Back to Blog
Data Protection
8 min read

Data Retention and Secure Disposal for Healthcare Records

Data you no longer need is pure liability: it can still be breached and it still has to be produced. Setting defensible periods and actually deleting when they expire.

GuardsArm Team

Security Experts

January 5, 2026

Data retention and disposal

Healthcare organisations keep everything, because deleting feels risky and keeping feels free. It is not free. Every record retained past its requirement remains in breach scope, remains discoverable, and remains something you must be able to produce. The cheapest data to protect is data you no longer hold.

Liability, not asset
Records past their retention period carry risk with no remaining obligation
Varies by type
Clinical, billing, employment and audit records all have different clocks
Minors differ
Paediatric retention is often measured from the age of majority, not the date of care

Build the schedule before the technology

A retention schedule lists each record type, the period, the legal basis, the owner and the disposal method. Without it, every deletion decision is improvised, and improvised deletion is how organisations destroy something they needed.

Record typeDriverNote
Adult clinical recordState law, often 6-10 years from last encounterVaries considerably by jurisdiction
Paediatric clinical recordFrequently age of majority plus a periodThe longest clock most hospitals run
HIPAA documentation (policies, risk analyses, BAAs)6 years from creation or last effective date45 CFR 164.316(b)(2)
Billing and claimsPayer contract and statuteOften shorter than clinical
Audit logsSecurity policy, investigation needUsually the shortest, often too short
Employment recordsEmployment lawSeparate owner, frequently forgotten
Research dataGrant and IRB termsCan be decades

Get the actual requirements in writing from legal for your jurisdictions. Do not build a schedule on a generic template — the variation between states is large enough to matter.

Longer is not safer
Over-retention is a defensible-sounding choice that quietly increases breach scope, discovery cost and storage spend. A schedule that says "keep forever" is not a conservative policy; it is the absence of a policy.

Legal hold has to override everything

When litigation or an investigation is reasonably anticipated, relevant records must be preserved regardless of the schedule. This needs to work mechanically, not by memory:

  • A defined trigger and a named person who can place a hold
  • A mechanism that suspends automated deletion for the affected scope
  • Scope that reaches backups and archives, not just primary systems
  • A release process, so holds do not become permanent by inertia
  • An audit trail of what was held, when, and by whom

Automated deletion that cannot be suspended is worse than no automation.


Deletion that reaches everywhere

Where a deleted record actually livesDeletion in the primary system leaves copies in replicas, backups and archives; each needs its own treatment before the record is genuinely gone.Primary systemrecord deletedReplicaspropagatedBackupsaged out or purgedArchivesexplicitly removedVerifyconfirm, do not assume
Backups are the usual survivor — a record deleted today can persist for the full backup retention period.

The honest position on backups is that a deleted record persists until the backup containing it expires. That is acceptable provided it is documented and bounded. What is not acceptable is believing the record is gone when it is recoverable for another seven years.

For cloud storage, confirm the provider's deletion semantics explicitly — soft-delete windows, versioning and snapshot retention all keep data past the delete operation.


Physical disposal

For media holding PHI, deletion is not disposal:

  • Cryptographic erase where the drive supports it and the key was properly managed
  • Physical destruction — shredding or degaussing — for anything else
  • Certificate of destruction naming serial numbers, retained as evidence
  • Chain of custody from removal to destruction, especially with a third-party vendor
  • Do not overlook multifunction printers, imaging workstations and medical devices with internal storage, all of which routinely leave a hospital with data still on them

That last point catches organisations out regularly. A leased MFP returned at end of contract has a hard drive holding years of scanned documents.


Where to start

Pick one record type with a clear, short retention period — audit logs or billing records are usually easiest — and implement the full cycle end to end: schedule, hold mechanism, automated deletion, verification. Proving the pipeline on something low-risk is what makes the clinical record conversation possible.

This pairs directly with decommissioning legacy systems, since retention is almost always the reason those systems are still running.

GuardsArm helps healthcare organisations build defensible retention schedules and verify that deletion reaches every copy. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Data Retention and Secure Disposal for Healthcare Records”

Talk to the GuardsArm team about how these services apply to your environment.