HIPAA Compliance for Optometry
How Long Do I Have to Keep HIPAA Records?
Nearly every retention mistake in a small practice comes from collapsing those two rules into one number. They are not the same rule, they do not cover the same documents, and they do not start on the same day.
Clock one: HIPAA documentation — six years
The Security Rule requires covered entities to retain required documentation for six years from the date of its creation or the date when it last was in effect, whichever is later. This is the clock people mean when they say "HIPAA is six years." It covers the paperwork that proves your program existed:
- Security risk analyses and risk management plans
- Written policies and procedures, including retired versions
- Workforce training records and signed acknowledgments
- Business associate agreements, including expired ones
- Incident and breach logs, investigations, and notification records
- Access authorization records, account reviews, and termination checklists
- Notices of Privacy Practices and acknowledgment records
- Patient authorizations, restriction requests, and accountings of disclosures
- Sanction records, contingency plan tests, and system activity reviews
- Certificates of destruction for disposed media and paper
"Or last in effect" is the part that trips people up
A policy written in 2018 and replaced in 2025 is not eligible for disposal in 2024. It was in effect until 2025, so the six-year clock starts in 2025 — meaning you hold it until 2031. The same applies to a BAA signed years ago with a vendor you dropped last quarter: six years from when the agreement ended, not from when it was signed.
Clock two: patient records — state law, not HIPAA
HIPAA does not set a medical record retention period. That comes from your state's optometry or medical board, your state's general health records statute, Medicare and Medicaid conditions of participation, and your commercial payer contracts. Requirements commonly land somewhere in the five to ten year range for adults, and are frequently much longer for minors — often measured from the age of majority rather than the date of service.
If you are licensed in more than one state, or you see patients from neighboring states, the practical answer is to apply the longest requirement that touches you. Verify the current rule with your state board rather than relying on a number someone repeated at a conference — these get amended, and the penalty for guessing short is worse than the cost of storage.
Retention is the easy half. Retrieval is the hard half.
Six years of evidence you cannot produce on demand is functionally the same as no evidence. Investigators do not grade you on whether documents exist somewhere; they grade you on what arrives before the deadline in the letter.
To count, a record generally needs to be:
- Dated — and dated by something more reliable than the file's modification timestamp, which changes the moment somebody opens and re-saves it.
- Attributable — tied to a specific person, not "the front desk."
- Unaltered, or versioned — you can show what the document said at the time it mattered.
- Findable — retrievable in hours, not by digging through a former manager's e-mail archive.
What a workable retention setup looks like
- One managed store. Every compliance document lives in one place. If a policy exists as a Word file on somebody's desktop, that is not a document — it is a finding.
- Write-once storage for evidence. Logs, signed reports, and incident records should land somewhere they cannot quietly be edited or deleted, including by you. Immutability is what turns a file into evidence.
- Version, do not overwrite. When a policy is updated, the old one stays, dated. Overwriting destroys the record of what was in effect during the period being investigated.
- Index by obligation, not by folder mood. Organize the way a data request is written — risk analysis, training, BAAs, incidents, access — so producing documents is retrieval rather than a search party.
- Keep departed employees' records. Training records, acknowledgments, and termination checklists for former staff are frequently the exact documents requested, and frequently the first ones deleted.
- Confirm your storage vendor is covered. If backups or archives contain PHI, that vendor needs a BAA too.
When you do dispose of something
Destruction is a compliance event of its own. PHI must be rendered unreadable — shredding or approved destruction for paper, and secure wiping or physical destruction for drives. Get a certificate of destruction and keep it, because the certificate is now part of your six-year documentation.
That old server in the closet, the retired lane PC, the imaging workstation swapped out three years ago: if the drives were never wiped and never documented, you have both an unmanaged copy of patient data and no record of what happened to it. This is a routine finding and an entirely avoidable one.
Common questions
Do I keep BAAs for vendors I no longer use?
Yes — six years from the date the agreement was last in effect. Terminating the relationship starts the clock, it does not clear it.
Do I keep training records for employees who left?
Yes. If an investigation covers a period when that person worked for you, their training record is exactly what proves your program was real at the time.
Can I keep everything digitally?
Yes, provided the electronic copies are complete, protected, retrievable, and the originals were destroyed properly and documented.
Is it a problem to keep records longer than required?
Generally no for HIPAA documentation. For patient records the calculus is different — data you hold is data you must protect and may have to produce in litigation — so follow a written retention schedule rather than keeping everything forever by accident.
Question twelve of the self-assessment asks a simple thing: could you produce six years of compliance evidence without scrambling? Three minutes, an honest grade, and a list of exactly what you would be missing.
Take the Free Self-AssessmentMacula Networks provides HIPAA compliance evidence and IT services to independent optometry practices nationwide. This article is general information, not legal advice. Retention periods, state requirements, and penalty amounts change; verify current requirements for your state and situation.