This document states how long protected health information (PHI) in PaceSetter is retained, and how deletion is handled, both during normal operation and at the end of a client relationship.
Each client organization is responsible for identifying and complying with the record retention minimum that applies in its own jurisdiction — the Texas rule above is cited as a baseline example, not a universal one. PaceSetter does not enforce a specific retention period in software today; see Section 3.
As of this writing, PaceSetter has no automatic purge or deletion workflow for patient records, charts, notes, or appointments — all data persists indefinitely until an administrator manually deletes it. This is a deliberate, conservative default: given that retention laws set minimums for keeping records, not maximums, an automated early-deletion feature carries real legal risk if misconfigured. The one exception is the general system audit log, which does have a configurable, admin-set retention/purge cycle (1–20 years, default 7) unrelated to patient record data itself.
PaceSetter Healthware LLC is the Business Associate providing the PaceSetter platform. Each client organization (the Covered Entity) owns the decision of when a given patient record has satisfied its retention requirement and may be deleted, and is responsible for requesting that deletion. PaceSetter Healthware does not unilaterally delete a client's patient data.
Each client deployment runs on its own dedicated hardware — an PaceSetter Healthware-provided appliance or the client's own server, in the client's own facility. PaceSetter Healthware does not host or operate client data on its own infrastructure. There is currently no automated offboarding/deletion workflow triggered by contract end. On termination of a client relationship:
Because each client's PaceSetter deployment runs on hardware the client owns and controls (whether PaceSetter Healthware-provided or the client's own server), PaceSetter Healthware never physically possesses the drives or media that store a client's ePHI. Secure wiping or physical destruction of storage media when a client retires, replaces, or disposes of that hardware is the client's own responsibility — the same as it would be for any other server the client operates. PaceSetter Healthware's own infrastructure (Bender) holds no real client ePHI (see the Vendor Security Register and Risk Analysis asset inventory) and so carries no client-data media-disposal obligation of its own.
If a configurable, automated purge workflow is built in the future (e.g., "delete patient records N years after last activity, per client-configured setting"), this policy must be updated to reflect the real mechanism, its safeguards, and how the retention period is set per client. Until then, this document describes the actual current behavior: retention is effectively indefinite, and deletion is manual and client-directed.