Atypia Moles Records: Retention Clocks and Disposal
Fourteen banker's boxes left your storage closet last Thursday. The shredding vendor's driver scanned a manifest, your office manager initialed it, and a certificate of destruction arrived by email two days later. Nobody opened the boxes first. Nobody recorded what date ranges were inside. And roughly a third of those charts were dermatology records — pathology reports, referral letters, and follow-up notes tied to atypia moles biopsies from a decade ago. If a patient or a plaintiff's attorney asks for one of those files next month, you have a certificate that proves something was destroyed and no record of what.
This post is about the administrative machinery around that problem: which retention clock actually governs, what "secure destruction" means when a regulator reads your policy, which vendors in that chain need a Business Associate Agreement, and what your destruction log has to contain so the purge holds up years later. It is not clinical guidance and it will not help you make a care decision.
Why Atypia Moles Records Sit in Four Places at Once
Skin lesion evaluation is a multi-organization workflow by design. A primary care visit produces a referral. A dermatology practice performs a biopsy and generates a procedure note. An outside pathology laboratory produces a report. The dermatologist sends results back to the referring physician, and sometimes a surgical or oncology consult adds a fourth custodian.
That single clinical thread produces records in at least four separate designated record sets, held by four separate covered entities, each running its own retention clock under its own state's law. Your practice does not control the others. You control yours — and you are accountable for yours.
The practical consequence for records administration: the chart in your system for a patient with atypia moles findings is almost never complete on its own. It contains inbound documents you did not author. Those inbound pathology reports and consult letters are part of your designated record set once you receive and maintain them, and they are subject to the same retention and disposal rules as anything your own clinicians wrote.
HIPAA Does Not Set a Medical Record Retention Period. Two Other Things Do.
This trips up new privacy officers constantly. The HIPAA Rules contain a six-year retention requirement, but it applies to your compliance documentation — policies, procedures, Notices of Privacy Practices, risk analyses, authorizations, accounting-of-disclosure logs, sanctions records — not to patient charts.
Under 45 CFR 164.530(j)(2) and the parallel Security Rule provision at 45 CFR 164.316(b)(2)(i), you keep required documentation for six years from the date of creation or the date it was last in effect, whichever is later. Read the regulation text on the HHS Privacy Rule page rather than a summary — the "last in effect" language matters when you retire an old policy version.
The clocks that actually govern the chart
State law. Every state sets medical record retention minimums for licensed practices, and they vary widely in both length and starting point. Some run from the date of last treatment; some run from the date the record was created. Minors get a separate, longer rule in most states, typically tied to the age of majority plus a term of years.
Payer and program rules. Medicare and Medicaid participation carries its own documentation retention expectations, and commercial payer contracts frequently specify a term. Check your contracts folder before you set a number — your managed care agreements may quietly impose a longer clock than your state board does.
Your written policy should state the controlling clock, the trigger date, and the exceptions in one paragraph. If your policy says "records are retained in accordance with applicable law," you do not have a policy. You have a sentence.
How Long Should You Keep Atypia Moles Records? The Short Answer
Keep the chart for the longest applicable period among: (1) your state's medical record retention statute or board rule, measured from its specified trigger date; (2) any payer or federal program retention term in your contracts; and (3) your malpractice carrier's recommended term. For minors, apply the state's extended clock. Keep HIPAA compliance documentation — policies, authorizations, disclosure accountings, risk analyses — for six years from creation or last effective date, separately from the chart. Suspend all destruction immediately upon notice of litigation, an investigation, or a records request. Destroy only by a method that renders PHI unreadable and unreconstructable, and log every destruction event.
What "Secure Destruction" Means When OCR Reads Your Policy
The standard is functional, not brand-specific: PHI must be rendered unreadable, indecipherable, and unable to be reconstructed. HHS spells this out in its guidance on disposal of protected health information, and the recurring enforcement fact pattern is boring and preventable — paper records in an unsecured dumpster, a filing cabinet sold with charts still inside, a copier traded in with an imaged hard drive.
Paper
Cross-cut shredding, pulverizing, or incineration. Strip-cut shredders are not sufficient for PHI. If a vendor performs the destruction off-site, the boxes are PHI in transit the entire time they sit on your loading dock and in the truck — which means chain of custody starts when the box leaves your locked storage, not when the truck arrives at the plant.
Electronic media
Use NIST Special Publication 800-88, Guidelines for Media Sanitization as your reference standard and name it in your policy. It defines three levels — Clear, Purge, and Destroy — and maps them to media types. Deleting a file or emptying a recycle bin is none of the three.
Build an inventory of media that touches dermatology and pathology workflows specifically: the dermatoscope or clinical photography storage, the scanner workstation where inbound pathology reports land before import, the fax server, the backup appliance, and the multifunction copier in the clinical hallway. Photographic documentation of lesions is PHI, it accumulates on devices nobody thinks of as an EHR, and it is regularly missed at decommissioning.
