Retention and removal
This page is for owners, registered managers and coordinators. It covers removing a client, the eight-year retention period, the retention report, and destroying a record when the time comes.
There are two separate acts here, and the difference matters. Removing a client takes them off the working list and keeps everything. Destroying a record deletes it for good, and only becomes possible eight years later.
Removing a client
Section titled “Removing a client”Open the client and press Remove. The dialog says the person leaves the working list, their care ends today, and the record is kept until a named date, then reviewed.
Confirming does four things:
- Ends their recurring care schedules, so no new visits are projected for them.
- Stamps today as the end of care, which starts the retention clock.
- Takes them off the working client list.
- Keeps everything: visits, doses, checklist ticks, care plan, incidents, photo and the whole trail.
You cannot remove a client who still has visits coming up. Deal with those first. This is deliberate: a client cannot quietly vanish from a rota somebody is about to work.
Finding and restoring a removed client
Section titled “Finding and restoring a removed client”On the clients list, press the Removed toggle. That shows the removed clients instead of the working list, each with a Restore button.
Restoring puts them back on the list, clears the end-of-care date so the retention clock stops, and brings their care schedules back so the rota refills.
The retention period
Section titled “The retention period”Records are kept for eight years from the end of care, then reviewed. That is the Records Management Code’s schedule for adult social care records.
A child’s record is kept longer. If the client was under 18 when care ended, the record is kept until their 25th birthday, or their 26th if they were 17 at the time, whichever of that and the eight years is later. That is the Code’s schedule for children’s records (Records Management Code of Practice for Health and Social Care, Appendix II). The date of birth on the record decides it; a record with no date of birth is kept the eight years.
Nothing expires by itself. The clock does not delete anything when it runs out. It only makes destruction possible, and somebody still has to decide.
The retention report
Section titled “The retention report”Reports, then Retention. Owners, admins, registered managers and an inspector; the office is not.
It lists every client whose care has ended, oldest first, with:
- Care ended, the date the clock started.
- Kept until, eight years later, or a child’s 25th birthday. A child’s row says so under the date.
- Status, either Kept or Due for review in red.
Filter by status to see only what is due, search by name, and Export CSV for exactly the rows on screen.
Opening the report writes a line in the audit trail, like any other list of care records.
Destroying a record
Section titled “Destroying a record”Owners only. An admin sees the report but not the button.
On a row that is due, press Destroy record. The dialog names the person and says what will happen: every entry about them is deleted for good, including visits, medication, care plan, incidents and their photo. It asks Why, and the reason is required. The buttons are Keep the record and Destroy for good.
The platform refuses if the retention date has not passed, and names the date it is waiting for.
Destruction happens in one go, so it cannot half-finish. Two things survive it:
- The destruction log. A row recording who destroyed the record, when, what the person was called, when their care ended, the reason given, and how many entries of each kind were deleted. It is never edited. The Records Management Code wants a destruction log an inspector can read after the record itself is gone.
- The audit trail. The lines about that client remain, and one more is added saying the record was destroyed, with the reason.
This is the only place in WholeVisit where care data is genuinely deleted, and it cannot be undone.
Nothing else deletes
Section titled “Nothing else deletes”Everywhere else, a delete is a removal. A cancelled visit is a cancelled visit forever. A removed medication, absence, checklist tick or incident stays in the record and stays in the timeline. Removing a team member keeps every visit they delivered and every dose they recorded.
Care that has already been delivered cannot be cancelled or unassigned at all. The record outranks the plan.