A payer audit letter lands on your desk in July 2026 asking for the order, the fitting measurements, and the proof of delivery for a set of pressure stockings for DVT dispensed in March 2021. Your state's medical record law says seven years. Your practice purged that chart at year five because someone read the HIPAA six-year rule and applied it to the wrong thing. You now have an audit you cannot answer and a document destruction log that proves, in writing, that you destroyed the evidence.

This article is about the records side of compression therapy encounters: which documents get created, how many separate retention clocks run against them, who holds copies outside your walls, and how to destroy the originals in a way that survives scrutiny. No clinical guidance here — that belongs to your clinicians. This is the paperwork.

The Document Set a Single Compression Garment Encounter Produces

Administrators consistently underestimate this. A prescription for pressure stockings for DVT is not one page in the chart. It is a small file that spans at least three organizations.

  • The referral or consult note — often from a vascular specialist or hospital discharge coordinator, arriving by fax, direct message, or portal upload.
  • The written order or prescription, including compression class and dispensing details.
  • Measurement and fitting documentation — limb circumference values, sometimes recorded on a paper worksheet before anyone types them in.
  • Photographs, if staff documented fit or skin condition. These are PHI and they frequently start life on a personal phone.
  • Supplier records — proof of delivery, serial or lot documentation, signed receipt.
  • Payer paperwork — prior authorization, coverage determination, denial and appeal correspondence, patient financial responsibility notices.
  • Replacement history, because garments wear out and each replacement generates its own order trail.

Seven artifact types, three or four custodians, and no single system holding all of it. That is why retention policy for this category fails more often than it fails for a routine office visit.

Three Retention Clocks Run at Once, and Only One Is HIPAA's

The HIPAA clock covers your documentation, not the chart

The Privacy Rule requires covered entities to retain the documentation the rule itself demands — policies, notices, authorizations, complaint records, sanction records, designations — for six years from creation or from the date it was last in effect, whichever is later. HHS has been explicit that the rule does not set a retention period for medical records themselves. If your policy says "we keep records six years per HIPAA," your policy is wrong on its face.

State law sets the chart clock

Your state medical practice act, board regulation, or hospital licensing rule sets the actual chart retention floor. Common ranges run six to ten years from the last date of service for adults, with a separate and longer rule for minors — frequently measured from the patient's age of majority rather than the encounter date. If you operate in more than one state, you follow the longest applicable period per location unless counsel tells you otherwise in writing.

The payer and program clock usually runs longest

Federal enrollment rules require providers and suppliers who order or certify durable medical equipment to maintain the ordering and supporting documentation for seven years from the date of service, and DMEPOS supplier standards impose their own retention obligations. Commercial payer contracts routinely add their own terms — sometimes longer, sometimes tied to the end of the contract rather than the encounter. Pull the retention clause out of every payer agreement you have signed and put the number in your policy.

Then add the clock nobody schedules: litigation hold. The moment your practice reasonably anticipates a claim, an investigation, or a board complaint touching a patient, the destruction calendar stops for that record. A hold overrides every routine purge date in this article.

How Long Should You Keep Records for Pressure Stockings for DVT?

Keep them for whichever period is longest among these four:

  1. Your state's medical record retention requirement (commonly six to ten years from last date of service; longer for minors, often to age of majority plus a set number of years).
  2. Seven years from the date of service for ordering, certifying, and supplier documentation tied to durable medical equipment claims under federal enrollment rules.
  3. Your payer contract terms, which may extend past both of the above.
  4. Any active litigation hold or open investigation, which suspends destruction entirely.

Separately, retain HIPAA-required documentation — authorizations, accounting of disclosures, your Notice of Privacy Practices versions, complaint and sanction records — for six years from creation or last effective date. In most practices the practical answer for pressure stockings for DVT documentation lands at ten years from last date of service, which safely clears every clock at once and eliminates the per-record arithmetic that causes mistakes.

The Copies You Do Not Control

Your retention schedule governs your systems. It does not govern the fitting worksheet the supplier scanned into their own portal, the fax archive at your document service, the imaging cache on the multifunction copier at the front desk, or the appeal packet sitting in a staff member's sent-mail folder from 2022.

Build a copy map for this encounter type. For each artifact, name the system of record, every downstream holder, and the destruction obligation each holder carries. Then check that a signed agreement actually imposes that obligation.

That last step is where most practices stall. The DME supplier who fits and delivers compression garments on your behalf, the transcription service, the scanning contractor, the shredding company, the release-of-information vendor — each creates, receives, maintains, or transmits PHI for you, and each needs a business associate agreement that addresses return or destruction of PHI at termination. If you have vendors on that list operating without a current signed agreement, a six-step wizard that generates a signature-ready Business Associate Agreement with PDF and DOCX export will close the gap this week rather than next quarter. One-time purchase, no subscription, and the termination and destruction language is already in the document.

