Costochondritis Treatment Records: Retention & Disposal
A shredding vendor sends your office manager a quote for a one-time purge of 41 banker's boxes. Somewhere in those boxes are charts from 2014 that include a chest-wall pain workup: an ED transfer summary, a cardiology consult that ruled out cardiac causes, a chest film report, and three follow-up notes documenting costochondritis treatment. Your manager wants a yes or no by Friday.
This post is about that yes or no. Not the clinical content of the encounter — the records lifecycle around it: which retention clock actually governs the chart, what belongs in the designated record set, which vendors hold copies you cannot see, and what secure destruction has to look like when a regulator asks you to prove it happened. If you sign the vendor contracts and answer the records requests, this is your problem.
Three Different Clocks Run on a Costochondritis Treatment Record
Administrators routinely collapse these into one number and get it wrong. They are separate obligations with separate triggers.
Clock one: the six-year HIPAA documentation clock
HIPAA requires covered entities to retain compliance documentation — policies, procedures, risk analyses, authorizations, notices of privacy practices, and required action logs — for six years from the date of creation or the date it was last in effect, whichever is later. See 45 CFR 164.316(b)(2)(i) for the Security Rule version and 164.530(j) for the Privacy Rule version.
This clock does not govern the medical record. It governs your paperwork about the medical record. Your signed authorization allowing the cardiology group to receive the chart is on the six-year clock. The chart itself is not.
Clock two: state medical record retention law
Your state's medical practice act, licensing board rules, or health department regulations set the retention period for the chart. The range across states is wide — commonly somewhere between five and ten years from the last date of service for adults, with a separate and longer rule for minors that runs from the date the patient reaches the age of majority.
Write your state's citation into the policy. Not "per state law." The actual section number, the actual number of years, and the actual trigger event. When a records request arrives for a 2017 encounter, whoever is at the desk needs to answer from the policy, not from memory.
Clock three: payer, program, and contract terms
Medicare and Medicaid participation conditions, managed care contracts, and grant agreements impose their own document retention requirements, and several run longer than typical state medical record rules. Some managed care contract provisions require retention of records supporting claims and encounter data for ten years. Pull the actual contract language for every payer you bill and log the longest requirement in one place.
The operating rule: your retention schedule is the longest applicable clock, not the average. If state law says seven years and a payer contract says ten, the chart lives ten years.
How Long Must You Keep Costochondritis Treatment Records?
There is no HIPAA-specified retention period for medical records. HIPAA sets a six-year retention requirement for compliance documentation only. The chart documenting an evaluation and costochondritis treatment is retained according to (1) your state's medical record retention statute, (2) the longest applicable payer or program contract term, and (3) any active legal hold. In practice, most practices land on a single published number — often seven to ten years from last date of service, longer for minors — and apply it uniformly rather than trying to sort charts by diagnosis. Destroy only after all three conditions clear.
Diagnosis-Based Retention Rules Fail in Practice
Some administrators want a tiered schedule: short retention for minor musculoskeletal complaints, long retention for chronic disease. Don't. A chest wall pain episode is exactly the case that breaks the tier.
Chest pain workups generate multi-organization records by design. A patient presenting with chest discomfort is frequently evaluated to exclude cardiac and pulmonary causes before a musculoskeletal cause is identified, which means the chart in your office may include an ED record, an imaging report, a cardiology consult, and lab results — all originating elsewhere. The visit that ends in documented costochondritis treatment is a low-acuity encounter attached to a high-acuity paper trail.
Your staff cannot reliably sort that at the file level, and diagnosis-driven purging invites an error you can never undo. Apply one retention period to the entire record, keyed to the last date of service.
Define the Designated Record Set Before You Destroy Anything
The designated record set is what a patient can request under the right of access. It is not everything in your building, and it is not everything in your practice management system.
Outside records you received are yours now
When the cardiology group faxes back a consult note and you file it in your chart, that note becomes part of your record and is subject to your retention schedule and your access obligations. The same is true of the CD-ROM of imaging a patient hand-carried in, if your staff imported it. If it informs your care decisions and lives in your chart, treat it as in scope.
Duplicates, scan queues, and shadow copies
Scanning workflows leave residue. The paper original sits in a "to be shredded" bin for weeks. The scanner's local cache holds images. The intake email account still has the PDF the referring office sent. The front-desk workstation has a folder called scans_temp.
Inventory those locations by name in your policy, assign an owner to each, and set a clearing interval. A retention schedule that governs the chart but ignores the scan queue is a paper policy.
Things outside the designated record set
- Peer review and quality assurance materials, where state law protects them
- Internal incident reports about a mis-sent fax
- Duplicate working copies staff created for convenience
- Business records — billing system audit logs, appointment reminder delivery logs
Excluded from access does not mean unregulated. Those items still contain PHI and still need secure disposal.
The Referral Trail Creates Copies You Don't Control
Count the organizations that touched one chest pain episode: your practice, the imaging center, the cardiology group, the billing company, the release-of-information service, the cloud backup provider, the document storage warehouse, the shredding vendor. Seven or eight entities, and your retention schedule reaches only the first one.
Each vendor relationship needs a Business Associate Agreement that addresses what happens to PHI at the end of the engagement — return or destruction, and what the vendor does when return is not feasible. This is the clause administrators skip and later regret, because it is the only leverage you have when a records storage company sends a going-out-of-business notice with 60 days' warning.
