Home Health Agency Data Retention: How Long to Keep Records and How to Delete Them Securely
Compliance

Home Health Agency Data Retention: How Long to Keep Records and How to Delete Them Securely

13 min read
SF
Obi Ibeto

Data retention is the compliance obligation that home health administrators most consistently defer until something forces them to address it. The forcing functions are rarely pleasant: an OCR audit requests…

Data retention is the compliance obligation that home health administrators most consistently defer until something forces them to address it. The forcing functions are rarely pleasant: an OCR audit requests documents from six years ago that were deleted because no one knew they were supposed to be kept. A patient files a right-of-access request for records that were destroyed two years before the retention period expired. Litigation counsel asks for the audit logs from the period surrounding a staff termination and discovers they were overwritten on a 30-day cycle because the backup system was never configured for HIPAA retention. A ransomware attacker encrypts 11 years of patient records that could have been securely deleted 4 years earlier, tripling the breach notification scope.

In thirty years of healthcare cybersecurity and compliance work, I have watched the data retention problem cost home health agencies far more than the cost of managing it correctly would have. It is not a glamorous compliance topic. It does not generate the anxiety that ransomware does or the urgency that an OCR letter produces. But the liability it creates — from records retained too long, from records deleted too soon, and from records destroyed without adequate documentation of the destruction — is as real as any other compliance gap in the HIPAA framework.

This guide provides the complete data retention and secure deletion framework for home health agencies: what must be kept, for how long, under which regulatory authority, and how to ensure that what is destroyed is destroyed in a manner that holds up to forensic scrutiny.

The Two Distinct HIPAA Retention Frameworks — and Why Confusing Them Is Costly

The most common data retention mistake at home health agencies is applying a single retention rule to all records — typically "keep everything for seven years" or "keep everything for ten years" — without distinguishing between the two distinct retention frameworks that HIPAA and state law create. Understanding the distinction is foundational because the frameworks have different triggering documents, different retention periods, and different legal authorities.

Framework 1: HIPAA Documentation Retention

The HIPAA Privacy Rule at 45 CFR § 164.530(j) and the Security Rule at 45 CFR § 164.316(b)(2) require covered entities to retain the documentation required by those rules for a period of six years from the date of its creation or the date when it was last in effect, whichever is later. This framework applies specifically to the compliance programme documentation that HIPAA requires you to create and maintain — not to patient clinical records.

The "date when it was last in effect" provision is particularly important for policies and procedures. A HIPAA security policy that was replaced by an updated version in 2023 was "last in effect" in 2023, not when it was originally written in 2018. The six-year clock runs from 2023 — meaning the superseded 2018 version must be retained until 2029. Most home health agencies delete superseded policies when they adopt new ones. This is wrong under HIPAA. Every version of every policy must be retained for six years from the date it was superseded.

Framework 2: Patient Medical Record Retention

Patient clinical records — the actual records of care delivered, including OASIS assessments, visit notes, care plans, medication records, and physician orders — are not governed by HIPAA's six-year documentation retention requirement. They are governed by state medical record retention laws, which vary significantly across states and which impose requirements that in many cases exceed six years. A home health agency that applies HIPAA's six-year rule to patient clinical records may be compliant with HIPAA but non-compliant with the state medical record laws that actually govern those records.

Applying the wrong framework to the wrong record type creates two categories of liability simultaneously: destroying records too soon (because state law required longer retention than HIPAA's six years) and retaining records too long (because a rigid seven-year or ten-year blanket policy keeps records past any applicable retention requirement, expanding breach scope unnecessarily).

HIPAA Documentation: The Complete Six-Year Retention Inventory

The following categories of documentation must be retained for six years from the date of creation or the date last in effect, whichever is later. This list is not exhaustive — any document that a HIPAA provision requires you to create, maintain, or review falls within the retention obligation — but it covers the documents most commonly requested in OCR audits and most commonly missing when they are needed.

