AZ’s Largest Independent Record Storage Facility. Call: (480) 462-6479

How to Store HIPAA Documents

The Health Insurance Portability and Accountability Act (HIPAA) applies to two types of organizations, covered entities and business associates. Covered entities include treatment, operations and healthcare payment organizations. Business associates include institutions that process patient data in the course of performing services for covered entities. Organizations within these categories need HIPAA-compliant storage.

Your main consideration with HIPAA storage is the Security Rule, which includes administrative, technical, and physical protections that should be used to prevent unauthorized access. Following the Security Rule requires organizations to do the following:

Verify that the health records they produce, receive, store or send are all strongly available, with their integrity and privacy maintained. Establish defenses against threats to the documents that are reasonably anticipated like security issues, and fire and water damage. Set up protections to prevent the use or disclosure that is not allowed and is reasonably foreseen. Be certain that your employees are following compliance guidelines.

Data Storage Centers is HIPAA compliant, and we follow regulatory guidelines to make sure HIPAA records are stored properly in a safe and secure area. We also ensure our clients that their HIPAA documents will remain their private property and can only be accessed by them and those they have qualified.

Does HIPAA apply to paper records?

The Health Insurance Portability and Accountability Act is a federal law created in 1996. Under this law national standards were created to protect the personal information of health patients from being disclosed without their knowledge or consent. 

The HIPAA Privacy Rule prohibits the unauthorized disclosure of a patient’s health information in any format, including paper records. The Privacy Rule’s goal is to protect and individual’s private health information while allowing the flow of health information when needed to provide quality health care. The Privacy Rule is setup to protect the patient’s rights while permitting the use of important information by medical professionals. 

Permitted uses and disclosures of medical information without a patient’s consent includes public health activities, health oversight activities, law enforcement, organ donation, when required by law, essential government functions, research, identification of deceased persons, victims of abuse, judicial and administrative proceedings, to prevent a serious threat to health, and workers compensation.

How long does HIPAA require records to be kept?

State laws typically dictate how long medical records are to be kept. The Health Insurance Portability and Accountability Act (HIPAA) administrative rules require companies like Medicare to keep documentation for six years. The timeframe starts from the date of the document’s creation or the date when it was last in effect, whichever date is later. HIPAA requirements overwrite state laws if they require shorter periods. Check with your state’s Health and Human Services Department to see if your state requires longer retention periods. 

The HIPAA Privacy Rule does not have medical record retention requirements. The Privacy Rule does require entities like Medicare to apply appropriate technical, administrative and physical safeguards to protect the privacy of a patient’s medical records for however long the entity maintains the information through the document’s disposal.

HIPAA paper records storage tips

Whether you are using a paper filing system or an electronic health record system and only occasionally printing documents reducing access and implementing security procedures are key.

You can control the access to a patient’s paper records by storing them in locked filing cabinets and only the necessary people should have key access. Patient’s records should never be left unattended on desks or open shelving. Offices, storage rooms and anywhere a patient’s records could be compromised need to be locked with keys, ID cards and alarm keypads.

It is also a good idea to create a tracking process for the location of patient records along with a check in system to storage facilities. This can be as simple as a sign in sheet with the name of the person checking out the records with the time and date noted next to it. Electronic systems requiring the swiping of ID cards is a more technical and secure way to track records.

Keep all of a patient’s records together. Do not separate documents from the file. If you are in your office and a colleague comes in turn over the document or cover it as to not expose private information. When disposing of documents always shred them. Never throw away whole patient records. Throwing away intact documents can lead to identity theft, so any documents containing personal information must be shredded. Cross-cut shredding is the preferred method of disposing these documents.

These basic tips will help keep your patient’s records safe and secure.

If you’re an Arizona resident or business in need of record storage contact us by filling out the form to the right or giving us a call at 602-273-3045.