The most common wrong answer in dentistry is "seven years." The second most common is "six years, because HIPAA." Neither is a rule, and the second one confuses two entirely different requirements.
Clinical record retention is set by state law. HIPAA's six-year requirement applies to your compliance documentation, not to patient charts. Layer on top of that a malpractice statute of limitations that tolls for minors, payer contract terms, employment record rules, and tax recordkeeping, and you get a schedule with six or seven different clocks running at once.
This article gives you the framework and tells you where to go for your own numbers. It deliberately does not list state retention periods, because they change, they are drafted differently in every state, and an out-of-date table is worse than no table. Use it with the overview in Chapter 6: Compliance and confirm your state's rules with your board and your attorney.
Key takeaways
- No federal law sets a dental chart retention period. Your state dental practice act or health records statute does, and periods, start dates, and definitions vary widely.
- HIPAA requires six years of retention for HIPAA documentation: policies, risk analyses, BAAs, training records, breach assessments, and authorizations. It says nothing about how long to keep a chart.
- For minors, most states run the clock from the age of majority rather than the last visit, which can mean keeping a record for two decades or more.
- Radiographs and images are part of the dental record. Keep them for the same period as the chart, and remember that image files live in a different place than the database.
- Where two rules conflict, the longer period governs in practice. Where your malpractice carrier recommends longer than your state minimum, follow the carrier.
- Destruction has to be as deliberate as retention: a written policy, an approved method, and a log of what was destroyed and when.
Start by separating four different kinds of records
Retention arguments almost always come from treating one pile of paper as one obligation. Split them first.
| Category | Examples | Who sets the period |
|---|---|---|
| Clinical patient records | Chart notes, treatment plans, radiographs and images, perio charts, lab prescriptions, consents, referral letters, models and scans | State dental practice act or health records law, plus malpractice risk management |
| HIPAA compliance documentation | Privacy and security policies, risk analyses, BAAs, training records, breach risk assessments, authorizations, accounting of disclosures, NPP acknowledgments | 45 CFR 164.316(b)(2) and 164.530(j): six years from creation or last effective date, whichever is later |
| Employment and safety records | Personnel files, I-9s, payroll, OSHA training records, hepatitis B declinations, exposure records | OSHA, DOL, USCIS, and state labor law, each with its own period |
| Business and financial records | Tax returns, ledgers, bank records, leases, loan documents, corporate filings, equipment purchases, insurance policies | IRS guidance, lenders, landlords, and your CPA |
Once separated, each category gets its own retention line in a written schedule. That schedule, not anyone's memory, is what makes destruction defensible.
Clinical records: how state rules actually vary
Every state approaches this differently, and the differences are not just in the number of years. When you look up your own rule, read for all six of these variables:
- The length. Some states set a specific number of years. Some set none at all and leave it to the standard of care and the statute of limitations.
- The start date. Most commonly the date of the last treatment or last entry. Some run from the date of record creation, some from the date of discharge or the end of the provider relationship.
- Where the rule lives. It may be in the dental practice act, in board regulations, in a general health records statute, or in medical records rules that apply to all licensees. Some states have more than one source with different answers, which is why you ask counsel rather than guessing.
- What counts as the record. Some rules enumerate contents (history, examination findings, diagnoses, treatment, radiographs, lab work, prescriptions). Radiographs are almost always included.
- Minors. Nearly always treated separately. See below.
- Obligations on closure, sale, retirement, or death. Many states require that records be retained and remain accessible, that patients be notified, and sometimes that the board be told where the records are held. This catches sellers and estates by surprise constantly.
Where to look for your own answer, in order: your state dental board's rules (usually online and searchable), your state dental association's practice management resources, your malpractice carrier's risk management department, and a dental-specific attorney in your state. Our state resources pages point to board and agency contacts, including Illinois, Texas, California, Florida, and New York.
Do not rely on a retention table you found on a vendor's blog. These tables circulate for years without being updated, they frequently cite the wrong statute, and several conflate medical and dental rules. The ADA's own guidance says the period varies by state and federal law and directs dentists to their attorney, state board, or state dental association. That is the correct instinct: get the citation, not the number.
Minors: the clock you will forget
Most states extend retention for patients treated as minors, and the mechanism is usually the statute of limitations. A minor's right to bring a claim is typically tolled until they reach the age of majority, and then the limitations period runs from there. Retention rules tend to follow that logic, so the required period is commonly expressed as "until the patient reaches a stated age" or "a number of years after the age of majority," whichever is longer than the ordinary adult period.
