Retention Rules
The Patient Data Retention Service applies distinct policies based on the category of data stored in Health Gorilla systems. Each type of data has different clinical, operational, and compliance requirements, and retention settings must be configured accordingly.
Retention rules define how long data remains available before it is deleted. Once deleted, the data is moved to an internal archive for audit and compliance purposes and cannot be restored to production environments.
Data Categories and Recommended Retention
| Data Category | Recommended Retention | Notes |
|---|---|---|
| Patient360 Data | 90 days | External records are often re-retrieved or duplicated. Shorter retention reduces storage usage. |
| Clinical Data | 365 days | Retained longer to support reference use, clinical audits, and quality reporting. |
| Demographic Data | 1095 days | Longer retention maintains continuity in the enterprise Master Patient Index (eMPI). |
Note: The retention period for Patient360 data must be less than or equal to the period defined for clinical data.
Considerations by Data Type
- Patient360 Data: Includes all records retrieved via the
$p360-retrieveoperation, such asEncounter,Observation,Condition, andDocumentReferenceresources. Retention applies only to externally sourced records that are matched to a registered patient. - Clinical Data: Includes data generated or stored within the solution, such as lab results, medications, allergies, and uploaded documents tied to clinical workflows. Uploaded documents tied to Patient360-sourced data are excluded from deletion. Uploaded documents tied to clinical or demographic records may be deleted if included in your retention configuration.
- Demographic Data: Includes Patient, RelatedPerson, and associated identifiers. Deleting these records updates the eMPI to remove references and unlink identities.
Enforcement Details
- No records are deleted unless a retention rule is defined for the corresponding data type.
- The service runs daily and evaluates each record’s age relative to its retention threshold.
- Archiving occurs automatically before deletionp it is always enabled and cannot be turned off. Archived copies support audit traceability, legal discovery, and compliance reviews but are not accessible to clients and cannot be restored.
- Retention rules are configured at the tenant level and reviewed by Health Gorilla before enforcement.
Summary
Retention rules vary by data type and must reflect your organizational policies and compliance requirements. Define thresholds carefully to balance storage usage, record availability, and identity continuity. Records that exceed defined retention periods are archived and permanently deleted through the automated daily workflow.