Texas insurance record retention requirements do not run on a single clock. How long an insurer, HMO, or agent must keep a record depends on the record type and the line of business, with common floors ranging from three years for market conduct files to six years for HIPAA-covered documents, and longer for certain tax and life insurance records. The rules come from the Texas Insurance Code and Title 28 of the Texas Administrative Code, and they overlap with federal obligations under HIPAA, the Internal Revenue Code, and the FACTA Disposal Rule.1State of Texas. Texas Insurance Code Section 401.251
How Long You Must Keep Each Type of Record
Texas sets retention periods rule by rule rather than in one master schedule. The periods that trace directly to a specific regulation are the ones to build a policy around.
- Utilization review records. A utilization review agent must retain information generated during the review process for at least four years.
- Workers’ compensation injury records. Employers must keep a record of each workplace injury for five years from the last day of the year in which the injury occurred, or for the period required by OSHA, whichever is longer.2Legal Information Institute. 28 Tex. Admin. Code 120.1 – Employer’s Record of Injuries
- Market conduct records. Under the NAIC Market Conduct Record Retention Model Regulation, which Texas uses as a framework for examination standards, books, records, and documents kept for market conduct purposes should be retained for the current calendar year plus three additional years. Producers must keep a file for each policy sold, containing all work papers and written communications, for the same period.
- Financial statement and audit records. Insurers and HMOs must maintain the books and records supporting their financial condition under Title 28 of the Texas Administrative Code, which sets standards for independent audits and internal control reporting.3Legal Information Institute. 28 Tex. Admin. Code 7.88 – Independent Audits of Insurer and HMO Financial Statements and Insurer and HMO Internal Control over Financial Reporting
As a practical floor, most insurers keep policy and claims files for at least five years from the date of creation or from the conclusion of the related transaction, whichever is later. Life insurance records are commonly held for at least five years after policy termination to cover potential beneficiary disputes. Annuity suitability documentation is often kept longer because of the extended disclosure and suitability review obligations tied to those products. Check the specific TAC subchapter governing your line of business, because the floor differs across property and casualty, life, health, and workers’ compensation.
What Counts as a Record You Have to Keep
Retention obligations reach across most functions of an insurance operation. Policyholder files include applications, declarations pages, endorsements, and correspondence about coverage changes; declination files also belong here, with the underwriting decision and the reason for denial documented. Claims files should be detailed enough that an examiner can reconstruct every significant event and its date, from the notice of loss through investigation, adjustment, settlement or denial, and payment.
Financial and accounting records take in premium receipts, commission structures, financial statements, and reinsurance agreements. Suitability analyses and consumer disclosures belong with the transaction file for annuities and similar products. On the compliance side, Texas law requires insurance agents to maintain all insurance records, including customer complaint files, separate from any other business the agent operates.4State of Texas. Texas Insurance Code Chapter 4001 – Agent Licensing in General Continuing education documentation, licensing records, regulatory filings, and copies of advertising and promotional materials fall under retention rules too.
Federal Rules That Can Extend the Texas Period
HIPAA
Health insurers and HMOs that qualify as HIPAA covered entities must keep certain documents for six years from the date of creation or the date the document was last in effect, whichever is later. This applies to authorizations for disclosure of protected health information, privacy policies, and other compliance documentation. HIPAA does not set a period for the underlying medical records; that falls to state law. When a document qualifies under both Texas insurance rules and HIPAA, the longer period controls.
IRS Recordkeeping
Insurers owe federal taxes on premium income and take deductions for losses, so IRS rules apply alongside Texas requirements. The general rule is to keep records supporting any item on a tax return until the period of limitations for that return runs, typically three years from the filing date. If unreported income exceeds 25 percent of gross income shown on the return, the period extends to six years. For claims involving bad debts or worthless securities, the window is seven years.5Internal Revenue Service. Topic No. 305, Recordkeeping Fraudulent returns carry no limitations period at all, meaning supporting records should be kept indefinitely.