If any vendor in that chain is operating on a handshake, a purchase order, or a BAA you inherited from a predecessor and have never read, fix it before your next purge cycle. You can produce a signature-ready Business Associate Agreement through a six-step BAA wizard with PDF and DOCX export — one-time purchase, no subscription — which is faster than waiting three weeks for a vendor's legal department to send a template you will have to redline anyway.
Ask every records vendor four questions in writing
- What is your destruction method, and does it follow a recognized media sanitization standard?
- Do you subcontract destruction, and are those subcontractors under your BAA?
- What does your certificate of destruction contain, and how fast do we get it?
- What happens to our PHI if you are acquired, close, or we terminate?
Secure Destruction: Paper, Drives, and the Fax Machine Nobody Decommissioned
The Privacy and Security Rules require you to implement policies for the final disposition of PHI and the media it sits on — see 45 CFR 164.310(d)(2)(i) and (ii). HHS has published direct guidance on what covered entities must do when disposing of PHI, and the reference standard for media sanitization is NIST Special Publication 800-88 Revision 1. Cite both in your policy so the method is not a matter of opinion.
Paper
Cross-cut shredding, pulping, or incineration. Recycling bins are not destruction. A locked shred console in a hallway is fine; an unlocked cardboard box under the copier is a reportable incident waiting to happen. If a vendor collects, the console stays locked until the vendor's truck.
Electronic media
Workstations, laptops, external drives, backup tapes, and the internal storage in multifunction copy/fax machines. That last one is the most commonly missed item in a small practice. When a leased copier goes back to the leasing company, the drive inside it may hold years of scanned charts and inbound faxes — including everything a referring cardiology office ever sent you.
Decide per device: clear, purge, or destroy, using the NIST definitions. Log the serial number, the method, the date, and the person who performed or witnessed it.
Certificates of destruction
Keep them for at least six years. A certificate should identify the material or media, the destruction date and method, the facility, and an authorized signature. "Services rendered" on an invoice is not a certificate. When an investigator asks how you disposed of the 2016 charts, the certificate is the answer; your recollection is not.
A Worked Example: Retiring the 2019 Cohort
Say your published schedule is ten years from last date of service, and it is June 2026. You are eligible to consider charts whose last service date falls in 2016 or earlier. Here is the sequence.
- Generate the candidate list. Practice management report: all patients with no encounter after 12/31/2016. Export to a controlled worksheet, not someone's desktop.
- Screen for minors. Any patient who was under the age of majority at last service moves to a separate list with a different trigger date. This step is non-negotiable.
- Screen for holds. Cross-check against open claims, malpractice notices, workers' compensation matters, subpoenas, board complaints, active OCR or state AG inquiries, and any payer audit. Holds override the schedule every time.
- Screen for payer terms. If a chart supports claims under a contract with a ten-year term, confirm the clock ran from the correct trigger — often claim payment or contract expiration, not date of service.
- Get sign-off. Privacy Officer approves the final list in writing. Clinical leadership initials it. Both signatures go in the destruction file.
- Destroy and document. Vendor pickup or on-site destruction, certificate received, list attached to certificate, entry made in the destruction log.
- Purge the shadow copies. Scan queue, temp folders, the release-of-information portal, the old backup set, and the offsite storage manifest. Same list, same sign-off.
- Update the index. Record that the chart was destroyed and when. This is what lets your front desk answer a 2028 records request accurately.
That last step matters more than administrators expect. Under the right of access you must respond to a request within 30 days. If the record no longer exists, your response says so and identifies the destruction date and the policy that authorized it. If you have no index entry, your response is a shrug — and a shrug looks like concealment.
Two Things You Keep Even After the Chart Is Gone
First, the accounting of disclosures. Patients can request an accounting covering the six years prior to the request, so disclosure logs survive the chart's destruction. Do not let a purge sweep away the log that documents where those records went.
Second, the destruction record itself, plus the retention policy version that was in effect on the destruction date. Policies change. Being able to show which version governed a 2026 purge is the difference between a documented decision and an unexplained gap.
Assign Names, Not Departments
Retention schedules fail because nobody owns the calendar. Put four names on the policy: who runs the annual candidate report, who performs the hold screening, who signs the approval, and who verifies the certificate arrives. Set the purge as a recurring calendar item with a fixed month.
Then include retention and disposal in your annual risk analysis. Unmanaged offsite boxes, undocumented copier drives, and vendors without current BAAs are all findings a reviewer will identify — and all are cheap to fix before someone else names them. If you are rebuilding the underlying document set, a platform that automates HIPAA risk analysis and policy generation will get the retention policy, the disposal procedure, and the vendor inventory into consistent shape faster than assembling them from scratch. For payer-side requirements, verify current program rules directly against CMS guidance rather than relying on a consultant's summary.
Do This Before Friday
Answer the shredding quote by checking three things: your state's citation, the longest payer term you are bound to, and whether any hold touches the boxes. If all three clear and you have a signed BAA with the destruction vendor, proceed and file the certificate. If the BAA is missing, that is the one item that has to come first — draft and export a signature-ready agreement before the truck arrives, then destroy with the paperwork behind you.