Parasite Symptoms Records: Retention and Disposal Rules
It is a Tuesday in June 2026 and your records clerk is holding a banker's box labeled "2016 — GI/ID overflow." Inside are paper intake forms, a stack of faxed reference lab reports, and a handful of specialist consult letters from a workup for parasite symptoms — travel history, stool studies, an infectious disease referral. Your state retention floor for adult records ran out last year. Your shredding vendor's contract expired in March and nobody renewed it. This article is about that box: what clock applies to each piece of paper in it, who owns the decision to destroy, and how to document the destruction so it survives an audit.
You are the person who signs the retention policy, not the person who read the stool study. Nothing here is clinical guidance.
The Six-Year Federal Clock Covers Your Paperwork, Not Your Charts
HIPAA does not set a medical record retention period. This is the single most common misunderstanding I correct in practice policy reviews.
What the Security Rule does require, at 45 CFR 164.316(b)(2)(i), is that you retain required documentation for six years from the date of creation or the date it was last in effect, whichever is later. That covers your risk analysis, your policies, your sanction records, your incident logs, your workforce training rosters, and your Business Associate Agreements. The Privacy Rule adds its own six-year obligations — notably the accounting of disclosures under 164.528, and retention of signed authorizations.
The chart itself is governed by state law, by your payer contracts, and by facility conditions of participation. Those clocks vary widely. Some states set five or seven years from the date of last treatment for adults. CMS conditions of participation impose their own floors on hospitals and critical access hospitals. Medicare managed care plan contracts commonly require ten years. Malpractice statutes of repose can stretch further.
Your retention schedule needs at least three columns: federal documentation clock, state chart clock, and contractual clock. You keep to the longest one that applies. You can review the federal framework directly on the HHS Security Rule guidance pages.
Documents with a hard federal six-year life
- Risk analyses and risk management plans, including superseded versions
- Business Associate Agreements — six years from termination, not from signature
- Notice of Privacy Practices acknowledgments and every prior version of the NPP
- Signed authorizations for disclosure, including those covering specialist referrals
- Accounting-of-disclosures logs, including public health reports
- Breach risk assessments, even the ones concluding no breach occurred
- Sanction documentation and workforce training records
Why a Parasite Symptoms Encounter Scatters Records Across Four Organizations
The administrative reason this anchor matters: workups involving parasite symptoms tend to travel. A primary care visit generates a specimen, the specimen goes to an outside reference lab, the result routes back electronically and often on paper, an infectious disease referral moves a chart summary to a second practice, and certain confirmed conditions are reportable to your state public health authority under 164.512(b).
That single encounter now exists in at least four places. Your retention schedule only governs one of them. But your accounting-of-disclosures obligation, your BAA inventory, and your breach exposure cover all four.
The shadow copies your purge will miss
- Faxed lab reports sitting in a scan queue folder on a shared drive
- Referral packets assembled as PDFs and left in an outbound directory
- Patient portal message threads discussing follow-up, stored separately from the chart
- Employer, school, or food-handler clearance letters generated at patient request
- Public health reporting forms and their transmission confirmations
- Release-of-information vendor copies of everything they fulfilled on your behalf
- Backup snapshots and archived email attachments
Write these into your schedule by name. A retention policy that says "medical records" and nothing else does not tell your staff what to do with the scan queue.
How Long Do You Keep Records From a Parasite Symptoms Visit?
Keep the clinical chart for the longest period required by your state's medical record retention statute, your payer contracts, and your facility's conditions of participation — commonly five to ten years from the date of last treatment for an adult, and until a minor reaches the age of majority plus the state period for a pediatric patient. Keep the surrounding HIPAA paperwork — authorizations, disclosure accounting, BAAs, breach assessments — for six years under 45 CFR 164.316(b)(2). HIPAA itself sets no chart retention period. Destroy paper by cross-cut shredding, pulping, or incineration, and sanitize electronic media using a recognized method, then log the destruction with date, custodian, method, and record range.
The Clocks That Start Late, or Not at All
Pediatric records
For a minor, most states start the retention clock at the age of majority, not at the date of service. A workup for parasite symptoms performed on a six-year-old in 2018 may have a destruction-eligible date in the 2030s. Your EHR's default purge rules almost certainly do not know this. Check whether your system calculates eligibility from date of service or from date of birth, and if it uses date of service, flag every pediatric record for manual review.
Legal holds
Any notice of claim, subpoena, records request tied to litigation, OCR inquiry, or payer audit freezes destruction for the records in scope. Your policy needs a named person who issues holds, a written hold log, and a release procedure. Destroying a record under hold is not a HIPAA violation by itself — it is a spoliation problem that will cost you far more.
Open patient requests
A pending right-of-access request freezes the record until you fulfill it. Do not let a scheduled quarterly purge run through a chart your ROI queue is still working. Sequence the purge after the access queue clears, every time.
