Facility-Level Data Retention Policy: Overview
Internal: Sales, Support & Customer Success => This article introduces facility-level data retention in HoffWeb — how admins configure it, how the nightly deletion job works, and what to check before advising or troubleshooting for a customer.
NOTE: Status: Draft — implementation status not yet confirmed.
This is in preparation for the upcoming policy
The source Confluence page ("Facility-Level Data Retention Policy - Internal", TDP space, restricted / CTO-administered) states that its contents are "for illustration only", "not suitable for external share", and "subject to change", and it asks readers to check with the Product team (Anna Zaltsman) with any questions.
Confirm with Product/Engineering that facility-level retention is actually live in production and that the behaviour below still matches it.
Facility-level data retention lets an organisation's administrator set how long audio, transcripts and encounters are kept for a Scribe facility before they are automatically and permanently deleted.
Deletion is permanent
Once a retention setting causes data to be removed by the nightly job, that data cannot be recovered. This applies independently to audio, transcripts and full encounters. Anyone advising a customer on retention settings, or handling a support request about missing data, should treat this as irreversible and act with caution, particularly when a customer asks to change or lower an existing retention period.
How retention is configured in Dictate Web
Retention settings are configured at the facility level by authorised administrators.
An administrator configures retention by signing in to Dictate Web with admin credentials, opening Facility Settings, selecting the Scribe tab, and scrolling down past the Billing section to Retention Settings.
There are three independent controls:
| Control | Retains | What is deleted | What is preserved |
|---|---|---|---|
| Audio | Raw recordings, for a set number of days | Audio files, permanently | Encounter metadata, generated documents and the transcript |
| Transcript | The consultation transcript, for a set number of days | The full transcript | Encounter metadata, generated documents and audio (if audio retention is off or set to a longer period) |
| Encounter | The entire consultation record, for a set number of days | The full consultation record: encounter, transcript and audio | Nothing — the encounter no longer exists |
All three toggles are off by default, meaning data is retained indefinitely until an administrator changes this.
Turning a toggle on triggers a warning that the admin must explicitly confirm before the setting takes effect.
Once enabled, the number of days must be a positive integer of at least 1. Each control is independent: changing one does not affect the other two retention settings for that facility.
Because Encounter retention deletes everything, including audio and transcript, a facility whose Encounter retention period is shorter than its Audio or Transcript retention period will lose that data earlier than the individual audio or transcript settings suggest. This is worth flagging to a customer who sets these independently.
How the nightly deletion job works
The deletion job runs automatically every night at 02:00 UTC and processes all facilities with retention settings enabled.
The job measures age from the date and time a recording or encounter was first created, not from any later edit or document regeneration. It works through matching records in batches, so it can run at scale without affecting system performance.
Every deletion is recorded in the facility's audit history, logged under system user 2, as one of:
Audio deleted for Dictation [id]Transcript deleted for Dictation [id]Encounter deleted with id [id](this single log entry covers the encounter and its audio and transcript together)
This audit trail is the place to check when a customer asks for proof that data was deleted in line with their retention policy.
What clinicians see in Scribe Web and Mobile
As audio, transcripts and encounters are deleted, Scribe's web and mobile apps adjust automatically to reflect what remains.
| Action | Audio deleted, transcript kept | Transcript deleted, encounter kept | Encounter deleted |
|---|---|---|---|
| Appears in the Encounters list | Yes (duration shows as "–") | Yes | No — removed entirely |
| Open and view existing documents | Yes | Yes | Not applicable |
| Edit text in existing documents | Yes | Yes | Not applicable |
| Approve document (sync to HoffWeb) | Yes | Yes | Not applicable |
| Regenerate a document | Yes (uses the transcript) | No — disabled | Not applicable |
| Generate a new document | Yes (uses the transcript) | No — disabled | Not applicable |
| Resume the consultation / recording | No — disabled | No — disabled | Not applicable |
| Dictate into the document | No — disabled | No — disabled | Not applicable |
| Add a context note | Yes | No — disabled | Not applicable |
| Edit patient details | Yes | No — hidden | Not applicable |
| Direct link to the recording screen | Redirects to the document view | Redirects to the document view | 404 / returns to the list |
When only audio has been deleted, the Resume button is disabled with the message "Audio no longer available, resuming is not possible", and dictation controls on the document toolbar are disabled. A direct link to the recording screen redirects to the document screen without an error. Everything else keeps working as normal: the clinician can still regenerate documents, add context notes, create new documents from the transcript, and approve and sync to HoffWeb.
When the transcript has also been deleted, the transcript panel shows an empty state explaining that it is no longer available due to the retention policy. Because document generation needs the transcript, both regenerating a document and creating a new one are disabled. The patient details edit icon is hidden, to avoid the encounter's patient information becoming out of sync. The clinician can still read and manually edit the text of documents that were already generated, and can still approve them.
When the whole encounter has been deleted, it is removed from the Encounters list on both Web and Mobile, and no broken links or leftover entries remain.
Advising customers on retention strategy
A common approach, and a reasonable starting point when a customer asks for guidance, is to tier the three settings by how long each type of data is actually needed:
- Audio — a short period (for example, 7–14 days), enough to allow the clinician to review or resume a recent recording, while limiting how long voice data is stored.
- Transcript — a medium period (for example, 30–90 days), enough to allow document regeneration or template changes after the consultation.
- Encounter — a long period, or switched off, so the record is retained until the approved note has been committed to the customer's EHR/PAS.
Always check whether the customer's Encounter retention period is shorter than their Audio or Transcript period. If it is, the encounter — and everything in it — will be deleted first, which cuts short the longer audio or transcript window they may be expecting.
Support: common questions
"Why is the Resume button disabled on a consultation from last week?" The facility's audio or transcript retention setting has already deleted the recording. If the transcript is still present, the clinician can edit the existing document text or regenerate it from the transcript.
"Why can't I click Regenerate on my clinical note?" The transcript has been deleted by the facility's transcript retention setting. The document can no longer be regenerated; advise the clinician to edit the existing document text directly instead.
"We reduced retention from 30 days to 7 days by mistake — can we restore yesterday's data?" This depends on whether the nightly job (02:00 UTC) has already run. If it has run, the data cannot be recovered. If it has not yet run, revert the setting back to 30 days immediately, before 02:00 UTC.
"Where can I see proof that data was deleted according to our policy?" Check the facility's audit log in HoffWeb for entries logged under system user 2: Audio deleted..., Transcript deleted... and Encounter deleted....
© 2026