Intertrigo Treatment Records: Retention and Disposal
Six years is the only retention number HIPAA hands you outright, and it does not apply to the chart. It applies to your policies, your risk analyses, your signed authorizations, your accounting-of-disclosures log — the paperwork about the paperwork. So when a staff member asks how long to keep the records from an intertrigo treatment visit — the encounter note, the dermatology referral packet, the skin-fold photographs someone captured on a practice iPad — the answer comes from state law, payer contracts, and the retention schedule you wrote (or never wrote). This post covers which clocks run, when they start, what stops them, and how to destroy the records without creating a reportable breach.
What One Intertrigo Treatment Encounter Actually Leaves Behind
Intertrigo is a skin-fold condition typically managed in primary care, urgent care, or dermatology, and it is one of those diagnoses where clinicians photograph the affected area to document change over time. That single administrative fact — images plus a frequent referral pathway — is what makes the records footprint messier than a sore-throat visit.
Inventory a representative encounter and you will usually find artifacts in five places:
- The EHR. Encounter note, problem list entry, orders, patient instructions.
- The image store. Clinical photographs, sometimes inside the EHR, sometimes in a separate imaging module, sometimes on a shared device's camera roll.
- The referral trail. Outbound fax or direct message to dermatology, the consult note that comes back, the cover sheet sitting in a desk tray.
- Paper at the front desk. Scanned-and-not-yet-shredded intake forms, printed superbills, the day's schedule with names and reasons for visit.
- The billing system and clearinghouse. Claim, remittance, any appeal correspondence describing the condition.
A retention schedule that only covers "the medical record" governs the first bucket and abandons the other four. That is the gap auditors and plaintiffs' attorneys find first.
How Long Do You Keep Intertrigo Treatment Records? The Short Answer
There is no federal medical-record retention period. Retention for the clinical chart is set by state law, and it commonly runs somewhere in the range of six to ten years from the date of last treatment for adults, with longer periods for minors (frequently measured from the patient's age of majority). Layer on top of that:
- HIPAA administrative documentation: six years from creation or from the date it was last in effect, per 45 CFR §164.530(j)(2) and §164.316(b)(2)(i). This covers policies, BAAs, authorizations, NPP acknowledgments, sanction records, and risk analyses — not the chart.
- Payer and program requirements: Medicare and Medicaid participation rules and managed care contracts impose their own retention floors, and some run longer than your state's medical-record statute.
- Malpractice statute of repose: your carrier will often recommend retention beyond the statutory minimum.
Operating rule: apply the longest applicable period to each record class, document why you chose it, and never destroy on the shorter clock because it is more convenient. Your schedule should name the source of every number in it.
Start the Clock Correctly
Most retention disputes are not about the length of the period. They are about the start date. "Date of last treatment" for a chronic or recurring skin condition is not the date of the first intertrigo treatment visit — it resets with every subsequent encounter, including a telehealth follow-up or a refill that generated documentation. Build your purge queries around the most recent encounter date in the record, not the record creation date.
For minors, the clock usually does not begin until the patient turns 18. That means a pediatric chart may need to survive two EHR migrations. Flag those records at intake, not at purge time.
Legal Hold: The Override That Beats Your Schedule Every Time
The moment your practice knows of — or reasonably anticipates — litigation, an OCR investigation, a payer audit, a subpoena, or a board complaint, routine destruction stops for everything within scope. This is not a HIPAA rule; it is an evidence rule, and it is the single fastest way a records program turns into a legal problem.
Write a hold procedure that answers four questions in one page:
- Who can issue a hold? Name the roles — practice administrator, privacy officer, outside counsel. Not "management."
- How does it reach the systems? A hold notice that stops the shred vendor but not the EHR's automatic archive purge is worthless.
- Who acknowledges it? Custodians sign. Keep the signatures.
- Who releases it? Holds that nobody lifts become permanent retention by accident, which is its own risk.
One practical trap: a patient's request for records under the right of access is not itself a legal hold, but destroying a record after you receive the request and before you fulfill it is indefensible. Freeze anything under an open access request until the response is delivered and logged.
Secure Destruction That Survives an Audit
HHS has been explicit that leaving PHI in dumpsters, unsecured recycling bins, or on discarded electronics is a Privacy Rule failure, and OCR has resolved multiple enforcement matters over exactly that pattern. The agency's guidance on disposal of protected health information is short and worth putting in front of your office manager.
