
One of the most important steps in transitioning a medical practice to a records custodian is also one of the most frequently underestimated: getting the data out of the electronic health record system in a format that will remain usable long after the system access ends.
For practices that have operated on paper, the transition to custodianship is relatively straightforward. Records exist as physical documents that can be transferred, inventoried, scanned, and stored. For practices that have used an EHR (or EMR) system, the challenge is more complex. Patient records exist as structured data, attached documents, clinical notes, lab results, billing information, and audit logs inside a software environment that belongs to a vendor. When the practice closes and the vendor contract ends, access to that environment may end too, and anything not exported before that point may become inaccessible or lost.
The solution is advance planning and a thorough understanding of what needs to come out of the EHR, in what format, and how it needs to be organized before it goes to a medical records custodian. This article addresses each of those questions.
What an EHR Actually Contains
The term “patient record” is deceptively simple. In a modern EHR system, the full scope of what constitutes a patient’s record extends well beyond clinical notes and includes multiple categories of structured data, attached documents, and system-generated records.
A comprehensive EHR contains:
- Patient demographics: Name, date of birth, address, contact information, insurance identifiers, and emergency contact data
- Problem lists: Active and resolved diagnoses, coded in ICD or SNOMED format
- Medication records: Current prescriptions, medication history, dose changes, and discontinued medications
- Allergy and adverse reaction records
- Clinical notes: Progress notes, SOAP notes, assessments, discharge summaries, consultation notes, and any narrative documentation of patient encounters
- Immunization records: Administered vaccines, dates, lot numbers, and any reporting to state registries
- Lab results and diagnostic reports: Ordered tests, resulting values, reference ranges, and ordering provider information
- Imaging orders and radiology reports: Note that the images themselves are often stored separately in a PACS system and may require a separate export process
- Referral records: Orders sent to specialists, responses received, and coordination of care documentation
- Consent forms and signed documents: Scanned or electronically signed consents, HIPAA acknowledgments, and authorization forms
- Patient communications: Secure portal messages, appointment history, and communication logs
- Billing and insurance records: Charge data, claims, remittance, and payment history
- Audit logs: System records of who accessed each patient record, when, and what action they took
Not all of these categories are always part of a standard EHR export, and understanding which ones are included, which are excluded, and which require specific steps to capture is essential before the export process begins.
What HIPAA’s Designated Record Set Means for Export Completeness
HIPAA defines the “designated record set” as the set of records maintained by or for a covered entity that patients have the right to access. Under 45 CFR Section 164.524, patients have the right to access the records in their designated record set, and a medical records custodian assumes responsibility for fulfilling those access requests after the practice closes.
The designated record set includes medical records and billing records maintained by the covered entity, as well as enrollment, payment, claims adjudication, and case or medical management records used to make decisions about the patient. This is a broader category than just the clinical record, and it has direct implications for what needs to be exported and preserved.
A custodian that receives only the clinical notes from an EHR export, without the corresponding billing records, lab results, or attached documents, cannot fully satisfy a patient’s right to access their designated record set. That gap creates both a compliance problem and a practical one: patients who request complete records and receive only a portion of what exists are likely to file complaints, and regulatory authorities take incomplete access seriously.
Before beginning the export process, practices should confirm with their EHR vendor exactly what the export will include, compare that against the full scope of the designated record set, and plan separately for any components the standard export does not capture.
EHR Export Formats: What Works and What Does Not
The format of an EHR export determines whether the data it contains will be readable, organized, and usable for the duration of the retention period, which for most adult patients is seven to ten years from the date of last treatment, and longer for minors.
The most common export formats have meaningfully different characteristics:
CCDA (Consolidated Clinical Document Architecture) is an XML-based standard format that captures structured clinical data in a way that can be exchanged between different healthcare systems. CCDA exports are human-readable with appropriate tools and contain structured data that can be parsed, searched, and transmitted. They are the standard format for interoperability, but they may not capture every component of the designated record set, and clinical narratives within them can be dense and difficult for non-technical staff to navigate.
