Jump to a section
Key takeaways
- Use aggregate or properly de-identified information when it can answer the diligence question. Removing a name alone is not necessarily de-identification.
- Qualifying transaction diligence can fall within HIPAA health care operations, but the conditions and safeguards still matter.
- HIPAA’s Privacy Rule does not set a universal medical-record retention period; other applicable requirements must be checked.
- Test record access and migration before closing so people’s care and access requests do not depend on an unavailable seller account.
Which records and entities are involved?
Start by inventorying the information, not by choosing a file-sharing product. A care business may hold assessments, care plans, visit notes, billing records, medication information, incident reports, family communications, employee files and marketing contacts in different systems. Each category can have different access and retention considerations.
Identify the legal entity responsible for each system and the roles of vendors. A non-medical home care agency is not automatically a HIPAA covered entity merely because it serves older adults. Conversely, information held outside an electronic health record can still be protected. State privacy law and contractual duties may apply even where HIPAA does not.
Keep the assessment specific to the transaction. Buying assets, buying equity and changing the software vendor may create different custody and access arrangements. Ask healthcare counsel and the privacy officer to document the applicable framework before sensitive diligence begins.
What can be reviewed without identifiable records?
Many commercial questions can be answered with aggregate information: revenue by payer, completed service hours, age of receivables, staff coverage and trend summaries. These can support early screening without identifying individual patients or residents.
Use codes consistently when record-level analysis is needed, and restrict the code key. A coded schedule is not automatically de-identified if the recipient can reconnect it to individuals or if other fields disclose identity. Keep exact dates, small populations and unusual combinations under review.
HHS describes two HIPAA de-identification methods, expert determination and Safe Harbor. Neither should be replaced by the informal instruction to remove names and send the spreadsheet. (Source: HHS de-identification guidance)
| Diligence question | Less intrusive starting evidence | When specialist review may be needed |
|---|---|---|
| Is revenue concentrated? | Coded payer and referral totals | Contract or eligibility disputes |
| Are services being billed? | Aggregated completed and billed activity | Documentation or medical-necessity review |
| Are refunds outstanding? | Coded liability and aging schedule | Resident agreement interpretation |
| Can the team maintain care? | Roles, schedules and coverage summaries | Individual care-plan continuity |
| Can records move safely? | System inventory and export specifications | Controlled migration and access testing |
When can transaction diligence be a health care operation?
The HIPAA definition includes a sale, transfer, merger or consolidation involving a covered entity and another covered entity, or an entity that will become one, and related diligence. That text is a starting point for legal analysis of a qualifying transaction. It is not a universal authorization for a broker, investor or competitor to receive any requested information. (Source: 45 CFR 164.501, current text retrieved 2026)
Document the actual purpose of the request and the recipient's role. A reimbursement reviewer checking a defined claims issue has a different need from an investor deciding whether to attend a first meeting. Limit the scope and consider whether a summary of the review can answer the buyer's question.
The transaction team should also identify other potentially applicable requirements, including state law, special categories of records and existing patient or resident agreements. A permissive provision in one framework does not settle every other obligation.
How does minimum necessary change the data room?
Where the standard applies, configure access around the task. Give the reviewer the categories and period needed to answer a documented question. Consider view-only access, restricted downloads and controlled outputs where appropriate. Technical restrictions support a process; they do not create disclosure authority on their own.
HHS guidance explains that covered entities must make reasonable efforts to limit applicable uses, disclosures and requests to the minimum necessary. It also describes exceptions, so avoid presenting it as an identical rule for every disclosure. (Source: HHS minimum necessary guidance)
Keep an access register with the recipient, approved purpose, material released and access end point. Give reviewers a clear route for requesting additional evidence. That is more useful than either releasing everything at once or preventing qualified experts from obtaining evidence needed to evaluate material risk.
What is the difference between an NDA and a business associate agreement?
An NDA is a commercial confidentiality agreement. A business associate agreement addresses specific obligations where a party is a business associate under HIPAA. One document should not be assumed to perform the other's job simply because both discuss confidentiality.
HHS describes business associate functions and the circumstances in which written assurances are required. The parties should assess what the broker, accountant, lawyer, hosting vendor or other service provider actually does with protected information. Not every transaction participant has the same role. (Source: HHS business associate guidance)
Have counsel review the contractual chain, including relevant subcontractors. Do not put protected information into personal email, an unapproved AI service or a general consumer file account merely because the buyer signed an NDA. The approved process should identify which tools and recipients are permitted for the material.
What should a record-custody schedule contain?
List each system and record category, the current custodian, proposed post-closing custodian, retention authority, access permissions, storage location, vendor contract and export method. Identify who answers requests, corrects records and supports audits concerning pre-closing services.
