Most behavioral health programs can tell a surveyor where their current charts live. Far fewer can answer the follow-up questions: how long do you keep a discharged client’s record, which policy says so, and how do you prove that the records you no longer have were destroyed properly? Retention stays invisible until a records request, payer audit, sale or breach forces it into the open.
This guide is for owners, clinical directors and compliance officers. It is operational guidance, not legal advice. Retention periods are set largely by state law and your contracts, so confirm the specifics for every state you operate in.
The six-year HIPAA rule is not a medical record retention rule
The single most common misunderstanding we see in policy reviews is a retention policy that reads “records are retained for six years per HIPAA.” That sentence conflates two different things.
The HIPAA six-year retention requirement applies to a covered entity’s compliance documentation, not to the clinical record itself. Under the HIPAA Privacy and Security Rules, a behavioral health program must keep its required HIPAA documentation (policies and procedures, risk analyses, training records, signed acknowledgments, breach assessments and similar records) for six years from the date the document was created or the date it was last in effect, whichever is later. HHS has stated directly that the Privacy Rule does not set a retention period for medical records; how long a program keeps client charts is governed by state law, payer contracts and accreditation expectations. A retention policy that cites HIPAA as the source of its chart retention period is citing the wrong authority.
The practical consequence is that a superseded privacy policy must be kept for six years after it was replaced, not six years after it was written. If you revised your Notice of Privacy Practices or your Part 2 consent forms to meet the February 16, 2026 compliance date for the revised Part 2 rule, the prior versions now start their own six-year clock from the day they were retired. HHS explains the medical record point in its HIPAA FAQ on medical record retention.
Which clocks actually govern your clinical records
A behavioral health program usually sits under several retention obligations at once. The defensible approach is to identify every clock that applies, then keep each record type for the longest one.
- State licensing rules: Most state licensing regulations for mental health and substance use disorder programs set a minimum retention period for client records, often with a separate, longer rule for minors that runs from the age of majority rather than from discharge.
- State medical records statutes: Some states have a general medical records statute that applies in addition to, or in place of, the licensing rule, and the two do not always agree.
- Medicaid and managed care contracts: State Medicaid provider agreements and MCO contracts frequently impose their own retention period and require records to remain available for audit. They are routinely missed because they live in a contract binder, not the policy manual.
- Medicare and Medicare Advantage: Programs that bill Medicare or contract with Medicare Advantage plans inherit retention and audit-access obligations through those arrangements. Read the plan contract for the period it specifies.
- Accreditation: The Joint Commission and CARF expect a written retention policy that reflects applicable law and is actually followed. Surveyors check consistency with state rules and whether staff can describe it.
- Litigation holds: Any record related to a pending or reasonably anticipated claim, investigation or audit must be preserved regardless of its scheduled destruction date.
For multistate operators, this is where policies break: a single corporate retention period copied across locations will be too short somewhere, most often for minors.
Where 42 CFR Part 2 changes the destruction picture
Substance use disorder treatment records covered by 42 CFR Part 2 carry obligations that general medical records do not. The 2024 final rule aligned many Part 2 provisions more closely with HIPAA, including breach notification, and set a compliance date of February 16, 2026. It did not remove the program’s responsibility to protect Part 2 records through their full life cycle, including disposal.
Two situations deserve particular attention. First, when a Part 2 program closes or is acquired, the regulation addresses what must happen to client records, including when records may be transferred and when they must be retained or sanitized. Build that step into any change-of-ownership timeline. Second, Part 2 records that have been disclosed to other parties under a consent remain subject to redisclosure restrictions, so destruction at your program does not end your responsibility for how those records were shared. SAMHSA’s Part 2 resources and the regulation text are the primary sources to check before finalizing a closure or transfer plan.
What a defensible destruction process looks like
HHS guidance is clear that HIPAA requires covered entities to apply reasonable safeguards when disposing of PHI, in any medium, and to train workforce members on disposal procedures. HHS points to methods such as shredding, burning, pulping or pulverizing paper so PHI is unreadable and cannot be reconstructed, and clearing, purging or destroying electronic media. See the HHS FAQ on disposing of protected health information.
The method is rarely what fails under scrutiny. The proof is. In practice, a defensible process has four parts:
- An authorized destruction list: Before anything is destroyed, someone with authority signs a list of the records, including client identifier or record range, record type, date range, and the retention rule that has expired.
- A litigation hold check: The compliance officer confirms in writing that none of the listed records are subject to a hold, open audit, pending records request or grievance.
- A destruction certificate tied to the list: A vendor certificate that records only the weight of paper shredded does not prove which records were destroyed. The certificate should reference your list, the date and the method.
- A permanent destruction log: The authorization, the hold check and the certificate are kept together. The log itself is a compliance record and is retained like one.
The gaps that surface during audits and transactions
The failure points we encounter most often:
- Orphaned paper archives: Boxes of pre-EHR charts sit in an off-site storage unit, sometimes tied to a location the program left years ago, with no inventory and no one sure whose name is on the storage contract.
- EHR exit terms nobody read: The EHR vendor contract specifies how long you have to export data after termination and in what format. Programs switching systems often find the window closed while the obligation to produce that data remains.
- Shared drives and email: Retention policies cover the EHR but ignore clinical information sitting in scanned intake packets on a shared drive, email attachments and texting platforms.
- Retired devices: Laptops, copiers and phones leave service without documented sanitization. Copiers that store scanned images are a frequent blind spot.
- No owner: Retention is assigned to “medical records” in the policy, but no specific person runs the annual destruction review, so it never happens and records accumulate indefinitely.
Keeping everything forever is not the safe answer. Every record held past its retention period is one more record to protect, produce in discovery and report if breached.
What to do this week
Pull three documents and put them side by side: your current record retention policy, the client records section of the licensing regulation for each state you operate in, and the records clause from your largest Medicaid or MCO contract. Check whether your policy’s retention period meets the longest of the three, whether it has a separate rule for minors, and whether it cites HIPAA as the source of its chart retention period. If it does, rewrite that line.
Then add two items to your compliance calendar: an annual destruction review with a named owner, and a check on your EHR contract’s data export terms at least a year before renewal. If you want a second set of eyes on the policy, our behavioral health compliance services team reviews retention and destruction programs as part of broader readiness work, and our HIPAA compliance checklist is a useful starting point for the documentation side. Call (888) 458-6619 to talk through your situation.
Bringing retention under one owner
Record retention touches licensing, privacy, billing and IT, so it tends to belong to no one. Programs that handle it well assign it to a single accountable person, keep one schedule that maps every record type to its governing rule, and treat the destruction log as evidence rather than paperwork. For organizations without an in-house compliance lead, a fractional compliance officer can own the schedule, run the annual review and keep the documentation survey-ready.
If a change of ownership, EHR migration or expansion is coming, address retention first. Reach Circa Behavioral at (888) 458-6619.
This article provides general operational guidance and is not legal advice. Retention requirements vary by state, payer and program type. Confirm specific requirements with the issuing agency or qualified counsel.