Skip to main content

HIPAA-Focused Folder Template with Retention Hints

HIPAA generally requires retaining HIPAA-related documentation (policies, procedures, notices, complaints) at least six years from creation or last effective date.

Top-Level Layout

/
├── clinical/
├── administrative/
├── security-privacy/
├── billing-revenue/
└── research/

Schema Reference

Data Structure

field_name:
type: string
required: true
description: Field description
example: "example_value"

API Reference

Endpoint Overview

MethodEndpointDescription
GET/api/v1/resourceList resources
POST/api/v1/resourceCreate resource
PUT/api/v1/resource/:idUpdate resource
DELETE/api/v1/resource/:idDelete resource

Folder Hierarchy

Within Each Domain

{domain}/
├── us/
│ ├── policy/
│ │ ├── controlled/
│ │ ├── draft/
│ │ └── archive/
│ ├── procedure/
│ ├── sop/
│ ├── form/
│ ├── notice/
│ └── log/
├── state-{xx}/
│ └── ...
└── global/
└── ...

Retention Categories in Folder Names

For operational clarity (while actual enforcement is via metadata & jobs):

FolderContentsRetention
security-privacy/us/policy/ret-6y/HIPAA policies, procedures, noticesMin 6 years
clinical/us/record/ret-6y-plus-state/Patient records (HIPAA + state)6 years + state law
billing-revenue/us/record/ret-7y/Financial records7 years

Example Structure

security-privacy/
├── us/
│ ├── policy/
│ │ ├── ret-6y/
│ │ │ ├── controlled/
│ │ │ │ ├── HSP-POL-001-privacy-notice-v3.0.md
│ │ │ │ ├── HSP-POL-002-breach-notification-v2.1.md
│ │ │ │ └── HSP-POL-003-data-retention-v1.5.md
│ │ │ ├── draft/
│ │ │ └── archive/
│ │ └── ret-permanent/
│ └── procedure/
│ └── ret-6y/
│ └── HSP-PROC-001-privacy-incident-v2.0.md
└── eu/
└── policy/
└── ret-gdpr/
└── ...

clinical/
├── us/
│ ├── policy/
│ │ └── ret-6y/
│ │ └── CLN-POL-001-patient-consent-v4.0.md
│ ├── sop/
│ │ └── ret-6y/
│ │ └── CLN-SOP-010-medication-reconciliation-v1.4.md
│ └── record/
│ └── ret-6y-plus-state/
│ └── ... (patient records by state law)
└── state-ca/
└── record/
└── ret-10y/
└── ... (CA pediatric records - 10 years)

Filename Pattern

{PREFIX}-{TYPE}-{NUMBER}-{slug}-v{major}.{minor}.md

Examples:

  • HSP-POL-001-privacy-notice-v3.0.md
  • CLN-SOP-010-medication-reconciliation-v1.4.md
  • SEC-PROC-005-breach-response-v2.1.md

Prefix Guide

PrefixDomain
HSPSecurity/Privacy (HIPAA Security & Privacy)
CLNClinical
ADMAdministrative
BILBilling/Revenue
RSHResearch

Type Guide

TypeDescription
POLPolicy
PROCProcedure
SOPStandard Operating Procedure
FORMForm/Template
LOGLog/Record

State-Specific Retention

StateRecord TypeRetention
CaliforniaPediatric records10 years after 18th birthday
New YorkGeneral medical6 years
FloridaGeneral medical5 years
TexasGeneral medical7 years

Key Principle

The folder name ret-6y is advisory; the authoritative retention is in metadata and a central retention table.

References