C-CDA, CSV, PDF: what each export preserves and loses
Summary
Ask for all three, not one: a C-CDA carries structured, computable clinical data — problem list, meds, allergies, results — your new EHR can import directly; a CSV or database dump captures everything the vendor holds, including fields no standard covers, but arrives unstructured; a PDF or print-to-image preserves the chart exactly as a human would read it, the safest format for your own permanent archive, but useless for re-import.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
Request all three formats, not just one
When leaving an EHR, request all three export formats, not whichever one the vendor offers by default: a C-CDA for structured clinical data your new system can actually import, a raw CSV or database export as your safety net for anything the C-CDA standard doesn't cover, and a PDF or print-to-image archive as the version you keep regardless of what happens to either system.
This isn't the same problem as downtime, when the system is briefly unavailable — here the system is leaving for good, and the export is the only thing that survives it.
| Format | What it preserves | What it loses | Best use |
|---|---|---|---|
| C-CDA | Structured problem list, meds, allergies, results, coded fields | Anything the old EHR tracked outside the standard's data elements | Importing into a new EHR |
| CSV / database export | Every field the vendor's database holds | Clinical narrative structure and context between fields | A backup safety net, not a working chart |
| PDF / print-to-image | The chart exactly as written, human-readable | Machine-readability — nothing can be re-imported from it | Your permanent legal/archival copy |
If you're exporting because your vendor issued a sunset notice rather than because you chose to leave, the same three formats apply — just on a shorter clock.
C-CDA: structured, computable, but only what's coded
A C-CDA is a standardized, machine-readable document format built to carry discrete clinical data — problem list, medications, allergies, immunizations, and results — in fields a receiving EHR can read and file automatically rather than dump as an attachment. It's the format the information-blocking rule and the broader interoperability framework are built around, and clinicians count as actors with obligations under that rule 1Ref 1Office of the National Coordinator / ASTP (2026).Information Blocking.That the information-blocking rule and interoperability framework are built around structured exchange formats and that clinicians count as actors, supporting the discussion of what a C-CDA is for..
That same standard is what moves across the TEFCA network of Qualified Health Information Networks when records need to travel between systems that have never exchanged data before 2Ref 2Office of the National Coordinator / ASTP (2026).TEFCA — Office of the National Coordinator for Health Information Technology.That TEFCA establishes the national floor for network-to-network exchange via QHINs, supporting the claim that C-CDA-formatted data is what moves across that network.. Its limit is real: only what's coded rides along. Narrative free text your old system stored outside the standard fields, scanned attachments, and anything tracked in a custom field typically won't survive the trip.
CSV: a complete dump, but no clinical structure
A raw CSV or full database export is the opposite trade: it captures everything the vendor's database holds, field by field, with nothing filtered out by a data standard — which makes it your real safety net if the C-CDA turns out to be missing something you needed. What it doesn't carry is structure: a spreadsheet of two hundred columns and ten thousand rows is not a chart, and no new EHR will import it directly.
Treat a CSV export as insurance, not as a working file. You're unlikely to open it unless something's missing from the C-CDA — but if something is missing, it's the only place left to look.
PDF: human-readable, but not machine-usable
A PDF or print-to-image export renders each chart note exactly as a human would read it — formatting, structure, and all — which is precisely why it's the version you should keep regardless of what happens to either EHR afterward. It carries zero machine-readable structure, so a new system can't import a single field from it; treat it as your permanent archive copy, not a working migration format.
When a payer, a board, or a former patient asks for a record years from now, the PDF is what you'll actually reach for — not the CSV, and possibly not even the new EHR if it never imported everything cleanly.
What the patient access right actually requires you to produce
None of these three formats is automatically what a patient is owed when they ask for their own records: HIPAA's access right entitles them to a copy in the form and format they request, where you can readily produce it, within 30 days, with one 30-day extension available 3Ref 3HHS Office for Civil Rights (2026).Individuals' Right under HIPAA to Access their Health Information.That patients have a right to a copy of their records in the form and format they request, within 30 days plus one extension, supporting the distinction between migration-format choice and the patient access obligation.. If a patient specifically asks for a PDF or a paper copy rather than a C-CDA, the request controls, not your migration preference.
Keep the two questions separate: what format you need for your own system-to-system migration is an operations decision; what format a patient is entitled to when they ask is a compliance obligation with its own deadline.
Negotiate export terms before you sign, not on your way out
Data-export terms belong in the contract you sign, not the conversation you have on your way out the door — negotiate the format, the cost, and the timeline for a full export before you ever go live, because a vendor with no contractual export obligation has no reason to make your departure easy 4Ref 4Office of the National Coordinator (2016).EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print.ONC's guidance that data-export format, cost, and timeline are contract terms to negotiate before signing, supporting the recommendation to secure export terms up front.. Ask specifically whether a full C-CDA export and a raw database export are both included, and at what fee.
This is exactly the kind of term that belongs in your planning for the ehr migration, not a detail you discover once a slow response from support has already turned into an escalation you didn't want to need.
Treat the export file itself as a security event
An export file is a complete, portable copy of every patient you've ever treated, so treat it like the highest-value file in the practice: encrypt it in transit and at rest, and if a third-party migration vendor handles the transfer, confirm a signed business associate agreement covers them before they receive a single file 5Ref 5HHS Office for Civil Rights (2026).Business Associates.That a vendor handling PHI on the practice's behalf is a business associate requiring a BAA, supporting the caution about third-party migration vendors handling the export file.. The same risk-analysis discipline the Security Rule expects of daily operations applies to a one-time export of everything at once 6Ref 6HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.That the Security Rule's risk-analysis obligation applies to ePHI handling generally, supporting the claim that a one-time export deserves the same risk-analysis discipline as daily operations..
Once the export is done and verified, what you do with each copy next is a records-retention question, not an export-format one — store it the way you'd store the original chart, for as long as the original chart would need to be kept.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.Office of the National Coordinator / ASTP (2026). Information Blocking. HealthIT.gov. link ✓That the information-blocking rule and interoperability framework are built around structured exchange formats and that clinicians count as actors, supporting the discussion of what a C-CDA is for.
- 2.Office of the National Coordinator / ASTP (2026). TEFCA — Office of the National Coordinator for Health Information Technology. HealthIT.gov. link ✓That TEFCA establishes the national floor for network-to-network exchange via QHINs, supporting the claim that C-CDA-formatted data is what moves across that network.
- 3.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThat patients have a right to a copy of their records in the form and format they request, within 30 days plus one extension, supporting the distinction between migration-format choice and the patient access obligation.
- 4.Office of the National Coordinator (2016). EHR Contracts Untangled: Selecting Wisely, Negotiating Terms, and Understanding the Fine Print. HealthIT.gov (ONC). link ✓ONC's guidance that data-export format, cost, and timeline are contract terms to negotiate before signing, supporting the recommendation to secure export terms up front.
- 5.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkThat a vendor handling PHI on the practice's behalf is a business associate requiring a BAA, supporting the caution about third-party migration vendors handling the export file.
- 6.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule's risk-analysis obligation applies to ePHI handling generally, supporting the claim that a one-time export deserves the same risk-analysis discipline as daily operations.
https://www.gale.care/for-providers/cde-export-formats · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.