Legal Length of Time to Keep Medical Records by State

A medical records administrator organizes patient files in a secure healthcare archive.

Medical records are crucial legal documents, and healthcare providers have to keep them for specific periods. The length of time you need to keep medical records depends on both federal rules and state laws.

Most states require records to be kept between 5 and 10 years for adult patients, but some states ask for longer. Knowing these requirements protects both providers and patients.

A medical records administrator organizes patient files in a secure healthcare archive.

Health professionals have legal and professional obligations to maintain proper medical records. The rules around medical record retention can get complicated because different laws apply depending on your location and the records you keep.

Things like patient age, type of treatment, and possible legal claims all affect how long you should keep these documents. If you know the correct retention period, you’ll stay compliant and avoid storing files longer than needed.

Key Takeaways

  • Medical record retention periods vary by state, usually ranging from 5 to 10 years for adults.
  • Special rules apply to minors and certain sensitive records, which might need longer storage.
  • Providers must securely destroy records after the retention period to protect patient privacy.

Which Rules Set the Retention Deadline?

A healthcare compliance professional reviews organized medical records beside a secure archive, laptop, calendar, and legal symbols.

Several layers of regulations determine how long you have to keep medical records. State laws usually set the main requirements, but federal rules like HIPAA and Medicare add their own timelines.

State Laws Usually Control Clinical Records

State laws set the basic retention periods for patient records. Each state sets its own minimum timeframes, often between five and ten years after the last patient visit.

Your state medical board or health department typically publishes these rules. Some states make you keep records longer for minors—sometimes until the patient reaches adulthood plus extra years.

Hospitals must maintain accurate records and follow regulations for destroying them. State statutes of limitations for medical malpractice also affect how long you keep records, since you may need them for legal claims.

HIPAA’s Six-Year Documentation Rule

The Health Insurance Portability and Accountability Act (HIPAA) requires covered entities to keep certain documentation for six years. This HIPAA compliance requirement covers policies, procedures, and records about HIPAA Privacy and Security rules.

You need to keep records showing how you protected health information (PHI) and maintained security. This means saving privacy practices documentation, breach notifications, business associate contracts, and training materials.

The six-year period starts from when you created the document or when it was last in effect, whichever is later. HIPAA doesn’t actually set a retention period for patient medical records themselves—state law does that.

Medicare, Medicaid, and Program-Specific Requirements

Medicare Conditions of Participation require providers to keep medical records for at least five years. Medicare managed care organizations follow similar timelines.

Medicaid programs might have different requirements, depending on your state. Federal rules usually ask for five years, but your state Medicaid agency could require more.

If you take part in research, clinical trials, or grant-funded programs, you might have to keep records even longer. Sometimes, you need to keep them for three years after the final financial report.

Use the Longest Applicable Requirement

When more than one rule applies, you need to follow the longest retention period. Check your state law, federal rules, and any program-specific requirements.

Set up a retention schedule that lists all the rules for each type of record. This helps you stay compliant.

You must retain records for the minimum period set by federal and state legal guidelines and keep a log for destroyed records. Protected health information stays under HIPAA during the retention period, so you have to keep it secure until it’s destroyed.

State-by-State Retention Periods

A healthcare compliance professional organizes medical records beside a map of the United States.

Retention requirements for medical records vary a lot by state. Some states want records kept for 10 years or more, while others set shorter timelines or leave it up to providers.

How Adult and Hospital Requirements Differ

Most states set different rules for adult patient records and other types of documentation. Adult patient records usually need to be kept for 5 to 10 years after the last visit or discharge.

Hospitals often have to keep records longer than individual doctors or clinics. Hospitals may need to keep surgical records, ER visits, and inpatient notes for extended periods.

This difference matters because you might work in a place where several retention periods apply. For instance, a hospital may need to keep records for 10 years, while a private practice keeps them for 7. Always check which rules apply to your setting.

Some states also separate active and inactive records. Active records are for patients still getting care, while inactive ones are for those not seen in years.

States With Extended Retention Rules

Some states require you to keep adult medical records for 10 years or more. These longer periods often relate to legal risks and the value of historical health information.

