Epclusa Records: Retention Clocks and Secure Disposal
There is a banker's box in your records room labeled "HCV PA 2019." It holds prior authorization packets, payer denial letters, fax confirmations from a specialty pharmacy, income verification forms for a manufacturer assistance program, and lab printouts that were scanned but never shredded. Somebody asks whether it can go. If your answer is "probably," you do not have a retention policy — you have a habit. This post walks through how to build an actual retention and destruction schedule for Epclusa treatment records: which clocks start when, which files sit outside your EHR, and what "secure destruction" has to mean before you sign a certificate.
The clinical context matters only because it shapes the paperwork. Epclusa is a direct-acting antiviral for hepatitis C, dispensed through specialty pharmacy channels, almost always gated by prior authorization, and delivered over a finite, time-limited course. That combination produces a dense burst of documentation across four or five organizations in a short window — and then the patient's episode of care closes. Records that arrive in a burst tend to be retained by accident and destroyed by accident. Both are audit findings.
What Actually Lands in Your Files During an Epclusa Course
Before you can write a retention schedule, inventory the artifacts. Most practices underestimate this by half, because they think about the chart and forget the operational exhaust around it.
- Inside the EHR: encounter notes, referral documentation, lab results returned from the reference lab, medication list entries, and the results of any post-treatment follow-up visit.
- Outside the EHR, on paper: the prior authorization packet and its attachments, payer denial and appeal correspondence, faxed shipment confirmations and refill coordination sheets from the specialty pharmacy, signed patient assistance or copay-support applications with financial documentation attached, and printed lab reports used to assemble the PA.
- Outside the EHR, electronic: PDFs saved to a shared drive by whoever assembled the appeal, portal downloads sitting in a staff member's Downloads folder, secure-message threads with the specialty pharmacy, spreadsheet trackers listing patients by name and treatment status, and the fax server's stored image archive.
- Administrative and financial: claims, remittance advice, patient statements, financial hardship determinations, and — if your organization participates — 340B eligibility and dispensing documentation.
Every item on that list is PHI. The spreadsheet tracker is PHI. The fax server archive is PHI. Your retention policy has to name each category and assign it a clock, an owner, and a destruction method. A policy that only governs "the medical record" leaves the majority of Epclusa-related documentation unmanaged.
How Long Should You Keep Epclusa Treatment Records?
Short answer: HIPAA does not set a medical record retention period. HIPAA's six-year requirement at 45 CFR 164.316(b)(2) applies to your compliance documentation — policies, procedures, risk analyses, authorizations, accounting-of-disclosure logs, and business associate agreements — for six years from creation or from the date it was last in effect. The clinical record itself is governed by state law, your payer contracts, and program-specific rules such as Medicare conditions of participation and 340B requirements. In practice, most organizations land on a schedule of six to ten years from the date of the last encounter for adults, longer for minors, and defer to whichever rule is strictest.
So for a patient who completed an Epclusa course in August 2019, the question is not one clock but five running in parallel. You retain until the last one expires.
The clocks to write into your schedule
- State medical record retention. Usually expressed as N years from the last date of service, with a separate rule for minors keyed to age of majority. Pull your state's actual statute or board rule and cite it in the policy by number.
- HIPAA documentation — six years. Signed authorizations for disclosure to a manufacturer assistance program, your accounting of disclosures, and the BAA with the shredding vendor all live here.
- Payer and federal program audit windows. Medicare and Medicaid audit and overpayment recovery periods, plus whatever your commercial contracts specify. Claims-supporting documentation for a high-cost specialty drug is exactly what a payer audits.
- 340B and manufacturer program records, if applicable — eligibility determinations and dispensing records carry their own retention expectations, often longer than your state's clinical minimum.
- Litigation hold. Any hold overrides every clock above. Your policy needs a named person who can suspend destruction and a mechanism to flag held records so a scheduled purge does not sweep them.
Write the schedule as a table your records clerk can read without calling you. Category, retention period, trigger date, destruction method, approver.
When 42 CFR Part 2 Rides Along With Epclusa Records
Hepatitis C treatment is frequently coordinated alongside substance use disorder treatment, and that is where retention policy gets sharp edges. If any portion of the record originated from a federally assisted Part 2 program, those records carry restrictions that follow the record into your files — including, in many cases, a prohibition on redisclosure without specific consent.
The 2024 final rule aligning 42 CFR Part 2 more closely with HIPAA reached its compliance date in February 2026, which means your policies should already reflect it. Two operational implications for retention: first, Part 2 records commingled into your general chart may pull the entire record into a stricter disclosure regime unless you segregate them; second, Part 2 contains its own rules about what happens to records when a program discontinues operations. If your practice absorbs records from a closing referral partner, you inherit those obligations.
