Thyroid Gland Nodules Ultrasound: Chart Retention Rules
Your ultrasound cart comes off a 48-month lease in September. The leasing company wants it back in working order, with the hard drive intact so they can refurbish and redeploy it. That drive holds four years of studies — including every thyroid gland nodules ultrasound your practice performed since 2022, with patient names, dates of birth, and accession numbers baked into the DICOM headers. If it leaves your building unsanitized, you have made an impermissible disclosure, and you will be the one filling out the breach risk assessment.
This article is about the records side of thyroid imaging: what a study actually consists of, how long you have to keep each piece, where duplicate copies end up, and how to destroy the originals in a way you can prove three years later. No clinical guidance here — that belongs to the physicians reading the study.
What a Thyroid Ultrasound Record Actually Contains
Administrators tend to think of an imaging study as one thing. It is at least six, and each one may live in a different system with a different retention clock and a different custodian.
- The DICOM image set — often several hundred frames plus cine loops, stored on the modality, in PACS, or in a cloud archive.
- The structured measurement worksheet — nodule dimensions and locations captured by the sonographer, sometimes as a separate DICOM SR object, sometimes as a PDF.
- The interpreting physician's report — dictated, transcribed, signed, and pushed into the EHR as a discrete document.
- The order and the clinical indication — living in your practice management system.
- The referral packet — what you sent to endocrinology or surgery, and how you sent it.
- Prior comparison studies received from outside organizations on CD, through an image exchange, or as a flattened PDF.
Thyroid nodules are common and frequently followed over years, which means these records get requested repeatedly and travel between organizations. That is the administrative reality driving everything below: your retention policy is not a filing decision, it is an availability decision that other people's clinicians depend on.
The Two Clocks People Confuse: HIPAA's Six Years vs. Your State's Record Law
This is the single most common error I see in practice policies. HIPAA does not set a medical record retention period. It never has.
What the six-year rule actually covers
45 CFR 164.316(b)(2) requires you to retain documentation required by the Security Rule — policies, risk analyses, sanction records, designations — for six years from creation or from the date it was last in effect. The Privacy Rule imposes a parallel six-year clock at 164.530(j) for things like your notice of privacy practices, complaint records, and accounting-of-disclosure logs. None of that touches the images. See the HHS Privacy and Security Rule regulatory text if your policy binder still says otherwise.
Where the real clock comes from
Medical record retention for a thyroid gland nodules ultrasound is governed by state law, your professional licensure board, your malpractice carrier's contractual requirements, and — for Medicare and Medicaid work — federal program rules. These periods routinely run longer than six years, and the minor-patient rules run longer still, typically measured from the age of majority rather than the date of service.
Practical instruction: build a one-page retention schedule with four columns — record type, governing authority, retention trigger, retention period — and have counsel confirm the state entries in writing. Update it annually. Do not let each department invent its own answer.
Payer and program clocks that sit on top
Claims documentation supporting a billed ultrasound has its own life. Federal healthcare program requirements, cost-report obligations, and False Claims Act exposure all argue for holding the order, the report, and the billing record longer than the image set alone. If your imaging contracts include payer-specific audit provisions, read them — several impose ten-year retention by contract regardless of what state law says.
How Long Should You Keep Thyroid Ultrasound Images and Reports?
Short answer: keep the images and the signed report for the longest period required by (1) your state's medical record retention statute, (2) your licensure board rules, (3) any payer or federal program contract term, and (4) any active litigation hold — whichever runs latest. HIPAA's six-year rule applies to your compliance documentation, not to the study. For patients who were minors at the time of imaging, the clock usually starts at the age of majority, not the exam date. Set one number per record type, write it down, and destroy on schedule.
Every Place a Copy of the Study Ends Up
Destruction policies fail because they only address the system of record. Map the copies first. For a single thyroid study, the realistic inventory looks like this:
- The ultrasound machine's internal drive (frequently retains studies long after PACS transfer).
- PACS or the cloud archive, plus any disaster-recovery replica.
- The EHR document repository holding the signed report.
- The transcription or dictation vendor's platform.
- The image-exchange gateway used to push priors to the endocrinology group.
- Burned CDs or USB drives handed to patients or couriers.
- The referral fax queue — including the fax vendor's stored transmission images.
- A workstation's local cache in the sonography room.
- Whatever your release-of-information vendor retained after fulfilling a records request.
Items 4, 5, 7, and 9 are business associates. Item 2 usually is. Item 1 becomes one the moment the leasing company takes possession of an unsanitized drive — which is precisely the fact pattern behind OCR's well-known settlement with a health plan that returned leased photocopiers containing unwiped hard drives, resolved for more than $1.2 million.
