Guide

C-CDA, CSV, PDF: what each export preserves and loses

Summary

Ask for all three, not one: a C-CDA carries structured, computable clinical data — problem list, meds, allergies, results — your new EHR can import directly; a CSV or database dump captures everything the vendor holds, including fields no standard covers, but arrives unstructured; a PDF or print-to-image preserves the chart exactly as a human would read it, the safest format for your own permanent archive, but useless for re-import.

By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.

Request all three formats, not just one

When leaving an EHR, request all three export formats, not whichever one the vendor offers by default: a C-CDA for structured clinical data your new system can actually import, a raw CSV or database export as your safety net for anything the C-CDA standard doesn't cover, and a PDF or print-to-image archive as the version you keep regardless of what happens to either system.

This isn't the same problem as downtime, when the system is briefly unavailable — here the system is leaving for good, and the export is the only thing that survives it.

FormatWhat it preservesWhat it losesBest use
C-CDAStructured problem list, meds, allergies, results, coded fieldsAnything the old EHR tracked outside the standard's data elementsImporting into a new EHR
CSV / database exportEvery field the vendor's database holdsClinical narrative structure and context between fieldsA backup safety net, not a working chart
PDF / print-to-imageThe chart exactly as written, human-readableMachine-readability — nothing can be re-imported from itYour permanent legal/archival copy

If you're exporting because your vendor issued a sunset notice rather than because you chose to leave, the same three formats apply — just on a shorter clock.

C-CDA: structured, computable, but only what's coded

A C-CDA is a standardized, machine-readable document format built to carry discrete clinical data — problem list, medications, allergies, immunizations, and results — in fields a receiving EHR can read and file automatically rather than dump as an attachment. It's the format the information-blocking rule and the broader interoperability framework are built around, and clinicians count as actors with obligations under that rule 1.

That same standard is what moves across the TEFCA network of Qualified Health Information Networks when records need to travel between systems that have never exchanged data before 2. Its limit is real: only what's coded rides along. Narrative free text your old system stored outside the standard fields, scanned attachments, and anything tracked in a custom field typically won't survive the trip.

CSV: a complete dump, but no clinical structure

A raw CSV or full database export is the opposite trade: it captures everything the vendor's database holds, field by field, with nothing filtered out by a data standard — which makes it your real safety net if the C-CDA turns out to be missing something you needed. What it doesn't carry is structure: a spreadsheet of two hundred columns and ten thousand rows is not a chart, and no new EHR will import it directly.

Treat a CSV export as insurance, not as a working file. You're unlikely to open it unless something's missing from the C-CDA — but if something is missing, it's the only place left to look.

PDF: human-readable, but not machine-usable

A PDF or print-to-image export renders each chart note exactly as a human would read it — formatting, structure, and all — which is precisely why it's the version you should keep regardless of what happens to either EHR afterward. It carries zero machine-readable structure, so a new system can't import a single field from it; treat it as your permanent archive copy, not a working migration format.

When a payer, a board, or a former patient asks for a record years from now, the PDF is what you'll actually reach for — not the CSV, and possibly not even the new EHR if it never imported everything cleanly.

What the patient access right actually requires you to produce

None of these three formats is automatically what a patient is owed when they ask for their own records: HIPAA's access right entitles them to a copy in the form and format they request, where you can readily produce it, within 30 days, with one 30-day extension available 3. If a patient specifically asks for a PDF or a paper copy rather than a C-CDA, the request controls, not your migration preference.

Keep the two questions separate: what format you need for your own system-to-system migration is an operations decision; what format a patient is entitled to when they ask is a compliance obligation with its own deadline.

Negotiate export terms before you sign, not on your way out

Data-export terms belong in the contract you sign, not the conversation you have on your way out the door — negotiate the format, the cost, and the timeline for a full export before you ever go live, because a vendor with no contractual export obligation has no reason to make your departure easy 4. Ask specifically whether a full C-CDA export and a raw database export are both included, and at what fee.

This is exactly the kind of term that belongs in your planning for the ehr migration, not a detail you discover once a slow response from support has already turned into an escalation you didn't want to need.

Treat the export file itself as a security event

An export file is a complete, portable copy of every patient you've ever treated, so treat it like the highest-value file in the practice: encrypt it in transit and at rest, and if a third-party migration vendor handles the transfer, confirm a signed business associate agreement covers them before they receive a single file 5. The same risk-analysis discipline the Security Rule expects of daily operations applies to a one-time export of everything at once 6.

Once the export is done and verified, what you do with each copy next is a records-retention question, not an export-format one — store it the way you'd store the original chart, for as long as the original chart would need to be kept.

Common questions

Request all three if you can. The C-CDA is what your new EHR will actually import; the CSV or database export is your insurance against anything the C-CDA standard doesn't carry; the PDF is your permanent archive regardless of what happens to either system. Skipping any one of them is a bet you might regret months later.

Only what the standard defines as structured data — problem list, medications, allergies, immunizations, and results, mainly. Free-text narrative, scanned documents, and anything your old EHR tracked outside those standard fields typically won't transfer inside a C-CDA, which is why the raw database export matters as a backstop.

You'll have a complete, human-readable archive, but nothing your new EHR can import automatically — every field would need to be re-entered by hand. A PDF-only export solves the legal-record problem and creates a data-entry problem at the same time.

The vendor performs the technical export, but you should verify it, not just receive it: spot-check that the C-CDA opens correctly, that the CSV row counts look complete, and that the PDF pages match your patient count before you consider the old system safe to decommission.

Store them encrypted, in at least two locations, and treat their retention period the same way you'd treat the original chart's retention period — an export doesn't shorten how long you're expected to keep the underlying record, it just changes its format.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.Office of the National Coordinator / ASTP (2026). Information Blocking. HealthIT.gov. linkThat the information-blocking rule and interoperability framework are built around structured exchange formats and that clinicians count as actors, supporting the discussion of what a C-CDA is for.
  2. 2.Office of the National Coordinator / ASTP (2026). TEFCA — Office of the National Coordinator for Health Information Technology. HealthIT.gov. linkThat TEFCA establishes the national floor for network-to-network exchange via QHINs, supporting the claim that C-CDA-formatted data is what moves across that network.
  3. 3.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients have a right to a copy of their records in the form and format they request, within 30 days plus one extension, supporting the distinction between migration-format choice and the patient access obligation.
  4. 4.Office of the National Coordinator (2016). EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print. HealthIT.gov (ONC). linkONC's guidance that data-export format, cost, and timeline are contract terms to negotiate before signing, supporting the recommendation to secure export terms up front.
  5. 5.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor handling PHI on the practice's behalf is a business associate requiring a BAA, supporting the caution about third-party migration vendors handling the export file.
  6. 6.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule's risk-analysis obligation applies to ePHI handling generally, supporting the claim that a one-time export deserves the same risk-analysis discipline as daily operations.

https://www.gale.care/for-providers/cde-export-formats · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)