Paper
Cross-cut shredding, pulping, or incineration. Locked collection consoles — not open bins — in every area where PHI is printed, including the back office and the provider workroom. If shredding happens on site, someone from the practice witnesses it and signs the log. If it happens off site, you get a certificate of destruction that identifies the pickup date and container count.
Electronic Media
Deleting a file is not sanitization. Emptying a recycle bin is not sanitization. Use NIST Special Publication 800-88 Rev. 1 as your standard and pick the appropriate level — clear, purge, or destroy — based on whether the device leaves your control. Copiers, multifunction scanners, and fax machines contain hard drives; put them on the same list as laptops.
Clinical Photographs
Images from an intertrigo treatment visit are the record type most likely to be stranded on a device. If a photo was ever taken on a phone or tablet camera roll before being imported, deleting the EHR copy does nothing to the device copy. Your device offboarding checklist — for staff departures, trade-ins, and warranty returns — needs an explicit image-store step, verified by someone other than the departing user.
Legacy Systems
When you migrate EHRs, the old system usually survives as a read-only archive. That archive holds real PHI, needs real access controls, and needs a real end-of-life date. Decide at migration time who terminates it, on what date, and what evidence of destruction you will accept from the vendor.
Every Link in the Disposal Chain Is a Business Associate
The shredding company. The off-site box storage company. The IT firm that wipes and recycles your workstations. The archive host running your decommissioned EHR. The scanning bureau that digitized your legacy charts. Each one creates, receives, maintains, or transmits PHI on your behalf, and each one needs a signed business associate agreement before the first pickup — not after.
Two clauses matter more than the boilerplate in a disposal BAA: a specified destruction method (name the standard), and an obligation to provide certificates of destruction that your practice retains. If a vendor's certificate says only "materials destroyed," it will not help you reconstruct what happened when someone finds a chart page in a parking lot.
If your vendor list has grown past what you can paper by hand, generate a signature-ready agreement with the six-step business associate agreement builder — it exports PDF and DOCX, it is a one-time purchase rather than a subscription, and it gets a new shred or storage vendor under contract the same afternoon you onboard them.
Assigning the Work: Who Does What, and When
A retention policy nobody executes is worse than no policy, because it documents the standard you failed to meet. Assign named roles.
- Privacy officer — annually. Reviews the retention schedule against current state law and payer contracts. Signs and dates the review, even if nothing changed.
- Practice administrator — quarterly. Runs the purge-eligible report, checks it against the open legal hold list, approves or defers each batch in writing.
- Records custodian — monthly. Reconciles shred vendor certificates against pickup logs. Missing certificate means a call, not a shrug.
- IT lead — at each device retirement. Records serial number, sanitization method, date, and technician. This log is itself a HIPAA document with a six-year life.
- Front desk supervisor — daily. Clears printers, fax trays, and workstation surfaces at close. Ninety percent of paper incidents start here.
A Worked Example
A 42-year-old patient is seen in March 2016 for an intertrigo treatment visit, referred to dermatology, and seen once more in May 2016. No further encounters. Assume a state minimum of seven years from last treatment and a payer contract requiring ten years for claims documentation.
The chart becomes purge-eligible in May 2026 under the longer of the two clocks — not May 2023. The referral letter and consult note are part of the designated record set and go with it. The authorization the patient signed to release records to the dermatologist is HIPAA administrative documentation, retained six years from signature and therefore already past its floor, though most practices keep it with the chart. The claim and remittance ride the ten-year payer clock. When the batch is approved, the destruction log records: record type, date range, patient count, method, vendor, certificate number, and the approver's name. That log is retained for six years.
If a demand letter arrives in April 2026, everything above freezes until counsel releases it.
Documentation Is the Deliverable
When OCR or a state regulator asks about disposal, they are not asking whether you shred. They are asking for the policy, the schedule with legal citations, the approval records, the vendor BAAs, the certificates, and the training roster showing that the person emptying the console knew why the console was locked. Breach reports involving improper disposal are visible on the HHS breach portal, and they are unforgiving precisely because the failure is so mundane.
If your retention schedule, disposal policy, and supporting document set are still living in three different Word files with inconsistent dates, automated HIPAA policy and risk analysis generation will get you to a consistent, dated, reviewable set faster than another round of copy-paste.
Start Here This Week
Pull one closed encounter — an intertrigo treatment visit works fine because of the photos and the referral — and trace every copy of it across your systems, vendors, and devices. Whatever you cannot account for is your retention gap. Close it with a written schedule, a legal hold procedure, and a signed agreement with every vendor who touches the record on its way out. If a disposal vendor is currently working without one, generate the BAA before the next pickup.