How Long Should Providers Keep EOBs on File?

Most healthcare providers should keep EOBs on file for ten years. That is longer than any single rule strictly demands, but it is the point at which the overlapping requirements from Medicare, the False Claims Act, the IRS, ERISA, state medical-records laws, and private payer contracts all run out. Shorter policies are legally defensible in some practices, but ten years is the cleanest answer to the question of how long providers should keep EOBs on file, and it is what most healthcare compliance consultants recommend.

Why Ten Years Is the Practical Floor

The False Claims Act is the main reason compliance officers land on a decade. The statute lets the federal government bring a civil fraud action up to six years after a violation, or three years after the government learns of it, whichever is later. An absolute outer limit of ten years applies regardless of when the government discovers the issue.1Office of the Law Revision Counsel. 31 USC 3731 – False Claims Procedure

A billing decision made today could therefore be challenged a decade from now. If the EOB, remittance advice, and underlying documentation no longer exist, defending that claim becomes very hard. Ten years is not a flat legal mandate across the board, but it closes the longest window a provider realistically faces.

What Medicare Requires

Medicare’s own rules vary by how a provider participates. Providers and suppliers who furnish services under Medicare Part A or Part B must maintain documentation of orders, certifications, referrals, prescriptions, and payment requests for seven years from the date of service.2eCFR. 42 CFR 424.516 – Additional Provider and Supplier Requirements EOBs and remittance advice fall squarely within that category.

Medicare Advantage organizations face a stricter rule. Under their CMS contracts, they must retain books, records, and documents for ten years, covering financial statements through cost data used in bid preparation.3eCFR. 42 CFR 422.504 – Contract Provisions

Providers who participate in both fee-for-service Medicare and a Medicare Advantage network should default to the ten-year period for everything rather than sort documents into separate buckets.

The Six-Year Overpayment Lookback

Federal law also requires providers to report and return any self-identified Medicare overpayment within 60 days of discovery, with a lookback window stretching six years from the date the overpayment was received.4Centers for Medicare & Medicaid Services. Medicare Overpayments Fact Sheet A compliance review five years in that reveals a duplicate payment needs the original EOB to calculate the refund and document the return. Destroying the record before the six-year window closes can turn a manageable refund into a False Claims Act exposure.

HIPAA Does Not Set an EOB Retention Period

There is a persistent belief that HIPAA requires six years of EOB retention. It does not. HHS has stated explicitly that the HIPAA Privacy Rule does not include medical record retention requirements, and that state laws generally govern how long medical records must be maintained.5U.S. Department of Health & Human Services. Does the HIPAA Privacy Rule Require Covered Entities to Keep Medical Records for Any Period of Time

The six-year rule people associate with HIPAA applies only to compliance documentation: the written policies, procedures, and communications that HIPAA requires a covered entity to create. A covered entity must retain those compliance records for six years from creation or from the date they were last in effect, whichever is later.6eCFR. 45 CFR 164.530 – Administrative Requirements That covers privacy notices, breach notification procedures, and business associate agreements. EOBs and patient billing records are not on that list.

HIPAA still applies to EOBs in another way: any protected health information a provider holds, including EOBs, must be safeguarded for as long as the provider keeps it. The obligation governs how you protect the data, not how long you keep it.

IRS and ERISA Timelines

EOBs double as financial records that support a practice’s tax returns. The IRS requires businesses to keep records supporting income and deduction items until the period of limitations for that return expires. For most providers that means at least three years from the filing date, stretching to six years if a return underreports gross income by more than 25%. Employment tax records must be kept at least four years after the tax is due or paid.7Internal Revenue Service. How Long Should I Keep Records IRS guidance lists “paid bills, invoices, receipts, deposit slips, and canceled checks” among supporting documents businesses should retain, and EOBs fit that category.8Internal Revenue Service. What Kind of Records Should I Keep

Providers who administer or interact with employer-sponsored group health plans face an ERISA layer. ERISA requires every person who files (or would file but for an exemption) a report under the statute to keep records for at least six years after the filing date of the documents those records support, including vouchers, worksheets, receipts, claims records, and plan documents.9Office of the Law Revision Counsel. 29 USC 1027 – Retention of Records Because the Form 5500 is often filed months after the plan year ends, the practical period runs closer to seven years from the end of the plan year, and many plan administrators round up to eight.

State Laws and Payer Contracts

State medical-record retention laws create the most variation. Required periods range from as few as three years to indefinite retention, with most states landing around seven years for adult patient records. The triggering event varies too. Some states measure from the date of the last encounter, others from discharge, and others from when the record was created. When a state requirement exceeds the applicable federal period, the state law controls.

Private payer contracts stack another layer on top. An insurer’s provider agreement may require seven, eight, or ten years of record retention regardless of what federal or state law says. These obligations are enforceable, and breaching them can lead to payment recoupment, contract termination, or network exclusion. The only way to know what a specific contract requires is to read it. Practices with multiple payer relationships should keep a chart of each contract’s retention clause and default to the longest period across all of them.

Longer Retention for Minor Patients

Records involving minors almost always need to be kept longer. The general rule is to retain records until the patient reaches the age of majority (18 in most states) plus the state’s statute of limitations for medical malpractice. In a state with a two-year malpractice limitations period that does not begin running until the patient turns 18, records from a newborn’s care could need to remain on file for 20 years after the date of service. Some states toll the period further for minors with certain disabilities.

EOBs tied to pediatric services should follow the same extended timeline, because the EOB showing what was billed, paid, and adjusted is part of the defense file in any later dispute. Providers who treat children should build their retention schedule around the longest possible minor-patient timeline in their state rather than applying the same periods used for adult records.

What Happens If You Can’t Produce an EOB

Missing documentation is the audit scenario that drives retention policies. Medicare Recovery Audit Contractors can look back three years from the date a claim was paid, and other audit programs reach further. If supporting documentation no longer exists, the auditor treats the claim as unsupported and the provider owes the money back, sometimes with interest. Across hundreds of claims, that math compounds quickly.

Inadequate records also weaken the provider’s position in every downstream dispute: payer recoupment demands, patient billing complaints, malpractice litigation, and False Claims Act investigations. The storage cost for a decade of EOBs is small compared to the cost of not having the document when someone asks for it.

Secure Storage and Destruction

Keeping EOBs for the right length of time only works if they are secured in the meantime and properly destroyed afterward. HIPAA’s Security Rule requires covered entities to implement policies governing the receipt, removal, and disposal of hardware and electronic media containing electronic protected health information, along with administrative, physical, and technical safeguards for that information.10eCFR. 45 CFR 164.310 – Physical Safeguards11HHS. The Security Rule

Paper EOBs should sit in locked cabinets or secure rooms with controlled access. Electronic EOBs belong on encrypted servers or cloud platforms with role-based access controls, audit logging, and regular security assessments. Whatever the format, every EOB must stay retrievable throughout its retention period for audits, legal requests, and patient inquiries.

Once an EOB has passed every applicable retention deadline, destroy it. Holding protected health information indefinitely raises breach risk for no compliance benefit. HHS guidance recognizes shredding, burning, pulping, and pulverizing as acceptable methods for paper records containing PHI. For electronic records, acceptable approaches include overwriting media with non-sensitive data, degaussing, or physically destroying the media through disintegration, pulverization, or incineration. The goal is to render the information unreadable and unrecoverable.

Document every destruction event: what was destroyed, when, the method used, and who performed it. That destruction log is itself a compliance record subject to HIPAA’s six-year documentation retention requirement.