Practical step: flag at intake whether any incoming Epclusa-related documentation carries a Part 2 notice, and route it to a segregated storage location with its own destruction workflow. Do not let it land in the general scan queue.
What "Secure Destruction" Has to Mean
HHS guidance on disposal is unambiguous: PHI must be rendered essentially unreadable, indecipherable, and otherwise cannot be reconstructed. Dumpsters, recycling bins, and "we tore it in half" do not satisfy that standard, and OCR's enforcement history includes cases built entirely on paper records found where the public could reach them. Read the department's guidance on disposing of protected health information and keep a copy attached to your policy.
Paper
Cross-cut shredding, pulverizing, or incineration. If you shred in-house, the shredder specification belongs in the policy and the machine belongs in a locked area. If you use a service, your locked collection consoles must actually be locked, and the console key must not live in the same unsecured drawer as the exam room keys. Reconcile the volume you deposit against the certificate of destruction you receive — a certificate that never varies in weight month to month is a certificate nobody is generating from real data.
Electronic media
Deleting a PDF from a shared drive does not sanitize the media it lived on. Use NIST Special Publication 800-88 Revision 1 as your reference: Clear, Purge, and Destroy are distinct outcomes, and the right one depends on the media type and whether the device leaves your control. For the specific artifacts an Epclusa workflow generates, that means the fax server's image store, the copier hard drive, the laptop of the staff member who assembled the appeal packets, and any external drive used for a backup that predates your current retention rules.
One more disposal obligation catches practices by surprise: if your financial-assistance screening ever pulls information from a consumer reporting agency, the FTC's Disposal Rule applies on top of HIPAA. The FTC's summary of how to dispose of consumer report information is two pages and worth reading before your next hardship-application cycle.
The Vendors Holding Your Epclusa Records — and the BAAs You Owe
Retention policy fails at the vendor boundary more often than anywhere else. Walk the Epclusa record path and list every outside party that touches, stores, or destroys PHI on your behalf:
- The document destruction company and any offsite storage facility
- Your scanning or release-of-information vendor
- The cloud fax provider retaining transmission images
- The prior authorization platform or clearinghouse
- The IT contractor who decommissions and disposes of workstations and copiers
- Backup and archive providers holding copies you cannot see
Each is a business associate. Each needs an executed agreement that specifies not only safeguards but what happens to your data at termination — return, destruction, or continued protection if return is infeasible. That termination clause is the one most practices never read, and it is precisely the clause that decides whether a vendor's copy of your Epclusa files disappears when you switch providers or sits on their storage array indefinitely.
If you find a vendor on that list without a current signed agreement — and the shredding company and the copier disposal contractor are the two most commonly missed — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. One-time purchase, no subscription. Get it signed before the next pickup, not after.
A Worked Example: The 2019 Box
Back to the banker's box. Here is how a policy resolves it in about twenty minutes.
Step one: identify the latest date of service represented in the box. Say the most recent post-treatment follow-up was October 2019.
Step two: apply the longest applicable clock. If your state requires seven years from last encounter, that expires October 2026 — the box stays. If it requires six, it expired October 2025, and you move to step three.
Step three: check the exceptions. Any minors? Any litigation or investigation hold? Any 340B or program documentation with a longer independent requirement? Any signed authorizations, which carry the separate six-year HIPAA documentation clock and may need to be pulled and retained even after the clinical content is destroyed?
Step four: confirm the electronic duplicate exists and is retrievable, if the paper was scanned. Destroying a paper original whose scan is corrupt is how practices fail records requests two years later.
Step five: log it. Date, category, volume, method, vendor, certificate number, approver. Retain that log for six years — it is HIPAA documentation, and it is the artifact that proves destruction was policy-driven rather than convenient.
Where These Programs Break
Four failure patterns show up repeatedly in practices handling specialty-drug workflows:
Shadow copies nobody inventoried. The PA packet exists in the EHR, in a shared drive folder, in a fax archive, and in an email attachment. Your destruction event covered one of four. Fix this by assigning a system-of-record for each artifact type and prohibiting working copies outside it.
Trackers that outlive their purpose. The spreadsheet built to monitor a cohort through treatment becomes a permanent file on a shared drive. Give operational trackers an explicit expiration and a named owner.
Destruction without documentation. Records go, the certificate is filed nowhere, and the practice cannot demonstrate compliant disposal during an investigation. Treat certificates of destruction as compliance records, not receipts.
No trigger date on the record. If nothing on the folder tells the clerk when the clock started, the clerk will guess. Stamp the retention-through date at filing.
If your retention schedule, disposal procedure, and vendor inventory don't yet exist as written documents, that is the gap to close first — automated risk analysis and policy generation will produce the document set faster than drafting from scratch, and a written schedule is what turns "probably" into a defensible decision. Start with the box you already know about.