FACTA Disposal Rule
The Fair and Accurate Credit Transactions Act reaches any business that uses consumer reports for a business purpose, and insurance underwriting counts. When an insurer no longer needs consumer report information, the federal Disposal Rule requires reasonable steps to destroy it so it cannot be read or reconstructed.6Federal Trade Commission. FACTA Disposal Rule Goes into Effect June 1 Acceptable methods include shredding or pulverizing paper records, erasing or destroying electronic media, and hiring a vetted document destruction contractor.7Federal Trade Commission. Disposing of Consumer Report Information? Rule Tells How The standard flexes with the sensitivity of the data, the cost of different methods, and available technology, but flexible does not mean optional. Tossing unshredded underwriting files in a dumpster creates real FACTA liability.
Secure Disposal When the Retention Period Ends
Knowing when you can destroy a record is only half the problem. Paper files containing policyholder data, claims information, or consumer report material should be shredded or pulverized. Electronic files should be wiped or destroyed so the data cannot be recovered. If you outsource destruction to a third party, conduct due diligence on the contractor and make sure the contract specifically identifies the categories of information being destroyed.
Retaining records past their required period may feel cautious, but indefinite storage of sensitive data creates its own risk, particularly if those records are later exposed in a breach. A retention schedule should have a destruction step built into it, not a shelf that grows.
What Happens if Retained Records Are Breached
Under the Texas Business and Commerce Code, any person who conducts business in Texas and owns or licenses computerized data containing sensitive personal information must notify affected individuals of a breach no later than 60 days after determining the breach occurred.8State of Texas. Texas Business and Commerce Code 521.053 – Notification Required Following Breach of Security of Computerized Data The only exceptions are a law enforcement request to delay because notice would compromise a criminal investigation, or additional time needed to determine the scope of the breach and restore system integrity.
If you maintain computerized data on behalf of another entity, which is common in third-party administrator and managing general agent arrangements, you must notify the data owner immediately after discovering the breach. The statute’s definition of breach of system security includes unauthorized acquisition of encrypted data if the intruder also obtained the decryption key. Good-faith access by an employee acting within the scope of their job is excluded, unless that employee then uses or discloses the information in an unauthorized way.8State of Texas. Texas Business and Commerce Code 521.053 – Notification Required Following Breach of Security of Computerized Data
Penalties for Getting Retention Wrong
The Commissioner of Insurance can impose administrative penalties on any person licensed or regulated under the Insurance Code who violates the code, another insurance law, or a rule or order adopted under them.9State of Texas. Texas Insurance Code Chapter 84 – Administrative Penalties Fines are the starting point. After notice and a hearing, the Commissioner can cancel or revoke an insurer’s or agent’s authorization to do business in Texas.10State of Texas. Texas Insurance Code 82.051 – Cancellation or Revocation of Authorization
Other available sanctions include suspending an authorization for up to one year, ordering a cease-and-desist, directing the payment of administrative penalties, requiring restitution to affected consumers, or any combination of these.11State of Texas. Texas Insurance Code 82.051 – Cancellation or Revocation of Authorization – Section: 82.052 Other Sanctions The severity depends on whether the violation was intentional, whether it harmed consumers, and whether the insurer obstructed the examination. Failing to produce records during an examination is one of the fastest ways to escalate what might have been a routine review into a full enforcement action.
When to Bring in an Attorney
Most retention compliance is a matter of internal policy, not legal emergency. A few situations do call for counsel. If TDI issues a subpoena or an examination turns adversarial, an attorney can manage document production, assert any applicable privileges, and avoid the missteps that turn a records issue into a disciplinary proceeding. Litigation adds its own wrinkle: discovery obligations may require you to preserve records beyond your normal schedule, and destroying documents after litigation is reasonably anticipated, even if the retention period has technically expired, can lead to spoliation sanctions. A litigation hold pauses destruction where it needs to pause.
Building the retention policy itself is worth legal input. The overlap between the Insurance Code, TAC rules for your line of business, HIPAA, IRS rules, and federal disposal obligations means a one-size schedule is likely to leave gaps. Counsel familiar with insurance regulation can map the longest applicable period for each record category and set the disposal procedures that keep you compliant on both ends.