Write one termination provision you will actually enforce: on contract end, the business associate returns or destroys all PHI, certifies the action in writing within 30 days, and identifies by category anything retained because return or destruction is infeasible — along with the protections applied to it. File that certification with the closed contract.

Destruction That Holds Up: Paper, Drives, and Devices

HHS guidance on disposal of protected health information is short and unambiguous: PHI must be rendered unreadable, indecipherable, and otherwise unable to be reconstructed. Placing paper in a dumpster, a recycling bin, or an unlocked container in a hallway does not meet that standard. Neither does deleting a file or reformatting a drive.

Paper

Cross-cut shredding on site, or a locked-console pickup service with a chain-of-custody record. Measurement worksheets and printed fitting notes are the ones that go astray — they are informal, they live in exam rooms, and staff treat them as scratch paper once the values are entered. Put a locked destruction bin in every room where those worksheets are generated, not just at the front desk.

Electronic media

Follow NIST Special Publication 800-88 Rev. 1 for media sanitization and pick the right tier: Clear for media staying inside your control, Purge for media leaving your control, Destroy for media that is failed, obsolete, or too sensitive to release. This applies to workstation drives, scanner and copier hard disks, retired tablets used for photo documentation, external backup drives, and the USB stick someone used to move an appeal packet in 2021.

Devices and backups

Two blind spots: the multifunction copier at the front desk stores images of everything it scans and faxes, and it is usually a leased asset returned to a vendor without sanitization. And your backup rotation may hold restorable copies of records your production system purged years ago. Document how backup expiry interacts with your retention schedule, or your "destroyed" records are simply hibernating.

What the certificate of destruction must contain

  • Date and physical location of destruction
  • Description and volume of material, by category and date range
  • Method used (cross-cut shred, degauss, physical destruction, cryptographic erase)
  • Name of the vendor and the individual who performed or witnessed it
  • Signature of your authorized staff member

Retain destruction logs permanently. They cost nothing to store and they are the only proof that a missing record was destroyed under policy rather than lost, stolen, or removed by an employee.

Worked Example: The 2019 Fitting Note

A patient was fitted for pressure stockings for DVT on 14 March 2019 following a vascular referral. Replacement garments were dispensed 2 September 2021. A denial was appealed and closed 8 December 2021. No further contact since.

Last date of service is 2 September 2021. A ten-year internal standard makes the earliest destruction date 2 September 2031 — not 2025 counting from the original fitting, and not 2027 counting six years from the appeal. Two errors avoided: counting from the wrong service date, and applying the HIPAA documentation clock to a clinical record.

If the patient was 16 at fitting, the minor rule in your state may push the date past 2031 entirely. Flag minor records at creation. Nobody catches them at purge time.

Assign the Work or It Will Not Happen

A retention policy without named roles is a document that gets reviewed once and cited never.

  • Privacy Officer — owns the retention schedule, approves each destruction batch in writing, holds the destruction log, and issues litigation holds.
  • Practice Manager — runs the annual purge cycle on a fixed calendar date, reconciles the purge list against active holds before anything moves.
  • IT or managed service provider — executes media sanitization to NIST tiers, certifies device disposal, and confirms backup expiry aligns with the schedule.
  • Front desk lead — verifies destruction bins are locked, sited in every room where paper PHI is generated, and emptied on schedule.
  • Contract owner — collects destruction certifications from terminating business associates and files them with the closed agreement.

Run the purge annually on the same date. Produce a batch list, reconcile it against holds and open payer disputes, get written Privacy Officer approval, destroy, log, file. Five steps, one day a year.

Five Failure Modes Worth Auditing This Quarter

  1. Unlocked or overflowing destruction bins in clinical areas.
  2. Leased copiers and scanners returned to the vendor with drives intact.
  3. Terminated vendors with no destruction certification on file.
  4. Backups holding restorable copies past the purge date.
  5. Fitting photographs on personal phones that were never inventoried, never governed, and never deleted.

Number five is the one that shows up in breach reports. Address it with a written prohibition, a sanctioned capture workflow, and a documented device check at offboarding.

Next Step

Start with the vendor list. Pull every organization that touches compression garment records for your practice — supplier, fax service, scanning contractor, shredding company, release-of-information vendor — and confirm each has a current signed agreement with enforceable return-or-destroy terms. Where one is missing, generate a signature-ready Business Associate Agreement and send it the same day. If your broader policy set and risk analysis are also overdue, automated HIPAA risk analysis and policy generation will get the retention schedule written down where an auditor can find it.