How to Archive Old EHR Records

Every medical practice accumulates years of patient data. Over time, your active EHR system fills with records from patients who moved away, passed on, or simply haven’t been seen in years. Left unaddressed, this data buildup slows your system, complicates audits, and creates unnecessary security exposure.

The answer isn’t deletion — it’s proper archiving. Done correctly, EHR archiving keeps your practice HIPAA compliant, reduces operational overhead, and ensures records remain accessible when you need them. This guide walks through exactly how to do it.

6 yrs

Required HIPAA compliance documentation: six years from creation or last effective date, whichever is later; not a universal medical-record period.

Varies

Medical-record retention depends on applicable law, provider or facility type, patient age and other requirements.

Legal holds

Confirm applicable retention requirements and any legal holds before authorizing secure disposal.

Why Archiving Old EHR Records Matters

Medical practices often treat record archiving as a back-burner task — something to deal with later. But the longer inactive records sit in an active EHR, the more problems accumulate:

  • System performance degrades. Bloated databases slow query times, reporting, and overall EHR responsiveness — affecting every provider in your practice.
  • Security surface expands. Every record in an active system is a potential breach target. Inactive records that aren’t needed for daily care should be removed from your primary attack surface.
  • Audits become harder. Sifting through years of undifferentiated data to respond to an audit or legal request wastes time and increases error risk.
  • Storage costs rise. Cloud-based EHR pricing often scales with data volume. Archiving old records to lower-cost storage tiers can meaningfully reduce your annual costs.
  • Compliance risk increases. Medical records must be retained for the applicable period and protected while maintained. HIPAA safeguards continue to apply to archived PHI; keeping older records in an active EHR is not, by itself, a retention violation.

HIPAA & State Retention Requirements

Before archiving or disposing of records, identify the requirements that apply to the record type, provider or facility, patient and program. Do not assume a single HIPAA retention period governs all medical records. Have your compliance team or legal counsel resolve overlapping obligations and any legal holds.

Federal HIPAA Requirements

The HIPAA Privacy Rule does not set a universal retention period for patient medical records. Its six-year documentation rule, 45 CFR §164.530(j), applies to documentation required by that rule, measured from creation or the date last in effect, whichever is later. The Security Rule has a separate six-year requirement for its required documentation under 45 CFR §164.316(b)(2)(i). Neither should be presented as a general six-year clinical-record deadline. See HHS guidance on medical-record retention and the HHS Security Rule summary. PHI must remain appropriately safeguarded while it is maintained, including during disposal.

State-Specific Requirements

State medical-record rules are separate from HIPAA documentation-retention requirements. The examples below identify their scope; they are not a complete retention schedule. Physician practices, hospitals and other licensed facilities may have different rules. Minor-patient records, payer or program obligations and legal holds can require additional retention.

Record or settingSource-linked guidanceWhat to verify
HIPAA compliance documentationRequired Privacy and Security Rule documentation generally has a six-year retention requirement, measured from creation or last effective date, whichever is later. HHS Security Rule summary.Identify which documentation is required; do not apply this period automatically to patient charts.
Texas physician recordsThe Texas Medical Board states that physicians must retain records for at least seven years after the last treatment.Check minor-patient rules, longer applicable requirements and legal holds. Do not use this physician example as a hospital schedule.
California physician recordsThe Medical Board of California explains that physicians must retain medical records for at least seven years after the last service, under the requirement effective January 1, 2024.Other laws can require longer retention, including certain Medi-Cal situations. Confirm the rules applicable to the patient and setting.
Other states, hospitals, facilities and minor patientsUse the current rules of the relevant licensing board, health department and applicable programs. HHS explains the distinction between medical-record retention and HIPAA safeguards.Confirm the applicable period, triggering date, age-related extensions and legal holds with qualified counsel before disposal.

This guidance is educational, not a complete legal retention schedule. Confirm your organization’s specific obligations before adopting a retention or disposal policy.