Security Programme Documentation

       HIPAA Security Officer designation documentation: the written designation of the individual serving as Security Officer, the date of designation, and any changes in designation. Each designation document is retained for six years from the date it was superseded or from the date the Security Officer role ceased.

       Risk analyses and risk management plans: every version of the annual HIPAA Security Rule risk analysis, with its findings and risk ratings, and the corresponding risk management plan documenting controls implemented or planned. Retain each version for six years from its completion date — not from the date it was superseded by the next year's analysis.

       All HIPAA security and privacy policies: every version of every policy in the written information security programme, including superseded versions. Date-stamp every policy with its effective date and its supersession date. A policy document without a clear effective date is difficult to defend in an OCR audit when the investigator asks whether the policy was in effect during a specific period.

       Sanctions policy and documentation of sanctions applied: the policy itself plus any documentation of specific sanctions applied to workforce members for HIPAA violations. Sanctions documentation is often retained in HR files rather than compliance files — ensure both retention systems apply the six-year rule.

Training and Workforce Documentation

       Security awareness training records: individual completion records for every workforce member, for every training cycle, for six years. This is the documentation that most commonly appears in OCR requests and most commonly reveals retention gaps. A training record that shows the completion date, the individual's name, and the training content covered is what HIPAA requires. A class attendance sheet with a checkmark is not.

       Training content and curriculum: the actual training content delivered in each annual cycle — slides, video content descriptions, quiz questions and answers. Retain for six years from the training date. This allows you to demonstrate not just that training occurred but what it covered, which matters when OCR asks whether training addressed a specific requirement that was in effect at the time.

Vendor and Agreement Documentation

       Business Associate Agreements: every executed BAA, including BAAs with vendors who have since terminated their relationship with the agency. An expired BAA with a vendor who no longer has access is still a document that HIPAA required you to have — and OCR may ask whether you had a BAA with a specific vendor during a specific period. Retain for six years from the date the relationship ended.

       BAA amendment and modification documentation: any amendment, addendum, or modification to a BAA, retained for six years from the date of the amendment or from the date the relationship ended, whichever is later.

Incident and Breach Documentation

       Security incident documentation: records of every security incident assessed during the six-year retention period, including incidents that were assessed and determined not to be reportable breaches. The four-factor breach risk assessment record, even for a non-breach determination, is HIPAA documentation subject to the six-year retention requirement.

       Breach notification records: for incidents determined to be reportable breaches — the breach notification letters sent to affected individuals, the HHS OCR breach portal submission, any media notification (for breaches affecting 500 or more residents of a state), and all correspondence with OCR related to the breach. Retain for six years from the date of the notification.

Audit and Monitoring Documentation

       Audit log review records: documentation of each periodic audit log review — who conducted the review, what systems and time period were reviewed, what anomalies were identified, and how they were resolved. The audit logs themselves must also be retained for six years. An audit log that is generated but overwritten on a 90-day cycle does not satisfy the HIPAA audit control and documentation retention requirements simultaneously.

       Vulnerability scan results: reports from each biannual vulnerability scan, including the findings and the remediation tracking documentation. Retain for six years from the date of the scan.

       Penetration test reports: the full penetration test report and the remediation documentation from each annual test. Retain for six years from the date of the test.

Patient Medical Records: The State Law Matrix

Patient clinical records are governed by the state medical record retention laws of the states where care was delivered. For a home health agency serving patients in multiple states, this creates a state-by-state compliance obligation that must be tracked at the patient record level — the applicable retention period is determined by where the patient received care, not where the agency is headquartered.

Key State Requirements for Home Health Agencies

The following represents the retention requirements for patient clinical records in the states with the largest home health populations. Confirm current requirements with legal counsel in each state where you operate, as state laws are subject to revision:

       New York: home care patient records must be retained for at least six years from the date of service, or three years after a patient reaches the age of majority if the patient was a minor at the time of service — whichever period is longer. For most adult patients, this aligns with the HIPAA six-year documentation retention standard. For paediatric patients, the retention obligation extends significantly.

