NPI Number Lookup Records: Retention and Destruction
A payer's special investigations unit sends your practice a letter asking you to substantiate the referring provider identifiers on 214 claims submitted in 2023. Your biller says she checked every one of them. Can you prove it? That question is why an npi number lookup — a thirty-second task at the front desk or in the billing queue — turns into a records retention problem three years later.
This post is for the person who owns records policy at a practice: the administrator, privacy officer, or compliance lead. It covers what an NPI verification leaves behind, which retention clocks apply, who owns each one, and how to destroy the material when the clock runs out. No clinical guidance here — this is filing, timing, and vendor management.
What an NPI Number Lookup Actually Leaves Behind
The lookup itself is a query against the NPPES database, which CMS publishes as a public NPI Registry. Nothing about querying a public directory is protected. The problem is the artifact your staff creates when they document the result.
In most practices, that artifact takes one of five forms. Each lands in a different system, under a different owner, with a different lifespan.
Where the artifacts land
- Screenshots pasted into email. "Confirmed Dr. Reyes, NPI ending 4471, for the Whitfield referral." Now a patient name and a referral fact live in an inbox with no retention rule.
- Credentialing files. Initial and re-credentialing packets typically include a printed NPPES record, taxonomy code, and a date-stamped verification note.
- Claim scrubbing logs. Your clearinghouse or billing system records validation passes and failures, often tied to claim IDs and therefore to patients.
- Referral tracking spreadsheets. The shadow system almost every specialty practice runs on a shared drive, mapping patients to outbound specialists and their identifiers.
- Provider directory exports. Periodic pulls used to refresh your internal referral list or a payer-facing roster attestation.
Four of those five are invisible to the retention policy you wrote last year, because that policy talks about "medical records" and these are not medical records in the way your staff thinks about them.
When a Lookup Record Becomes PHI
Draw the line clearly and train to it: a bare NPI is public data; an NPI attached to a patient is protected health information.
An exported list of orthopedic surgeons within twenty miles is a business directory. A note reading "verified NPI for Mrs. Alvarez's cardiology referral, 3/4/2026" identifies an individual and relates to the provision of health care to that individual. It is PHI, it may fall inside your designated record set if it informs decisions about the patient, and it inherits every obligation that comes with that status — access, amendment, accounting of disclosures, breach analysis, and disposal.
The practical consequence: your retention schedule needs two lanes. Directory-type records follow business-record rules. Patient-linked verification records follow health-record rules, which are almost always longer.
How Long to Keep NPI Number Lookup Records
Short answer: HIPAA sets no retention period for patient records themselves, but it requires six years of retention for required policy and compliance documentation. Patient-linked NPI verification records generally follow your state's medical record retention law. Records supporting ordered or referred Medicare services follow a seven-year federal clock. Credentialing verifications follow whatever your payer contracts and accreditation standards require — often ten years.
Practical floor for most practices:
- Six years — HIPAA-required documentation, including your disposal policy and workforce training records (45 CFR 164.316(b)(2) and 164.530(j)(2)).
- Seven years — documentation supporting orders and referrals for Medicare beneficiaries, measured from the date of service (42 CFR 424.516(f)).
- Ten years — the outer edge for federal false-claims exposure and the retention term written into many payer and delegated-credentialing contracts.
- State law — often six to ten years for adults, and for minors, a period measured from the age of majority. Whichever period is longest governs.
When two clocks conflict, keep the record for the longer one. That is not a legal opinion; it is the only version of the rule your staff will remember.
Four Retention Clocks, and Which One Wins
The six-year HIPAA documentation clock
This one trips people up because it does not cover charts. It covers the paperwork about your program — the retention and destruction policy itself, the log showing which drives you sanitized in 2021, the certificates of destruction from your shredding vendor, the training attestation your biller signed. Six years from creation or from the date the document was last in effect, whichever is later.
Meaning: if you revise your disposal policy in 2026, you keep the 2019 version until 2032, not until 2025.
The seven-year ordering and referring clock
If your physicians order or certify Medicare items and services, the supporting documentation carries a seven-year retention requirement from the date of service. Where an NPI verification is part of how you established that the ordering provider was eligible, that verification travels with the order documentation.
The payer contract and credentialing clock
Read your contracts. Delegated credentialing arrangements and government-program contracts routinely specify ten years and audit rights that outlive the contract. If you are re-credentialing on a three-year cycle, each cycle's primary-source verification packet — including the dated NPPES record — starts its own clock. Do not purge the 2019 packet just because the 2022 packet exists.