Archiving vs. Deleting: What’s the Difference?

These terms are sometimes used interchangeably — but in the context of healthcare compliance, they mean very different things with very different consequences.

FactorArchivingDeletion
Record statusPreserved in secure, read-only storagePermanently removed
Retention and safeguardsPreserve records and maintain applicable safeguardsDo not dispose before applicable retention requirements and legal holds are resolved
RetrievabilityAccessible within defined timeframeNot recoverable
Audit supportSearchable and auditableNo audit trail
System loadRemoved from active EHRRemoved from active EHR
Legal exposureLow, if properly managedHigh if retention period not met

Before disposal, confirm that all applicable retention requirements have been met, that no legal hold or other preservation obligation applies, and that authorized personnel have approved the action. Use secure disposal procedures appropriate to the records and document the decision. HIPAA safeguards apply to PHI through disposal.

What Records Should Be Archived?

Not all records need to move to archive at the same time. A well-structured archiving policy identifies specific triggers that move a record out of the active EHR. Common criteria include:

  • Inactive patients — Patients with no visits, prescriptions, or clinical activity within the last 3–5 years (based on your policy)
  • Deceased patients — Records should be archived, not deleted, and retained per applicable state law
  • Transferred care — Patients who have formally transferred to another provider
  • Legacy system records — Records migrated from a previous EHR that are no longer actively referenced
  • Resolved legal matters — Records tied to workers’ comp, litigation, or no-fault cases that have fully closed

Best Practices for EHR Archiving

A compliant, efficient archiving program doesn’t happen by accident. The following best practices are aligned with HHS guidance on HIPAA administrative safeguards and widely accepted healthcare records management standards.

1. Develop a Written Records Retention Policy

Maintain a written retention policy identifying applicable periods, archiving triggers, storage safeguards and disposal approvals. Review it periodically and when applicable requirements or operations change. Retain documentation required by the HIPAA Privacy or Security Rule for six years from creation or the date last in effect, whichever is later; assess any additional applicable retention obligations.

2. Use Encryption for All Archived Data

Archived records are still Protected Health Information (PHI). Whether stored on-premises or in the cloud, they must be encrypted at rest (AES-256 is the current standard) and in transit (TLS 1.2 or higher). This is a technical safeguard requirement under HIPAA’s Security Rule (45 CFR §164.312).

3. Maintain Access Controls and Audit Logs

Access to archived records should be restricted to authorized personnel only — not open to all clinical staff by default. Every access event must be logged, creating an audit trail that demonstrates compliance in the event of an investigation.

4. Ensure Retrievability Within a Reasonable Timeframe

Archiving cannot mean “impossible to find.” If a patient requests their records, or if you receive a subpoena or audit request, you must be able to retrieve archived records in a reasonable timeframe. Define this expectation (e.g., within 5 business days) in your policy.

5. Execute Business Associate Agreements (BAAs)

If you use a third-party cloud storage vendor or archiving service, a signed BAA is required under HIPAA before any PHI is transmitted or stored on their platform. Failure to have a BAA in place is one of the most common HIPAA violations found during audits.

6. Document Your Archiving and Disposal Activities

Document archiving and disposal actions, including what was done, when, by whom and under what authority. Determine the applicable retention period for each record of the action. Where documentation is required by the HIPAA Privacy or Security Rule, apply the relevant six-year documentation requirement, measured from creation or last effective date, whichever is later, along with any additional applicable obligations.

7. Train Your Staff

Staff who handle records — including front desk, billing, and clinical personnel — should understand your archiving policy, why it matters, and how to execute it. HIPAA requires workforce training on privacy and security policies.

Choosing an EHR Archiving Solution

The right archiving solution depends on your practice size, technical infrastructure, and budget. Here are the main approaches:

Built-In EHR Archive Features

Many modern EHR platforms include native archiving capabilities that allow you to flag records as inactive without removing them from the system entirely. This is the simplest option but may not fully reduce system overhead or storage costs.

