Submitting an information return is an event.
Proving what happened afterward is a process.
Healthcare payers preparing for IRIS should not treat record retention as a final administrative step completed after filing season. The records created during submission, acknowledgment, correction, recipient distribution, and vendor communication are part of the filing control itself.
When a provider questions a 1099, an auditor requests evidence, a correction is required, or a filing vendor becomes unavailable, the organization needs more than a spreadsheet labeled “final.”
It needs a reconstructable history.
A strong IRIS record retention program should allow the payer to answer:
- What data was filed?
- Which provider records were included?
- When was the transmission sent?
- Which IRS identifiers were returned?
- Was the transmission accepted?
- What errors were reported?
- What corrections followed?
- Who approved each action?
- What copy was provided to the recipient?
- Where did the source data come from?
That is the difference between storing files and preserving evidence.
Understand the Basic Retention Periods
Publication 5718 instructs filers to retain a copy of information returns, or remain able to reconstruct the data, for at least three years from the reporting due date.
Returns reporting federal withholding should generally be retained for four years. Form 1099-C should also be retained for at least four years from its due date.
These are baseline filing-record requirements.
Healthcare payers may have additional legal, contractual, tax, audit, security, or document-retention obligations.
The organization should therefore coordinate the IRIS retention schedule with its broader records policy rather than creating a separate filing-season folder with an arbitrary deletion date.
Retain the Data, Not Only the Form Image
A PDF copy of a 1099 may be useful.
It is not the complete IRIS filing record.
IRIS A2A relies on identifiers that connect transmissions, submissions, and individual records.
Those identifiers can include:
- Unique Transmission Identifier
- Receipt ID
- Submission ID
- Record ID
- Original Unique Submission Identifier
- Unique Record Identifier
The Receipt ID, Submission ID, and Record ID are used to track filings and support corrections and replacements. The IRS describes the Receipt ID as key information that should be protected from loss or deletion.
If the organization retains only the recipient-facing form, it may lose the technical evidence needed to correct or replace the underlying IRS record later.
What an IRIS Filing Package Should Contain
For every production transmission, maintain a filing package containing:
Source data
The provider and payment data used to create the return.
Final transmitted data
The actual electronic records sent through IRIS.
Approval evidence
Documentation showing who reviewed and authorized the submission.
Transmission identifiers
The UTID, Receipt ID, Submission IDs, and Record IDs.
Acknowledgment
The final IRS status, not merely evidence that the transmission was received.
Error details
Any schema, business-rule, transmission-level, submission-level, or record-level errors.
Corrective action
Documentation of corrections, replacements, provider outreach, approvals, and resubmission.
Recipient-copy evidence
The copy furnished to the provider and available evidence of distribution.
Vendor communications
Relevant support records, status reports, incident numbers, and escalation history.
Reconciliation
Evidence that the filing population and payment totals were reviewed against the underlying systems.
This package creates a connected narrative.
Without that connection, the organization may have dozens of files but no reliable way to explain how they relate.
A Receipt ID Is Not the Final Result
IRIS may issue a Receipt ID when a transmission passes initial processing.
The organization must still retrieve the final acknowledgment.
A final status may be:
- Accepted
- Accepted with Errors
- Partially Accepted
- Rejected
- Processing
- Not Found
An audit-ready file should contain both the receipt information and the final outcome.
The difference matters.
A Receipt ID confirms that IRIS received the transmission.
It does not prove that every submission or record was accepted.
A payer that preserves only the initial receipt may be documenting the beginning of the process while losing the ending.
Retain Correction and Replacement Linkage
Corrections and replacements should never become detached from the original filing.
A corrected record should be linked to:
- Original provider record
- Original Receipt ID
- Original Submission ID
- Original Record ID
- Reason for correction
- Corrected values
- Approval
- Correction transmission
- New acknowledgment
- Corrected recipient copy
A replacement should similarly be linked to the rejected transmission or submission it addresses.
This allows an auditor, employee, or provider-service representative to follow the record from the original filing through its final accepted state.
Without linkage, the organization may know that two versions exist but not why.