States with 10+ years retention:

  • California: 7 years minimum, but longer if there are pending legal matters
  • Massachusetts: 30 years for hospital records
  • New York: 6 years from discharge, longer for some records
  • Florida: 5 years from last contact, but longer for minors

Some states tie retention periods to statute of limitations for malpractice claims. This means you might need to keep records even longer than the administrative minimum.

Rhode Island and Connecticut have extended timelines for some hospital records. These rules reflect the complex care hospitals provide and possible future needs.

States With Shorter or No Fixed Statutory Period

Not every state sets a specific retention period in law. Some leave it up to providers, professional standards, or federal rules.

States without set periods include Wyoming, South Dakota, and others that rely on professional guidelines. In these places, you usually follow Medicare’s five-year rule or your professional association’s advice.

Common approaches in flexible states:

  • Use federal Medicare/Medicaid rules
  • Follow medical association guidelines
  • Keep records according to facility policy
  • Retain records for the statute of limitations period

Even if the state doesn’t set a rule, you should keep records long enough for possible legal claims, continuity of care, and audits. No state rule doesn’t mean you have no responsibility.

Texas, Georgia, and Illinois have mixed rules—some records have set periods, others rely on professional judgment. This variation in telemedicine and medical records laws can make things tricky for practices in multiple states.

How to Verify a Current State Requirement

You should check requirements often, since states can change health legislation and update retention schedules.

Start with your state’s health department or medical licensing board website. Most states post retention rules in administrative codes or facility regulations.

How to check:

  1. Look up your state medical board or health department
  2. Review hospital or facility licensing rules
  3. Ask your liability insurance carrier
  4. Check with your state hospital association
  5. Consider talking to a healthcare attorney

Washington’s RCW 70.41.190 is one example of a law that sets out hospital record retention. Your state probably has similar rules.

Professional associations often give guidance that blends legal minimums and best practices. These resources help you know not just what’s required, but what’s smart.

Retention laws now include electronic records and set timelines for each type of information. Make sure you check rules for both paper and digital records.

Special Rules for Minors and Sensitive Records

Minor patient records have different rules because the statute of limitations doesn’t start until the patient becomes an adult. Mental health and certain specialized records may also need to be kept longer.

Calculating the Deadline for Minor Patient Records

You need to keep minor patient records longer than adult ones. The retention period usually begins when the patient turns the age of majority, not when you provided care.

Most states want you to keep records until the minor reaches the age of majority plus the statute of limitations. For example, if your state says keep records for seven years and adulthood is 18, you’d keep them until the patient turns 25.

Common ways to calculate:

  • Age of majority + statute of limitations
  • Age of majority + standard period (often 7–10 years)
  • Until the patient is 21–26, depending on state law

Always check your state’s specific rules—they can differ a lot.

The Age of Majority and Statute of Limitations

In most states, the age of majority is 18, but a few set it at 19 or 21. This age starts the clock for potential malpractice claims.

California requires you to keep minor records at least one year after the patient turns 18. Nevada asks you to keep them until the patient is 23 or for five years after treatment, whichever is longer. North Carolina wants you to keep them until the patient turns 19 plus the standard retention period.

The statute of limitations for medical malpractice claims varies by state, usually between two and six years. When keeping records for minors, you have to consider both the age of majority and the limitations period to protect yourself from legal trouble.

Mental Health and Other Specialized Records

Mental health records require special confidentiality protections. These records often have longer retention requirements than general medical records.

You may need to keep them longer because they’re sensitive and might be important for future patient care. Many states require you to keep mental health, substance abuse, and HIV/AIDS records for extended periods.

Some jurisdictions say you must keep these sensitive records permanently or much longer than standard medical records.

Specialized records with unique requirements include:

  • Substance abuse treatment records
  • HIV/AIDS testing and treatment
  • Genetic testing results
  • Records involving abuse or neglect

You should check both federal regulations and your state’s rules for these records. They often include extra privacy protections beyond HIPAA.

Building a Defensible Retention Schedule

A defensible retention schedule starts with identifying record types, setting trigger dates, and following legal timelines. It’s also smart to plan for changes in your practice that might affect how you keep records.

Identify the Record Type and Trigger Date

Different records have different rules for how long you keep them. Electronic health records and paper records usually need separate trigger dates for when the retention period starts.