Hypothetical example of the arithmetic. Suppose a state requires adult records for a set number of years after the last visit, and minors' records until a specified number of years past the age of majority. A patient seen at age three and never seen again could require retention into their twenties. If you apply your adult period to that chart, you will destroy it far too early.
Practical handling: flag every chart where the patient was a minor at the last visit, and store the calculated destruction-eligible date on the record rather than recalculating later. In most practice management systems you can run a query on date of birth and last visit date to produce this list. If you use Open Dental, the query tools in Module 7: Reports and Queries are the right place to build it.
HIPAA's six years: what it actually covers
HIPAA requires covered entities to retain required documentation for six years from the date of its creation or the date when it last was in effect, whichever is later. That obligation applies to documents the rules require you to create or maintain, including:
- Privacy and security policies and procedures, including superseded versions
- Security risk analyses and risk management plans
- Business associate agreements, including expired ones
- Workforce training records and sanctions
- Notices of Privacy Practices and acknowledgments, and any revisions
- Patient authorizations and revocations
- Requests for access, amendment, restriction, and confidential communications, and your responses
- Accounting of disclosures records
- Breach risk assessments, breach logs, and copies of notifications sent
- Designations of the privacy and security officials
Note the "last in effect" wording. A policy you replaced in 2024 after 10 years in force must be kept until six years after it stopped being effective, not six years after it was written. Same for a BAA: the clock starts when the agreement ends.
Why the confusion persists. Six years is a real HIPAA number and it is not a chart retention period. If your only written retention policy says "six years," an auditor will read it as a HIPAA documentation policy and your state board may read it as a violation of the clinical rule. Write two separate lines in the schedule and cite the source for each.
Radiographs, images, and digital artifacts
Radiographs are part of the dental record. Where a state enumerates record contents, images are nearly always listed. Retain them for the same period as the rest of the chart, and understand the practical complications digital imaging adds:
- Images usually live outside the database. Most systems store the database separately from an images or documents folder. A retention or destruction process that only touches the database leaves the images behind, and a backup that only covers the database leaves them unrecoverable. See dental office IT setup.
- Format obsolescence is real. Proprietary image formats from a discontinued vendor can become unreadable long before the retention period ends. When you switch imaging software, confirm that historic images are migrated and viewable, not merely archived. Keep a documented way to open anything you still hold.
- Film and paper still exist. Many practices hold decades of film and paper charts in a closet. Those are still records, they are still subject to retention, and they still need secure destruction at the end of it. Scanning them is fine if your policy addresses the legal status of the scanned copy and destruction of the original, which is worth a conversation with counsel.
- Ownership versus copies. The record is practice property; the patient has a right of access to copies. Patients asking for "their x-rays" are entitled to copies, generally within 30 days, with one 30-day extension if you notify them, at a reasonable cost-based fee. Never release originals and never condition access on a paid balance.
- Models, scans, and printed appliances. Physical models are usually treated as part of the record while retained. Digital scan files are cheaper to keep than to argue about, so store them with the images.
Everything else: a working schedule
The table below collects the non-clinical periods that have clear federal sources. Confirm each against your state, which may require longer.
| Record | Minimum retention | Source |
|---|---|---|
| HIPAA required documentation | 6 years from creation or last effective date, whichever is later | 45 CFR 164.316(b)(2); 164.530(j) |
| Bloodborne pathogens training records | 3 years from the date of training | 29 CFR 1910.1030(h)(2) |
| Employee exposure and medical records, including hepatitis B vaccination status | Duration of employment plus 30 years | 29 CFR 1910.1030(h)(1); 1910.1020 |
| Amalgam separator inspection, maintenance, and disposal records | 3 years | 40 CFR Part 441 |
| Form I-9 | 3 years after hire or 1 year after employment ends, whichever is later | USCIS |
| Payroll records | 3 years; timecards and wage computation records 2 years | FLSA |
| Sterilization monitoring logs | Set by state or local rule; CDC defers to those | State board rules |
| Radiation equipment registration and inspection records | Set by your state radiation control program | State radiation regulations |
| Controlled substance records | 2 years federally; many states require longer | 21 CFR 1304; state law |
| Tax and financial records | Per IRS guidance and your CPA; commonly 7 years for supporting records, permanently for returns and entity documents | IRS; CPA advice |
| Payer and Medicaid records | Per contract and program rules, often longer than state clinical minimums | Your provider agreements |
Leases, loan documents, equipment purchase records, warranties, and insurance policies deserve their own line. Keep purchase documentation for equipment as long as you own it plus the period your CPA advises for depreciation support, which matters if you took Section 179 or bonus depreciation, and it matters again when you sell, as covered in pricing your equipment when selling.
