HEART Score Records: Retention Clocks and Disposal Rules
A patient presented to the emergency department with chest pain in March 2019. The ED documented a heart score, ran serial troponins, and discharged with instructions to follow up with your practice. Your office received a 41-page fax, scanned it, and closed the loop. It is now June 2026 — seven years later — and a plaintiff's firm has sent a preservation letter naming that encounter. Your records clerk finds the scanned PDF in the chart, a duplicate in a shared network folder, an unindexed copy in the fax server's sent items, and a set of paper originals in a storage unit nobody has audited since 2021. This article is about that mess: how long you must keep those records, where the copies hide, and how to destroy them in a way that survives an audit.
What a HEART Score Encounter Leaves Behind in Your Records
The HEART score is a risk-stratification tool used during chest pain evaluation. Administratively, what matters is not the score itself but the fact that it is a composite — it pulls from history documentation, an ECG tracing, laboratory results, and demographic data, and it usually triggers a decision about whether the patient goes home, gets admitted, or gets referred out.
That means a single HEART score encounter almost never lives in one place. The narrative note sits in your EHR. The ECG tracing may live in a separate cardiology device system or as an imported image. The troponin results arrive through a lab interface and may also exist as a standalone PDF. If the encounter originated at a hospital and landed in your practice, you hold a copy of someone else's designated record set alongside your own.
Retention and destruction policy has to account for all of it. A policy that says "we keep charts for seven years" and stops there is not a policy. It is a sentence.
How Long Do You Have to Keep HEART Score Records?
HIPAA does not set a medical record retention period. The Privacy and Security Rules require you to retain compliance documentation — policies, procedures, risk analyses, BAAs, authorizations, notices, and required accountings — for six years from creation or from the date it was last in effect, under 45 CFR 164.316(b)(2)(i). Patient charts are governed by other clocks:
- State medical record law. The controlling minimum for most practices. Common ranges run from six to ten years after the last patient encounter for adults, with longer periods for minors.
- Medicare Conditions of Participation. Hospitals must retain medical records at least five years (42 CFR 482.24); critical access hospitals, six years from the last entry (42 CFR 485.638).
- Federal program contracts. Certain managed care and risk-contract arrangements impose ten-year retention on records supporting payment and encounter data.
- Laboratory records. CLIA sets its own minimums for test requisitions and reports, measured in years and separate from the chart retention clock.
- Minors. Most states run the clock from the age of majority, not the date of service. A HEART score documented for a 16-year-old can carry a retention obligation into the next decade.
- Litigation hold. Overrides every clock above. Once you have notice of a claim, destruction stops.
Your policy should state a single institutional retention period equal to the longest applicable clock, not a per-record calculation your front desk has to perform. Complexity at the point of destruction is how records get shredded early.
The Number You Actually Publish
Pick one number, document how you derived it, and cite the underlying authorities in the policy itself. When counsel or a surveyor asks why you chose ten years, the answer should be a paragraph in your retention policy, not a recollection from a 2022 staff meeting.
Mapping Every Copy Before You Write the Destruction Procedure
You cannot destroy what you have not inventoried. Before your policy has any operational meaning, walk the path a single HEART score record takes through your organization and list every resting place.
The Twelve Places to Check
- The EHR chart and its audit log
- Scanned-document repository or DMS
- Fax server inbound and outbound queues
- Secure messaging or referral portal attachments
- Cardiology device systems holding ECG tracings
- Lab interface staging tables and result PDFs
- Release-of-information vendor's platform
- Billing and claims scrubbing systems with attached clinical documentation
- Shared network folders used for referral packets
- Staff mailboxes and sent items
- Offsite paper storage boxes
- Backups, snapshots, and archived EHR instances from a prior vendor
Numbers 10, 11, and 12 cause most of the trouble. Legacy EHR archives are the quiet killer — practices migrate systems, keep the old database "just in case," and never apply a retention schedule to it. Ten years later it contains records that should have been destroyed in 2020 and is running on an operating system nobody patches.
What Secure Destruction Actually Requires
HHS is direct on this point: PHI must be rendered unreadable, indecipherable, and unable to be reconstructed. Paper goes to cross-cut shredding, pulping, pulverizing, or incineration. A recycling bin is not disposal. A locked bin awaiting pickup is storage, and it is your responsibility until the vendor takes custody.
