All articles

7 Year Baseline for Clinics: Data Retention in Australia, Checklist

7 Year Baseline for Clinics: Data Retention in Australia, Checklist

Decorative data retention checklist title card

Adult patient records must be retained for a baseline period commonly set at seven years from the last entry, and records for patients who were minors are generally kept until they reach early adulthood, such as 25 years of age. State and territory laws can extend this baseline, and one rule overrides everything else: if a formal complaint, adverse outcome, or possible litigation is on the table, the record stays indefinitely. Get this wrong and you’re not just risking a fine. You’re risking a defence you can’t mount.


TL;DR:

  • Retention periods start from the last entry in a patient’s record, not the first, and can be extended by state laws or contractual obligations.
  • If a medico-legal event occurs, records must be preserved indefinitely, especially in cases of complaints, adverse outcomes, or legal threats.
  • Practices should develop a written, well-structured retention policy that includes secure disposal, transfer procedures, and designated policy owners.
  • Multi-site clinics must apply the longest applicable retention period across all locations and consider old systems and archived files that may require ongoing access.
  • Proper record de-identification needs removal of all potential re-identifiers beyond just names, with thorough destruction of backups and detailed disposal logs to meet compliance.

Table of Contents

The Privacy Act 1988 sets the national floor. Under Australian Privacy Principle 11, health providers must destroy or permanently de-identify personal information once it’s no longer needed for any authorised purpose, unless a state or territory law says otherwise. That “unless” matters more than most practices realise, because it’s usually the state rule that ends up governing your actual retention period.

NSW legislation requires records to be kept for at least seven years from the date of last entry, and until the patient turns 25 if they were under 18 when that entry was made. The RACGP points to the same figures as the practical baseline most private providers apply across the country, adult records for seven years, minors’ records until 25.

Calculating the start date trips up more clinics than the length itself. The clock starts from the last entry in the file, not the first consultation. A patient you saw for a decade doesn’t get seven years added onto their first visit. It’s seven years from whenever you last wrote in their notes.

Watch for these extra triggers when setting your clock:

  • Public sector archive requirements, which can impose longer minimums than private practice rules
  • Contractual obligations with insurers, hospitals, or government-funded programs
  • Professional indemnity policy terms that specify their own retention expectations

When retention becomes indefinite

Baseline periods assume nothing has gone wrong. The moment something has, or might, the calculation changes entirely. RANZCP guidance is unambiguous here: where there’s an actual or potential medico-legal matter, a formal complaint, an adverse outcome, or foreshadowed legal proceedings, records must be kept indefinitely, well beyond the standard statutory clock.

A few scenarios that should trigger indefinite retention:

  1. A patient lodges a formal complaint with a health complaints commission or AHPRA
  2. An adverse clinical outcome occurs, even if no complaint follows immediately
  3. A solicitor’s letter arrives foreshadowing a claim
  4. A patient dies in circumstances connected to their treatment
  5. A guardianship order or retrospective claim surfaces years after treatment ended

Practically, this means flagging the file the moment any of these arise, not waiting for a lawyer to ask for it. Consent forms, complex case notes, and anything tied to a disputed outcome deserve a permanent flag in your practice management system.

Pro Tip: Build a discrete ‘medico-legal’ flag into your records system now, before you need it. A flag that’s visible in transfer logs and archived exports means nobody accidentally deletes a file during a routine clean-up years later.

Building a retention policy you can actually follow

A retention policy that lives in a folder nobody opens isn’t a policy, it’s a liability waiting to be discovered during an audit. Every clinic, whether a solo practitioner or a multi-site allied health group, needs a written policy that a new staff member could follow without asking questions.

Start with these fundamentals:

  • Set your baseline at seven years for adults and until age 25 for minors, then apply the strictest jurisdictional rule if you operate across state lines
  • Map each record type to its retention trigger, clinical notes, diagnostic images, billing records, referrals, and informed consent forms each may have different sensitivities
  • Document transfer procedures for when a practice is sold, closed, or a practitioner retires, including who holds access afterwards
  • Build secure disposal into the policy, not as an afterthought but as a scheduled task with sign off
  • Assign one person as the retention policy owner and set an annual audit date

RACGP standards guidance recommends consulting a medical defence organisation when setting or revising this policy, particularly for complex cases involving minors, mental health records, or disputed treatment outcomes.

