EMStool LLC — Cadence MIH Scheduling Platform

PHI Retention & Deletion Policy

Policy #: HIPAA-SEC-009 Effective Date: July 15, 2026 (rev. July 16, 2026) Version: 1.1 Next Review: July 15, 2027

1. Purpose

This document states how long protected health information (PHI) in Cadence is retained, and how deletion is handled, both during normal operation and at the end of a client relationship.

HIPAA itself does not set a specific retention period for PHI — it requires only that a covered entity define and follow one (45 CFR §164.316(b)(2) sets a 6-year floor for the policies/documentation themselves, not the PHI). Actual medical record retention minimums come from state law, not HIPAA. For Texas-based agencies, 22 TAC §165.1 requires adult patient records be kept a minimum of 7 years from the date of last treatment, and minor patient records until the patient turns 21 or 7 years from last treatment, whichever is later.

2. Retention Period

Each client organization is responsible for identifying and complying with the record retention minimum that applies in its own jurisdiction — the Texas rule above is cited as a baseline example, not a universal one. Cadence does not enforce a specific retention period in software today; see Section 3.

3. Current System Behavior

As of this writing, Cadence has no automatic purge or deletion workflow for patient records, charts, notes, or appointments — all data persists indefinitely until an administrator manually deletes it. This is a deliberate, conservative default: given that retention laws set minimums for keeping records, not maximums, an automated early-deletion feature carries real legal risk if misconfigured. The one exception is the general system audit log, which does have a configurable, admin-set retention/purge cycle (1–20 years, default 7) unrelated to patient record data itself.

4. Division of Responsibility

EMStool does not decide when to delete a client's data

EMStool LLC is the Business Associate providing the Cadence platform. Each client organization (the Covered Entity) owns the decision of when a given patient record has satisfied its retention requirement and may be deleted, and is responsible for requesting that deletion. EMStool does not unilaterally delete a client's patient data.

5. Deletion at Contract Termination

Each client deployment runs on its own dedicated hardware — an EMStool-provided appliance or the client's own server, in the client's own facility. EMStool does not host or operate client data on its own infrastructure. There is currently no automated offboarding/deletion workflow triggered by contract end. On termination of a client relationship:

  1. The client's Cadence instance can be suspended (access blocked, data intact) remotely — this is the default first step, not deletion.
  2. If the client requests their data be exported before offboarding, EMStool will provide an export.
  3. Actual deletion of a client's database only happens on the client's explicit written request. Since the database runs on the client's own hardware, deletion is normally performed by the client directly, or by EMStool if EMStool has been granted support access to that specific deployment for this purpose — consistent with how every other irreversible data action in Cadence is handled (manual, authenticated, logged).

6. Hardware & Media Disposal

Hardware disposal is the client's responsibility, not EMStool's

Because each client's Cadence deployment runs on hardware the client owns and controls (whether EMStool-provided or the client's own server), EMStool never physically possesses the drives or media that store a client's ePHI. Secure wiping or physical destruction of storage media when a client retires, replaces, or disposes of that hardware is the client's own responsibility — the same as it would be for any other server the client operates. EMStool's own infrastructure (Bender) holds no real client ePHI (see the Vendor Security Register and Risk Analysis asset inventory) and so carries no client-data media-disposal obligation of its own.

7. Future State

If a configurable, automated purge workflow is built in the future (e.g., "delete patient records N years after last activity, per client-configured setting"), this policy must be updated to reflect the real mechanism, its safeguards, and how the retention period is set per client. Until then, this document describes the actual current behavior: retention is effectively indefinite, and deletion is manual and client-directed.