PFT Test Records: Retention Clocks and Secure Disposal
A patient's attorney sends your office a request for every pulmonary function record from 2013 forward. You find the interpreted reports in the EHR. You find nothing else. The paper tracings went to a storage unit your practice stopped renting in 2019, the spirometer that produced them was traded in during a 2021 equipment refresh, and nobody wrote down who took it. That gap is a records management failure, and it is the reason retention and disposal policy for pft test records deserves its own page in your manual rather than a line item in a generic chart policy.
This article is for the person who owns records retention at your organization — practice administrator, privacy officer, or office manager wearing both hats. It covers where these records actually live, which clocks govern them, how to destroy each format defensibly, and what to document so the destruction holds up three years later.
What Lives in a PFT Test Record — and Where It Actually Sits
Pulmonary function testing routinely involves a referral, an in-office or mobile testing encounter, and an interpretation performed by someone other than the person who ran the test. That structure alone means the record fragments across organizations. Your retention policy has to name every fragment.
In a typical practice, one testing encounter produces:
- An order or referral document, sometimes faxed from an outside clinician
- Raw measurement data and flow-volume curves stored in the testing device's internal memory or on an attached workstation
- A printed or PDF report, often with graphics the EHR stores as a scanned image rather than discrete data
- An interpretation or over-read from a pulmonologist or contracted reading service, returned by portal, secure email, or fax
- Technician notes, calibration logs, and quality records that reference patient identifiers
- Billing and prior-authorization correspondence naming the test and the patient
Six artifacts, potentially four custodians: your practice, the device vendor's support platform, the reading service, and whatever clearinghouse handled the claim. A retention policy that only addresses "the chart" governs one of them.
Map custody before you set clocks
Build a one-page inventory that lists each artifact, the system it lives in, the person accountable for it, and the retention rule that applies. Do this once, review it annually, and update it whenever you change devices or reading vendors. Without the map, every retention decision becomes a guess.
HIPAA Sets No Retention Period for Medical Records — It Sets One for Everything Else
This trips up more privacy officers than any other retention question. The HIPAA Rules do not tell you how long to keep a patient's clinical record. There is no federal HIPAA chart retention period.
What HIPAA does require, at 45 CFR 164.316(b)(2), is six years of retention for the documentation the Rules themselves generate: your written policies and procedures, your risk analyses, your Notice of Privacy Practices versions, signed authorizations, business associate agreements, sanction records, and accountings of disclosures. Six years from creation or from the date it was last in effect, whichever is later. That clock is federal, firm, and independent of anything a state says about charts.
Where the chart clock actually comes from
State medical records statutes and licensing board rules set the retention floor for the clinical record itself, and they vary widely — commonly somewhere between five and ten years from the last encounter for adult patients. Payer contracts frequently impose longer terms. Federal program participation adds its own documentation expectations, and the False Claims Act's multi-year lookback is a practical reason not to destroy billing-linked documentation on the earliest possible date.
For minors, most states run the clock from the age of majority rather than the date of service, which can push retention on a pediatric pft test report well past a decade. If your practice tests children, your policy needs a separate minor-patient rule and a way to flag those charts so nobody purges them on the adult schedule.
How Long Should You Keep PFT Test Records?
Keep the interpreted report and supporting data for whichever period is longest among these four:
- Your state's medical records retention statute — the floor, measured from the last date of service, or from the age of majority for minors.
- Your payer and program contract terms — read the actual retention clause; several run longer than state law.
- Six years for any HIPAA-required documentation attached to the encounter, such as a signed authorization to release the report to an employer or an outside specialist.
- Duration of employment plus 30 years if the testing was performed as part of an occupational medical surveillance or respirator clearance program subject to OSHA's records rule at 29 CFR 1910.1020.
Never destroy on the earliest applicable date without confirming the other three. And never destroy anything covered by a litigation hold, a pending access request, or an open investigation.
The Occupational Testing Overlay Most Policies Miss
If your practice performs spirometry for respirator clearance, employer surveillance programs, or workplace exposure monitoring, you are operating under a second retention regime entirely. OSHA's access-to-employee-exposure-and-medical-records standard requires employee medical records be preserved for the duration of employment plus thirty years, with narrow exceptions. Thirty years is not a typo, and it is not a HIPAA number — it comes from a different agency with a different enforcement posture.
There is a companion nuance worth writing into your policy: when an employer holds testing results in its capacity as an employer, those are employment records, which sit outside HIPAA's definition of protected health information. When your clinic holds the same results as the treating or examining provider, they are PHI. The same test result can be governed differently depending on who is holding it and why. Your release workflow and your retention schedule both need to reflect that split, and your staff need to know which hat they are wearing when an employer calls asking for a result.