PDF exports are the most accessible format for anyone who needs to review a patient’s record without specialized health IT tools. A well-structured PDF export, ideally in PDF/A format for long-term archival stability, can be read by any standard PDF viewer and can be produced to patients, attorneys, or other authorized requestors without translation or conversion. The limitation of PDFs is that the data within them is not structured in a way that allows systematic query or exchange with other systems.
Vendor-specific proprietary formats are the most problematic for custodianship purposes. Some EHR systems store data in formats that can only be accessed through their own software. If a custodian receives data in a proprietary format and the vendor goes out of business, changes their pricing, or discontinues the product, the data may become inaccessible. Proprietary formats should be converted to standard formats before custodianship begins.
CSV or database exports are common for billing and practice management data, which often lives in a separate system from the clinical EHR. These exports contain structured tabular data that requires a database viewer or spreadsheet application to interpret meaningfully. They are valuable for billing records and appointment data but are not the appropriate format for clinical notes or complete patient records.
For most custodianship situations, the most practical approach is a combination of PDF/A exports for human-readable records and CCDA or FHIR-compliant data for structured clinical information, with any scanned attachments and lab documents included as embedded files within the PDF or as separately organized accompanying files.
What Gets Left Out of a Standard EHR Export
Even a well-executed standard EHR export often leaves out categories of information that are part of the designated record set or that patients and authorized requestors may need access to.
Common gaps include:
- Scanned attachments and embedded documents: Many EHR systems allow staff to scan external documents, such as referral letters, outside lab results, paper consent forms, and records received from other providers, and attach them to patient records. These attachments are not always included in standard data exports and may require separate extraction.
- Audit logs: Records of who accessed each patient’s record and when are metadata rather than clinical data, and they may not be included in patient-facing exports. However, audit logs are important for compliance purposes and for responding to breach-related inquiries.
- Secure portal messages: Patient communications sent through a patient portal may be stored separately from the main clinical record and require a specific export step.
- Imaging and PACS data: Radiology images, pathology slides, and other imaging data are typically stored in a Picture Archiving and Communication System separate from the EHR. The EHR may contain radiology reports and orders, but the images themselves require a separate process to export and preserve.
- Deleted or amended records: Some systems maintain records of deleted entries, amended notes, and version history. Whether these are part of the designated record set depends on the system and the nature of the record, but they may be relevant for legal or audit purposes.
- Insurance and billing data: Practice management or billing systems are often separate from the clinical EHR. If the custodian is responsible for the complete designated record set, billing records must be exported separately and organized alongside the clinical records.
Before finalizing an export plan, practices should request a detailed inventory from their EHR vendor of exactly what is and is not included in their export offering. Any gaps identified should be addressed through supplemental export steps, manual extraction, or documentation of what was not available.
The Timing Problem: When to Start
The export process must begin before the practice closes or the vendor contract ends, not after. This sounds obvious, but the timing is frequently underestimated.
EHR vendors typically require advance notice to process a data export, sometimes 30 to 60 days, and the export itself can take days to weeks depending on the size of the patient population and the complexity of the data. Some vendors charge significant fees for exports, particularly for large datasets or for formats other than their standard export offering.
Practices in the middle of a closure process, already managing lease negotiations, staff transitions, patient notifications, and regulatory filings, sometimes do not prioritize the export until too late.
There is also a contractual dimension. Some EHR subscription agreements specify what happens to data at contract termination. A vendor may retain data for a defined period after contract end, during which the practice can retrieve it, after which the data is deleted. The length of that retention window varies by vendor and may be shorter than expected.
The practical guidance is to begin planning the EHR export as soon as the decision to close or transition is made, contact the vendor immediately to understand export options, timelines, costs, and format limitations, and not finalize custody arrangements with a medical records custodian until the export plan is confirmed and the data transfer logistics are understood.