The trigger date often begins when you close a patient file or finish their last treatment. For adults, most states want you to keep records for 5 to 10 years after that date.

Minor patient records usually need to be kept longer—often 1 to 3 years after the patient reaches the age of majority. Medicare and Medicaid records must be kept at least 5 years from the date of service.

You should group records by type, such as:

  • Treatment records (progress notes, test results, imaging)
  • Administrative records (billing, insurance claims, authorizations)
  • Consent forms (surgery consents, HIPAA authorizations)
  • Correspondence (referral letters, patient communications)

Each group might have different state and federal retention rules.

Account for Audits, Claims, and Legal Holds

Sometimes you need to keep records longer because of audits, claims, or litigation. Legal holds stop you from destroying records if they’re part of an ongoing case or investigation.

The statute of limitations in your state sets how long patients can file malpractice claims. You need to keep records until that window closes.

Some states allow claims up to 10 years after the event or when the harm was discovered. Medicare audits can look back 4 years from the date of service.

State licensing boards might request records during investigations, sometimes with no time limit. You should keep records that are part of:

  • Active lawsuits or threatened legal action
  • Government audits or investigations
  • Insurance claim disputes
  • Board complaints or peer reviews

Your electronic records system should flag any files under legal hold so you don’t delete them by mistake.

Preserve Records Through Practice Closures and Transfers

If you close your practice or transfer ownership, you need to make sure patients can still get their records. State boards require you to notify patients and give them enough time to request copies.

You must plan to store records for the full retention period, even after closing. You can transfer them to another provider, use a storage company, or scan paper records into an electronic system.

The new custodian must follow all HIPAA security requirements for both electronic and paper records.

Your closure plan should include notifying patients at least 30 to 90 days ahead. Tell them where their records will be and how to access them.

Some states want you to publish closure notices in local newspapers or keep a forwarding address for record requests.

Patient Access and Secure Record Management

Healthcare providers have to balance giving patients quick access to their records and keeping health information secure. This applies to both paper and electronic records, from start to finish.

Maintaining Access Throughout the Retention Period

The HIPAA Privacy Rule says you must give patients access to their protected health information within 30 days of their request. This rule lasts as long as you keep the records—7 years or more, depending on state law.

You need systems to retrieve both active and archived records. For electronic health records, your software should let you access old data, even after upgrades.

For paper records, keep storage organized and indexed. Patients can ask for copies in the format they prefer, if possible.

You can charge reasonable fees for copying and mailing, but you can’t deny access because of unpaid bills. Your privacy notices should explain how to request records and what fees apply.

Track and respond to all access requests within the required time. If you can’t meet the 30-day deadline, you can extend once by 30 days, but you need to explain this in writing to the patient.

Protecting PHI in Paper and Electronic Files

The HIPAA Security Rule sets standards for protecting electronic records, while the Privacy Rule covers all PHI. You should run regular risk assessments to spot weak points in how you store and send PHI.

Electronic records need:

  • Encryption for stored and transmitted data
  • Access controls to limit who sees what
  • Strong passwords and multi-factor authentication
  • Automatic logoff for idle sessions
  • Regular software updates and security patches

Paper records need locked cabinets, restricted areas, and secure disposal like shredding. Never leave paper files unattended in public spaces.

Both types require staff training on handling procedures and HIPAA compliance. Have written policies for storing, sending, and destroying records securely.

Documenting Access, Changes, and Disclosures

Audit trails show who accessed patient info, when, and what they did. Electronic health records systems must keep detailed logs of all user activity.

Your logs should note login times, records viewed, changes made, and any printing or downloading. You have to keep these logs for at least 6 years under HIPAA.

Track all disclosures of PHI, except for treatment, payment, healthcare operations, or those the patient authorized. Patients can ask for a list of disclosures from the past 6 years.

Your tracking system should record the date, recipient, purpose, and info shared. Reviewing audit trails regularly helps catch suspicious access, like staff looking at records of family or famous people.

Investigate anything odd as soon as possible and take action if needed.

Destruction After the Retention Period Ends

When the retention period ends, you need to destroy records securely. Make sure it’s allowed, use approved methods, and document everything.

