Retention periods depend on service requirements, customer instructions, audit obligations, legal requirements, and backup architecture.
1Retention Principles
Retention should be limited to service, contractual, clinical, audit, security, financial, and legal needs.
2Record Categories
Categories may include account records, SBAR communications, uploaded documents, physician responses, audit logs, billing records, support records, backups, and security incidents.
3End of Service
Customer data export, return, deletion, and post-termination retention should follow the signed service agreement and BAA.
4Backups
Deleted data may persist temporarily in protected backups until scheduled rotation. Restored data remains subject to confidentiality obligations.
5Secure Destruction
When retention is no longer required, information should be securely deleted, overwritten, cryptographically erased, de-identified, or physically destroyed as appropriate.