Not for emergencies. If someone is seriously unwell or in immediate danger, call 999. For urgent medical help use NHS 111 or your local urgent-care route.
Display: Accessibility statement

Healing Process policy suite

Records Retention, Audit Trail and Data Integrity Policy

StatusWorking draft
Version1.0-draft
OwnerRecords Manager and Data Protection Officer
Review date23 July 2027 or earlier
Approval status: this is a substantive governance draft for review. It is not evidence that a production control has been implemented, audited or approved. Each live NHS or care deployment must align it with the provider’s policies, law, contract and configured service.

1. Purpose

To ensure that Healing Process records are authentic, complete, attributable, available for the required period and disposed of lawfully, while clearly distinguishing source images, derived images, messages and clinical decisions.

2. Scope and status

This policy covers patient and carer records, professional actions, images, derivatives, messages, consent, reports, audit logs, support, safety, regulatory, research, financial and corporate records. Customer-controlled clinical records follow the provider’s approved schedule and instructions.

Core supplier and product policy

3. Policy principles

  • Retention is purpose-led and evidence-based; neither indefinite storage nor indiscriminate deletion is acceptable.
  • An original photograph is not overwritten by processing. Corrections and entered-in-error actions preserve history and attribution.
  • The authoritative clinical record and the role of Healing Process in it must be defined for each deployment.
  • Audit records must be useful, proportionate, protected and reviewable, not merely accumulated.

4. Mandatory requirements

  • Maintain a retention schedule mapping record class, owner/controller, trigger, period, legal basis, archive, deletion and hold procedure.
  • Assign immutable identifiers and integrity controls to original images; record derivative type, source, version, time and creator/system.
  • Log enrolment, consent, access, capture, upload, processing, view, export, message, review, decision, correction, sharing, configuration and deletion events at a proportionate level.
  • Use synchronised time sources and display user-relevant timestamps with timezone clarity.
  • Define what must be written to the provider’s authoritative record and how reconciliation or failed writeback is managed.
  • Provide export in an intelligible, secure and appropriately structured format with provenance and context.
  • Apply legal or investigation holds that suspend ordinary deletion and record the authority and release of each hold.
  • Delete securely and verifiably at the end of retention, including replicas and backups according to the approved technical design.
  • Restrict audit-log access and prevent ordinary administrators from altering historical events.

5. Procedure and escalation

  • A record cannot be silently edited. The user submits a correction or entered-in-error request; the authorised process records the original, change, reason, actor and time.
  • At deployment setup, provider and supplier approve the record-of-care model, retention matrix, export and contract-exit process.
  • Automated retention jobs produce completion and exception reports. Failures are investigated and held data is excluded until authorised.
  • At decommissioning, data is reconciled, exported or transferred, access removed and deletion certified according to controller instruction and law.

6. Roles and responsibilities

Records Manager

maintains schedule, integrity and disposal rules.

DPO

ensures retention is lawful, necessary and transparent.

Engineering

implements immutable provenance, logging, export and deletion.

Clinical teams/providers

identify the authoritative record and ensure clinically significant decisions are documented.

All users

make accurate, timely entries and correct errors through the approved route.

7. Records, confidentiality and retention

The records created under this policy are themselves retained according to the approved schedule, including retention decisions, holds, deletion reports, integrity checks, exports and reconciliation evidence.

Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.

8. Monitoring, assurance and review

Review annually and after legal, contract, architecture or record-model change. Audit missing provenance, duplicate/wrong records, writeback failures, deletion exceptions, unauthorised exports and log integrity.

Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.

9. Training and communication

The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.

10. Related documents

11. Approval record

RoleNameDecision/date
Policy ownerTo be completedDraft pending approval
Clinical/technical specialistTo be completedDraft pending approval
Board or delegated committeeTo be completedDraft pending approval
Return to policy centre