ComplyCreate
HomeResourcesHIPAA Deadline Tracker
Reference Tool

HIPAA Deadline Tracker 2026

Every HIPAA response window, retention period, and annual deadline — with the 45 CFR citation for each.

Time-Sensitive Patient Rights Response Deadlines

Request TypeStandard DeadlineExtension AvailableCitation
Right of Access — provide copy of records30 days from receiptOne 30-day extension with written notice to patient45 CFR § 164.524(b)(2)
Right to Amend — respond to amendment request60 days from receiptOne 30-day extension with written notice to patient45 CFR § 164.526(b)(2)
Accounting of Disclosures — provide list of disclosures60 days from receiptOne 30-day extension with written notice to patient45 CFR § 164.528(c)(1)
Restriction Request — respond with decisionReasonable time (no prescribed limit)N/A — best practice is prompt response45 CFR § 164.522(a)
Confidential Communications — accommodate requestReasonable timeN/A45 CFR § 164.522(b)

Breach Response Breach Notification Deadlines

Notification RequirementDeadlineNotesCitation
Individual notification — notify affected individuals60 days from discovery"Discovery" is when CE knew or should have known of the breach45 CFR § 164.404(b)
HHS notification — report to HHS SecretaryWithin 60 days if 500+ affected; within 60 days of year-end if fewer than 500Submit via HHS Breach Reporting Portal45 CFR § 164.408
Media notification — notify prominent media (500+ in a state)60 days from discoveryRequired when 500+ individuals in a single state or jurisdiction are affected45 CFR § 164.406
Business Associate → CE notification60 days from BA discoveryBA must notify CE without unreasonable delay, allowing CE to meet its 60-day window45 CFR § 164.410(b)
Substitute notice — if contact info is outdated/insufficientSame 60-day windowPost on website or major print/broadcast media45 CFR § 164.404(d)

Retention HIPAA Records Retention Periods

Document TypeRetention PeriodStart DateCitation
HIPAA policies and procedures6 yearsFrom date of creation or last effective date, whichever is later45 CFR § 164.530(j)
Notice of Privacy Practices6 yearsFrom date of creation or last effective date45 CFR § 164.520(e)
NPP patient acknowledgment6 yearsFrom date of signature45 CFR § 164.520(e)
Business Associate Agreements6 yearsFrom date of creation or last effective date45 CFR § 164.530(j)
Security Risk Analysis and Risk Management documents6 yearsFrom date of creation or last effective date45 CFR § 164.316(b)
Breach log and breach investigation records6 yearsFrom date of breach or investigation45 CFR § 164.530(j)
Workforce training records6 yearsFrom date of training45 CFR § 164.530(j)
Sanctions documentation6 yearsFrom date of sanction45 CFR § 164.530(j)
Complaint records6 yearsFrom date of complaint45 CFR § 164.530(j)
Authorization forms6 yearsFrom date of signature45 CFR § 164.530(j)

Note: Patient medical records retention (vs. HIPAA compliance records) is governed by state law and is typically longer — often 7–10 years for adults, until age of majority plus for minors.

Annual Annual Compliance Tasks

TaskFrequencyBest Practice TimingCitation / Basis
Security Risk AnalysisAt least annually and when significant changes occurQ1 of each year; also after major system changes, acquisitions, or new software45 CFR § 164.308(a)(1)
Workforce HIPAA trainingAt hire and periodically thereafter (no prescribed interval)Annual refresher training; immediately for new hires45 CFR § 164.530(b)
BAA review and updateWhen business arrangements change; no prescribed renewal periodAnnual audit of all active BAAs; update on contract renewal45 CFR § 164.504(e)
NPP review for material changesWhen material changes to privacy practices occurAnnual review; update when laws change or new services added45 CFR § 164.520(b)(3)
Contingency plan testingPeriodically (no prescribed interval)Annual tabletop exercise; annual data recovery test45 CFR § 164.308(a)(7)
Access control reviewPeriodically (no prescribed interval)Quarterly user access review; immediate review on employee termination45 CFR § 164.312(a)(1)
Audit log reviewPeriodically (no prescribed interval)Monthly review of audit logs for anomalies45 CFR § 164.312(b)
Sanction policy enforcement reviewOngoingAnnual policy review; enforce immediately when violations occur45 CFR § 164.530(e)

Key Penalty Statute of Limitations

Violation TypeStatute of LimitationsCitation
Civil money penalties — OCR enforcement6 years from the date the violation occurred (not from discovery)45 CFR § 160.306(c)
Criminal HIPAA violations5 years (general federal criminal statute of limitations)18 U.S.C. § 3282

Ready to get your compliance documents in order?

Knowing the deadlines is step one. Having the actual documents — BAAs and an NPP — is what keeps you protected when OCR comes knocking.