
Healthcare providers generate and maintain an enormous amount of patient information—from clinical notes and diagnostic results to treatment histories, billing documentation, insurance information, authorizations, and electronic health records.
But how long should medical records be kept in Texas?
For Texas physicians, the general rule is straightforward: medical records must generally be retained for at least seven years from the date of the patient’s last treatment. Special requirements apply to records involving minors, and other federal or state laws may sometimes require longer retention.
For medical practices, understanding these requirements isn’t simply an administrative task. A well-designed medical record retention policy supports regulatory compliance, continuity of care, audits, billing and revenue-cycle documentation, patient requests, and responsible protection of protected health information (PHI).
This guide from Nexa Digital Pro explains the key medical record retention requirements in Texas and what physician practices should consider when developing their record-management policies.
Important: This article provides general educational information and is not legal advice. Retention requirements can vary by provider type, facility type, payer contract, record type, and other applicable laws.
According to the Texas Medical Board, physicians are generally required to retain medical records for at least seven years from the date of the patient’s last treatment.
This is an important distinction.
The retention period is generally measured from the last treatment date, rather than simply from the date the record was originally created.
For example, if an adult patient was treated by a physician in 2022 but returned for another treatment in 2026, the relevant seven-year period would generally run from the later treatment date.
Practices should therefore avoid creating retention policies based only on calendar year or original date of service without considering the applicable rule.
For adult patients treated by Texas physicians, the standard rule is generally:
The Texas Medical Board specifically states that physicians are required to retain medical records for at least seven years from the last treatment date
However, seven years should not automatically be interpreted as the required retention period for every healthcare record maintained by every healthcare organization in Texas.
Different rules may apply depending on factors such as:
Healthcare organizations should therefore establish their retention schedules according to the rules that actually apply to their organization and records.
Records involving minors require particular attention.
Texas’s physician retention rule provides that when a patient is under 18, records should be maintained until the patient reaches age 21 or for seven years from the date of last treatment, whichever is longer. The current Texas rulemaking language reflects this standard.
Suppose a patient receives their last treatment from a physician at age 10.
Seven years later, the patient would be 17.
Because the patient has not yet reached age 21, disposing of the record merely because seven years have elapsed would not satisfy the longer-period requirement.
Practices should therefore configure their record-retention processes so that minor records are identified separately rather than being subjected automatically to the standard adult retention schedule.
This is one of the most common sources of confusion in healthcare compliance.
The U.S. Department of Health and Human Services explicitly states that the HIPAA Privacy Rule does not require covered entities to retain patients’ medical records for a specific period. State laws generally determine how long the medical records themselves must be retained.
So where does the commonly cited six-year HIPAA rule come from?
HIPAA requires certain documentation required by the Privacy and Security Rules to be retained for six years from its creation or from when it was last in effect, whichever is later.
This can include applicable compliance documentation such as policies, procedures and other records required to document compliance.
Therefore:
Texas physician medical records: generally 7 years from last treatment.
Certain HIPAA-required documentation: generally 6 years from creation or when last in effect, whichever is later.
These are two separate requirements and should not be confused.
No.
Another common misconception involves deceased patients.
HIPAA generally protects a deceased individual’s protected health information for 50 years after death, but HHS specifically explains that this does not mean a healthcare provider must retain the medical record for 50 years.
Medical records may be destroyed when permitted under applicable state or other law.
The distinction is between:
how long information remains protected if it exists
and
how long the provider must retain the record.
Those are not necessarily the same thing.
A comprehensive medical record retention policy should address more than progress notes.
Depending on the practice and applicable requirements, its records environment may include:
Not every document necessarily has the same legally required retention period.
That is why practices should avoid a simplistic policy such as “delete everything after seven years.”
Instead, records should be classified according to their applicable legal, regulatory, contractual and operational requirements.
Medical practices should also consider how their medical billing and revenue cycle management records relate to their overall record-retention strategy.
A patient’s revenue cycle may generate documentation related to:
Eligibility Verification → Prior Authorization → Coding → Claim Submission → Payment Posting → Denial Management → A/R Follow-Up → Appeals → Patient Billing
This information may be important for payer disputes, audits, appeals, underpayment reviews, recoupments, and other revenue-cycle activities.
For example, an old claim may appear closed in the billing system but still have supporting documentation relevant to a payer review or other compliance requirement.
Practices should therefore coordinate their clinical record retention policy and RCM documentation policy rather than allowing each department to independently delete records.
Moving from paper charts to an Electronic Health Record (EHR) system doesn’t eliminate retention obligations.
Electronic records must remain accessible for the required retention period.
The Texas Medical Board’s retention framework expressly emphasizes maintaining access to medical records throughout the applicable retention period.
That means practices should consider:
A common operational risk occurs when a practice changes EHR or practice-management systems and assumes that historical records will automatically remain available.
Before terminating an EHR, billing, clearinghouse, document-management, or cloud-storage relationship, determine how historical information will be retained, exported, and accessed.
Closing a practice does not necessarily eliminate responsibility for medical records.
The Texas Medical Board explains that records may still need to remain accessible after a physician retires, closes an office, or dies, and patients may need information about the custodian responsible for those records.
A practice preparing for closure should therefore establish a documented process addressing:
Record management should be part of the practice’s closure plan—not something addressed only after the doors close.
Records that have satisfied all applicable retention requirements may generally become eligible for destruction, but practices should not automatically destroy records simply because a standard retention period has expired.
