Skip to main content

HIPAA Retention Schedule

D
Written by Drew Salisbury
Updated over 6 months ago

Purpose:

Specify retention periods for HIPAA-related documentation under §164.530(j).

Instructions:

  • Categorize records by type (e.g., training logs, disclosure logs).

  • Define retention periods and review annually.

  • Ensure secure archival or disposal.

Optional Template:

Purpose:

This template provides a framework for tracking and enforcing HIPAA’s six-year documentation retention rule, ensuring compliance with §164.530(j).

Instructions for Use

  1. Populate with All Relevant Document Types:
    Include all HIPAA-related documentation, such as training records, NPP acknowledgments, and complaint logs.

  2. Ensure Secure Storage:
    Specify secure storage locations to prevent unauthorized access or loss.

  3. Audit Compliance Regularly:
    Verify that all required documents are retained for the full retention period and destroyed securely afterward.

  4. Assign Ownership:
    Clearly define who is responsible for maintaining, reviewing, and securely destroying records.

Retention Schedule Template

Field

Description

Document Type

Type of record (e.g., training logs, disclosure logs, access requests).

Retention Period

Time period for retention (e.g., six years from the date of creation or use).

Regulatory Requirement

Relevant HIPAA section requiring retention (e.g., §164.530(j)).

Storage Location

Location where the document is stored (e.g., secure server, filing cabinet).

Responsible Party

Person or department responsible for maintaining the document.

Destruction Method

Secure method for disposing of records once retention period has expired.

Did this answer your question?