Secure Destruction: Paper, Disk, and the Device Itself
The Privacy and Security Rules require that PHI be rendered unreadable, indecipherable, and otherwise unable to be reconstructed at disposal. HHS's guidance on disposal obligations for covered entities is short and worth circulating to your whole team. OCR has resolved multiple enforcement matters involving paper records left in unsecured dumpsters and containers — this is one of the most avoidable categories of breach in the entire enforcement record.
For electronic media, use NIST Special Publication 800-88 Revision 1 as your technical standard. It defines three sanitization levels — Clear, Purge, and Destroy — and tells you which applies to which media type. Cite it by name in your policy so an auditor sees you adopted a recognized standard rather than improvising.
The spirometer nobody sanitizes
Testing devices and their attached workstations store patient names, dates of birth, and result histories locally. When that equipment is retired, traded in, sent for warranty repair, sold to a used-equipment broker, or donated, the stored data goes with it unless someone purges it first.
Add a hard gate to your asset disposal workflow: no diagnostic device leaves the building until the privacy officer signs off that internal storage has been sanitized to the standard, or until the receiving vendor is under a business associate agreement that covers the data still on it. Log the serial number, the sanitization method, the date, and the two people who verified it. Do the same for the laptop the technician used to print reports, the multifunction printer with a hard drive, and the backup drive in the equipment closet.
Your shredding vendor is a business associate
A document destruction company that takes custody of PHI-bearing paper is a business associate, and so is an IT asset disposition firm that hauls away drives. Onsite witnessed shredding does not remove the need for an agreement if the vendor's employees handle records at any point. Certificates of destruction are useful evidence, but they are not a substitute for the contract.
If you cannot immediately produce a signed agreement for every disposal vendor on your list — shredding, IT asset disposal, equipment resale, offsite storage, mobile testing partner, reading service — close that gap this week. You can generate a signature-ready Business Associate Agreement through a six-step wizard and export it as PDF or DOCX for countersignature. It is a one-time purchase with no subscription, which makes it practical for the one-off vendor you only use during an equipment refresh.
Build the Destruction Log Before You Need It
Destruction you cannot prove is indistinguishable from a loss you failed to report. Your log should capture, for every disposal event:
- Description and approximate volume of what was destroyed (record type, date range, patient count if known)
- Media type — paper, hard drive, solid-state media, optical, device memory
- Method used and the standard it maps to
- Date, location, and vendor name
- Names of the workforce member who authorized it and the one who witnessed it
- Certificate of destruction reference number
- Confirmation that no legal hold was active
Keep destruction logs longer than you keep the records they describe. A log that expires before the underlying retention question can be raised has no defensive value.
Events That Stop the Clock
Four situations suspend routine destruction, and every person with purge authority needs to recognize them.
Litigation hold. Once your practice reasonably anticipates litigation, a claim, or a board complaint, scheduled destruction of anything potentially relevant stops until counsel releases the hold in writing.
Pending access or amendment request. A patient exercising the right of access starts a 30-day response clock. Destroying responsive records mid-request creates an access failure on top of a records problem. HHS's right of access guidance lays out the timing and fee limits your front desk should already be working from.
Open investigation or audit. An OCR inquiry, a payer audit, or an internal breach investigation freezes everything in scope.
Practice closure or sale. Closure does not extinguish retention obligations. State law generally dictates custodianship, patient notification, and how long records must remain retrievable after the doors shut.
A Worked Example: Twelve Years of Records in a Storage Unit
Say your policy sets a ten-year retention period for adult charts, measured from last date of service, and your state statute supports it. In August 2026 you are reviewing boxes from a pulmonary testing program that ran from 2010 to 2016.
Step one: pull the box inventory and identify every box whose latest date of service is on or before August 2016. Step two: cross-check against the minor-patient flag list and pull anything involving a patient under 18 at the time of service. Step three: cross-check against the occupational testing roster — any pft test performed under a respirator or surveillance program goes back on the shelf under the 30-year rule. Step four: check active legal holds. Step five: confirm nothing in scope is subject to a pending access request.
What survives all five filters gets scheduled for destruction under a signed vendor agreement, witnessed by two staff, and logged. What does not survive gets a re-review date on the compliance calendar. The whole exercise takes an afternoon if your inventory is decent and a month if it is not — which is the real argument for maintaining the inventory.
Assign It, Calendar It, Close It Out
Retention policy fails for boring reasons: nobody owns it, the review never gets scheduled, and the storage unit keeps accumulating. Name one accountable person, put a quarterly retention review on the calendar, and require a written close-out for every destruction event. Tie equipment disposal to privacy officer sign-off so no device leaves without a sanitization record.
If your written policy set is thin or dated, the fastest path forward is to generate your risk analysis and policy documents in one pass and then layer the retention specifics your testing program requires on top. And before the next shredding pickup or equipment trade-in, confirm you hold a current agreement with that vendor — build and export the BAA in an afternoon rather than discovering the gap during a breach investigation.