Data Retention and Secure Disposal for Healthcare Records
Data you no longer need is pure liability: it can still be breached and it still has to be produced. Setting defensible periods and actually deleting when they expire.
GuardsArm Team
Security Experts
Healthcare organisations keep everything, because deleting feels risky and keeping feels free. It is not free. Every record retained past its requirement remains in breach scope, remains discoverable, and remains something you must be able to produce. The cheapest data to protect is data you no longer hold.
Build the schedule before the technology
A retention schedule lists each record type, the period, the legal basis, the owner and the disposal method. Without it, every deletion decision is improvised, and improvised deletion is how organisations destroy something they needed.
| Record type | Driver | Note |
|---|---|---|
| Adult clinical record | State law, often 6-10 years from last encounter | Varies considerably by jurisdiction |
| Paediatric clinical record | Frequently age of majority plus a period | The longest clock most hospitals run |
| HIPAA documentation (policies, risk analyses, BAAs) | 6 years from creation or last effective date | 45 CFR 164.316(b)(2) |
| Billing and claims | Payer contract and statute | Often shorter than clinical |
| Audit logs | Security policy, investigation need | Usually the shortest, often too short |
| Employment records | Employment law | Separate owner, frequently forgotten |
| Research data | Grant and IRB terms | Can be decades |
Get the actual requirements in writing from legal for your jurisdictions. Do not build a schedule on a generic template — the variation between states is large enough to matter.
Legal hold has to override everything
When litigation or an investigation is reasonably anticipated, relevant records must be preserved regardless of the schedule. This needs to work mechanically, not by memory:
- A defined trigger and a named person who can place a hold
- A mechanism that suspends automated deletion for the affected scope
- Scope that reaches backups and archives, not just primary systems
- A release process, so holds do not become permanent by inertia
- An audit trail of what was held, when, and by whom
Automated deletion that cannot be suspended is worse than no automation.
Deletion that reaches everywhere
The honest position on backups is that a deleted record persists until the backup containing it expires. That is acceptable provided it is documented and bounded. What is not acceptable is believing the record is gone when it is recoverable for another seven years.
For cloud storage, confirm the provider's deletion semantics explicitly — soft-delete windows, versioning and snapshot retention all keep data past the delete operation.
Physical disposal
For media holding PHI, deletion is not disposal:
- Cryptographic erase where the drive supports it and the key was properly managed
- Physical destruction — shredding or degaussing — for anything else
- Certificate of destruction naming serial numbers, retained as evidence
- Chain of custody from removal to destruction, especially with a third-party vendor
- Do not overlook multifunction printers, imaging workstations and medical devices with internal storage, all of which routinely leave a hospital with data still on them
That last point catches organisations out regularly. A leased MFP returned at end of contract has a hard drive holding years of scanned documents.
Where to start
Pick one record type with a clear, short retention period — audit logs or billing records are usually easiest — and implement the full cycle end to end: schedule, hold mechanism, automated deletion, verification. Proving the pipeline on something low-risk is what makes the clinical record conversation possible.
This pairs directly with decommissioning legacy systems, since retention is almost always the reason those systems are still running.
GuardsArm helps healthcare organisations build defensible retention schedules and verify that deletion reaches every copy. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Data Retention and Secure Disposal for Healthcare Records”
Talk to the GuardsArm team about how these services apply to your environment.


