Fourteen banker's boxes sit in the storage closet behind your billing office. Three of them hold endoscopy reports, pathology slips, and referral letters from 2011 — the paper tail of colonoscopy age screening from back when your practice faxed everything. Nobody has opened them in a decade, and nobody in the building can tell you whether you are allowed to shred them.

This article is for the person who has to answer that question. It covers how to build a retention and destruction policy for the records generated around a screening encounter, who holds copies you have forgotten about, what your Business Associate Agreements have to say about destruction, and how to document disposal so it survives a records request or an OCR inquiry six years later. There is no clinical guidance here — only clocks, custodians, contracts, and shred logs.

Why a Colonoscopy Age Chart Has a Longer Tail Than Most Encounters

A sore throat visit generates one note and one claim. A screening referral generates a chain that crosses organizational boundaries and then sits quiet for years.

The primary care office writes the referral and holds the result. The gastroenterology practice holds the consult and procedure note. The ambulatory surgery center holds its own facility record. The anesthesia group bills separately. The pathology lab holds the specimen report. Your billing vendor holds the claim, the remittance, and often a PDF of the supporting documentation.

One patient, six custodians, six retention clocks — and they do not run in sync.

The other complication is cadence. Screening intervals are set clinically and can run years between encounters, so a chart that looks dormant is frequently still active for recall purposes. When guidance for average-risk adults moved the recommended start age from 50 to 45, practices absorbed an entire additional cohort into their recall lists. Administratively, that meant more charts sitting in a long-hold state and more reminder correspondence to track. Whether any individual patient is due is a clinical judgment your clinicians make, not a records decision — but the records consequence lands on your desk.

How Long Do You Have to Keep Colonoscopy Age Screening Records?

HIPAA does not set a medical record retention period. It sets a six-year retention period for HIPAA compliance documentation — policies, notices, authorizations, accountings of disclosures, risk analyses, and signed agreements. The clinical record itself is governed by state law, payer contracts, and federal conditions of participation.

In practice, three clocks apply to a screening chart:

  • State medical record retention statute. Typically measured in years from the last date of service, commonly in the six-to-ten year range for adults, with longer periods for minors. Your state's number is the floor you actually operate against.
  • HIPAA's six-year documentation clock. Runs from creation or from the date the document was last in effect — whichever is later. This covers the authorization the patient signed to release records to the GI practice, not the procedure note itself.
  • Federal facility and payer requirements. Medicare conditions of participation impose their own minimum retention on hospitals and ambulatory surgery centers, and payer contracts frequently require records be produced for audit for a defined period after payment.

Take the longest applicable clock, add a documented buffer if your counsel recommends one, and write that number into a policy. Do not let "we keep everything forever" stand in as a policy. Indefinite retention is a growing breach surface with no offsetting benefit, and it will not read as reasonable diligence if you ever have to explain your safeguards. The HHS Privacy Rule guidance is the starting point; your state statute is the binding number.

The Reset Rule Most Practices Get Wrong

Retention clocks usually run from the last date of service, not the date of the procedure. A patient screened in June 2016 who returned for an unrelated visit in March 2021 has a chart whose clock restarted in 2021. If your purge job keys off the procedure date, you will destroy records that are still legally required.

Key your destruction eligibility to the most recent encounter date in the designated record set, and make that a field your practice management system can actually report on. If it cannot, that is a system requirement to raise at your next vendor review.

Find Every Copy Before You Write the Policy

A retention policy that only governs the chart in your EHR is a policy that governs maybe sixty percent of the protected health information you hold. Before you set destruction rules, inventory the duplicates.

The places a screening record actually lives

  • The scanned-document queue, where inbound faxed reports wait to be indexed — and where unindexed items can sit for years
  • Your e-fax vendor's server-side archive, which often retains sent and received documents independently of your local copy
  • The secure messaging or portal thread where the referral coordinator sent demographics to the GI office
  • A shared network folder named something like GI referrals 2019 that one staff member created and never deleted
  • The multifunction copier's internal drive, which stores images of everything it scanned
  • Backup snapshots and disaster-recovery replicas, which will hold a record long after you purge production
  • Your billing company's document management system
  • Paper: the boxes in the closet, and the manila folder in the referral coordinator's desk drawer

Assign a custodian to each location by name and role. Write the retention rule for each. Locations without a named owner do not get purged, and unowned PHI is what shows up in breach reports.

The BAA Clause That Governs Destruction — and Usually Doesn't

Your Business Associate Agreements are supposed to say what happens to PHI when the relationship ends. The Privacy Rule requires the agreement to provide that, at termination, the business associate returns or destroys all protected health information it received or created — and if return or destruction is not feasible, extends the protections indefinitely and limits further use. HHS publishes sample business associate agreement provisions that include the language.

