How long should a clinic keep patient records?

Why there is no single answer, what actually decides the period, and how to run a retention policy that executes instead of sitting in a document.

The honest answer is that nobody can give you a number without knowing which country you practise in, what kind of clinic you run, and how old the patient was when you treated them. Anyone who does give you a number without asking those three things is guessing on your behalf.

What can be given is the shape of the decision, which is the same everywhere — and it is more useful than a number, because it also tells you what to do when the number changes.

Four things set the period

  • A statutory minimum, set by health legislation or your regulator, and usually the longest of the four. This is the floor and it is not yours to shorten.
  • The limitation period for a claim. Records are the evidence in a dispute, and a clinic that destroys them on the legal minimum can find itself defending a claim without the notes.
  • The age of the patient at treatment. Almost every regime extends the period for minors, frequently counting from when they reach adulthood rather than from the visit.
  • Data protection law pulling the other way. GDPR and the regimes modelled on it require you not to keep personal data longer than necessary — so "keep everything forever" is itself a breach, not a safe default.
Important

The last two are the ones clinics get wrong in opposite directions. A paediatric record deleted on the adult schedule is deleted too early; a marketing list kept for twelve years because the clinical records are is kept too long. They are different categories with different answers.

Not everything is a patient record

This is where most retention policies fall apart. "Patient data" is treated as one thing with one period, when a clinic actually holds several categories that answer to different rules.

What it isGoverned mostly byTypically
The clinical recordHealth legislation and claims exposureThe longest period you hold
Financial recordsTax and accounting lawIts own period, often shorter
Appointment historyNecessity — it is operationalShorter, once it stops being useful
Chat and enquiry transcriptsNecessity, and little elseThe shortest, and rarely worth keeping long
Marketing consent and listsData protection lawUntil withdrawn, and no longer

Splitting them is the single most useful thing you can do, because it lets you delete the categories with the weakest justification without touching the ones you are obliged to keep. A clinic that cannot separate them ends up keeping everything for the longest period, which is the outcome data protection law was written to prevent.

Where to get your actual number

Three places, in this order, and none of them is a blog.

  1. Your professional regulator or health ministry. They publish this, usually as guidance rather than something you must hunt for.
  2. Your professional indemnity insurer. They have a view, it is often longer than the statutory minimum, and it is the view that matters if you are ever defending a claim.
  3. A local adviser, for the interaction between the two and for anything about minors.
Note

If you treat patients in more than one country, build to the strictest of them. Running different periods per patient is possible in theory and unmanageable in a real clinic.

A policy that executes

Most retention policies are a document. A document is not a policy — the personal data is still there on the day somebody asks about it, and "we have a policy" is not an answer to "why do you still have this".

What makes it real is that something deletes on a schedule without anybody remembering to.

  1. Write down a period per category, not one period for everything.
  2. Set the shortest one first — usually chat transcripts, which almost nothing requires you to keep.
  3. Make the deletion automatic, on a recurring schedule.
  4. Keep a record of what was deleted and when, so the policy is demonstrable rather than asserted.
  5. Review it when the law changes, and when you start doing something new.

Being plain about our own scope: in Clinic+ the automatic side covers conversations, appointments and financial transactions — the categories where over-retention is common and the legal case for keeping them is weakest. The clinical record is deliberately not on that list. It is the category with the longest obligations and the least room for a mistake, so deleting it stays a decision somebody makes rather than a job that runs at two in the morning.

Deletion is not one action

Two distinctions worth having straight before you promise anybody anything.

  • Removed from view is not erased. A recycle bin that holds a record for thirty days is good practice — most deletions are mistakes — but for those thirty days the data still exists, and a deletion request is not satisfied until the window closes.
  • Backups have their own timeline. Data deleted from the live system persists in backups until those rotate. That is normal and generally accepted; what matters is being able to say how long it takes rather than claiming it is instant.

This quarter

  1. List the categories you actually hold. Most clinics find more than they expected.
  2. Get the number for the clinical record from your regulator and your insurer.
  3. Set periods for everything else on necessity, and make them shorter than you are comfortable with.
  4. Automate the shortest category first and check it ran.
  5. Write the whole thing down in one page a patient could be shown.

That last page is what turns this from an internal setting into something you can point at when somebody asks — which, sooner or later, somebody will.

Common questions

How many years should patient records be kept?
There is no universal figure, and any article giving you one without asking your country, your speciality and the patient's age is guessing. The period is set by your health legislation or regulator, extended by the limitation period for claims and extended again for patients who were minors. Get it from your regulator and your indemnity insurer, in that order.
Is it safer to keep everything forever?
No. Under GDPR and the regimes modelled on it, keeping personal data longer than necessary is itself a breach, so "forever" is not a safe default — it is the opposite one. The safe position is a defensible period per category, applied consistently.
Do financial records follow the same period as clinical ones?
Usually not. Financial records answer to tax and accounting law, which typically sets its own and often shorter period. Treating them as one category is what makes clinics keep everything for the longest applicable period, which is exactly what data protection law is trying to prevent.
What about records for patients who were children?
Almost every regime extends the period, and many count from when the patient reaches adulthood rather than from the date of treatment. It is the most common way a clinic deletes something too early, and it is worth confirming specifically rather than assuming your standard period covers it.
Does deleting a record remove it from backups immediately?
No, and that is normal. Data deleted from the live system persists in backups until they rotate. What matters is knowing how long that takes and being able to say so, rather than claiming a deletion is instantaneous when it is not.

Read next

A period that runs, not a paragraph that sits.

Retention windows per category, swept nightly, with a record of what was removed — covering conversations, appointments and transactions. The clinical record stays a decision somebody makes rather than a job that runs at two in the morning.

Where your data lives