The state medical record clock
State law governs the chart. If a patient-linked verification note sits in the chart, it retains for as long as the chart does. This is the reason many practices stop trying to segregate these records at all and simply apply the chart schedule to anything patient-linked. That is a defensible choice, and it is far cheaper than the litigation over a record you destroyed early.
Building a Retention Schedule Your Staff Will Actually Follow
A schedule nobody executes is worse than no schedule, because it documents that you knew what to do and did not do it. Keep it to one page and assign a named owner to every row.
A worked example for a twelve-provider multispecialty group:
- Credentialing packets, including NPPES printouts. Owner: credentialing coordinator. Retention: ten years from the end of the credentialing cycle. Location: credentialing platform, one system only.
- Patient-linked referral verification notes. Owner: clinical operations manager. Retention: chart schedule. Location: the EHR referral module — not a spreadsheet.
- Claim scrubbing and clearinghouse logs. Owner: revenue cycle manager. Retention: ten years. Location: vendor system, with a written confirmation of the vendor's own retention setting.
- Directory exports and roster attestations. Owner: practice administrator. Retention: three years, or contract term plus three. Location: a single shared folder with quarterly cleanup.
- Ad hoc screenshots and email confirmations. Owner: everyone, which is the problem. Retention: purge at ninety days after the artifact is filed into an authoritative system.
Row five is the one that saves you. Every artifact should have exactly one authoritative home; copies elsewhere are transient and get deleted on a short cycle. If you cannot say where the authoritative copy of an npi number lookup verification lives, you do not have a retention program, you have a search problem.
Secure Destruction: Paper, Drives, and the Screenshots Nobody Owns
HHS is explicit that there is no single required disposal method, but PHI must be rendered unreadable, indecipherable, and unable to be reconstructed. Its guidance on disposing of protected health information is short and worth circulating to your office manager verbatim.
Use the NIST vocabulary in your policy
NIST Special Publication 800-88 Revision 1 gives you three defensible verbs: Clear, Purge, and Destroy. Write your policy in those terms and your auditor stops asking follow-up questions.
- Paper — cross-cut shred, pulverize, or incinerate. Not a recycling bin, not a locked bin that a janitorial crew empties into a dumpster.
- Workstation drives and laptops — Purge via cryptographic erase where full-disk encryption was enabled from first use, otherwise Destroy.
- Copiers, MFPs, and fax machines — every one has a hard drive. Handle them at lease return, and get it in writing from the leasing company before the truck arrives.
- Cloud systems — you cannot shred a tenant. Deletion means confirming the vendor's deletion timeline, backup expiry, and whether "deleted" means purged from replicas.
The vendor gap most practices miss
Your shredding company is a business associate. So is the credentialing platform that stores dated NPPES verifications alongside patient-linked referral data, and so is the clearinghouse holding your scrubbing logs. Each needs an executed agreement covering return or destruction of PHI at termination — and each needs a defined process for what happens to the data when you switch vendors.
If you inventory your systems and find a signed agreement missing for the shredding vendor or the credentialing platform, you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX. One-time purchase, no subscription — which matters when the gap is one vendor and not a program overhaul.
Also collect the certificate of destruction. Every time. File it under the six-year documentation clock, because it is the only proof that a record's absence was policy rather than negligence.
Legal Hold Beats the Calendar
The moment you receive an audit letter, a records subpoena, a demand letter, or notice of an OCR inquiry, routine destruction stops for anything in scope. Write the hold procedure now, while nothing is pending:
- Named person who can issue a hold — usually the privacy officer, with the administrator as backup.
- Written notice to every affected staff member and to affected vendors, including the shredding service.
- Suspension of automated deletion rules in email, the EHR, and the billing system.
- A dated release notice when the matter closes, so records do not sit in permanent limbo.
The failure mode is mundane: a scheduled purge runs on the same shared drive that holds referral verification records under hold. Automation does not read letters.
A 90-Day Cleanup Plan
Days 1–30. Inventory. Ask every staff role — front desk, referral coordinator, biller, credentialing — where they put the result when they perform an npi number lookup. Write down every answer, including the embarrassing ones. Expect to find at least one spreadsheet on a personal desktop.
Days 31–60. Designate authoritative systems, one per record type. Set retention values in each system where the software supports it. List the vendors touching these records and check each against your executed agreements.
Days 61–90. Write the one-page schedule, assign owners by name, train in a fifteen-minute staff meeting, and run the first purge of transient copies. Log what you destroyed, when, by what method, and who authorized it. That log is your evidence for the next six years.
If the inventory turns up more structural gaps than you can close by hand — missing policies, no current risk analysis, no destruction log at all — automating the risk analysis and policy set is a faster path than drafting from scratch. Start with the agreements for the vendors already holding your data, then work outward. The audit letter arrives on its own schedule, not yours.