For electronic media, the reference standard is NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization. It distinguishes three outcomes — clear, purge, and destroy — and matches each to media type and risk. Deleting a file is none of them. Reformatting a drive is not purging. Your policy should name the method by media class: workstation SSDs, imaging device drives, backup tapes, USB media, and the multifunction copier in the billing office that has been quietly storing scanned HEART score packets on an internal disk since 2019.
Improper disposal remains its own breach category in OCR's public reporting. You can review the reported incidents on the HHS Breach Portal, and the pattern is consistent: paper left in an unsecured dumpster, and devices sold or returned to a lessor without sanitization.
Documentation That Makes Destruction Defensible
Every destruction event needs a record that survives longer than the records destroyed. Capture: date, description of what was destroyed (record type, date range, volume — never patient names in a log that is itself retained loosely), method, the person who authorized it, the person who witnessed or performed it, and the vendor's certificate of destruction with its serial or tracking reference.
Keep destruction logs at minimum six years, aligned with your 164.316 documentation clock. In practice, keep them indefinitely. They are small, and they are the only proof that the 2019 chart you no longer have was disposed of on schedule rather than lost.
Your Shredding and Storage Vendors Are Business Associates
This is the most commonly missed BAA in ambulatory practice. A shredding company that picks up locked bins containing HEART score packets creates, receives, maintains, or transmits PHI on your behalf. So does the offsite storage facility, the IT asset disposition firm that wipes your retired laptops, and the release-of-information vendor that pulls records for attorney requests.
Check three things in each agreement. First, does a signed BAA exist and does it name the correct legal entity — not a parent company that dissolved in a 2023 merger? Second, does it require the vendor to bind its own subcontractors, since national shredding brands frequently franchise routes to local operators? Third, does it address 45 CFR 164.504(e)(2)(ii)(J) — return or destruction of PHI when the agreement terminates, and what happens if return or destruction is infeasible?
If you find a vendor operating without a current agreement, you can produce a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export, one-time purchase and no subscription. That is faster than routing a template through counsel for a routine shredding contract, and it closes the gap before your next audit rather than after it.
A Worked Timeline for One Encounter
Adult patient, chest pain workup with documented HEART score, ED encounter March 2019, referred to your cardiology practice, last visit with your office November 2019. Assume a state minimum of seven years and an institutional policy of ten.
- Nov 2019: Retention clock starts at last encounter, not date of the ED visit.
- Nov 2020: Paper originals boxed and sent to offsite storage. Box manifest records destruction-eligible date of November 2029.
- 2022: EHR migration. The legacy instance is archived — and gets its own line on the retention schedule, with the same 2029 date.
- June 2026: Preservation letter arrives. Legal hold applied across EHR, archive, storage boxes, and the ROI vendor's platform. The 2029 date is suspended, and the suspension is documented.
- Hold release: Privacy officer confirms in writing, clock resumes, records return to the standing schedule.
- Nov 2029 (assuming no hold): Destruction batch assembled, authorized by the privacy officer, executed with certificate, logged.
The failure point in that sequence is the 2022 migration. If nobody assigned the archived instance a retention date, it sits forever, unpatched, holding records you have no obligation to keep and every obligation to protect.
Assigning the Work
Privacy officer: owns the retention schedule, authorizes every destruction batch, applies and releases legal holds in writing.
Practice manager: owns the vendor inventory and BAA currency, verifies certificates of destruction arrive and get filed.
IT or MSP: owns media sanitization methods, decommissioning of legacy systems, and confirmation that backups age out on the same schedule as production data.
Records staff: executes batches, maintains logs, flags anything under hold before it enters a destruction queue.
Run the destruction cycle quarterly, not annually. Annual cycles produce large batches, and large batches produce mistakes.
Five Questions to Ask This Quarter
- Can you produce your written retention schedule in under five minutes, with the authorities it relies on cited?
- Does every shredding, storage, ITAD, and ROI vendor have a current BAA naming the correct entity?
- When did you last receive and file a certificate of destruction?
- What is the retention date assigned to your archived legacy EHR instance?
- Who has authority to suspend destruction when a preservation letter arrives, and what happens if they are on vacation?
Next Step
Start with the vendor list — it is the shortest task and the one most likely to be out of date. Pull every entity that touches records containing HEART score documentation in transit, storage, or disposal, and confirm each has a signed agreement covering destruction obligations at termination. Where one is missing, generate a BAA you can send for signature the same day. If your broader policy set and risk analysis need the same attention, automated HIPAA documentation tooling will get the retention policy itself into writing. Neither is a certification, and no product carries government endorsement — but both produce the documents an investigator will ask to see.