Confirm That Destruction Is Permitted

Before destroying records, double-check that the required retention time is over based on your state’s laws. Don’t destroy records if there’s a legal hold, lawsuit, or ongoing investigation involving the patient.

Some record types have extra rules. For example, minor patient records often need to be kept until the patient is an adult, plus the standard retention time.

Records tied to malpractice claims or government audits must be kept, even if the regular retention period is up.

Always review your retention schedule against current laws before moving forward. Laws and procedures for medical records retention can vary a lot depending on where you are.

Methods for Destroying Paper and Electronic Records

You must use HIPAA-compliant methods so PHI can’t be read or put back together. For paper records, shred, burn, or pulverize them until the info can’t be reconstructed.

Electronic records need different methods. Degaussing scrambles magnetic data, making it unrecoverable. You can also crush or shred hard drives and storage devices.

Never just delete files or toss paper records in the trash. Those methods don’t meet HIPAA standards. Make sure no one can access any info after disposal, no matter the format.

Maintain a Destruction Log and Vendor Documentation

Keep detailed records of every destroyed medical record. Your destruction log should include the patient name or ID, date destroyed, method used, and who did or watched the destruction.

If you use a vendor, get certificates of destruction to prove HIPAA-compliant methods were used. Keep these certificates permanently.

This documentation shows you followed the rules if anyone questions what happened to the records later. Your destruction log is proof you kept records for the right amount of time and disposed of them properly.

Frequently Asked Questions

How long you must keep medical records depends on federal and state law, provider type, and the patient’s age. Different strategies and laws exist regarding retention time in different places.

How long are hospitals required to keep patient medical records?

Hospitals usually have to keep adult patient records for at least six years from the last treatment or discharge. This comes from Medicare rules for hospitals receiving federal funds.

Many hospitals actually keep records longer than the minimum. They do this to protect themselves from legal issues, since medical malpractice claims can show up years after treatment.

For minors, hospitals generally keep records until the patient reaches adulthood plus the statute of limitations. This can mean holding onto pediatric records for many years after treatment.

How long must doctors retain medical records after a patient’s last visit?

Private doctors usually need to keep records for at least six to seven years after your last visit. The exact time depends on your state’s medical board rules and the statute of limitations for malpractice.

Some states require even longer. Some doctors prefer to keep records longer just in case you come back for care.

Do medical record retention requirements vary by state?

State laws stipulate different retention periods for medical records. Some states have a set timeframe for all records, while others vary it based on provider type or patient age.

You’ll need to check your own state’s regulations to know the exact requirements. Federal law sets a minimum, but states can require more.

How long are medical records kept after a patient dies?

After a patient dies, providers usually keep records for the same amount of time as for living patients. This is typically six to ten years from the date of death, depending on state law.

Some places keep deceased patient records longer. These records might be needed for legal matters, family health history, or research.

Can I request medical records from more than 20 years ago?

You can ask for old records, but the provider might not have them anymore. After the legal retention period ends, facilities can destroy records according to their policy.

Many providers now use electronic systems that make long-term storage easier. But if your records were made before electronic systems, they might have been destroyed after the retention period.

Your best bet is to contact the facility directly and see if they still have them.

What happens to medical records after the required retention period ends?

Healthcare providers can legally destroy medical records after the required retention period ends. The destruction of medical records raises legal concerns that facilities must carefully consider.

Providers have to follow clear procedures when they destroy records. Most use shredding or secure electronic deletion to make sure your privacy stays protected.

Some facilities decide to keep records for longer than the law requires. That usually depends on things like storage space, what kind of records they are, or whether they might help with future patient care or research.

Leave a Reply

Your email address will not be published. Required fields are marked *

Prev
Is Medical Law in Demand? Careers and Growth Drivers
A lawyer, physician, and healthcare administrator discuss documents in a modern office.

Is Medical Law in Demand? Careers and Growth Drivers

Medical law sits at the crossroads of healthcare and legal practice

Next
Legal Medicine vs Forensic Medicine: Key Differences

Legal Medicine vs Forensic Medicine: Key Differences

A lot of people use “legal medicine” and “forensic medicine” like they’re

You May Also Like