Secure Destruction: What Actually Counts
OCR has been consistent for years that PHI must be rendered unreadable, indecipherable, and unable to be reconstructed. The HHS disposal FAQ is short, plain, and worth printing for your records room wall. Paper: shred, burn, pulp, or pulverize. Electronic media: clear, purge, or destroy.
For electronic media, use NIST Special Publication 800-88 Revision 1 as your reference standard and cite it by name in your policy. It gives you a defensible vocabulary — clear, purge, destroy — and a decision framework based on how the media will be reused or released. When a leased copier or a retired scanner leaves your building, the drive inside it is in scope. Copier hard drives have been the subject of OCR enforcement, and the lesson has never changed.
The disposal failures that turn into breach reports
Look at the OCR breach portal and filter by improper disposal. The pattern is boring and repeatable: records left in an unlocked dumpster during an office move, a storage unit whose lease lapsed, a departing physician's boxes in a garage, a shredding bin that overflowed into the regular trash. None of these involve a hacker. All of them are the responsibility of somebody with your job title.
Your Vendor List Is Where Retention Actually Breaks
Trace one lab result from a parasite symptoms workup and count the business associates it touches: the reference lab's interface vendor, your document imaging service, your offsite storage company, your shredding contractor, your ROI fulfillment vendor, your backup provider, your EHR host. Every one of them holds a copy with its own retention behavior, and most of them retain longer than you do because retention is cheaper than deletion for them.
Your Business Associate Agreement is the only instrument that governs this. Under 45 CFR 164.504(e)(2)(ii)(J), the BAA must require the business associate to return or destroy all PHI at termination, or — if return or destruction is infeasible — to extend protections and limit further use. That last clause is where vendors quietly park your data forever. Read it in each of your agreements and find out which of your vendors invoked infeasibility.
If your shredding contractor, storage vendor, or imaging service is operating without a current signed agreement — and after a contract lapse or an acquisition, that happens more than anyone admits — you can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX the same afternoon. It is a one-time purchase with no subscription, which makes it practical for the one-off vendor you discovered mid-audit rather than the twenty you already track.
What to require from a destruction vendor
- A current BAA on file, dated after any change of ownership
- Certificates of destruction that identify date, method, and a specific record range or container ID — not a generic annual attestation
- Chain-of-custody documentation from pickup to destruction, with named handlers
- Written notice before any subcontracting, and subcontractor BAAs on request
- Witnessed or video-verified destruction for high-sensitivity batches
- Locked, tamper-evident collection containers with a documented service frequency
File certificates of destruction with your six-year Security Rule documentation. They are the evidence that the missing chart was destroyed on schedule rather than lost.
A Quarterly Disposal Run, With Names Attached
Policies fail when nobody owns a step. Here is a workable cadence for a mid-sized practice.
Weeks 1–2: Identify
Your records custodian runs an eligibility report from the EHR and from the offsite storage inventory. Output is a candidate list with patient identifier, date of last treatment, date of birth, and record type. Pediatric records route to manual review.
Week 3: Clear the holds
Your privacy officer cross-checks the candidate list against the legal hold log, the open ROI queue, the pending payer audit list, and any active OCR or state correspondence. Anything matching gets pulled and annotated with the reason.
Week 4: Approve and schedule
The practice administrator signs the approved destruction list. Nobody destroys anything on verbal authorization. The signed list is the record you produce when a patient asks in 2031 why their 2019 chart is gone.
Weeks 5–6: Execute and certify
Paper goes to the vendor with a container manifest. Electronic records are purged from production and — this is the step everyone skips — from backups on the next backup rotation cycle, with a documented note that restoration of an older snapshot would reintroduce destroyed records. Certificates come back, get matched against the approved list, and get filed.
Ongoing: Reconcile
Once a year, reconcile your destruction logs against your vendor inventory and your BAA list. If your storage vendor bills you for forty boxes and your inventory says thirty-two, find out what is in the other eight before someone else does.
Where This Fits in Your Document Set
A retention and disposal policy is not a standalone artifact. It references your risk analysis, your BAA inventory, your access request procedure, and your incident response plan, and all of them need to say the same thing about the same records. If those documents were written at different times by different people, the contradictions will surface during an investigation rather than before one. Practices that need to rebuild the whole set at once can automate risk analysis reports and the supporting policy library instead of assembling them piecemeal.
Start with the box. Pick one shelf of legacy records — the parasite symptoms overflow, the old GI referrals, whatever your version of that banker's box is — and work it end to end through the four-week cycle above. You will find the gaps in your vendor agreements faster that way than by reading your policy again. When you find a vendor holding PHI without a current agreement, get a signature-ready BAA drafted and exported before the next pickup, and close the gap while you can still document that you closed it yourself.