Before destruction, the practice should determine whether another requirement applies.
For example, records potentially relevant to pending litigation, an investigation, an audit, or another legal obligation may need to be preserved beyond an ordinary retention schedule.
Healthcare organizations should establish a formal record destruction policy that includes appropriate review before records are permanently destroyed.
Medical records contain highly sensitive information.
Simply throwing paper records into ordinary trash or deleting files casually can create serious privacy and security risks.
HHS states that HIPAA-covered entities must use appropriate administrative, technical and physical safeguards to protect medical records and other PHI for as long as the information is maintained, including during disposal.
Depending on the format, secure destruction may involve appropriate methods for rendering PHI unreadable or inaccessible.
Practices should also consider documenting:
Retention isn’t useful if the practice cannot retrieve the record when needed.
The Texas Medical Board states that physicians must maintain medical records for the required period, and Texas law provides mechanisms for patients to obtain copies of their records or authorize them to be sent to another provider or third party.
A strong records-management process therefore addresses both:
Retention — keeping information for the required period.
Accessibility — being able to locate and produce information appropriately when needed.
A seven-year archive that nobody can retrieve is not an effective records-management system.
Healthcare practices can reduce compliance risk by watching for several common problems.
HIPAA’s six-year requirement applies to specified HIPAA documentation—not as a universal medical-record retention rule.
Minor records may require longer retention.
Other laws, payer requirements, litigation holds, facility rules, or record-specific requirements may require longer retention.
Records stored in a former EHR or practice-management platform may still need to remain accessible.
Clinical and revenue-cycle records often interact. Billing documentation can be important during audits, appeals, recoupment disputes, and A/R review.
Keeping everything indefinitely is not necessarily good records management either. Excessive retention can increase storage, security, privacy, and administrative burdens.
A defined retention and destruction schedule is preferable.
A well-designed policy should clearly identify:
1. What records are maintained
Create categories for clinical, billing, administrative, compliance, financial, and other records.
2. Which retention requirement applies
Determine the applicable Texas, federal, payer, contractual, and facility-specific requirements.
3. When the retention period begins
For Texas physician records, the relevant rule generally centers on the date of last treatment.
4. How minors are handled
Ensure pediatric/minor records aren’t automatically destroyed under the adult schedule.
5. Where records are stored
Document EHR, billing-system, archive, cloud, and physical-storage locations.
6. Who can access records
Establish appropriate role-based access and safeguards.
7. How legal or compliance holds work
Records subject to litigation, investigation, audit, or another preservation requirement should not be destroyed simply because their routine retention period expires.
8. How destruction is authorized
Create a formal review and approval process.
9. How destruction is documented
Maintain appropriate evidence of the destruction process.
10. How the policy is reviewed
Healthcare regulations, technology, payer requirements, and practice operations change. Review retention policies periodically.
Record management is also part of an efficient healthcare revenue cycle.
Claims, denials, appeals, prior authorizations, payment information, payer correspondence, and A/R follow-up can depend on accurate historical documentation.
When clinical and billing information is fragmented across multiple systems, revenue-cycle teams may have difficulty researching old claims, responding to payer requests, or supporting appeals.
An organized RCM environment can help practices maintain clearer connections between:
Patient → Encounter → Documentation → Coding → Claim → Payment → Denial → A/R
That visibility can be particularly valuable when reviewing aging accounts or investigating recurring reimbursement problems.
Nexa Digital Pro provides healthcare administrative and revenue-cycle support for physicians, clinics, medical groups, and specialty practices across the United States.
Our services include:
Our goal is to help healthcare practices create more organized workflows across billing, administrative operations, and revenue-cycle processes.
Record-retention decisions and legal compliance policies should remain under the direction of the practice and its qualified legal/compliance advisers, while an organized RCM operation can help maintain the billing documentation needed for day-to-day revenue-cycle work.
Texas physicians generally must retain medical records for at least seven years from the patient’s last treatment date.
For physician records, the applicable Texas rule provides for retention until the patient reaches age 21 or seven years from the date of last treatment, whichever is longer.
No. HHS specifically states that the HIPAA Privacy Rule does not establish a general medical-record retention period. State law generally governs retention of the medical records themselves. Certain HIPAA-required documentation, however, is subject to a six-year retention requirement.
Not because of HIPAA’s deceased-person privacy rule. HHS specifically says that the 50-year protection period does not require covered entities to retain the deceased person’s records for 50 years.
Using electronic records instead of paper does not eliminate applicable retention requirements. Practices should ensure that records remain appropriately accessible and protected throughout the required period.
Potentially, but seven years should not be treated as an automatic destruction date for every record. Practices should first consider the patient’s age, provider/facility type, applicable federal requirements, litigation or other legal holds, payer requirements, and other laws or contractual obligations.
Understanding medical record retention requirements in Texas is essential for physician practices that want to maintain organized, accessible, and appropriately protected patient information.
For Texas physicians, the general rule is at least seven years after the patient’s last treatment, while special rules apply to minors. HIPAA does not create a universal medical-record retention period, although certain HIPAA-required compliance documentation generally must be retained for six years.
The most effective approach is a written retention policy that considers Texas law, federal requirements, patient age, provider type, billing documentation, electronic records, legal holds, secure storage and appropriate destruction.
Nexa Digital Pro helps healthcare providers manage the operational side of the revenue cycle—from medical billing and coding to denial management, A/R recovery, credentialing, prior authorization, and practice analytics.
Author: Michael Clarke