Key takeaways
- A commercial NDA and lawful patient-data access are separate requirements.
- Record retention depends on applicable rules; HIPAA does not supply one national medical-record retention period.
- Validate clinical records, images and attachments, not only the patient count shown after import.
- Name the person who will answer records requests and fund ongoing custody after closing.
What does records custody mean in a practice sale?
Custody is the ongoing responsibility to hold and manage records under the applicable duties. It includes more than moving a database from one computer to another. The plan needs to address patient requests, lawful seller access, storage, security, retention and eventual disposal.
The ADA's sale guidance identifies records and post-sale access as matters to plan. Use it to frame the discussion, then have healthcare counsel apply the relevant rules and contract terms. A national guide cannot assign custody or determine what notice is required for every practice. (Source: ADA: Patient records when selling a practice; checked September 5, 2026.)
Start with an inventory of where records live. Include paper charts, practice software, imaging systems, scanned forms and off-site storage where present. Ask the clinical and technology teams which items are needed to reconstruct care. A financial export that lists patient balances is not a complete clinical record.
Which responsibilities must be assigned before closing?
Use a custody matrix with a named person or entity for each duty. The purchase agreement, vendor arrangements and operating plan should tell the same story. If the buyer will hold the records, define how lawful seller access will work without leaving uncontrolled shared accounts.
| Responsibility | Decision to document | Evidence to keep |
|---|---|---|
| Custody | Who holds each record type after closing? | Counsel-reviewed agreement and inventory |
| Patient requests | Who receives, verifies and fulfills requests? | Contact route and staff procedure |
| Seller access | Which lawful purposes and controls apply? | Defined request and approval process |
| Retention | Which rules and holds apply to each group? | Dated retention analysis |
| System support | Who maintains access, backups and vendor help? | Contracts, account ownership and support contacts |
| Costs | Who pays storage, conversion and retrieval charges? | Budget and agreed responsibility |
Do not leave a duty assigned to the old practice when that entity will no longer have staff or systems. Identify who can perform the work after the seller retires. If responsibility changes later, the parties need a route to update the contact and preserve access.
What may be shared during buyer diligence?
Begin commercial screening with summary reports that do not identify patients. Define the financial or operational question before requesting more detail. The buyer can often review receipt trends, provider production and age bands without a named patient list.
HHS guidance addresses permitted treatment, payment and health-care-operations uses, including specified sale or transfer activities. That is not unlimited permission for every bidder or advisor to receive an entire database. Counsel should identify the lawful pathway, the participants and applicable limits for the actual transaction. (Source: HHS: Treatment, payment and health-care operations; checked September 5, 2026.)
A buyer NDA protects commercial confidentiality but does not create a HIPAA permission by itself. The HHS Privacy Rule summary explains the broader permitted-use and authorization framework. Resolve the basis before sharing identifiable records, then use access controls appropriate to the information. (Source: HHS: Summary of the HIPAA Privacy Rule; checked September 5, 2026.)
Keep a separate access log for protected material. Record the purpose, recipient, approved scope and means of access. If the buyer withdraws, follow the agreed and legally appropriate process for access removal and retained copies. Do not assume a deleted data-room account removes every downloaded file.
How do advisors and vendors fit the privacy process?
Identify what each outside person will do and what information that task requires. A software vendor, billing service, accountant or clinical reviewer may have different roles. Ask counsel which arrangements and safeguards are required before access begins.
HHS describes business-associate functions and agreements. A business-associate agreement is not a general waiver allowing any use of patient data. The role and permitted task still matter. Do not ask a vendor to repurpose records for a buyer's unrelated marketing campaign. (Source: HHS: Business associates; checked September 5, 2026.)
Use named accounts and appropriate permissions for the work. Decide who approves access, who can export records and when permissions end. Share credentials through the agreed secure process. A generic administrator password handed to everyone makes it difficult to trace who changed or viewed information.
Which retention and notice rules should be checked?
HHS states that the HIPAA Privacy Rule does not set medical-record retention periods. State law generally supplies those periods, while HIPAA safeguards remain relevant as records are held and disposed of. This does not remove other legal, contract or litigation-hold duties. (Source: HHS: HIPAA and medical-record retention; checked September 5, 2026.)
New York's dentistry guidance says records must be retained at least six years, with minor records kept at least six years and until one year after age 21. That is a New York statement, not a national rule. Have counsel apply the requirements to the actual records and any longer duties. (Source: NYSED: Dentistry practice guidelines; checked September 5, 2026.)
Texas provides a records-designation process concerning ownership and custody. The form identifies a task to investigate; it is not a full summary of Texas transfer, notice or retention law. (Source: Texas Board: Designation of records; checked September 5, 2026.)
Ask the relevant board and healthcare attorney about patient notice, closure, minors, access and record types. Keep the source date and the applicable rule in the file. Do not shorten retention merely because the practice has been sold or the prior software contract is ending.
How should the software transfer be planned?
Define what transfers before agreeing to a conversion fee. Ask about chart notes, images, document attachments, signed forms, balances and historical reports. Identify material that needs a separate viewer or archive. The clinical team should define what successful retrieval looks like.
| Transfer area | Question for the vendor and clinical team | Acceptance evidence |
|---|---|---|
| Chart notes | Are dates, authors and relevant history readable? | Agreed cases reviewed in the target system |
| Imaging | Do images open with the correct chart and dates? | Image retrieval checks and exception log |
| Attachments | Are scanned and signed documents linked correctly? | Selected file comparisons |
| Patient identity | Are merges and duplicate records handled correctly? | Documented mapping and clinical review |
| Balances | Do opening balances match the agreed cutoff? | Financial reconciliation separate from chart checks |
| Historical access | What remains in the old system or archive? | Tested access, support and cost plan |
A vendor's completed-import message reports a technical step. It does not prove clinical completeness. Agree on test cases and responsibility for correcting exceptions. Ask who can authorize the final cutover and what evidence that decision requires.
