Scope
Archived Is Not Retired
Most legacy projects stall in the same place. The data is extracted, the archive is live, staff have been trained — and the old system is still running. Still licensed, still on the network, still unpatched, still invoiced every year. The hospital has paid for the migration and captured none of the savings.
That gap exists because retirement is an operational and contractual project, not a data project, and it is owned by people the migration never involved: the CFO who signs the termination letter, the revenue cycle director whose claims are still adjudicating, the HR director who owns W-2s, and the privacy officer who has to attest that the data is gone.
Our legacy data archiving guide covers the first four steps — inventory, extract, validate, go live. This page starts where that fifth step begins, and assumes you already have a working archive.
The First Decision
Every Domain Has Its Own Freeze Date
There is no single day the old system goes quiet. Set four dates, not one — and let the latest of them, not the earliest, tell you when the hardware can go.
Clinical: 60–90 Days After the Last Encounter
A clinical system keeps receiving writes after you stop admitting to it. Late transcription, addenda, final pathology, and outside results land for weeks. Freeze clinical writes well after the last legacy encounter closes — not on the day the new EHR goes live.
Accounts Receivable: When the Runout Ends
Two different dates get confused here. The active workdown — a team on legacy accounts full time — commonly runs about three months past go-live. The date you can freeze the system is later: legacy-era claims keep adjudicating, denials keep appealing, and secondary balances keep working down, and a residual tail can sit open far longer. Ask revenue cycle for the aged AR curve, pick the point where what remains can be worked manually or from the archive, and expect that to land six to twelve months past clinical cutover. Staff the workdown for the first number, plan the freeze around the second.
Payroll: At a Calendar-Year Boundary
Payroll has a hard date the others do not. Cut mid-year and you own a manual year-end assembled from two systems. Freeze after the final payroll of the year processes and after W-2s and ACA filings have been produced from the system that ran them.
General Ledger: After Cost Report and Audit
Freeze at a fiscal-year boundary, but the binding deadline is usually the Medicare cost report rather than the financial statement audit. The cost report is due the last day of the fifth month after fiscal year end, CMS and the MAC examine it, and it can be reopened later — so GL detail has to stay producible well past filing. External audit fieldwork is the second gate. Confirm with your auditors and whoever prepares the cost report that a view-only archive satisfies a trace-to-source request, in advance of the freeze rather than after it.
The Sequence
Seven Steps from Live Archive to Dead Server
Timings are relative to each domain's freeze date. Run the sequence once per domain if their dates are far apart — the hardware only goes when the last one clears.
Confirm the Archive Stands Alone
Week 0Everything below assumes the archive is live, validated, and already the place staff go. If HIM is still opening the legacy system for routine lookups, you are not retiring anything yet.
Set a Freeze Date per Domain
Weeks 1–2Clinical, AR, payroll, and GL do not stop on the same day. Name the date and the owner for each one, and treat the earliest contract deadline as the constraint the rest of the plan bends around.
Get the Post-Notice Rights Executed
Weeks 2–6, and before noticeTermination can end your access to the source system. Before you serve notice, get signed terms — in the agreement or an amendment — covering continued environment access through a named date, extraction support and deliverable format, and a re-extract if validation finds gaps. This is a prerequisite, not a nice-to-have: notice served without it can leave you with no enforceable route back to data you have not finished validating.
Serve Contract Notice
Before the notice window closesMost legacy maintenance agreements renew automatically unless you give notice inside a defined window. Once the rights above are signed, serve notice by that date even if the extract itself is not finished — a slipped extract costs weeks, a missed notice costs a full term. If the vendor will not sign those rights and the window is closing, you have a genuine conflict rather than a checklist step: escalate it to counsel and your executive sponsor, because both paths carry real cost. Starting this in week 2 is what keeps it from becoming that decision.
Cut Over Access and Interfaces
At each freeze dateShut off access in stages: outside partners first, then interactive users, then service accounts and interfaces. Keep the ability to re-enable for a defined window and log every attempted connection you deny.
Capture and Validate the Final Delta
Freeze + 1 to 4 weeksEverything written between the first extract and the freeze has to move too. Re-run the extract for the delta window, load it, and validate the seam where the two extracts meet — that boundary is where records go missing.
Sign Off, Then Go Dark
A window you setCollect a signed validation memo per domain, then power the system off while keeping it fully restorable. A dark period surfaces the forgotten dependency while restoring is still a five-minute job. How long it runs is your call, not your archiving vendor's — agree it with IT and compliance. Thirty to ninety days is a reasonable starting point if you have no prior number to work from.
