Docs · consent privacy

Data lifecycle and HIPAA posture

How account deletion works, what is retained for six years, and a plain-language summary of Pippa's HIPAA posture.

This page explains what happens to a patient's data over time: when it is deleted, what is kept, and how Pippa positions itself under HIPAA. It is written in plain language, not legalese, so you can answer a patient's questions with confidence.

Account deletion happens in two stages

When a patient deletes their account, Pippa does not erase everything instantly. That gives the clinic a notice period and an export window before anything is permanently gone.

Immediately: disable and tombstone

The account is signed out and disabled (not yet deleted, so it can be restored if the deletion was a mistake). A tombstone is written with a purge date 30 days out, the roster row is marked deleted so you see it on your dashboard, and consent is revoked.

After 30 days: purge

A daily job permanently removes the app data, the meal photos, and the roster and consent rows, then deletes the login account last. After the purge there is no per-user residue left behind.

The 30-day window is intentional

The gap between disable and purge is the clinic's export window. If you need anything from a departing patient's record, retrieve it before the 30 days elapse.

What is retained, and why

A small set of compliance records is kept for roughly six years and is never purged, even after an account is fully deleted:

  • PHI access logs. Every time a staff member opens a patient's record, that access is logged as an append-only audit entry.
  • Deletion records. A record that an account was deleted, per institution.
  • Consent history. Grants and revocations, plus guardian confirmations and terms acceptances (see Minors and guardian consent).
Retention is for compliance, not surveillance

These retained records are audit and consent trails, not clinical data. They exist so the clinic can prove who accessed what and who authorized it. The patient's actual health content is purged on the normal schedule.

Plain-language HIPAA posture

  • Pippa acts as a Business Associate to the clinics it works with. HIPAA does not grant patients a blanket right to deletion, but as a Business Associate Pippa may purge patient data, and it does, with the notice and export window described above.
  • Access is minimized and logged. No individual clinical data is visible without a signed, per-clinician authorization, and every access to a record is audited.
  • Photos carry no location or biometrics. Location metadata is stripped and no facial or biometric processing is ever performed.
Some items are still being finalized

A few operational and legal items around deletion pass-through notice, export-window terms, and Business Associate Agreement clauses are still being finalized with institutions. Confirm the specifics in your institution's own agreement with Pippa.

Was this page helpful?