Time Limit

164.316(b)(2) Policies and Procedures Medium Risk Moderate

Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.

Implementation Guidance

Implement comprehensive retention procedures including retention schedules, storage requirements, and disposal procedures.

NIST References

NIST SP 800-66 Rev. 2: Section 3.5.3

Best Practices

Comprehensive retention schedules, effective storage procedures, proper disposal procedures, systematic record management.

Testing Procedures

Review retention schedules, test storage procedures, verify disposal procedures, assess record management.

Frequently Asked Questions

Q: How long must documentation be retained? A: Documentation must be retained for 6 years from creation or last effective date, whichever is later.

Control Information

Control ID:
164.316(b)(2)
Category:
Policies and Procedures
Subcategory:
Documentation
Risk Level:
Medium
Implementation Difficulty:
Moderate
Estimated Cost:
Medium
Implementation Timeframe:
1-3 months
Views:
2
Last Updated:
Sep 27, 2025

Related Controls

Additional Resources

NIST SP 800-66 Rev. 2: Time Limit Guidance, HHS Time Limit Guidance, Record Retention Best Practices