Browse docs
Docs · consent privacy

Data lifecycle and HIPAA posture

Archive, access removal, deletion, and clinic retention responsibilities.

On this page

Archive is not discharge or access removal

Archive moves a patient out of your active roster. It preserves records and existing consent, changes only your clinician relationship, and does not revoke access or complete a clinical discharge. Restore returns that relationship to your active roster; it does not grant consent that has been revoked.

To end your connection, use Consent waiver → Remove from my roster in the patient's record. Follow your clinic's discharge and handoff procedures separately.

Each new archive or restore transition records the clinician ID, patient ID, clinic, timestamp, action, and previous and resulting archive state. The event and roster change commit together: if the audit write fails, the change fails. Repeating an unchanged setting does not create another transition. Earlier actions cannot be reconstructed from this log. Clinic admins can filter archive and restore events in the access log.

Account deletion is separate

A patient account deletion disables the account, marks membership deleted, revokes consent, and schedules a purge 30 days later. The scheduled purge removes app data, photos, roster and consent rows, and the login account. Some audit and compliance records remain and can contain patient identifiers; they must remain protected.

The 30-day delay is not a guaranteed clinician export window: revoked consent can prevent access immediately. Arrange authorized record preservation before deletion where possible. Contact Pippa support if a retention obligation or legal hold conflicts with a pending purge. This page does not promise an automated legal-hold mechanism.

Retention must be agreed

HHS states that HIPAA's Privacy Rule does not set a medical-record retention period. Applicable law and clinic obligations determine how long clinical records must be kept. HIPAA's six-year documentation requirements are not a universal six-year rule for all patient records or every audit event.

The current account-purge path retains audit rows; that is not an implemented six-year expiry policy. Clinics and Pippa must document the applicable retention schedule, responsibility for preserving records, deletion handling, and holds in their policies and agreements. Archive is not a retention policy, and the app's 30-day purge must not be assumed to satisfy the clinic's recordkeeping obligations.

HIPAA posture

The archive audit trail supports accountability. It does not establish HIPAA compliance by itself. The clinic and Pippa must also verify applicable business associate agreements, authorized access, safeguards, audit review, backup and recovery, and retention and disposal procedures. See HHS's Security Rule summary.

Was this page helpful?