Dedicated Healthcare Archive Platforms

Purpose-built healthcare archiving platforms allow you to export and store records in a HIPAA-compliant environment entirely separate from your active EHR. These solutions typically offer robust search, access control, and audit logging — critical for larger practices or those switching systems.

Cloud Storage with HIPAA-Compliant Vendors

Access to archived records should be restricted to authorized personnel only — not open to all clinical staff by default. Every access event must be logged, creating an audit trail that demonstrates compliance in the event of an investigation.

Archiving When Switching EHR Systems

One of the highest-stakes archiving scenarios is when a practice switches from one EHR platform to another. This is a situation where records from the old system must be handled carefully — you cannot simply abandon them when your contract ends.

Key steps when switching EHR systems:

  • Request a full data export before your contract with the old vendor ends. Most EHR vendors are required to provide this under applicable data portability standards.
  • Export in an open, non-proprietary format such as C-CDA (Consolidated Clinical Document Architecture) or HL7 FHIR where possible, to ensure long-term readability.
  • Validate the exported data for completeness before terminating your old system subscription.
  • Store exported records in a HIPAA-compliant archive with a signed BAA from your storage vendor.
  • Document the entire process including export date, format, storage location, and who performed each step.

Medi-EHR supports data export in industry-standard formats and provides full documentation of data portability processes to help practices transition smoothly. See our Term, Termination and Return of Data FAQ for details.

Frequently Asked Questions

There is no universal HIPAA six-year retention period for patient medical records. Retention depends on applicable state law, provider or facility type, patient age, program requirements and any legal holds. The six-year HIPAA rules concern required compliance documentation, not a blanket clinical-record deadline. Confirm a record-specific schedule with your compliance team or legal counsel. See HHS guidance on medical-record retention.

Archiving preserves records for later retrieval; deleting removes them. Do not dispose of records until applicable retention requirements and legal holds have been resolved and the action has been authorized. HIPAA safeguards continue to apply to PHI while retained and during disposal. Follow documented, secure disposal procedures rather than assuming a six-year medical-record deadline.

Archiving does not reduce your HIPAA obligations — archived records are still PHI and must be encrypted, access-controlled, and auditable. The archiving process itself, if done correctly with proper documentation, actually supports compliance by demonstrating your practice’s adherence to a written retention and security policy.

Technically yes, but format choice matters long-term. Records stored in proprietary formats may become unreadable if the vendor is discontinued. Best practice is to archive in open, standard formats (such as C-CDA, PDF/A for documents, or structured data exports) that will remain readable regardless of what software changes occur in your practice.

Your HIPAA Privacy Officer and Security Officer should oversee the archiving program. Practical execution may involve your practice manager and IT staff (or your EHR vendor’s support team). Having a single designated owner for records management — with documented responsibilities — is a HIPAA administrative safeguard requirement.

Conclusion: Build a Sustainable Records Management Strategy

Archiving old EHR records is not a one-time project — it’s an ongoing practice management discipline. The practices that do it well share a few common traits: they have a written policy, they’ve trained their staff, they use secure and compliant storage, and they document everything.

The cost of doing this wrong — in fines, breach liability, audit failures, and system performance degradation — far outweighs the investment of building a proper archiving program.

Whether you’re managing decades of legacy records, preparing for an EHR migration, or simply trying to bring your current system under better control, the principles outlined in this guide provide a solid foundation. Always work with your HIPAA compliance officer and legal counsel to tailor these practices to your specific situation.

Get Started with Medi-EHR Patient Intake Software

Join thousands of healthcare practices that have eliminated paper forms,

reduced wait times, and improved patient satisfaction with Medi-EHR.

Previous Post
Improving Patient Care with Clinical Ambulatory EHR Systems in Modern Healthcare
Next Post
Why EHR Customization Is the Most Important Feature Your Practice Needs