Longer than the minimum: when and why
The state minimum is a floor, not a recommendation. Reasons to keep records longer:
- Malpractice defense. A claim you cannot defend because the chart is gone is worse than the storage cost. Ask your carrier's risk management line what they advise, and follow it. Carriers frequently recommend periods longer than state law.
- Statutes of limitations and repose can run longer than the retention rule, and discovery rules in some states extend them further.
- Payer contracts and audits. Dental benefit plans and Medicaid programs can have their own record and audit periods written into the participating provider agreement.
- Continuity of care. Old radiographs have genuine clinical value in a patient who returns after a decade.
- Practice sale. Buyers and their lenders expect records to be available. Records that were destroyed early become a diligence problem and occasionally a price problem. See planning a practice transition.
- Active litigation or an investigation. Once you know of a claim, a board complaint, or an audit, a litigation hold applies and normal destruction stops immediately for anything related. Altering or destroying records at that point is a far worse problem than the underlying case.
Digital storage is cheap enough that "keep longer" is usually the easy call for electronic records. The counterargument applies to paper and film, which cost real square footage, and to any data that increases your breach exposure without adding value.
Destruction: do it on purpose
The end of a retention period is not permission to throw records in the dumpster. HIPAA requires that PHI be rendered unreadable and unreconstructable, and improper disposal is a recurring enforcement theme. Some states also specify methods or require notice before destruction.
Records destruction protocol
- A written retention and destruction policy that lists each record category, its period, its legal source, and who approves destruction
- A hold procedure that suspends destruction for any record touched by a claim, complaint, subpoena, or audit
- Paper and film: cross-cut shredding or destruction by a vendor, under a signed business associate agreement, with certificates of destruction retained
- Electronic media: clearing, purging, or physical destruction consistent with recognized standards such as NIST Special Publication 800-88; do not rely on deleting files or a quick format
- Drives from retired computers, copiers, and imaging devices explicitly included (multifunction copiers store images)
- A destruction log recording the record category, date range, method, date, vendor, and the person who authorized it
- Verification that backups and archives containing destroyed records are also handled per policy
- Annual review of the schedule against current state and federal rules
Keep the destruction log indefinitely. It is the only way to answer "where is that chart" years later with something better than a shrug.
Closing, selling, or retiring: the case everyone gets wrong
Records do not stop existing when the practice does. Retention obligations survive a closure, a sale, a retirement, and the death of the owner, and many states impose specific duties: retain and keep records accessible for the balance of the period, notify patients of where records are held and how to obtain them, and in some states notify the board. In a sale, the asset purchase agreement should say explicitly who holds the records, who bears the cost of storage, how the seller can access records to defend a claim, and what happens to patients who never transfer.
An estate is the hardest version of this. If the owner dies, someone has to fulfill these obligations, and that person is usually a spouse with no idea the duty exists. Address it in your transition plan and in your wind-down checklist while you are still able to.
Build the schedule once
Spend an hour with your attorney and produce a one-page retention schedule with four columns: record category, retention period, legal source, and who owns it. Post it with your policies, put an annual review on the compliance calendar, and run a purge on the same date each year. That single page resolves most of the arguments, and it is the document that shows a regulator or a buyer that your practice is run deliberately.
Related reading: the compliance chapter for the full federal picture, HIPAA breach response for what happens when records are lost rather than destroyed, and ransomware prevention and recovery for keeping the records you are required to keep.
This article is educational and is not legal advice. Retention requirements for patient records are set by state law and vary significantly. Confirm your obligations with your state dental board, a dental-specific attorney in your state, and your malpractice carrier before destroying any record.
Educational content only. It is not legal, financial, tax, or clinical advice. Prices and ranges are approximate and vary by region, condition, and year. Verify current rules with your state dental board and qualified professionals. ChairsideSource is not affiliated with any manufacturer, the ADA, or the DAT.