Address records that remain with the seller as well as those moving to the buyer. The seller may need lawful access to respond to a claim, but unrestricted access to the buyer's live environment can create new risks. Define a request and response process with counsel rather than sharing a permanent administrator password.
Specify responsibility for storage costs, vendor fees, incident response and access when the seller retires or an entity dissolves. The plan should remain workable if the individuals who negotiated the deal are unavailable. Include contact roles and backups in the private closing records.
How long must records be retained?
HHS states that the HIPAA Privacy Rule does not prescribe medical-record retention requirements. This does not mean records may be discarded at closing. Applicable state rules, payer and licensing requirements, contracts and litigation holds need separate review. (Source: HHS medical-record retention FAQ, 2009)
Build a retention schedule by category and authority. Distinguish the underlying care record from HIPAA-required policy or other compliance documentation. A single “keep everything for six years” instruction can confuse those obligations and may be inadequate for the business.
Before ending a software agreement, confirm the ability to retrieve required historical information in a usable form. A large export file that nobody can search, interpret or authenticate may not support later care, access requests or audits. Record the format and the tested retrieval process.
How should electronic migration be tested?
Use an approved migration plan with a defined source, destination, field mapping, access controls, reconciliation and rollback responsibility. Test the process with suitable nonproduction or otherwise appropriately protected data before the final cutover. Do not treat a vendor's statement that data can be exported as proof the buyer can use the export.
Check that required documents, attachments and histories remain connected to the right records. Confirm that authorized staff can retrieve the information they need after the ownership change. Resolve missing fields or inaccessible documents before disabling the seller's system.
HHS's Security Rule summary describes the electronic-information safeguard framework for covered entities and business associates. The transaction plan should be reviewed within that framework rather than reduced to a promise that a cloud folder is secure. (Source: HHS Security Rule summary, retrieved 2026)
What happens if a deal does not close?
End buyer access according to the approved agreements and preserve evidence of what was shared. Address return or deletion obligations, permitted retained copies and legal holds with counsel. Removing a user account does not establish that downloaded copies have been handled appropriately.
The seller should continue supporting normal care and records requests without interruption. Keep the sale data room distinct from production systems so a failed transaction does not disable access for staff. Any suspected inappropriate disclosure should follow the business's incident-response process rather than being handled as an ordinary commercial dispute.
How should residents, patients and staff be informed?
Coordinate required notices with a practical communication sequence. Commercial confidentiality does not override a regulator's notice rule or an individual's rights. Explain what is changing, how continuity will be maintained and where people can direct records questions, using details approved for the stage of the transaction.
The seller and buyer should avoid promising that nothing will ever change. Instead, state the verified plan for the transition and identify the responsible operating team. Questions about care should go to the appropriate professionals; a business broker should not provide clinical assurances.
What is the closing-day readiness test?
Before the handoff, confirm who holds each record set, which users have access, which vendor contracts remain active, how historical requests will be handled and what happens if the migration fails. Check these items against the actual transaction documents and applicable obligations.
Jason Taken can help keep record-custody work on the deal timetable. The healthcare attorney, privacy officer, operating team and technology providers must determine and implement the appropriate legal and technical protections. The commercial outcome should preserve access to the information people need for continuing care.
Frequently asked questions
Does HIPAA forbid all buyer access before closing?
No. The definition of health care operations includes specified qualifying transactions and related due diligence. Applicability depends on the entities, purpose and circumstances. Counsel should determine the authority, access limits and safeguards rather than treating every buyer request as permitted.
Is removing names enough to de-identify a resident schedule?
Not necessarily. Dates, locations, unusual service patterns and other fields can identify someone alone or in combination. HHS describes expert determination and Safe Harbor methods. Use a reviewed method appropriate to the information and purpose.
Does HIPAA require all medical records to be kept for six years?
No. HHS says the Privacy Rule does not establish medical-record retention requirements. Separate HIPAA documentation duties are not a universal medical-record retention period. State laws, program rules, contracts and legal holds may create additional obligations.
Who should control records after the business is sold?
The transaction documents should assign custody, access, safeguards, costs and response responsibilities consistently with applicable law and care obligations. The answer may differ by record category and deal structure. Patient rights and ongoing care must remain supported.
Sources
Sources are dated to distinguish current guidance from earlier publications. They support the identified facts; the transaction questions and examples are educational analysis.
- 45 CFR 164.501: health care operations (2026). Retrieved September 5, 2026.
- HHS: minimum necessary requirement (2003). Retrieved September 5, 2026.
- HHS: business associates (2026). Retrieved September 5, 2026.
- HHS: medical record retention and HIPAA (2009). Retrieved September 5, 2026.
- HHS: summary of the HIPAA Security Rule (2026). Retrieved September 5, 2026.
- HHS: de-identification guidance (2026). Retrieved September 5, 2026.