The short answer: do not treat "three years" as a universal deletion rule
The Medical Council of India's 2002 ethics regulations state that physicians must maintain records concerning their indoor patients for three years from the start of treatment. The same section says requested medical records should be acknowledged and supplied within 72 hours, and encourages computerisation for quick retrieval. NMC Code of Medical Ethics Regulations, 2002.
The important word is "indoor." The provision should not be casually rewritten as "all clinic records may be deleted after three years."
The Clinical Establishments standards for clinics and polyclinics with observation or short-stay facilities separately say that copies of OPD, procedure, referral, and emergency records should be maintained according to applicable MCI guidance. They also require patient registration and documented assessment details. Clinical Establishment standards for clinics and polyclinics.
A clinic should consequently answer four questions before assigning a retention period:
- What type of record is this?
- Which law, professional rule, licence, programme, contract, or state requirement applies?
- Is the record still required for care, a complaint, an audit, a claim, or another legitimate purpose?
- What must remain after an account, duplicate registration, or communication preference is deleted?
The result should be a written schedule approved for that clinic's actual services.
Understand the current regulatory position
The 2002 professional-conduct rules remain an important starting point
The NMC continues to publish the 2002 Code of Medical Ethics, including its provisions on indoor records, requests, medical certificates, and computerised retrieval.
The NMC's 2023 Registered Medical Practitioner Professional Conduct Regulations should not be used as though they replaced those rules. The NMC's own regulations index records that the 2023 regulations were kept in abeyance by an amendment notification dated 23 August 2023. NMC rules and regulations index.
A clinic should verify whether the NMC or its State Medical Council has issued a later applicable direction before finalising its policy.
Clinical Establishment requirements depend on the clinic and jurisdiction
The Clinical Establishments Act framework includes single-doctor clinics, polyclinics, laboratories, and other healthcare facilities, but its application and implementation must be checked for the relevant state or union territory and establishment category.
The clinic's registration conditions may require particular OPD, procedure, referral, emergency, disease-surveillance, pharmacy, or diagnostic records. A general blog article cannot replace that local check.
The DPDP framework has a phased commencement
India notified the Digital Personal Data Protection Rules, 2025 in November 2025. The Act and Rules use phased commencement dates.
As of 22 August 2026, the main processing duties and data-principal rights in sections 3 to 17 of the DPDP Act are scheduled to commence eighteen months after the 13 November 2025 Gazette notification, which is 13 May 2027. The corresponding operational Rules 3 and 5 to 16 are also scheduled for the eighteen-month stage. DPDP Act commencement notification, G.S.R. 843(E) and Digital Personal Data Protection Rules, 2025.
Once applicable, the DPDP Act's framework includes correction and erasure rights, while preserving retention that remains necessary for the stated purpose or compliance with law. Digital Personal Data Protection Act, 2023.
The preparation window should be used to map data and build workable request, correction, security, and deletion processes. It should not be interpreted as permission to ignore existing medical confidentiality, record-maintenance, or security duties.
Build the retention schedule by record category
A useful schedule does not begin with "patient record: seven years." It separates the patient file into identifiable record classes.
For every class, record:
- The person responsible
- The event that starts the retention clock
- The minimum applicable period
- Reasons that can extend retention
- The approved archival format
- Who can authorise disposal
- What evidence of disposal must remain
Patient identity and registration data
This includes the clinic UHID, name, date of birth, contact details, address, guardian or family relationships, demographic corrections, and external identifiers.
Do not delete the identity anchor while keeping prescriptions, invoices, or reports that can no longer be matched safely to the correct patient.
Duplicate records need a merge or linkage process. They should not be treated as ordinary deletion candidates until the clinic has verified which record contains the authoritative clinical history.
For family registrations, preserve the distinction between the patient and the contact or guardian. See CliniKite's patient registration and family relationships guide.
Consultations, diagnoses, prescriptions, and clinical notes
Clinical records need their own retention decision because they explain what was observed, decided, prescribed, and communicated during care.
An issued prescription should remain connected to:
- The patient
- The encounter
- The prescribing doctor
- The issue date and time
- The medicine lines and instructions
- The authorised version
- Any later correction or replacement
A correction should not silently rewrite the historical prescription. The original and corrected versions should remain attributable. CliniKite's digital prescription software guide explains this version boundary in more detail.
Procedures, referrals, investigations, and attachments
A scanned referral, photograph, lab report, consent form, or procedure document should not be governed only by the retention setting for "file uploads."
The attachment carries clinical context. Its policy should identify:
- The patient and encounter
- The document type
- The source
- The date received or created
- The person who reviewed it
- Whether it is an original or a copy
- Whether another system retains the authoritative record
If a clinic sends an investigation to an external laboratory, it should document which organisation keeps the originating order, specimen status, final report, corrected report, and sharing history.
Pharmacy, billing, payment, and statutory records
A clinic with a pharmacy, diagnostic service, or taxable supply may have record duties that differ from its consultation records.
Invoices, payment entries, credit notes, stock movements, batch information, purchase records, and statutory registers should receive separately reviewed retention rules. A patient's request to remove an appointment reminder does not automatically authorise deletion of a required invoice or pharmacy register.
The clinical and financial copies may be connected, but their retention reasons should remain distinguishable.