The OAIC notes that a reasonable response time to a patient’s access request is generally 30 days, which means your retention system also needs to be retrievable, not just compliant on paper. A record you can’t locate within a month isn’t meeting the standard, even if it technically still exists somewhere in storage.

Handling records across multiple clinics and old systems

Practices with sites in more than one state face a genuine headache: NSW might require one thing, Queensland another, and the safest approach is rarely the average of the two. Sprintlaw’s guidance is clear that multi-site practices should adopt the strictest applicable retention rule across every location, rather than trying to run different policies per site.

A simple mapping exercise makes this manageable:

  • List every jurisdiction your clinic operates in
  • Note the retention period each jurisdiction requires
  • Apply the longest period found across the list to all patient records, regardless of which site they were seen at

Legacy formats are the other trap. Old imaging software, discontinued practice management systems, and archived paper files don’t disappear just because you’ve upgraded. If you still need to access those records within their retention window, you may need to retain the old hardware or software licence just to open them. A practice management dashboard that centralises these records reduces this risk considerably. When a practitioner retires, My Health Record can also support continuity, giving patients and future treating clinicians a way to access shared health information even after the original provider has left.

Secure storage, de-identification and disposal that actually meets the standard

Physical files need a locked, access-controlled space, ideally fire and water resistant, with a log of who accessed what and when. Electronic records need encryption at rest and in transit, role-based access controls, and backups that are tested, not just scheduled.

De-identification is where most clinics quietly fall short. RACGP guidance is direct about this: simply removing a patient’s name usually won’t meet APP11’s bar for permanent de-identification. Date of birth, address, Medicare number, rare diagnoses, and even distinctive treatment combinations can all re-identify someone if left in place.

Before disposal or de-identification, work through:

  • Removing or irreversibly altering names, dates of birth, addresses, and Medicare or health identifiers
  • Checking whether remaining clinical detail could still identify the patient through a rare condition or unusual treatment history
  • Coordinating destruction across your primary system, backups, and any cloud storage, all at once, not staggered
  • Keeping a short metadata log of the disposal, date, method, and who authorised it

A security questionnaire for your software vendor is worth running before you commit to any storage platform, and external resources like ClaroClaim’s security guidance offer a useful benchmark for the kind of controls a compliant system should have in place.

Pro Tip: Don’t dispose of backups on a separate schedule to your primary system. A record you “deleted” three years ago that’s still sitting in an old backup archive is a genuine data retention Australia compliance gap, and one auditors do look for.

A practical view on where clinics get retention wrong

Most clinics treat retention as a filing problem. It’s actually a workflow problem. The clinics that struggle aren’t the ones with bad intentions, they’re the ones where retention policy sits separate from recall systems, transfer processes, and day to day record access. Pair your patient recall system with your retention flags and you catch far fewer records slipping through the cracks. Easy access, continuity of care, and legal risk pull in different directions, and the clinics that manage all three well are the ones that built the connection deliberately, not accidentally.

— Taylor

Reduce the admin load of retention and continuity with Meddle

Meddle gives allied health clinics a central place to manage patient profiles, transfer logs, and secure messaging, so retention obligations don’t rely on someone remembering which drawer a file is in. Every match and referral generated through the platform is logged automatically, which means continuity of care and continuity of records happen in the same workflow instead of two separate ones.

Meddle

That matters most when a practitioner retires, a clinic changes hands, or a patient moves between providers, all moments where records historically go missing. Meddle’s integrations reduce the manual re-entry that causes half of these gaps in the first place, giving your team more time for patient care instead of file audits. If your clinic wants to see how this fits your current systems, visit Meddle for clinics to assess your setup and request a walkthrough of the practice management dashboard.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Sources

FAQ

How long do I need to keep adult patient records in Australia?

At least seven years from the last entry in the record, though some states and specific circumstances can extend this.

Do children’s health records need to be kept longer?

Yes. Records for patients who were minors must be retained until they turn 25 years of age.

What overrides the standard retention period?

Any actual or potential medico-legal matter, including formal complaints, adverse outcomes, or foreshadowed litigation, requires indefinite retention regardless of the standard timeframe.

Is removing a patient’s name enough to de-identify a record?

No. APP11 sets a high bar for permanent de-identification, and other identifiers like date of birth, address, or a rare diagnosis can still make a patient identifiable.

What happens to records when a practice closes or a practitioner retires?

Records must be transferred with a documented transfer log, and tools like My Health Record can help maintain access continuity for future treating practitioners.