Destruction logs: proving what no longer exists
Summary
With a destruction log that records the date, the method used, a non-identifying description of what was destroyed, and who performed it — plus the vendor's certificate of destruction if you outsource shredding or e-waste disposal. The log itself is HIPAA documentation and needs its own retention period. Before destroying anything, confirm no records request, subpoena, or litigation hold currently touches those records, since destroying something you were still obligated to produce is a far worse problem than destroying it a year late.
By Gale Editorial · Updated 2026-07-27. Every figure cited to a dated source. How we write.
Before you destroy anything: confirming the record is actually eligible
A destruction log's first job isn't documenting the act of destruction — it's proving the record was actually eligible for destruction when you did it. Behavioral-health record-keeping guidelines commonly use roughly seven years after last service for an adult as a retention example, longer for minors, always deferring to the specific rule your state sets 1Ref 1American Psychological Association (2007).Record Keeping Guidelines.The retention-norm example (roughly seven years after last service for adults, longer for minors, deferring to state law) used to establish when a record is actually eligible for destruction.. Destroy before that clock runs and the log becomes evidence against you rather than for you.
Run the eligibility check against your longest applicable clock — state rule, HIPAA's own documentation floor, and any malpractice-carrier recommendation — not just the first one you remember. A destruction log dated before that combined clock has run is worse than no log at all.
What a destruction log actually needs to contain
A usable log records the date of destruction, the method (cross-cut shredding, incineration, certified e-waste destruction, secure wipe), a description of what was destroyed that identifies the record range or category without reproducing any PHI in the log itself, and who performed the destruction. If a vendor did the work, the log should reference their certificate rather than restate its contents.
chart ownership matters here too: the log should show that whoever authorized the destruction actually had standing to do so — the treating clinician or the designated records custodian, not an outside biller or landlord deciding on their own that old boxes are in the way.
Resist the temptation to batch years of records into one vague log entry once a year. A separate line for each distinct cohort or destruction event — even if several happen the same afternoon — is what lets you answer a specific question later ("was patient X's chart in that batch") instead of pointing at one undifferentiated annual note.
Certificates of destruction: what to get from your vendor
A shredding or e-waste vendor's certificate of destruction should name the date, the method, an approximate volume or item count, and a statement that destruction was witnessed or verified rather than merely scheduled. Treat a vague one-line invoice as insufficient — ask for the actual certificate, not just proof you were billed for a pickup.
File the certificate with your own log entry rather than trusting the vendor to retain it on your behalf indefinitely; vendors change ownership, lose records, and go out of business, and the certificate is worthless to you the day you need it if only the vendor ever had a copy.
A solo practice doing its own on-site shredding, rather than contracting a vendor, still needs the equivalent of a certificate — a signed, dated note stating what was destroyed and by whom, even if that person is you. Self-certification isn't a lesser standard; it just means you're the one who has to be disciplined about creating the record.
The destruction log's own retention clock
The destruction log is itself HIPAA documentation, and documentation generated to satisfy the Security and Privacy Rules must be retained for six years from the date it was created or the date it was last in effect 2Ref 2Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.The §164.316 six-year documentation retention requirement, applied here to the destruction log itself as HIPAA documentation.. That means the log proving you destroyed a chart in year seven has to survive on its own for six more years after that.
audit logs work the same way — the record of an action can meaningfully outlive the record it describes, and for a solo practice, that surviving metadata is frequently the only evidence left that anything happened at all, in either direction.
Two checks before you shred: pending requests and legal holds
Before destroying anything, confirm no patient has an outstanding request for a copy of their records, since patients generally have a right to inspect and obtain their records within 30 days, with one permitted 30-day extension 3Ref 3HHS Office for Civil Rights (2026).Individuals' Right under HIPAA to Access their Health Information.The 30-day (plus one 30-day extension) right-of-access timeline that must be checked against pending requests before a scheduled destruction proceeds.. Destroying — or even delaying access to — records you still maintain in order to complete a scheduled destruction can implicate the information-blocking prohibition, since clinicians are treated as regulated actors under that rule regardless of practice size 4Ref 4Office of the National Coordinator / ASTP (2026).Information Blocking.That clinicians are regulated actors under the information-blocking prohibition, relevant when a scheduled destruction would interfere with a still-pending records-access request..
Separately, confirm no subpoena or court order currently reaches those records. HIPAA treats a court order and a bare subpoena differently — a court order authorizes disclosure of only what it specifies, while a subpoena without a court order requires satisfactory assurances of notice to the patient or a protective order 5Ref 5HHS Office for Civil Rights (2026).Court Orders and Subpoenas.The distinction between a court order and a bare subpoena, relevant to checking for an active legal hold before destroying records.. Either one in flight should pause your destruction schedule for the records it covers until it's resolved.
Electronic destruction: purging the EHR, not just shredding paper
Electronic records raise a different problem than paper: deleting a patient from your EHR's interface doesn't necessarily purge the underlying data from backups, and a secure wipe of a decommissioned device is a different action from deleting a record within an active system. Confirm with your EHR vendor specifically what "delete" actually does to backups and audit trails before assuming a purge is complete.
format migrations matters here too — if you're retiring an old EHR system rather than destroying specific records, confirm what happens to the data left behind: whether it's exported, archived in a readable format, or genuinely destroyed, and get that answer in writing before the contract ends, not after.
A one-page log format that actually gets maintained
A destruction log a solo practice will actually keep up with is short enough to fit on one page and reviewed on the same schedule as your broader retention policy, not built as a standalone project. A simple table covers most of what's needed:
| Date | Records description | Method | Performed by | Certificate on file |
|---|---|---|---|---|
| e.g. 2026-03-14 | Adult charts, closed 2018 cohort | Cross-cut shred, on-site | Licensed vendor | Yes |
Keep the description non-identifying — a cohort or date range, never a patient name — and treat a blank "certificate on file" column as an open item to chase down, not a formality to skip. tax retention runs on its own separate schedule if any of what you're destroying doubles as a business financial record, so check that column too before the shred truck arrives.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.American Psychological Association (2007). Record Keeping Guidelines. American Psychological Association. link ✓The retention-norm example (roughly seven years after last service for adults, longer for minors, deferring to state law) used to establish when a record is actually eligible for destruction.
- 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓The §164.316 six-year documentation retention requirement, applied here to the destruction log itself as HIPAA documentation.
- 3.HHS Office for Civil Rights (2026). Individuals' Right under HIPAA to Access their Health Information. U.S. Department of Health and Human Services. linkThe 30-day (plus one 30-day extension) right-of-access timeline that must be checked against pending requests before a scheduled destruction proceeds.
- 4.Office of the National Coordinator / ASTP (2026). Information Blocking. HealthIT.gov. link ✓That clinicians are regulated actors under the information-blocking prohibition, relevant when a scheduled destruction would interfere with a still-pending records-access request.
- 5.HHS Office for Civil Rights (2026). Court Orders and Subpoenas. U.S. Department of Health and Human Services. linkThe distinction between a court order and a bare subpoena, relevant to checking for an active legal hold before destroying records.
https://www.gale.care/for-providers/rr-destruction-certificates · 5 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.