Third-Party Filing Does Not Remove the Retention Obligation
Organizations using a third-party transmitter must obtain the records needed to maintain their own filing history.
The IRS instructs filers to obtain a copy of all electronic records within each submission, the Receipt ID for the transmission, the final acknowledgment, the returned status, and detailed errors.
These records are particularly important if the transmitter later goes out of business or becomes unavailable to process corrections.
A payer should not depend permanently on a vendor login to access its filing evidence.
Vendor contracts should address:
- Record ownership
- Export formats
- Retention period
- Access after termination
- Receipt ID delivery
- Acknowledgment delivery
- Error-detail delivery
- Correction history
- Data deletion
- Business continuity
The organization should download and preserve its records on an established schedule.
Use Role-Based Access
IRIS filing packages can contain sensitive provider information.
Not every employee who needs filing status needs access to full TINs or W-9 documents.
A retention system should use role-based permissions that distinguish among:
- Filing administrators
- Provider-data employees
- Finance reviewers
- Information technology
- Compliance
- Internal audit
- Executive reporting
- Vendor support
Sensitive information should be encrypted, protected from unnecessary downloads, and masked in routine reports whenever possible.
Record retention should preserve evidence without creating a sprawling new source of taxpayer-data exposure.
Separate Official Records from Working Files
Filing season often creates numerous temporary artifacts:
- Draft exports
- Research spreadsheets
- Email attachments
- Local downloads
- Test files
- Error extracts
- Provider-outreach lists
- Duplicate copies
- Screenshots
Some become part of the official filing history.
Others are temporary working files.
The retention policy should distinguish among:
Official records
The final data, approvals, identifiers, acknowledgments, corrections, and recipient-copy evidence.
Supporting records
Research, provider communications, W-9 documentation, and reconciliation work needed to explain the filing.
Temporary files
Intermediate exports and duplicate files that should be securely deleted after their purpose has ended.
Retaining everything forever is not a retention strategy.
It is digital accumulation with security consequences.
Create a Filing Index
An index makes the filing package usable.
For each issuer and tax year, the index should identify:
- Filing method
- TCC
- Software or transmitter
- Filing date
- Number of records
- Forms included
- Receipt ID
- Final status
- Open errors
- Correction count
- Replacement count
- Final completion date
- Storage location
- Retention expiration
- Record owner
This index gives management and audit teams visibility without requiring them to open every individual document.
It also helps the organization confirm that required records exist before employees or vendors change.
Test Whether the Record Can Be Reconstructed
A retention policy should be tested.
Select a prior filing and ask a person who was not directly involved to reconstruct:
- The provider data used
- The amount reported
- The submission date
- The IRS outcome
- Any correction
- The final accepted record
- The recipient copy
- The approving employee
If that person cannot complete the reconstruction without contacting the former filing owner, the records are not truly operational.
They may be stored.
They are not organized.
Use Retention Data to Improve the Process
A filing archive can also become a source of operational insight.
Track:
- Repeated TIN and legal-name mismatches
- Providers with recurring address problems
- Records corrected in multiple years
- Source systems producing frequent errors
- Returned recipient copies
- Vendor response times
- Average time to close corrections
- Acceptance and rejection rates
This information helps the organization move from annual cleanup to recurring process improvement.
The archive becomes more than a defense mechanism.
It becomes a diagnostic tool.
Final Thoughts
IRIS record retention should preserve the complete life cycle of an information return.
That includes the source data, transmitted record, Receipt ID, acknowledgment, errors, corrections, replacements, approvals, recipient copies, and vendor evidence.
Healthcare payers that retain only the final form may struggle to explain what happened before or after it.
An audit-ready filing history should be complete, connected, secure, searchable, and independent of any one employee or vendor.
BASELoad Can Help Strengthen Your IRIS Filing Records
BASELoad’s W-9 Corrections process provides healthcare payers with documented provider-data changes, corrected TIN and legal-name combinations, improved addresses, provider-outreach information, and recurring file-processing support.
That documentation can help payer teams build a clearer record of what was corrected, why it was corrected, and which information was used for filing.
Contact BASELoad to create a cleaner, more traceable provider-data foundation for your IRIS record retention and audit-readiness process.