Pull three BAAs from your vendor file right now — the billing company, the transcription service, the e-fax provider — and check three things:

  1. Does the termination clause actually specify return or destruction, and who chooses?
  2. Is there a deadline? "Upon termination" without a number of days is unenforceable in practice.
  3. Does it require written certification of destruction, and does it flow down to subcontractors?

Most agreements signed in a hurry fail at least two of those. If yours are thin — or if you have vendors handling referral logistics for whom you never executed an agreement at all — generate a clean, signature-ready agreement with a six-step BAA builder that exports to PDF and DOCX and re-paper the relationship before your next destruction cycle. It is a one-time purchase, and it takes less time than the phone call you would otherwise make to counsel.

Secure Destruction: What Counts and What Doesn't

HHS has been consistent that PHI must be rendered unreadable, indecipherable, and otherwise unable to be reconstructed. Dumpsters, recycling bins, and unlocked shred consoles in a hallway do not qualify. See the HHS guidance on disposal of protected health information for the baseline expectation.

Paper

Cross-cut shredding, pulping, or incineration. If you use a shredding vendor, they are a business associate — get the agreement, and get certificates of destruction that identify the pickup date, container count, and method. File those certificates with your compliance documentation for six years.

Electronic media

Use NIST Special Publication 800-88 Revision 1 as your reference for sanitization. It distinguishes clear, purge, and destroy, and it maps each to media type and risk level. For drives leaving your control — a replaced server, a retired laptop, the copier at end of lease — destroy or cryptographically erase, and document which.

The copier deserves its own line item. When your leased multifunction device goes back to the vendor, the drive inside it holds images of every referral, result, and insurance card it scanned. Make drive sanitization or retention a written term in the lease, not a verbal assurance from the sales rep.

Backups

You will not surgically remove one patient from a backup snapshot, and no one expects you to. Document your backup rotation and retention period, and state in your policy that purged records age out of backups on that schedule. Reasonable and documented beats perfect and undocumented.

A Destruction Calendar That Someone Actually Runs

Roles

  • Privacy officer — owns the policy, approves each destruction batch in writing, holds the certificate file
  • Records or HIM lead — generates the eligibility report, applies exclusions, stages the batch
  • Practice manager — confirms no open litigation, audit, or patient complaint touches the batch
  • IT contact — executes electronic purges and confirms media sanitization

Worked example

Assume a ten-year state clock from last date of service. In January 2026, your records lead runs a report of charts whose most recent encounter was on or before December 31, 2015. The report returns 812 charts, including a block of colonoscopy age screening encounters from 2014 and 2015 with no subsequent visit.

She removes 47 charts flagged with an active legal hold, an open payer audit, or a pending records request. The practice manager confirms the exclusions in writing. The privacy officer signs a destruction authorization listing the batch ID, the date range, the record count, and the method.

Paper goes to the shredding vendor on February 3; the certificate comes back February 6 and is filed. IT purges the electronic records on February 10 and emails confirmation with the job log. The privacy officer files the authorization, the certificate, the exclusion list, and the job log together as one packet. That packet is retained for six years.

Run this quarterly, not annually. Quarterly batches are small enough that exclusions get reviewed carefully; annual batches get rubber-stamped.

Holds Beat the Calendar, Every Time

A litigation hold, a subpoena, an open OCR investigation, a payer audit, or a pending patient complaint freezes destruction for the affected records — full stop. The hold must be written, dated, scoped, and communicated to everyone who could delete something, including your billing vendor and your IT provider.

Build the hold flag into the chart itself so the eligibility report excludes it automatically. Relying on someone's memory during a purge cycle is how practices destroy records they were formally obligated to preserve, which turns a records problem into a legal one.

Release holds in writing too. A hold placed in 2019 and never lifted is why storage closets fill up.

What Your Auditor Will Ask For

If you are ever asked to demonstrate that your disposal practices are sound, you will need to produce a short, specific set of documents. Assemble them now:

  • A written retention schedule by record type, citing the state statute or contract term that sets each period
  • A written disposal policy naming methods, approvers, and documentation requirements
  • Signed destruction authorizations and certificates for the past six years
  • Executed BAAs with every shredding, storage, backup, fax, and billing vendor
  • Workforce training records showing staff know not to put PHI in the regular trash
  • A current risk analysis that addresses storage locations and media disposal

Nothing on that list is exotic. All of it is the kind of documentation practices intend to build and then postpone. If your policy set and risk analysis are the gap, you can generate the full compliance document set rather than drafting from a blank page — then spend your time on the part that actually requires judgment, which is the retention schedule itself.

Before your next quarterly cycle, do two things: pull your vendor list and confirm every organization that touches a screening record has a current, enforceable agreement on file — you can build and export a signature-ready BAA in a single sitting if any are missing. Then open the storage closet and put a date on those fourteen boxes.

This article addresses records administration and does not provide clinical or legal advice. Retention periods vary by state and by contract; confirm yours with counsel.