Atypical Moles Cancerous Records: Retention and Disposal
Your shredding vendor swaps the locked console every other Tuesday. Ask your front desk which paper in that console is safe to destroy and which is sitting under a litigation hold, and you will probably get a shrug. That gap is the entire subject of this article: how a practice builds a defensible retention and destruction policy for the records generated when a patient is evaluated for atypical moles cancerous concerns — biopsy paperwork, pathology reports, clinical photographs, referral packets, and the vendor trail behind all of it. This is an operations post for privacy officers and practice managers. It contains no clinical guidance and nothing here should influence a clinical decision.
Where Atypical Moles Cancerous Workups Leave Records Behind
A lesion evaluation is administratively noisy because it crosses organizations. The encounter starts in your practice, a specimen goes to an outside pathology lab, a report comes back by interface or fax, and a referral packet goes out to a specialist. Each hop creates a record, and each record has its own home, its own custodian, and — if you have not written it down — its own undefined retention clock.
Inventory the actual artifacts before you write a schedule. In most practices the list looks like this:
- The encounter note and problem list entry in the EHR.
- Clinical photographs or dermoscopic images, which frequently live outside the EHR in an imaging folder, a tablet app, or a staff member's camera roll.
- The specimen requisition, its carbon copy, and the specimen log.
- The pathology report, often received as a fax PDF and again as a discrete interface result — two copies, two retention paths.
- The referral packet: a printed chart summary, a cover sheet, and the fax confirmation page.
- Release-of-information requests, patient authorizations, and the disclosure log entry.
- Prior-authorization correspondence and payer appeal files.
Seven artifact types, at least four custodians, and typically two or three business associates. A retention policy that only addresses "the medical record" leaves most of that list unmanaged.
How Long Do You Keep Records From a Suspicious Lesion Workup?
Short answer, because this is the question people search for: HIPAA does not set a medical record retention period. It requires you to retain HIPAA documentation — policies, procedures, risk analyses, business associate agreements, authorizations, notices, and disclosure accountings — for six years from creation or from the date last in effect, whichever is later, under the Security Rule and Privacy Rule documentation requirements. The chart itself is governed by state medical record law, by payer and Medicare participation requirements, and by your malpractice carrier's guidance. State floors commonly run somewhere between five and ten years for adults, with minors' records held until some period past the age of majority. Your written schedule must name the state statute you are following, not gesture at "applicable law."
Practical consequence: your retention schedule needs two columns, not one. Column A is the clinical chart, driven by state law and payer rules. Column B is compliance documentation, driven by the federal six-year rule. They expire on different days, and destroying Column B on the Column A schedule is a finding waiting to happen. HHS publishes the underlying regulatory text and guidance on its HIPAA laws and regulations page.
A Worked Example With Real Dates
Adult patient, first seen 12 March 2026 for evaluation of atypical moles cancerous concerns. Biopsy performed the same day. Pathology report received 19 March. Referral to a surgical specialist sent 23 March. Last visit in your practice: 6 May 2026.
Assume a state that requires seven years from the date of last treatment for adult records. The chart clock starts 6 May 2026 and runs to 6 May 2033. The patient's signed authorization allowing you to send records to the specialist is HIPAA documentation — six years from 23 March 2026, so 23 March 2032. The disclosure log entry recording that transmission carries its own six-year accounting obligation. The BAA with the pathology lab runs six years from the date the agreement is last in effect, which may be long after 2033 if the relationship continues.
Four artifacts, four different destruction dates, one patient. Multiply by your annual volume and you understand why "we shred when the box gets full" is not a policy.
The Shadow Repositories That Break Your Schedule
Retention policies fail in the same three places in almost every practice I have reviewed.
Clinical images. Photographs of lesions are PHI. If they are captured on a personal device, transferred by text, and never formally imported, they sit outside every retention rule you have written and outside every deletion process you have built. Fix the capture pathway first: practice-owned device, direct upload into the designated system, documented deletion from the capture device within a stated interval.
Fax and scan queues. Pathology reports arriving by fax land in a network folder or an inbound fax application. Staff scan them into the chart and then leave the source file in place. Six months later you have a parallel repository of oncology-adjacent results with no owner. Assign a purge interval — 30 or 60 days after successful filing — and audit it quarterly.
Multifunction printers and copiers. Every device that scanned a referral packet may have retained an image of it on internal storage. A device that leaves your building on a lease return without sanitization is a disclosure. That belongs in your offboarding checklist alongside laptops.
