Concussion Test Records: Retention Clocks and Disposal
An attorney's office calls your practice on a Tuesday asking for every concussion test result you hold for a patient who is now 22 years old. The baseline screening happened when she was 15, on a third-party testing platform your practice stopped paying for in 2021. The post-injury encounter notes are in your current chart system. Somewhere in a storage unit there is a banker's box of intake forms from the high school sports physical clinic you used to run in August.
This article is about that gap: how long you are required to keep concussion test records, where those records actually live, and how to destroy them in a way you can prove years later. It is a records and vendor management problem, not a clinical one.
Why Concussion Test Records Have More Than One Retention Clock
Operators routinely assume HIPAA sets a medical record retention period. It does not. HIPAA sets a six-year retention requirement for the documentation the rules themselves require — your policies, your risk analysis, your notices, your authorizations, your signed agreements — under 45 CFR 164.316(b)(2)(i). The chart itself is governed by state law, payer contracts, and program-specific rules.
Concussion-related encounters complicate this because the records tend to cross organizational lines. A baseline screening may be administered under a school athletics program, the post-injury encounter documented in your practice, and follow-up handled by a specialist elsewhere. Each holder has its own clock, and none of them are synchronized.
State medical record law sets the floor
Your primary retention period comes from your state's medical records statute or licensing board regulation. Periods commonly run from five to ten years after the last date of service for adults. Your compliance officer should have the exact citation written into the retention policy — not a number someone remembered from a webinar.
If your practice operates in more than one state, you do not get to pick the shorter period. Write the schedule by site, and note the governing citation next to each row.
The minor-age clock is the one that catches people
Concussion testing skews young. Most states extend retention for minors to the age of majority plus a fixed number of years. A 15-year-old tested in the summer of 2026 in a state requiring retention until age 18 plus seven years generates a destruction-eligible date of 2036 — a decade out, spanning at least one chart system migration and probably two vendor changes.
That is the single most common failure I see: the record is technically retained, but it sits in an archive nobody can search, in a format nobody can open, held by a vendor whose contract lapsed. Retention is not storage. Retention means retrievable and readable.
Payer, program, and research clocks stack on top
If the encounter touched a federal program, CMS-related documentation obligations may extend beyond your state period. If a school district or athletic association contract requires you to hold testing records for a defined term, that contract term is now part of your schedule. Read the contract before you purge.
How Long Should You Keep Concussion Test Records?
Short answer: keep them for the longest applicable period among (1) your state's medical record retention statute measured from the last date of service, (2) the minor-age extension if the patient was under 18 at the time of service, (3) any payer or school contract term, and (4) any active legal hold. HIPAA's six-year rule applies to your compliance documentation — policies, agreements, authorizations, disclosure logs — not to the clinical chart. When periods conflict, the longest one controls, and destruction stops entirely the moment a hold attaches.
Map Every Place a Concussion Test Record Lives
Before you can retire anything, you need an inventory. Do this as a half-day exercise with your records custodian, your IT contact, and whoever manages the sports medicine relationships. Walk the list literally, room by room and login by login.
- The chart system. Encounter notes, uploaded PDFs, scanned intake packets.
- The testing platform. Web-based screening tools store results on the vendor's infrastructure, often indefinitely, often under a school or district account rather than yours.
- Exported files. The PDF someone downloaded to a workstation desktop to fax to a specialist. Check shared drives and the folder named "scans."
- Email. Referral threads with attached results, sitting in three mailboxes.
- Paper. Sideline forms, parent consent packets, school clearance letters in the front-desk drawer.
- Backups and archives. Your previous chart system's export, the one on an external drive in the manager's office.
- Fax and print devices. Multifunction units store images on internal drives.
Every location on that list needs an owner, a retention rule, and a destruction method. If a location cannot be assigned an owner, that is your first finding.
The Vendor Contract Line Nobody Reads: Return or Destruction
When a business associate relationship ends, HIPAA expects the associate to return or destroy the protected health information it holds, or — if that is infeasible — to extend protections and limit further use. That obligation belongs in your written agreement, not in a support ticket you file after cancellation.
For concussion testing platforms specifically, ask three questions before you sign and again before you terminate:
- On termination, do we receive a complete export in a format we can read without your software? Name the format.
- How many days after termination do you destroy your copy, and will you issue written confirmation?
- Do your subcontractors — hosting, backup, analytics — hold copies, and are they bound to the same terms?