Sanitize and Close the Vendor Relationship
After the dark period closesWipe or destroy the media to a documented standard, pull the system out of backups and the DR plan, and get written confirmation that the vendor has returned or destroyed its copy of your data.
Confirm the Archive Stands Alone
Everything below assumes the archive is live, validated, and already the place staff go. If HIM is still opening the legacy system for routine lookups, you are not retiring anything yet.
Set a Freeze Date per Domain
Clinical, AR, payroll, and GL do not stop on the same day. Name the date and the owner for each one, and treat the earliest contract deadline as the constraint the rest of the plan bends around.
Get the Post-Notice Rights Executed
Termination can end your access to the source system. Before you serve notice, get signed terms — in the agreement or an amendment — covering continued environment access through a named date, extraction support and deliverable format, and a re-extract if validation finds gaps. This is a prerequisite, not a nice-to-have: notice served without it can leave you with no enforceable route back to data you have not finished validating.
Serve Contract Notice
Most legacy maintenance agreements renew automatically unless you give notice inside a defined window. Once the rights above are signed, serve notice by that date even if the extract itself is not finished — a slipped extract costs weeks, a missed notice costs a full term. If the vendor will not sign those rights and the window is closing, you have a genuine conflict rather than a checklist step: escalate it to counsel and your executive sponsor, because both paths carry real cost. Starting this in week 2 is what keeps it from becoming that decision.
Cut Over Access and Interfaces
Shut off access in stages: outside partners first, then interactive users, then service accounts and interfaces. Keep the ability to re-enable for a defined window and log every attempted connection you deny.
Capture and Validate the Final Delta
Everything written between the first extract and the freeze has to move too. Re-run the extract for the delta window, load it, and validate the seam where the two extracts meet — that boundary is where records go missing.
Sign Off, Then Go Dark
Collect a signed validation memo per domain, then power the system off while keeping it fully restorable. A dark period surfaces the forgotten dependency while restoring is still a five-minute job. How long it runs is your call, not your archiving vendor's — agree it with IT and compliance. Thirty to ninety days is a reasonable starting point if you have no prior number to work from.
Sanitize and Close the Vendor Relationship
Wipe or destroy the media to a documented standard, pull the system out of backups and the DR plan, and get written confirmation that the vendor has returned or destroyed its copy of your data.
Contracts
The Renewal Clause Sets the Deadline
Read the termination and renewal language before you plan anything else, and read it rather than assuming what it says. Auto-renewal is common in legacy maintenance agreements, and the notice window can close well ahead of the anniversary date. Find the exact date and the required form of notice in your own contract. Missing it costs a full term.
Then separate the license from the support, because they can terminate independently. Check which you hold and what the agreement says survives: if the right to run the software continues after support ends, you can keep the system up unsupported while the delta and the AR runout finish. If it does not, the final extract has to precede termination. This is a question for whoever holds the contract and, where the answer is not plainly written, for counsel — it is not safe to infer from the license type alone.
Get the rights signed before notice. Do not wait for the extract itself. Two different things are often collapsed into one decision. Written post-notice rights — environment access through a named date, extraction support and deliverable format, and a re-extract if validation finds gaps — are a prerequisite to serving notice. Serve without them and termination can end your access to a system whose extract you have not finished validating. The completed extract is not a prerequisite; holding notice for it risks a renewal you do not want.
Settle all of it early. Vendor cooperation, environment access, and the staff who remember how the system works are cheapest while the contract is running, and extract scope and fees are negotiable terms inside a live agreement where they become a quoted invoice afterwards. Starting in week 2 is what stops the rights negotiation and the notice window from colliding. If the vendor hosts the system, note how long they keep your data after termination — that clause can be short, and where the license is a term or subscription rather than perpetual, extraction has to finish before the term ends.
Ask the outgoing vendor, in writing
- What is the exact notice date on our current term, and what form must notice take?
- Is our license perpetual or term-based, and what survives termination?
- What is the deliverable format of a full extract, and does it include documents and images or only structured data?
- What does the extract cost, and is any of it already covered under the current agreement?
- How long do you retain our data after termination, and how is it destroyed?
- Who signs the confirmation of return or destruction, and when do we receive it?
Cutover
Find What Still Points at It — Don't Ask
Interviews produce a partial list every time. Turn on connection logging on the server and the database for 30 to 60 days before the freeze, and let inbound sessions by source IP build the inventory for you.
