MedTalk AI Logo
DATA GOVERNANCE

Data retention and disposal

How MedTalk manages the retention and secure disposal of information throughout its lifecycle.

Purpose

This policy defines how MedTalk manages the retention and secure disposal of information throughout its lifecycle, so that information is retained only for as long as necessary, protected in accordance with its sensitivity, and disposed of securely when no longer required.
  • Support compliance with legal, regulatory and contractual obligations
  • Reduce the risk of data breaches and unnecessary data exposure
  • Enable audits, investigations and legal processes
  • Ensure secure and verifiable disposal of information

Scope

Personnel

  • Employees
  • Contractors and consultants
  • Third-party service providers
  • Vendors handling MedTalk data

Information assets

  • Personal and healthcare-related data
  • Customer and partner data
  • Corporate and operational information
  • Emails and collaboration data
  • System logs and audit records
  • Backups and archived data

Technology environments

  • Cloud and SaaS platforms
  • Corporate systems and networks
  • Endpoints and mobile devices
  • Backup and archival systems
  • Third-party hosted environments

Governance and accountability

Executive leadership is responsible for ensuring appropriate governance is in place for managing information lifecycle risks, with retention practices reviewed periodically through risk and compliance governance forums.
  • Chief Information Security Officer: owns this policy, oversees secure data handling and disposal practices, and monitors compliance with retention requirements.
  • Data owners: classify information appropriately and define retention requirements based on business needs.
  • Legal and privacy functions: interpret legal and regulatory requirements and manage legal holds and investigations.
This policy aligns with the Australian Privacy Act 1988, the Notifiable Data Breaches (NDB) Scheme, and ISO/IEC 27001 Information Security Management. Where MedTalk operates across jurisdictions, additional regulatory requirements may apply.

Data retention principles

  • Minimum necessary retention: information is retained only as long as required to meet business, legal or regulatory obligations
  • Risk-based retention: decisions consider data sensitivity, business value, legal and regulatory requirements, and the risk of unauthorised access or exposure
  • Consistency and standardisation: retention requirements are applied consistently across systems and data types, supported by standardised schedules and automation where possible
  • Security throughout lifecycle: information is protected through appropriate controls during storage, archival and disposal
  • Auditability: retention and disposal activities are documented to support audit and compliance requirements

Retention, backups and media disposal

Retention requirements are documented in a Data Retention Schedule, which defines minimum retention periods, aligns with legal and contractual obligations, and is reviewed regularly. Where multiple requirements apply, the longest applicable retention period is followed.
  • Information hosted in cloud infrastructure is backed up at a frequency commensurate with its business criticality
  • Full snapshots of application environments and server configurations are captured at least every 24 hours
  • The recoverability of encrypted backup sets is verified through quarterly restoration testing
  • Audio recordings captured during service delivery are treated as transient data and are securely and irreversibly destroyed within 24 hours of creation, in practice immediately after transcription via burn-after-read audio destruction

Secure disposal

When information is no longer required and no legal hold applies, it is securely disposed of using approved methods appropriate to its sensitivity: secure deletion of electronic data, cryptographic erasure, or physical destruction of storage media or paper records, designed to prevent reconstruction or recovery of the data.
Disposal activities are logged, auditable, and supported by evidence such as certificates of destruction where required.

Third parties and data subject requests

Third-party providers handling MedTalk data must comply with defined retention and disposal requirements, implement appropriate security controls, and support data return or deletion on request. Third-party compliance is enforced contractually and monitored through vendor management processes.
Requests relating to personal information, including access, correction and deletion requests, are handled in accordance with legal obligations, balanced against retention requirements and any applicable legal holds.

Monitoring, exceptions and review

Compliance with this policy is monitored through periodic audits and reviews, monitoring of retention and deletion processes, and validation of system configurations. Non-compliance is addressed through risk management and remediation processes.
Exceptions must be formally documented with business justification, risk assessment and compensating controls, and approved by the Chief Information Security Officer.
This policy is reviewed at least annually, following significant regulatory or business changes, and after major security or data-related incidents.

Contact

Security & Compliance: support@medtalk.co

Legal / compliance: legal@medtalk.co

Get Started

Streamline your clinical notes with MedTalk AI

Intelligent medical scribe

Get A Free Trial