       California: patient records must be retained for a minimum of ten years following the date of service. For patients who were minors at the time of service, records must be retained until the patient reaches age 19 or for seven years following the last date of service, whichever is longer. California's ten-year requirement is among the most demanding in the country and applies to any California patient regardless of where the agency is headquartered.

       Massachusetts: patient records must be retained for at least seven years from the date of service. Massachusetts has additional requirements for records relating to workers' compensation cases and certain insurance claims that may extend retention obligations beyond seven years in specific circumstances.

       Texas: patient records must be retained for ten years from the date of service for adult patients. Records for minor patients must be retained until the patient reaches age 21 or for ten years from the date of service, whichever is longer.

       Florida: patient records must be retained for five years from the date of service for adult patients, or until the patient reaches age 18 for minor patients — whichever is longer. Florida's five-year retention period is shorter than the HIPAA six-year documentation retention standard; apply the longer period (six years) to satisfy both requirements simultaneously.

       Illinois: patient records must be retained for ten years following the date of service. Illinois also requires that medical records of deceased patients be retained for ten years following the date of death.

The Multi-State Retention Strategy

For home health agencies serving patients in multiple states, the practical approach is to apply the most conservative applicable retention period across the entire patient record set rather than tracking each record's applicable retention period individually. If your agency serves patients in California (ten years) and Florida (five years), retaining all patient records for ten years satisfies both state requirements simultaneously. The administrative cost of tracking state-specific retention periods at the individual record level almost always exceeds the cost of applying the most conservative standard uniformly.

The one exception: paediatric patient records, which have extended retention obligations in virtually every state and which should always be flagged at the time of service for the applicable paediatric retention calculation.

Secure Deletion: What "Deleted" Must Actually Mean

The gap between what most home health agencies mean when they say they deleted records and what HIPAA's disposal standard actually requires is one of the most consistent findings in healthcare compliance assessments. Standard file deletion — clicking "Delete," moving to the Recycle Bin, and emptying it — removes the file system entry that points to the data. It does not remove the data itself. The data remains on the storage medium, readable by any forensic tool until it is overwritten by new data. In a healthcare breach investigation, law enforcement or insurance investigators routinely recover data that was "deleted" years earlier.

This matters for two reasons. First, a breach that compromises a storage medium containing data an agency believed it had deleted still creates a breach notification obligation if that data was patient PHI. The agency incurs notification costs and regulatory exposure for records it thought it had destroyed. Second, an agency sued over a breach may face discovery requests for records it thought were gone — and the forensic recovery of "deleted" records it represented as destroyed creates serious credibility problems in litigation.

Compliant Electronic Record Disposal Methods

HIPAA requires that electronic PHI be disposed of in a manner that renders it "unreadable, indecipherable, and otherwise cannot be reconstructed." NIST Special Publication 800-88 (Guidelines for Media Sanitization) provides the technical standards that satisfy this requirement:

       Cryptographic erasure (crypto-shredding): for data stored on encrypted media, rendering the encryption key permanently irrecoverable makes the underlying encrypted data permanently unrecoverable — even if the physical storage medium is subsequently recovered. This is the most efficient disposal method for cloud-hosted data and for data on encrypted device storage. The key management documentation confirming key destruction should be retained as proof of compliant disposal.

       Secure overwriting: for active storage media that will be reused (hard drives, USB drives, SSDs), overwriting the storage space with random data using a NIST-approved overwriting algorithm renders the original data unrecoverable. The DoD 5220.22-M standard (overwrite with 0s, then 1s, then random data) is one commonly used method. Software tools that implement NIST-approved overwriting generate a certificate of completion that should be retained as documentation of compliant disposal.

       Physical destruction: for storage media that will not be reused — old hard drives, decommissioned servers, damaged devices — physical destruction that renders the storage medium permanently inoperable is the most reliable disposal method. Shredding (for hard drives), degaussing (for magnetic media), or destruction by a certified media destruction vendor produces a certificate of destruction that documents compliant disposal.