If your current agreements do not answer those questions, fix the paper before you fix anything else. HHS publishes guidance on business associate obligations and required contract provisions, and the required terms include the return-or-destroy clause. When you need to paper a new testing vendor, a scanning service, or a shredding contractor quickly, you can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — a one-time purchase, no subscription — rather than recycling a template of unknown origin.
Secure Destruction That Survives an Audit
Destruction means the information cannot be read or reconstructed. Tossing paper in a recycling bin, or deleting a folder and emptying the trash, does not qualify. HHS has been explicit on this point in its FAQ on disposal of protected health information, and improper disposal has generated enforcement activity for years, usually involving paper left in an unsecured container or devices sold without sanitization.
Paper
Cross-cut shred on site, or use a bonded vendor with locked collection containers and a chain-of-custody log. Require a certificate of destruction naming the date, volume, and method. File the certificate with your retention log — not in the shred vendor's portal you will lose access to.
Electronic media
Follow NIST's framework for media sanitization in Special Publication 800-88 Revision 1, which separates clear, purge, and destroy, and tells you which is appropriate for which media type and risk level. Apply it to workstations, laptops, servers, backup drives, tablets used for sideline testing, and the internal storage in copiers and fax machines when you return a lease.
Vendor-held data
You cannot shred what you do not physically hold. Your control is contractual: a termination clause, a destruction deadline, and written attestation. Track outstanding attestations on a simple list with dates. An unreturned attestation after 60 days is an open issue, not a formality.
Legal Hold Overrides Your Schedule
Head injury records draw litigation, workers' compensation claims, school district disputes, and disability determinations. The moment your practice receives notice of a claim, a subpoena, a records request from counsel, or a credible threat of litigation, destruction stops for those records — including automated purges.
Write the mechanics down. Who issues the hold notice? Who suspends the automated archive purge in the chart system? Who tells the shred vendor to skip a box? How is the hold released, and by whom? A retention policy without a hold procedure will eventually destroy something you needed.
Practical detail: your hold notice must reach the vendor too. If a testing platform runs a 24-month automatic deletion cycle, your hold is worthless unless someone sends it in writing and confirms receipt.
A Twelve-Month Destruction Calendar You Can Actually Run
Annual, scheduled, documented. Ad hoc purging is how organizations end up destroying the wrong year.
- January — Inventory refresh. Records custodian reconfirms every storage location, including any new testing platform added during the prior season.
- February — Eligibility report. Pull a list of records whose retention period expires this calendar year, segmented by adult, minor, and contract-governed.
- March — Hold screen. Privacy officer checks the eligibility list against open claims, subpoenas, and requests. Anything matched is removed and flagged.
- April — Approval. Practice administrator signs off on the final destruction list. Signature and date, on a document you keep for at least six years.
- May — Execution. Paper to the bonded vendor; electronic records purged from primary and archive systems; devices sanitized per NIST categories.
- June — Attestations. Collect certificates of destruction and vendor confirmations. File with the approved list.
- September — Vendor sweep. Confirm terminated vendors have destroyed their copies. Chase anything outstanding from prior years.
- November — Policy review. Check state statute changes, new payer or school contracts, and update the schedule.
Two roles, four artifacts, one calendar. That is the whole program.
What You Should Be Able to Produce in Ten Minutes
If a regulator, a plaintiff's attorney, or a school district compliance officer asks how you handled concussion test records for a given year, you should be able to hand over four documents without a search party:
- The written retention schedule, with the state citation and the minor-age rule stated explicitly.
- The signed destruction approval list for the year in question.
- The certificates of destruction and vendor attestations that match it.
- The business associate agreements for every vendor that touched those records, with the return-or-destroy clause visible.
If any of those four are missing, the practical exposure is not the missing paper — it is that you cannot demonstrate the record was destroyed on purpose rather than lost. Those look identical from the outside, and only one of them is defensible.
Practices building this from scratch usually need the surrounding document set too: the retention policy itself, the disposal procedure, the sanitization standard, and the risk analysis that ties them together. You can automate the risk analysis and full compliance document set rather than assembling it from scattered templates.
Start With the Vendor Paper
Pull your list of every platform, scanning service, storage facility, and shredding contractor that has touched a concussion test record in the last three years. Check each one for a current, signed agreement with an explicit destruction clause. Where one is missing, draft and export a signature-ready BAA this week — before the next season's testing volume arrives and the gap gets a decade older.