If any of those vendors is operating on a signed quote and a handshake, fix that before you touch the retention schedule. A signature-ready Business Associate Agreement generated through a six-step wizard gives you a document you can send to a PACS host, a transcription service, or a shredding contractor the same afternoon, exported as PDF or DOCX, with no subscription attached. Get the agreement in place, then negotiate the return-or-destroy language in it — that clause is what makes your disposal policy enforceable against someone else's server.
Secure Destruction: What "Unreadable, Indecipherable, and Unable to Be Reconstructed" Requires
HHS guidance on disposal of protected health information sets the standard in plain terms: PHI must be rendered unreadable, indecipherable, and otherwise incapable of being reconstructed. The Security Rule's device and media controls at 164.310(d)(2)(i) require a documented process for disposal of electronic media, and 164.310(d)(2)(ii) requires you to address removal of ePHI before media is reused.
The operational reference is NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization. It gives you three categories — Clear, Purge, Destroy — and a decision framework based on whether the media leaves your control. Write those three words into your policy and assign each media type to one of them.
The ultrasound cart and the sonography workstation
Before any imaging device leaves the building — trade-in, lease return, warranty swap, resale, donation — the drive gets Purged or Destroyed, and the technician who did it signs a form. Manufacturer service technicians will sometimes offer to "reset" the unit. A factory reset is not sanitization. If the vendor performs the sanitization, get the method and the standard in writing on their letterhead, and keep it with the asset record.
Paper, CDs, and the film jacket you forgot about
Cross-cut shredding for paper worksheets and printed reports. Physical destruction for optical media; a permanent marker across the label is not disposal. If you still hold legacy film or paper jackets from a prior practice acquisition, inventory them before you schedule a purge — acquired records inherit the retention clock of the original encounter, not the acquisition date.
What your certificate of destruction must actually say
Collect one from every destruction event, whether performed in-house or by a vendor. It should name the custodian, the date, the media type and serial or asset number, the sanitization method mapped to a NIST category, the volume, the person who performed it, and a witness. File these with your Security Rule documentation and hold them for six years. A destruction log with gaps is worse than no log, because it documents exactly when you stopped paying attention.
The Litigation Hold That Overrides Everything Above
The moment your practice receives notice of a claim, a subpoena, a board complaint, or an OCR inquiry touching a patient, all scheduled destruction for that patient's records stops. Assign this to a named role — usually the privacy officer or practice administrator — and give that person the ability to flag a chart in the EHR so an automated purge job cannot reach it.
Test the flag. I have watched a hold get placed in a spreadsheet while the archive's auto-purge ran on its original schedule, because nobody connected the two systems. That is a defensible-destruction problem that turns into a spoliation problem.
A Twelve-Month Retention Calendar You Can Run
Retention policies die from lack of cadence. Put these on the calendar with owners:
- January — Privacy officer reviews the retention schedule against current state law and payer contracts; documents any change.
- March — IT reconciles PACS, archive replicas, and modality drives against the schedule; produces a candidate destruction list.
- April — Practice administrator and clinical lead sign off on the destruction list; litigation-hold flags checked against it line by line.
- May — Destruction executed; certificates collected and filed.
- August — Vendor review: confirm every entity holding a copy of a thyroid gland nodules ultrasound has a current BAA with return-or-destroy terms.
- October — Asset disposal audit: every device retired in the prior twelve months has a matching sanitization record.
- December — Workforce refresher on disposal procedures; document attendance.
Five Questions an Auditor Will Ask, and the Evidence That Answers Them
- What is your retention period for diagnostic imaging, and what authority sets it? — Your written retention schedule with citations.
- Show me the destruction record for a study that aged out last year. — Destruction log entry plus certificate.
- Who holds copies of your imaging data? — Vendor inventory cross-referenced to executed BAAs.
- How was your last retired ultrasound unit sanitized? — Asset record with method and NIST category.
- How do you suspend destruction? — Litigation-hold procedure with a documented test.
If you cannot produce four of the five within an hour, the gap is documentation, not intent. HHS's privacy and security resources and the public OCR breach reporting portal are both worth an hour of your time — the portal in particular, because scrolling the improper-disposal and loss-of-device entries tells you exactly which failure modes are still happening in practices your size.
Start With the Paperwork You Can Fix This Week
Pick the two vendors touching your imaging data that have the weakest agreements — usually the transcription service and whoever hosts or backs up the archive — and get executed contracts in place. You can produce a signature-ready BAA in about ten minutes and have it out for signature before the end of the day, one-time purchase, nothing recurring. If your broader policy set and risk analysis are also overdue, automated HIPAA documentation tooling will get the retention and disposal policies drafted alongside them. Then put the March reconciliation on the calendar and give it a name.