← All posts
Filed in / hipaa · compliance

HIPAA Retention Requirements: Medical Records, Policies, and Audit Logs

In this piece
  1. 01 Does HIPAA require six years of medical records?
  2. 02 What does the six-year rule cover?
  3. 03 Must every audit log be kept for six years?
  4. 04 Create a schedule before choosing settings
  5. 05 Test preservation and deletion separately
  6. 06 Connect retention to everyday administration

HIPAA’s six-year documentation requirements are not a universal retention schedule for medical records or raw audit logs. Identify the record category and applicable requirements before choosing a deletion setting.

Start by identifying what the information is, which requirements apply, and when its retention clock begins. Then configure the systems that hold it.

Does HIPAA require six years of medical records?

HHS says the HIPAA Privacy Rule does not set a medical-record retention period; state law generally governs those schedules. HIPAA privacy safeguards still apply while the records are maintained, including during disposal. See the HHS medical-record retention FAQ.

Have the organization’s records owner and legal reviewer identify the applicable requirements for each record category and jurisdiction. Do not substitute a vendor’s default deletion setting for that review. A billing company handling records for multiple clients may need separate instructions for different relationships.

What does the six-year rule cover?

The Security Rule requires certain policies, procedures, and documentation of required actions, activities, or assessments to be retained for six years from creation or the date last in effect, whichever is later. See 45 CFR 164.316(b).

For covered entities, the Privacy Rule also has a six-year requirement for documentation within its scope, using the later of creation or last effective date. See 45 CFR 164.530(j).

Consider a security policy created in 2026 and replaced in 2029. If it was last in effect in 2029, its Security Rule documentation clock runs from that later date. Saving only the newest policy loses the history needed to explain which procedure applied earlier.

Must every audit log be kept for six years?

The audit-controls standard requires mechanisms to record and examine activity in systems containing or using ePHI. It does not state a universal retention duration for every raw event. See 45 CFR 164.312(b).

Distinguish the underlying event stream from documentation the rules require you to retain. Some log material may also become evidence supporting an assessment or investigation. Do not assume that either all raw events or none of them fall within a particular retention obligation.

Have the security and records owners document the decision for each log source, considering investigation needs and other applicable requirements. Confirm that the service can preserve and retrieve the evidence your process depends on.

Create a schedule before choosing settings

Use a worksheet that separates the categories:

Category Decision to document
Medical or clinical records Applicable schedule and event that starts it
Required HIPAA documentation Rule scope, creation date, and last effective date
Raw application logs Retention rationale and investigation needs
Incident evidence Preservation scope and responsible reviewer
Working copies and exports Whether they are records, and approved disposal conditions
Backups and archives Retained content, restore process, and expiration behavior

An email or chat message should be classified by its content and purpose, not just its file type. A mailbox-wide setting may contain several record categories. Resolve those conflicts with the records owner before enabling automatic deletion.

Evaluating how your approved schedule would work in a new workspace? Request a healthcare pilot with a retention exercise for IRONKEEP’s private beta. Bring a sample record category and its approved schedule to scope a test with fictional records and review BAA needs.

Test preservation and deletion separately

Use fictional records to evaluate how the proposed settings behave. Create two items in the same category, place one under a test preservation instruction if the service supports it, and confirm what happens when ordinary retention would remove them.

Ask who can change the schedule, who can release a hold, and what evidence records those actions. Check whether account deletion, an integration, or an export creates a different path from the one demonstrated.

Also ask how backups behave. An item disappearing from a user’s screen does not answer whether a retained copy exists elsewhere. Document which copy is being discussed whenever a vendor says information is deleted.

Connect retention to everyday administration

Use the test results to check whether the system follows the approved retention policy.

Link the schedule to your ePHI inventory and offboarding process. That helps the administrator distinguish ending a person’s access from disposing of organizational records.

Bring the approved schedule, the person authorized to change it, and the expected preservation result to the evaluation. Keep the test results with the policy decision so the next administrator can understand why the settings were chosen.

Healthcare · Private beta

Scope your healthcare workspace.

Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.

Request a healthcare pilot