       Cloud data deletion: for data stored in cloud services — Microsoft 365, Google Workspace, cloud-based EHR systems — the deletion mechanisms provided by the cloud platform may or may not satisfy HIPAA's disposal standard. Confirm with your cloud vendor whether their deletion process renders data unrecoverable at the storage infrastructure level, not just at the application level. Many cloud platforms retain deleted data in backup systems for 30–90 days after deletion. The vendor's BAA should address data disposal standards explicitly.

Compliant Paper Record Disposal

Paper PHI must be disposed of through cross-cut shredding that reduces documents to particle sizes that prevent reconstruction. Strip-cut shredding — which produces long strips that can be reassembled — does not satisfy the HIPAA disposal standard. Cross-cut shredding produces confetti-sized particles that are not reconstructable with reasonable effort.

The shredding company that handles your paper disposal is a business associate under HIPAA — they are handling your PHI in the course of providing their service. A signed BAA with the shredding company is a HIPAA requirement. The BAA should specify that the shredding company provides a certificate of destruction for each shredding event that documents the date, the volume of material destroyed, and the method of destruction. These certificates are your documented proof of compliant paper PHI disposal and should be retained for six years.

Building the Data Retention Policy: What It Must Contain

The data retention and disposal policy is a required component of the written HIPAA security and privacy programme. It must be a written document — not an informal practice, not something that exists in the institutional memory of whoever manages the file server — because HIPAA requires it to be documented, because staff must be trained on it, and because it must be producible to OCR when requested.

Required Policy Elements

       Scope: which records and data categories are covered by the policy, including the distinction between HIPAA documentation and patient clinical records

       Retention schedule: the specific retention period for each record category, with the regulatory authority that establishes the retention period (HIPAA citation for compliance documentation; state law citation for patient records)

       Retention triggering event: the event that starts the retention clock — date of creation, date last in effect, date of service, or another defined trigger — specified for each record category

       Disposal method requirements: the specific disposal methods required for each data format (electronic, paper, removable media), with reference to NIST standards where applicable

       Disposal documentation requirements: the certificates, records, and other documentation that must be retained to demonstrate compliant disposal

       Responsible party: who is responsible for managing retention and disposal for each record category — the HIPAA Security Officer, the records manager, the IT administrator, or another designated role

       Review frequency: how often the policy is reviewed and updated — annually at minimum, plus when applicable state laws change or when significant changes to the agency's data environment occur

The Operational Reality: Making Retention Management Sustainable

A data retention policy that exists as a document but is not operationalised into the agency's actual information management practices is a compliance document, not a compliance programme. The difference is what happens when a retention deadline actually arrives — whether someone knows about it, acts on it, and documents the action.

The practical approach for most home health agencies: build retention management into the annual compliance calendar. At the beginning of each calendar year, generate a list of records whose retention periods will expire during the year. Assign review and disposal responsibility to the HIPAA Security Officer or a designated records management role. Document the review, the disposal action taken, and the disposal certificate for each record category addressed. Update the data inventory to reflect that the records have been disposed of.

This annual process does not have to be burdensome. For an agency with well-organised compliance records, the review takes a few hours. What it produces — a documented annual record of retention management actions — is the evidence that your retention programme is operational rather than aspirational. It is also the evidence that OCR cannot find in the majority of home health agencies it audits.

 

ShieldForce builds and maintains your HIPAA compliance documentation programme — including the data retention policy, the annual retention review process, and the disposal documentation framework — as a standard component of every managed service engagement. When OCR asks for your retention policy and your disposal records, the file is ready. Start with a free assessment.

 

Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment

Explore Home Healthcare Cybersecurity — shieldforce.io/home-healthcare

View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

Share this post

Topics

#Compliance#Thought Leadership#board governance#risk assessment#HIPAA#HIPAA Compliance#HIPAA compliance#Home Health#Home Health Data Rentention#HIPAA Data Retention
Free Security Assessment

Ready to Secure Your Business?

Don't let cyber threats put your business at risk. Discover how ShieldForce protects organizations like yours — 24/7.