Healing Process policy suite
Records Retention, Audit Trail and Data Integrity Policy
1. Purpose
To ensure that Healing Process records are authentic, complete, attributable, available for the required period and disposed of lawfully, while clearly distinguishing source images, derived images, messages and clinical decisions.
2. Scope and status
This policy covers patient and carer records, professional actions, images, derivatives, messages, consent, reports, audit logs, support, safety, regulatory, research, financial and corporate records. Customer-controlled clinical records follow the provider’s approved schedule and instructions.
Core supplier and product policy
3. Policy principles
- Retention is purpose-led and evidence-based; neither indefinite storage nor indiscriminate deletion is acceptable.
- An original photograph is not overwritten by processing. Corrections and entered-in-error actions preserve history and attribution.
- The authoritative clinical record and the role of Healing Process in it must be defined for each deployment.
- Audit records must be useful, proportionate, protected and reviewable, not merely accumulated.
4. Mandatory requirements
- Maintain a retention schedule mapping record class, owner/controller, trigger, period, legal basis, archive, deletion and hold procedure.
- Assign immutable identifiers and integrity controls to original images; record derivative type, source, version, time and creator/system.
- Log enrolment, consent, access, capture, upload, processing, view, export, message, review, decision, correction, sharing, configuration and deletion events at a proportionate level.
- Use synchronised time sources and display user-relevant timestamps with timezone clarity.
- Define what must be written to the provider’s authoritative record and how reconciliation or failed writeback is managed.
- Provide export in an intelligible, secure and appropriately structured format with provenance and context.
- Apply legal or investigation holds that suspend ordinary deletion and record the authority and release of each hold.
- Delete securely and verifiably at the end of retention, including replicas and backups according to the approved technical design.
- Restrict audit-log access and prevent ordinary administrators from altering historical events.
5. Procedure and escalation
- A record cannot be silently edited. The user submits a correction or entered-in-error request; the authorised process records the original, change, reason, actor and time.
- At deployment setup, provider and supplier approve the record-of-care model, retention matrix, export and contract-exit process.
- Automated retention jobs produce completion and exception reports. Failures are investigated and held data is excluded until authorised.
- At decommissioning, data is reconciled, exported or transferred, access removed and deletion certified according to controller instruction and law.
6. Roles and responsibilities
Records Manager
maintains schedule, integrity and disposal rules.
DPO
ensures retention is lawful, necessary and transparent.
Engineering
implements immutable provenance, logging, export and deletion.
Clinical teams/providers
identify the authoritative record and ensure clinically significant decisions are documented.
All users
make accurate, timely entries and correct errors through the approved route.
7. Records, confidentiality and retention
The records created under this policy are themselves retained according to the approved schedule, including retention decisions, holds, deletion reports, integrity checks, exports and reconciliation evidence.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review annually and after legal, contract, architecture or record-model change. Audit missing provenance, duplicate/wrong records, writeback failures, deletion exceptions, unauthorised exports and log integrity.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