Every Link in the Disposal Chain Needs a BAA
A document shredding company is a business associate. So is an off-site records storage company, a scanning and digitization service, an IT asset disposition vendor that wipes and resells your workstations, and a release-of-information company that handles your records requests. It does not matter that the shredding driver never reads a chart — access to PHI in the course of performing a service is the test, not whether anyone actually looked.
Pull your vendor list and check three things for each disposal-chain vendor:
- A signed, current BAA on file — with a copy you can produce in under five minutes.
- Contract language obligating the vendor to return or destroy PHI at termination, and to notify you of a security incident within a defined number of days.
- A certificate of destruction that references your job number, date, method, and volume — not a generic form letter.
If any of those vendors is operating on a handshake or a service agreement with no HIPAA terms, close that gap this week. You can produce a signature-ready agreement in a few minutes with a six-step Business Associate Agreement wizard that exports to PDF and DOCX — one-time purchase, no subscription — and send it to the vendor the same day. A missing BAA with a shredding company is one of the easiest findings for an investigator to establish and one of the hardest for you to explain after the fact.
The Destruction Log Is the Deliverable
The purge itself is a one-day event. The log is what you will still be relying on in 2031. Treat the log as a permanent record — do not apply a retention period to it that is shorter than the longest chart retention period it documents.
Each entry should capture:
- Destruction date.
- Description of the records — record type, department, and the inclusive date range destroyed (for example, "dermatology paper charts, last date of service 2010–2013").
- Method used, mapped to your policy and, for electronic media, to the NIST 800-88 level applied.
- Vendor name and certificate of destruction number, if applicable.
- Name and title of the workforce member who authorized the purge.
- Name of the witness who verified box contents against the manifest before pickup.
- Confirmation that a legal hold check was performed, with the date and the person who performed it.
That seventh item is the one people skip and the one that saves you. If a patient with atypia moles records requests their chart and you destroyed it lawfully three years ago, your log lets you answer with a date, a method, and an authorization. Without it, your answer sounds like you lost the file.
Legal Holds Beat the Retention Schedule Every Time
The moment your practice receives notice of a lawsuit, a board complaint, an OCR inquiry, a subpoena, or a patient's written request for records, destruction stops for the affected records — regardless of what the retention schedule says.
Write down who has authority to issue a hold (usually the privacy officer or practice administrator), how it is communicated (a dated written notice to the records custodian and IT), and how it is released. Keep a running hold register. Then wire it into the purge workflow so that no box leaves the building until someone signs off against that register.
Note the interaction with access requests: a patient's request for their records is a hold trigger and a deadline trigger at the same time. You have 30 days to respond, and you cannot destroy responsive records while that clock runs.
A Twelve-Month Retention Calendar You Can Actually Run
January. Records custodian runs an eligibility report — everything past the controlling retention period, filtered by record type and patient age at last visit. Privacy officer reviews the minors exclusion.
February. Legal hold check against the hold register. Anything with a hold is pulled and flagged.
March. Boxes staged in locked storage, contents verified against a manifest by two people. Vendor BAA and insurance certificate verified as current before scheduling pickup.
April. Destruction executed. Certificate received, matched to the manifest, and filed with the log entry the same week.
July. Electronic media sweep. IT inventories decommissioned devices — workstations, imaging storage, backup drives, the copier lease returns — and sanitizes to the NIST level your policy names.
October. Annual policy review. Confirm state retention rules have not changed, confirm the six-year documentation clock is being applied to retired policy versions, and re-verify the disposal vendor list against your BAA inventory.
Assign each month to a named role, not a department. "Records custodian" is a person; "the front office" is nobody.
When Disposal Goes Wrong
Improper disposal is a breach when unsecured PHI is impermissibly disclosed. That means a risk assessment under the Breach Notification Rule, and potentially notification to affected individuals, HHS, and — above 500 residents of a state or jurisdiction — the media. The reporting mechanics are on the HHS breach notification page, and submitted breaches appear in the public OCR portal, where anyone can read them.
The determination hinges on evidence. A documented chain of custody, a verified manifest, and a specific certificate of destruction change the analysis materially. A blank folder does not.
Your Next Three Steps
Pull your retention policy and check whether it names a specific clock and trigger date. Pull your destruction log and check whether the last purge recorded a date range and a hold check. Pull your vendor list and identify every company that touches PHI on its way out the door.
If the third item turns up gaps, generate the agreements now — a signature-ready BAA takes minutes and closes the exposure permanently. If the first two turn up gaps, the broader policy set and risk analysis documentation behind them can be built and maintained in one place rather than reconstructed the week an investigator asks. Either way, do it before the next truck backs up to your loading dock.