Playbook, healthtech app

Erasing a health record is not the same as closing an account

Somebody asking you to delete everything you hold about them is exercising a right that exists in most data protection regimes, usually with a response deadline attached, and it arrives phrased as a support question rather than as a formal request. On a health product it is also more complicated than a yes, because clinical information frequently carries retention duties that survive the request entirely.

Why this is not the general answer

The handling pattern for data deletion requests holds across every trade. What follows is the part that does not.

  • Health records often carry a statutory retention period that outlives a deletion request, so the honest answer is a distinction rather than a confirmation.
  • The person usually means two different things at once, closing the account and erasing the data, and those have different processes and different outcomes.
  • In most regimes the response clock starts when the request is received rather than when somebody notices it, so a message left unrouted is already consuming the deadline.
  • The requester cannot be identified in chat, so nothing about their data can be confirmed even while the request itself is being taken seriously.

How it arrives

  • how do i delete my account and everything on it
  • i want you to erase all my data
  • will my records be deleted if i just stop using the app
  • can i get a copy of everything before it is deleted
  • does deleting the app delete my information
  • how long do you keep my data after i leave

What has to be indexed for this to work

Material behind this answer
The deletion and retention section of the privacy noticeWhat is erased, what is retained and on what basis, and how long each is kept. This is the paragraph that answers the question honestly, and it is usually the paragraph written last and buried deepest.
The retention schedule, including statutory exceptionsWhere a clinical or health related record has to be kept for a defined period regardless of a request. Saying this plainly is better than a promise you cannot keep, and it is the part most people have never been told.
The export routeHow somebody gets a copy of what you hold before anything is removed, in what format, and how long it takes. It arrives in the same breath as deletion often enough that it belongs in the same answer.
Who handles rights requests, and how they are loggedThe named route inside your organisation and the address the handover has to reach. This must land somewhere a person reads daily rather than in a general inbox, because the deadline is running from the moment the message is sent.

The reply

A reply worth copying
Closing the account and erasing data are two separate things here, and the privacy notice sets out both. Deleting the app on your phone does not delete anything held on our side, and while account data can be erased on request, certain health related records have to be kept for a retention period set out in the schedule, which is explained in the same section. You can also request an export of everything you hold before any deletion. I will pass your request on now so it is logged and handled within the published response period, and for that I need your name, your email and what exactly you would like done.

It corrects the assumption underneath the question, which is that uninstalling ends the relationship, before it does anything else. It states the retention exception honestly rather than promising an erasure the organisation cannot deliver, which is the difference between a good answer and a complaint in six weeks. It routes the request in the same message it answers it, because on this one the routing is time bound and cannot wait for the visitor to ask twice.

Where it stops

The trigger. Any message that reads as a request to delete, export or restrict personal data, routed immediately even when it has also been answered.

The handover, worded
I am passing this to the team who handle data requests so the clock starts properly rather than when somebody happens to read the chat. Leave your name, the email you use with the service and what you would like done, and they will confirm directly and set out anything they have to keep and why.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Confirmation or denial that a named person has an account, a record or any data with the service.
  • That data has been deleted, or that a request has been actioned.
  • A response deadline or retention period that is not stated in your own published notice.
  • A promise of erasure covering records that are subject to a retention duty.

Questions

Can it delete the account if we connect it to our systems?
No. It reads indexed material and writes into nothing, so deletion stays an action performed by a person or by an authenticated route inside the product. What it does is explain the process accurately and make sure the request reaches somebody in time.
Somebody says they are the person concerned. Does that change the answer?
No. Identity cannot be established in a chat box, and on a health product even confirming that somebody has an account is a disclosure. The assistant should decline to discuss individuals as a category, uniformly, which is why the wording matters more than the capability.
Where should these handovers land?
Somewhere a named person reads every working day. The response period in most regimes runs from receipt, so a rights request sitting in a shared inbox for a fortnight has already spent a large part of it before anybody has read the first line.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.