What a Medical Records Custodian Needs to Receive
A medical records custodian cannot manage, produce, or protect records that were not transferred in a usable form. From the custodian’s perspective, the ideal transfer package for EHR-originated records includes:
- Complete patient record files, organized by patient, in a standard readable format (PDF/A preferred for human-readable records, with CCDA or FHIR data where applicable)
- All scanned attachments and embedded documents associated with each patient’s record, linked to the appropriate patient file
- A patient index listing every patient in the export, with identifiers that allow the custodian to locate a specific patient’s records when a request is received
- Billing and practice management data covering the full designated record set, organized by patient or by account
- Documentation of what the export includes and excludes, so the custodian can accurately inform requestors if certain categories of records are not available
- Any paper records that were maintained alongside or outside the EHR, which may need to be scanned and integrated with the digital records
- A signed Business Associate Agreement confirming the custodian’s obligations under HIPAA to protect the records they are receiving
The quality of this transfer package determines how effectively the custodian can serve patients, respond to requests, and meet compliance obligations for the full duration of the retention period.
Frequently Asked Questions
What is an EHR export and why does it matter for medical records custodianship?
An EHR export is the process of extracting patient data from an electronic health record system into a portable format that can be stored and accessed outside of the original software. It matters for custodianship because when a practice closes or changes systems, access to the EHR may end. If patient records are not exported before that access terminates, they may become inaccessible or lost. A medical records custodian can only manage and produce records that have been successfully transferred in a usable format.
What is the designated record set and why does it define what needs to be exported?
HIPAA’s designated record set is the full set of records maintained by a covered entity that patients have the right to access. It includes clinical records, billing records, and other records used to make decisions about the patient. A custodian that receives only clinical notes, without billing records, lab results, or attached documents, cannot fully satisfy patients’ access rights under HIPAA. The designated record set defines the minimum scope of what must be exported and preserved.
What EHR export format is best for long-term medical records custodianship?
PDF/A is generally the most practical format for long-term custodianship of human-readable patient records. It is readable by any standard PDF viewer without specialized software, is stable for long-term archival, and can be produced to patients and authorized requestors directly. CCDA or FHIR-compliant formats are valuable for structured clinical data and interoperability with other systems.
Vendor-specific proprietary formats should be avoided for long-term storage because access depends on the availability of vendor software.
What happens to EHR data if a practice does not export it before closing?
The outcome depends on the EHR vendor’s data retention policy after contract termination. Some vendors retain data for a defined period, typically 30 to 90 days, after which it is deleted. Others may retain it longer for a fee. If a practice closes without arranging an export, patients may lose access to their records, and the practice may be unable to respond to access requests or legal inquiries.
Vendors are not required to serve as medical records custodians, and their data retention policies after contract end are not designed to meet clinical retention requirements.
Are radiology images included in an EHR export?
Typically no. Radiology images are stored in a separate PACS system and are not part of the standard EHR export. The EHR may contain radiology reports and orders, but the underlying images require a separate export process. Practices with significant imaging history should confirm with their radiology system vendor what options exist for exporting or migrating images as part of a closure or transition.
How long after closing must a custodian be able to produce EHR-originated records?
The retention period is set by state law and varies by state, typically ranging from seven to ten years from the date of the patient’s last treatment for adult patients, and longer for minors (often until the patient reaches the age of majority plus a defined additional period). The custodian must maintain the ability to produce records in response to authorized requests for the full applicable retention period. HIPAA’s Privacy Rule also requires that records of PHI handling be retained for six years.
If your practice is closing, switching EHR systems, or planning a transition and you need guidance on EHR data exports and medical records custodianship, Emerald Document Imaging can help. We work with practices to receive, organize, and maintain exported EHR records in a HIPAA-compliant environment, fulfilling patient access requests throughout the retention period.
Learn more about our Medical Records Custodian Services and contact us to discuss your transition.