Secure Destruction: What "Shredded" Has to Mean
The Privacy Rule requires reasonable safeguards when disposing of PHI, and HHS has been explicit that abandoning records in a dumpster or an unlocked container is not reasonable — see the HHS FAQ on what the Privacy Rule requires when disposing of information. Paper must be shredded, burned, pulped, or pulverized so it cannot be reconstructed. Electronic media must be cleared, purged, or destroyed.
For the electronic half, adopt NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization, by name in your policy. It gives you defensible vocabulary — clear, purge, destroy — and a decision framework tied to media type and risk. When an auditor asks how you sanitized the workstation that held a decade of scanned pathology PDFs, "we followed NIST 800-88 purge for the SSD and retained the verification record" is a complete answer. "We reformatted it" is not.
If your practice also handles consumer report information — background checks on staff, for instance — the FTC Disposal Rule applies on top of HIPAA. The FTC's guidance on disposing of consumer report information is short and worth handing to whoever manages hiring files.
The Destruction Log Nobody Has Until They Need It
Build one log, one row per destruction event, with these fields: date, description of records or media, date range covered, volume or serial numbers, method used, vendor name if applicable, certificate of destruction reference number, and the initials of the practice witness. Store the log for six years. Confirm that every certificate your vendor issues actually matches a row.
Certificates that arrive as generic monthly PDFs with no serials, weights, or date ranges are close to worthless in an investigation. Ask your vendor for itemized certificates before you need them.
Your Shredding Vendor and Your Pathology Lab Are Both Business Associates
A document destruction company that takes custody of PHI is a business associate, and so is an offsite storage company, a records-scanning contractor, and an electronic media disposal firm. Your pathology lab is a separate covered entity when it bills the patient directly, but the interface vendor, the fax service, and the image-hosting platform in between are business associates. Every one of them needs a signed agreement that survives the relationship — including provisions on return or destruction of PHI at termination.
Pull your vendor list and check three things for each entry: is there an executed agreement, does it address destruction and return of PHI at termination, and can you produce it in under ten minutes. If any answer is no, close the gap. A six-step wizard that generates a signature-ready Business Associate Agreement with PDF and DOCX export is a faster path than routing a redline through counsel for a shredding contract — one-time purchase, no subscription, and you can have the shredding vendor's agreement signed this week.
Termination clauses matter more here than anywhere else. When you leave a records-storage vendor, you need documented proof that they destroyed or returned everything. Write the standard for that proof into the agreement rather than negotiating it during an exit.
Legal Holds Override Every Clock You Just Wrote
Missed-diagnosis claims involving skin lesions can surface years after the encounter, and discovery rules in many states extend limitations periods accordingly. The moment your practice receives a preservation letter, a subpoena, a records request from plaintiff's counsel, or notice of a board complaint, retention stops being schedule-driven and becomes hold-driven.
Your policy needs a named hold owner — usually the privacy officer — and a written sequence: log the hold, identify affected records across all repositories including images and fax archives, suspend automated purge for those records, notify custodians in writing, and re-confirm the hold every 90 days until counsel releases it. Then document the release before anything is destroyed.
The failure mode is almost always automation. A retention job in the EHR or an archive tool runs on schedule and quietly purges records that were under hold because nobody wired the hold flag into the job. Test that path once a year with a dummy record.
A 60-Day Implementation Sequence
- Days 1–10. Privacy officer inventories every repository containing lesion-workup records, including image folders, fax queues, and offsite boxes. One spreadsheet, one owner per row.
- Days 11–20. Practice manager confirms the state retention statute and payer requirements, then drafts the two-column schedule: chart records and compliance documentation.
- Days 21–30. IT maps sanitization methods to media types using NIST 800-88 language and documents the process for workstations, drives, backup media, and multifunction devices.
- Days 31–40. Review every business associate agreement touching records handling. Execute missing ones. Confirm termination and destruction language in each.
- Days 41–50. Stand up the destruction log and the legal hold register. Train the two staff members who will actually maintain them.
- Days 51–60. Run one full cycle end to end on a small batch: identify eligible records, verify no hold, destroy, log, file the certificate. Fix what breaks.
Sixty days of unglamorous work buys you the ability to answer a records question in minutes instead of a weekend. If your broader documentation set — risk analysis, policies, workforce training records — is also overdue for a rebuild, tools that automate HIPAA risk analysis and the full policy set will get you further than another folder of templates.
Start with the vendor list, because it is the fastest gap to close. If your shredding company, your offsite storage provider, or your imaging platform is missing a signed agreement, generate and export a completed BAA today and get it signed before the next console pickup.