Is there an expiry date to HIPAA compliance?
HIPAA compliance itself does not have a fixed or formal expiry date. Instead, compliance is an ongoing obligation for covered entities and business...
2 min read
Liyanda Tembani
July 25, 2023
HIPAA regulations include guidelines for retaining protected health information (PHI) records and factors that influence retention periods which healthcare organizations and other entities handling PHI must be aware of.
Related: The guide to HIPAA compliant text messaging
The HIPAA security rule requires covered entities and business associates to have retention policies in place. These policies should outline the specific timeframes for retaining ePHI, taking into account factors such as :
The recommended guideline is to retain ePHI for at least six years from the date of creation or the date of the last effective date, whichever is later.
This timeframe allows for compliance with the minimum retention requirement set forth by the HIPAA privacy rule. However, organizations should consider that some states have specific laws mandating longer retention periods for certain types of health information.
Related: Understanding medical record retention requirements by state
Proper retention of PHI records is a component of HIPAA compliance. While the HIPAA privacy rule does not provide specific retention periods, the HIPAA security rule offers guidance for retaining ePHI. Organizations should establish policies and procedures that align with the minimum retention period of at least six years from the date of creation or the date of the last effective date.
HIPAA compliance itself does not have a fixed or formal expiry date. Instead, compliance is an ongoing obligation for covered entities and business...
The Combined Common Edits/Enhancements Module (CCEM) plays a role in Medicare claims processing by actively checking and validating the accuracy of...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.