HIPAA Compliance for Optometry

How Long Do I Have to Keep HIPAA Records?

Six years for HIPAA documentation — policies, risk analyses, training logs, business associate agreements, incident reports — measured from the date it was created or the date it was last in effect, whichever is later. Patient medical records are a different clock entirely, set by your state and your payer contracts, not by HIPAA.

Nearly every retention mistake in a small practice comes from collapsing those two rules into one number. They are not the same rule, they do not cover the same documents, and they do not start on the same day.

Clock one: HIPAA documentation — six years

The Security Rule requires covered entities to retain required documentation for six years from the date of its creation or the date when it last was in effect, whichever is later. This is the clock people mean when they say "HIPAA is six years." It covers the paperwork that proves your program existed:

"Or last in effect" is the part that trips people up

A policy written in 2018 and replaced in 2025 is not eligible for disposal in 2024. It was in effect until 2025, so the six-year clock starts in 2025 — meaning you hold it until 2031. The same applies to a BAA signed years ago with a vendor you dropped last quarter: six years from when the agreement ended, not from when it was signed.

Practical translation: for policies, contracts, and anything with a lifespan, retention is measured from the end, not the beginning. When in doubt, keep it.

Clock two: patient records — state law, not HIPAA

HIPAA does not set a medical record retention period. That comes from your state's optometry or medical board, your state's general health records statute, Medicare and Medicaid conditions of participation, and your commercial payer contracts. Requirements commonly land somewhere in the five to ten year range for adults, and are frequently much longer for minors — often measured from the age of majority rather than the date of service.

If you are licensed in more than one state, or you see patients from neighboring states, the practical answer is to apply the longest requirement that touches you. Verify the current rule with your state board rather than relying on a number someone repeated at a conference — these get amended, and the penalty for guessing short is worse than the cost of storage.

Retention is the easy half. Retrieval is the hard half.

Six years of evidence you cannot produce on demand is functionally the same as no evidence. Investigators do not grade you on whether documents exist somewhere; they grade you on what arrives before the deadline in the letter.

To count, a record generally needs to be:

The most common real-world failure is not deletion. It is a compliance history spread across three former employees' e-mail, a shared drive nobody indexed, and a filing cabinet in the break room.

What a workable retention setup looks like

When you do dispose of something

Destruction is a compliance event of its own. PHI must be rendered unreadable — shredding or approved destruction for paper, and secure wiping or physical destruction for drives. Get a certificate of destruction and keep it, because the certificate is now part of your six-year documentation.

That old server in the closet, the retired lane PC, the imaging workstation swapped out three years ago: if the drives were never wiped and never documented, you have both an unmanaged copy of patient data and no record of what happened to it. This is a routine finding and an entirely avoidable one.

Common questions

Do I keep BAAs for vendors I no longer use?

Yes — six years from the date the agreement was last in effect. Terminating the relationship starts the clock, it does not clear it.

Do I keep training records for employees who left?

Yes. If an investigation covers a period when that person worked for you, their training record is exactly what proves your program was real at the time.

Can I keep everything digitally?

Yes, provided the electronic copies are complete, protected, retrievable, and the originals were destroyed properly and documented.

Is it a problem to keep records longer than required?

Generally no for HIPAA documentation. For patient records the calculus is different — data you hold is data you must protect and may have to produce in litigation — so follow a written retention schedule rather than keeping everything forever by accident.

Question twelve of the self-assessment asks a simple thing: could you produce six years of compliance evidence without scrambling? Three minutes, an honest grade, and a list of exactly what you would be missing.

Take the Free Self-Assessment

Macula Networks provides HIPAA compliance evidence and IT services to independent optometry practices nationwide. This article is general information, not legal advice. Retention periods, state requirements, and penalty amounts change; verify current requirements for your state and situation.