Practice Owner Pro

Record-Keeping Requirements for New Optometry Practices

2026-08-21

Record-Keeping Requirements for New Optometry Practices
Photo: Joachim Schnürle / Pexels

Learn the essential record-keeping rules for new optometry practices, including patient records, billing, and compliance, with practical steps for 2026.

Starting an optometry practice means taking on significant administrative responsibilities, and record keeping sits at the top of that list. Federal and state regulations require you to maintain specific records for patient care, billing, and business operations. This guide outlines the core requirements, the realistic costs of compliance, and the steps you can take this week to build a solid system.

Why Record Keeping Matters in Optometry

Accurate records protect your patients and your practice. They support continuity of care, justify billing claims, and demonstrate compliance with HIPAA, Medicare, and state optometry board rules. Poor record keeping can lead to denied claims, fines, or even license discipline. In 2026, the standard is electronic health records (EHR), and most practices use a certified EHR system to meet Meaningful Use requirements if they participate in federal programs.

Core Record Types You Must Maintain

Patient Clinical Records

Each patient file must include:

  • Demographics: name, date of birth, contact information
  • Medical and ocular history
  • Chief complaint and reason for visit
  • Examination findings: visual acuity, refraction, slit lamp exam, intraocular pressure, retinal evaluation
  • Diagnosis codes (ICD-10) and procedure codes (CPT)
  • Treatment plan, prescriptions, and referrals
  • Informed consent for procedures or treatments
  • Progress notes for follow-up visits

Keep these records for at least the period required by your state, which is typically 5 to 7 years after the last patient encounter. For minors, many states require retention until the patient reaches the age of majority plus the statute of limitations, often 10 years or more.

Billing and Insurance Records

You must document every claim submitted to insurers, including:

  • Superbills and encounter forms
  • Explanation of benefits (EOBs)
  • Claim submissions and remittance advices
  • Prior authorizations
  • Patient payment history and outstanding balances

Retain billing records for at least 7 years to comply with Medicare and most commercial payers. Keep a record of your fee schedule and any changes.

HIPAA Compliance Documents

HIPAA requires you to maintain:

  • Notice of Privacy Practices (NPP) and proof of patient acknowledgment
  • Business associate agreements (BAAs) with vendors who handle protected health information (PHI)
  • Training logs for staff on privacy and security
  • Incident reports for any breach or suspected breach
  • Risk assessments and security policies

These documents must be kept for 6 years from the date of creation or last effective date.

Business and Financial Records

For tax and legal purposes, keep:

  • Income statements, balance sheets, and cash flow statements
  • Payroll records, including time cards and tax filings
  • Accounts payable and receivable records
  • Bank statements and canceled checks
  • Asset purchase receipts and depreciation schedules
  • Licenses, permits, and insurance policies

The IRS generally requires you to keep tax records for at least 3 years, but many advisors recommend 7 years to cover potential audits.

Federal and State Requirements

HIPAA Privacy and Security Rules

All optometry practices are covered entities under HIPAA. You must implement safeguards to protect electronic PHI (ePHI), conduct regular risk assessments, and train staff. The Office for Civil Rights (OCR) can impose penalties ranging from $100 to $50,000 per violation, with a maximum of $1.5 million per calendar year for identical violations.

Medicare and Medicaid

If you bill Medicare, you must comply with documentation requirements for evaluation and management (E/M) services and diagnostic tests. For example, you must document the medical necessity of each service. Keep records for at least 7 years from the date of service.

State Optometry Board Rules

Each state has its own record retention and content requirements. For instance, California requires records for 3 years after the last visit, while Texas requires 5 years. Check your state board’s website for specifics. Some states also require you to provide patients with copies of their records within a certain timeframe, usually 15 to 30 days.

Practical Steps to Build Your Record-Keeping System This Week

  1. Choose an EHR system that is ONC-certified and meets your practice size. Budget $200-$500 per provider per month for a cloud-based system, plus setup fees. Popular options include Modernizing Medicine, Eyefinity, and RevolutionEHR.
  2. Create a retention schedule based on your state and payer requirements. Write it down and post it in your office.
  3. Set up a secure backup system for electronic records. Use encrypted cloud storage with automatic backups, and test your restoration process quarterly.
  4. Draft a HIPAA compliance binder with your NPP, BAAs, training logs, and risk assessment. Update it annually.
  5. Train your staff on documentation standards, including how to write clear progress notes and how to handle patient requests for records.
  6. Review your current records for completeness. Use a checklist to audit a sample of patient files for missing elements like consent forms or diagnosis codes.

Costs of Record-Keeping Compliance

Item Typical Cost Range
EHR software (per provider/month) $200-$500
Cloud backup service (per month) $30-$100
HIPAA training (per staff member/year) $50-$200
Legal review of policies (one-time) $500-$2,000
Physical storage for paper records (if applicable) $50-$200/month

Common Pitfalls to Avoid

  • Incomplete documentation: Missing a chief complaint or exam findings can lead to claim denials.
  • Ignoring state-specific rules: Federal rules are a baseline; your state may have stricter requirements.
  • Using paper records without a transition plan: Paper is harder to secure and search. Plan to digitize within your first year.
  • Failing to update your NPP: You must distribute a revised NPP whenever you make material changes.
  • Not backing up data: A ransomware attack or fire can destroy years of records.

FAQ

How long must I keep patient records?

Most states require 5 to 7 years after the last visit. For minors, keep records until the age of majority plus the state’s statute of limitations, often 10 years or more. Check your state board’s regulations.

Do I need an EHR system, or can I use paper?

You can use paper, but EHR is the standard in 2026. It improves efficiency, supports telemedicine, and helps you meet HIPAA security requirements. Many payers and state programs expect electronic submission.

What should I do if a patient requests their records?

You must provide access within 30 days under HIPAA. You can charge a reasonable fee for copying, typically $0.10-$0.50 per page, but you cannot deny access for unpaid bills.

What are the penalties for non-compliance?

HIPAA fines range from $100 to $50,000 per violation, up to $1.5 million per year. State boards may impose additional sanctions, including license suspension.

The Bottom Line

Record keeping is not optional; it’s a legal and operational necessity. Start with a reliable EHR, understand your state’s retention rules, and build a culture of documentation from day one. The upfront investment of time and money is small compared to the cost of a compliance failure. Take one step this week: review your current records against a checklist and fill any gaps. Your future self will thank you.