Health providers have to keep patient records for years, and then, when retention ends, dispose of them securely. Both halves are obligations. Holding records too briefly breaches retention rules; keeping the data on old drives forever, or disposing of it carelessly, breaches privacy obligations. This guide explains how long patient records generally have to be kept in Australia, and how to destroy them and the IT that held them once that period is over.
In Australia, health records generally must be kept for a minimum period set by state and territory health records legislation, commonly at least seven years from the last entry for an adult, and for a child until they turn 25, though the exact period varies by jurisdiction and record type. Once the retention period ends and the records are no longer needed, privacy obligations require that they be securely destroyed or de-identified, which means the patient data on any drive, server or backup must be rendered unrecoverable, not merely deleted. The reason this is a two-sided duty is that patient information is among the most sensitive data an organisation can hold. Providers are required to retain it long enough to serve patients and meet legal needs, and then, crucially, to dispose of it properly when that need ends. Getting the disposal right, destroying the data on retired IT to a recognised standard with evidence, is what protects both the patient and the practice. It is central to responsible healthcare IT disposal.
Patient records have a defined life. They are created and added to through care, kept for a legally required minimum, and then, when they are no longer needed, they are supposed to be disposed of, not left to accumulate indefinitely on ageing systems. Healthcare organisations tend to focus hard on the keeping and much less on the disposing, which is understandable but risky, because the disposal end is where sensitive health data most often escapes. This guide is about handling both ends of that life properly.
Retention periods are set by law and depend on where you are and whose record it is. The common thread is a minimum, after which disposal becomes the obligation.
How long a health provider must keep a patient record is set by state and territory health records legislation, so the precise period depends on the jurisdiction and the type of record. As a widely applied general rule, adult health records are kept for at least seven years from the date of the last entry, and records for children are kept until the person reaches 25 years of age. Some records and circumstances attract longer periods, and providers should confirm the requirement that applies to them rather than assuming a single number covers everything. The principle behind these minimums is continuity of care and the ability to answer later questions, clinical or legal, about the treatment provided.
What matters for disposal is what happens at the other end of that period. Retention rules set a floor, not a mandate to keep records forever. Once the required period has passed and the records are genuinely no longer needed, the Australian Privacy Principles require that personal information be destroyed or de-identified, a live obligation under APP 11. For a health provider, that means patient data sitting on old servers, retired workstations, backup drives and imaging systems well past its retention period is not just clutter; it is sensitive information the organisation is expected to have disposed of. The retention clock, in other words, eventually becomes a disposal trigger.
Keeping records for the required period is mandatory. Keeping them, or the drives that hold them, long after the need has passed runs against the obligation to destroy or de-identify data no longer needed. The end of retention should trigger secure disposal, not indefinite storage on ageing hardware.
When retention ends, the data has to be genuinely destroyed. Five steps take patient records and the IT that held them out of existence, with evidence.
Verify that the records are past their required retention period and genuinely no longer needed for care, legal or other legitimate reasons, so that disposal is appropriate. Destroying records still within retention is as much a failure as keeping them too long.
Patient data spreads: practice servers, workstations, backup drives, imaging systems, old laptops. Identify all of it, because destroying the primary system while an old backup drive keeps a full copy leaves the data very much alive.
Securely erase the media to a recognised standard such as NIST 800-88, or physically destroy drives that cannot be reliably wiped, so patient data cannot be reconstructed. Deleting or reformatting is not destruction.
Move retired devices under a documented chain of custody from the practice to destruction, so there is an unbroken record of where sensitive health data went at every step.
Keep a certificate for each device recording what was destroyed and to what standard. For health data, being able to show the records were destroyed properly is as important as destroying them.
The safest pattern is to treat the end of a retention period, and every IT refresh, as a disposal trigger, routing retired devices holding patient data through certified destruction under chain of custody. Talk to our team about disposing of healthcare IT securely.
Created, retained for a legal minimum, then destroyed. Disposal is a stage of the lifecycle, not an afterthought.
Health is consistently the most breached sector in Australia, and health records are among the most sensitive data there is. Figures from named sources.
Health data is uniquely sensitive, revealing conditions, treatments and histories that patients expect to remain private for life, and it is exactly this data that a careless disposal exposes. Health is consistently the most breached sector in the country, and a breach that comes from an old practice server or backup drive is not softened by having been an oversight. The two-sided obligation is what makes this manageable: keep records for the period the law requires, then, when that period ends and the data is no longer needed, destroy it to a recognised standard and evidence it, rather than letting it linger on hardware nobody is thinking about. Against a maximum privacy penalty of $50M or more, and the particular gravity of health information, treating the end of retention as a genuine disposal event, one that renders patient data unrecoverable and produces a certificate, is how a healthcare organisation honours the trust patients place in it right to the end of a record's life. For any provider handling patient data, secure disposal is where that trust is kept or broken.
The questions healthcare providers ask most about keeping and then disposing of patient records.
It is set by state and territory health records legislation and depends on the jurisdiction and record type. As a widely applied general rule, adult records are kept for at least seven years from the last entry, and children's records until the person turns 25, with some records requiring longer. Because it varies, confirm the specific requirement that applies to your practice rather than relying on a single figure.
Once records are past their required retention and no longer needed, the obligation shifts to disposal. The Australian Privacy Principles require personal information to be destroyed or de-identified when it is no longer needed, so patient data on retired systems and drives should be securely destroyed, not left indefinitely. The end of retention is effectively a trigger to dispose of the data properly.
No. Deleting records or reformatting a drive typically leaves the underlying data recoverable, which for patient information is not secure disposal. The data must be rendered unrecoverable, by secure erasure to a recognised standard or physical destruction of the media, so it cannot be reconstructed. For health data especially, the difference between hidden and genuinely destroyed is the difference between compliance and a breach.
Beyond the main practice management system, patient data commonly sits on backup drives, old workstations and laptops, imaging systems, and servers that have been replaced but not disposed of. The frequent failure is destroying the primary system while an old backup or a retired workstation keeps a full copy. A thorough disposal starts by finding every place the data lives, not just the obvious one.
A certificate of data destruction for each device, recording what was destroyed and to what standard, ideally under a documented chain of custody from the practice to destruction. For health data, being able to demonstrate that records were destroyed properly is essential, because if a question is ever raised about disposed patient information, the certificate is what shows the obligation was met.
Yes, and it is often the most practical route. A small practice rarely has the tools to render drives unrecoverable to standard or the processes to document it. A data destruction service securely destroys the media, maintains chain of custody and provides certificates, so the practice meets its disposal obligation without needing to build the capability in-house. The retention decision stays with the provider; the secure destruction is handled for them.
See how ITC destroys patient data on retired practice servers, workstations, backup drives and imaging systems, to a recognised standard, under chain of custody, with a certificate for every device.
Evidence for your auditor
Regulators do not ask whether you recycled the hardware. They ask what happened to the data on it, who handled it, and where the record is. ITC holds ISO/IEC 27001:2022 for information security alongside ISO 14001:2015, ISO 9001:2015 and ISO 45001:2018, and issues serialised documentation on every job so the answer is already written down.