What does a practical migration test show?
The following numbers are invented to explain a test log. They are not a required sample size or an acceptable clinical error rate. Suppose the team selects 250 checks across notes, images and attachments using its own risk-based plan.
| Test category | Checks selected | Checks passed | Open exceptions |
|---|---|---|---|
| Notes and chart history | 145 | 140 | 5 |
| Image retrieval | 70 | 68 | 2 |
| Document attachments | 35 | 32 | 3 |
| Total | 250 | 240 | 10 |
The pass share is 96% for the selected checks. That does not establish a 96% success rate for the entire database or prove readiness for clinical use. The 10 exceptions may include issues that matter greatly to care. A high average can conceal one critical failure.
For each exception, record the affected item, expected result, actual result and owner. Use nonidentifying references in general project reports. Keep any patient-level detail in the approved secure system. Retest the corrected item and any related class of records that the team identifies as at risk.
Agree on a fallback before cutover. The fallback should preserve lawful access and a way to support care if the new system cannot retrieve needed history. Do not destroy the original source merely because one test batch passed.
How are patient requests handled after the handover?
Give staff a clear contact route and procedure. A patient should not be bounced between the retired seller, the buyer and the software vendor because no one owns the request. Define how identity and authority are checked and who handles exceptions.
Use counsel-approved notices and response procedures that fit the applicable rules. This guide does not prescribe one national response deadline, fee or notice method. Ask how requests received just before closing will be tracked so they do not disappear during the handover.
Keep a request log with dates, status and the responsible person. Limit the information in that log to what the workflow needs. Review unresolved requests at the first operating handover meeting and route clinical questions to qualified clinicians.
What access might the seller need later?
A seller may need lawful access for a care question, claim or other legitimate matter. Define the request path, scope, security and cost arrangements in advance with counsel. Continued ownership of a login is not the only way to address a valid access need.
Ask what happens if the buyer changes software, closes or sells again. The custody plan should address continuity of responsibility and the contacts needed for future requests. It should not rely solely on the personal availability of one employee who may leave.
Keep records-access questions distinct from ownership of receivables. A seller collecting old balances does not automatically receive unrestricted use of all clinical information. Match access to the lawful purpose and agreed controls.
Common mistakes in records transfer and custody
One mistake is using an NDA as the sole privacy control. Another is counting patient rows after import and assuming all images and attachments arrived. A third is treating a retained software backup as a usable archive without testing how anyone will retrieve it.
Also avoid leaving costs undefined. A low conversion quote can omit archive access, hosting or support. Ask for recurring costs and the period of access required by the actual retention plan. Compare the budget with duties that continue after closing.
Do not promise patients that every aspect of record access will remain unchanged without checking the plan. Coordinate the message, contact details and request workflow before it is sent. Staff need practical instructions they can carry out on the first day after transfer.
Summary: keep legal custody and usable access together
Name the custodian and verify the transfer basis. Inventory the records, test retrieval and resolve material exceptions through the responsible team. Define requests, lawful seller access, retention and costs. Closing should leave a workable system for patients and clinicians, with evidence of who remains responsible.
Frequently asked questions
Does an NDA let a buyer inspect all patient records?
No. An NDA alone does not establish the legal basis for patient-data disclosure. Have counsel determine the permitted purpose, recipients, scope and safeguards for the actual review. Start commercial screening with nonidentifying summary reports.
Does HIPAA require keeping every chart for six years?
The HIPAA Privacy Rule itself does not set medical-record retention periods. Check state law and other applicable duties, including holds or contracts. HIPAA safeguards can remain relevant while records are maintained and through disposal.
Can the seller retain access after a practice sale?
Plan lawful access with counsel for defined purposes. Specify how a request is made, who approves it and how information is provided securely. A shared unrestricted login should not replace that process.
Does a successful software import prove the records are complete?
No. Validate agreed clinical and financial test cases, including images and attachments. Record and correct exceptions. A row count or completed-import message alone does not prove that care history is usable.
Who answers records requests after closing?
The custody and operating plan should identify the responsible person or entity and a clear contact route. Staff need a procedure for requests received before and after closing, with unresolved items tracked through the handover.
Is the Texas designation form the full transfer rule?
No. It is one board process concerning records ownership and custody. Counsel should check the complete Texas requirements that apply to transfer, access, retention and notices in the actual situation.
Can old files be deleted to reduce storage cost?
Do not make that decision from the conversion budget alone. The responsible professionals must determine the applicable retention, access and hold duties and an appropriate disposal process. Preserve required usable access during the transition.
Are patient records the same as the accounts-receivable ledger?
No. Clinical records and financial balances can overlap but serve different purposes. Reconcile receivables separately and define access to clinical information under the proper privacy and custody process.
Sources
Retrieval dates appear beside each source. Figures retain their stated observation years; retrieval does not make older data current.
- ADA: Patient records when selling a practice · Retrieved
- HHS: Summary of the HIPAA Privacy Rule · Retrieved
- HHS: Business associates · Retrieved
- HHS: Treatment, payment and health-care operations · Retrieved
- HHS: HIPAA and medical-record retention · Retrieved
- NYSED: Dentistry practice guidelines · Retrieved
- Texas Board: Designation of records · Retrieved