This document states how long protected health information (PHI) in Cadence is retained, and how deletion is handled, both during normal operation and at the end of a client relationship.
Each client organization is responsible for identifying and complying with the record retention minimum that applies in its own jurisdiction — the Texas rule above is cited as a baseline example, not a universal one. Cadence does not enforce a specific retention period in software today; see Section 3.
As of this writing, Cadence has no automatic purge or deletion workflow for patient records, charts, notes, or appointments — all data persists indefinitely until an administrator manually deletes it. This is a deliberate, conservative default: given that retention laws set minimums for keeping records, not maximums, an automated early-deletion feature carries real legal risk if misconfigured. The one exception is the general system audit log, which does have a configurable, admin-set retention/purge cycle (1–20 years, default 7) unrelated to patient record data itself.
EMStool LLC is the Business Associate providing the Cadence platform. Each client organization (the Covered Entity) owns the decision of when a given patient record has satisfied its retention requirement and may be deleted, and is responsible for requesting that deletion. EMStool does not unilaterally delete a client's patient data.
Each client deployment runs on its own dedicated hardware — an EMStool-provided appliance or the client's own server, in the client's own facility. EMStool does not host or operate client data on its own infrastructure. There is currently no automated offboarding/deletion workflow triggered by contract end. On termination of a client relationship:
Because each client's Cadence deployment runs on hardware the client owns and controls (whether EMStool-provided or the client's own server), EMStool never physically possesses the drives or media that store a client's ePHI. Secure wiping or physical destruction of storage media when a client retires, replaces, or disposes of that hardware is the client's own responsibility — the same as it would be for any other server the client operates. EMStool's own infrastructure (Bender) holds no real client ePHI (see the Vendor Security Register and Risk Analysis asset inventory) and so carries no client-data media-disposal obligation of its own.
If a configurable, automated purge workflow is built in the future (e.g., "delete patient records N years after last activity, per client-configured setting"), this policy must be updated to reflect the real mechanism, its safeguards, and how the retention period is set per client. Until then, this document describes the actual current behavior: retention is effectively indefinite, and deletion is manual and client-directed.