- Interface-engine channels: ADT feeds, lab and radiology results, transcription, pharmacy
- Scheduled jobs and SFTP drops to payers, clearinghouses, and collection agencies
- State and registry submissions — immunization, syndromic surveillance, reportable labs, vital records, trauma and cancer registries — where these are worth checking is whether the feed was actually repointed at the new system or is still leaving from the old one
- Report tools pointed straight at the legacy database: Crystal Reports, Access front-ends, and Excel ODBC connections on somebody's desktop
- Device destinations: scanner drop folders, label and wristband printers, fax routing
- Service accounts, shared accounts, and the AD groups nobody ever removes
- Hostnames and IP addresses hard-coded in downstream configs, bookmarks, and desktop shortcuts
Then cut in stages rather than all at once: outside partners first, interactive users next, service accounts and interfaces last. Denying a connection and logging it is far more informative than powering a server off, and it stays reversible while people are still discovering what they used the old system for.
Sign-Off
What a Validation Memo Has to Contain
Reconciled counts prove rows moved. They do not prove documents moved — systems that keep document metadata in a database and the files themselves on separate storage, as Hyland OnBase does, can reconcile perfectly on counts while files are missing. Open documents from the sample, don't count them.
- Record counts reconciled by type — and a sample of documents actually opened, because counts alone never prove files moved
- A deliberately awkward sample: the oldest records, charts carried over from an earlier conversion, merged duplicate MRNs, names with accents or apostrophes, and one record from every year of the retention window
- Parity on the reports people actually run — the ROI packet, AR aging, payroll register, GL trial balance — not the vendor's report list
- An immutable copy of the raw extract files kept in your own storage with checksums, independent of the archive vendor
- A named signer per domain: HIM for the clinical record, revenue cycle for AR, HR for pay history, the controller for GL, privacy and security for access and audit, IT for the infrastructure
Disposal
Go Dark Before You Go Away
Image the system before you power it down, and keep the image offline. Powering off is reversible; wiping is not. Hold the system restorable but unreachable through a defined dark period — 30 to 90 days is a reasonable range — and see who notices. Nearly every project turns up one forgotten dependency in that window, and it is much cheaper to find while the machine still exists.
When the dark period closes, sanitize the media to a documented standard. NIST SP 800-88 Rev. 2 superseded Rev. 1 in September 2025 and changed shape in the process: it now describes how to run a media sanitization program — including validating that sanitization actually worked — and defers the technique detail to IEEE 2883 or another standard your organization approves, rather than prescribing methods by media type itself. If your security policy still cites Rev. 1, that reference is withdrawn and worth updating while you have the disposal work open. Collect certificates of destruction with serial numbers for anything that leaves the building.
Backups are the part people miss. Protected health information lives in the backup set and the disaster recovery replica long after the primary is wiped. Remove the system from backup jobs, expire the existing sets on a documented schedule, and drop it from the DR runbook and any replication target. Then close the loops in your systems of record: asset inventory, monitoring, endpoint protection, per-server licensing, firewall rules and vendor VPN access, the security risk analysis, and the business associate register.
Definition of Done
How to Know the System Is Actually Retired
Print this. A project is finished when every line is true and evidenced — not when the server stops responding to ping.
- Every domain has a signed validation memo with a named owner and the evidence they reviewed
- The vendor contract is terminated in writing, the notice date was met, and the final invoice is reconciled
- Written confirmation of data return or destruction is on file from the vendor
- No interface, scheduled job, or report resolves the legacy hostname — because the hostname resolves to nothing
- The servers are off the network, off the backup schedule, and out of the DR runbook and asset inventory
- Certificates of destruction, with serial numbers, are filed for any media that left the building
- HIM, billing, and HR know the archive is the documented source for release of information, audit, and legal hold
- The decommissioning file itself is retained — HIPAA requires Security Rule documentation be kept six years from creation or last effective date (45 CFR §164.316(b)(2)(i)), and these memos are exactly that
None of this is legal advice. Retention schedules, contract terms, and destruction obligations vary by state and by agreement — confirm yours with counsel before you sanitize anything.
FAQ
Common Questions
How long does it take to retire a legacy EHR system?
Can we shut the old system off as soon as the archive is live?
What is the difference between archiving and decommissioning?
What happens if we miss the maintenance renewal notice date on a legacy contract?
Do we need to keep the legacy hardware after the data is archived?
Will an archive satisfy an audit or records request three years later?
Working Through a Decommissioning Plan?
Bring us your system inventory and contract dates. We'll help you sequence the retirement — and CHA Viewer keeps the records searchable once the system is gone.