon Institute)
- Legal Information Institute, Cornell Law School
- Legal Information Institute, Cornell Law School
- Centers for Medicare & Medicaid Services (CMS)
- Record Nations
- Record Nations
- Armstrong Archives
- HIT Consultant (reporting KLAS Research US Acute Care EHR Market Share 2024)
- KLAS Research
- The HIPAA Journal
- Agency for Healthcare Research and Quality (AHRQ) Digital Healthcare Research
- Modern Image Atlanta
- Emerald Document Imaging