Consent, communication, and access records
Consent is not one permanent field.
The clinic may need separate evidence for:
- Clinic registration
- A procedure
- Record sharing
- WhatsApp communication
- Optional AI or audio processing
- A caregiver or authorised representative
- Marketing communication
- Withdrawal or refusal
Keep enough information to demonstrate what was agreed, for which purpose, when, through which channel, and when the preference changed.
The clinic should not retain every message forever merely because a conversation occurred. It should decide which communication is part of the clinical record, which proves an operational action, and which is temporary delivery data.
Audit and security records
The MoHFW EHR Standards for India recommend audit trails for actions involving electronic health information, including viewing, creation, permitted changes, printing, and deletion-related events. The guidance calls for date, time, record, user, and action identification. MoHFW EHR Standards for India, 2016.
Audit logs should not become editable notes. Their usefulness comes from showing who performed an action and when.
The clinic should define a retention period for audit and security logs that supports investigation and accountability without keeping unrelated technical data indefinitely.
Retention is not the same as backup
A retention policy decides how long the authoritative record should remain.
A backup protects that record against corruption, hardware failure, accidental deletion, or another operational incident.
These are different controls.
If a clinic decides that a record must be retained for a particular period, one copy inside the live application is not enough. It needs a backup and restore process capable of recovering the record.
If a record reaches its approved disposal date, removing it from the live database while leaving unlimited recoverable copies in old backups does not complete the deletion process.
A practical policy should define:
- Backup frequency
- Backup retention
- Restore testing
- Encryption
- Access to backup media
- Treatment of deleted data in rolling backups
- What happens during vendor exit
- How legal or investigation holds are preserved
Use CliniKite's backup and recovery checklist to review the recovery side separately.
Electronic retention requires accessibility and integrity
The Information Technology Act recognises electronic retention where a record remains accessible for later reference, accurately represents what was generated or received, and preserves information that identifies its origin, destination, date, and time. Information Technology Act, 2000, Section 7.
This means "stored somewhere in the database" is not a sufficient archival strategy.
The clinic should be able to:
- Find the correct patient
- Open the retained document
- Identify the author or source
- Distinguish drafts from issued records
- Interpret the stored format
- Export a readable copy
- Confirm that the record was not silently altered
- Restore it after a system failure
An old proprietary database that nobody can open is not a useful archive.
Handle corrections without destroying history
Patient information can be wrong. A name may be misspelled, a phone number may change, two patient registrations may be duplicates, or a clinical document may need a formal correction.
Software should distinguish three actions:
Correct current administrative information
Demographic fields such as an address or contact number may be updated while preserving an attributable change history where appropriate.
Link or merge duplicate identities
A merge should preserve the source identifiers, show which record survived, prevent records from being attached to the wrong family member, and remain reversible or reviewable according to clinic policy.
Amend an issued clinical record
The system should add an amendment, correction, or replacement version. It should not make the original authorised record disappear without evidence.
This protects both the patient and the clinician by preserving what was known and issued at each point in time.
Create a patient-record request workflow
A record request should not depend on one employee remembering where PDFs are stored.
The clinic should document:
- How the request is received and acknowledged.
- How the patient or authorised representative is verified.
- How guardian authority is checked for a child.
- Who approves the scope of disclosure.
- Which records are included.
- Which third-party or legally restricted information requires review.
- How the export is produced.
- How it is transmitted securely.
- When the request was completed.
- What request evidence remains afterward.
The NMC's 2002 regulations specify a 72-hour period for issuing requested medical records under that professional rule. A clinic should configure an internal target that allows identity verification, review, export, and delivery within the applicable period rather than beginning the search on the final day.
Role-based access matters here. A receptionist may acknowledge a request without receiving unrestricted authority to export every clinical record. See the role-based access guide.
Treat deletion requests as record-specific reviews
"Delete my account" and "delete my medical history" are not necessarily the same request.
A safe process should classify the information before acting:
- Incorrect duplicate registration
- Obsolete contact detail
- Communication preference
- Temporary upload
- Issued clinical record
- Invoice or payment record
- Pharmacy or statutory register
- Audit event
- Backup copy
- Data under an active complaint, investigation, or legal hold
The clinic should then identify whether correction, restriction, archival, anonymisation, or deletion is the appropriate action.
Do not give vendors or individual staff a global "erase patient" button that destroys linked consultations, prescriptions, payments, and audit history without review.
A practical clinic-software demonstration checklist
Ask the software vendor to demonstrate these actions with synthetic records:
- Find a patient record from several years ago
- Export the complete record in readable formats
- Show the original and corrected version of a prescription
- Update a demographic detail without rewriting an issued document
- Merge two duplicate registrations safely
- Identify who viewed or exported a record
- Restrict access by staff responsibility
- Apply a hold that prevents scheduled disposal
- Delete a temporary attachment without deleting the consultation
- Show how deletion affects backups
- Restore an archived patient record
- Export data during vendor exit
- Document a patient access request
- Record a refusal or partial completion with a reason
- Separate communication opt-out from clinical-record retention
If the vendor cannot demonstrate corrections, exports, audit history, and recovery, a configurable retention field will not solve the underlying problem.
Where CliniKite fits today
CliniKite's current public pages describe longitudinal patient records, role-based access, attributable activity, backups, documented exports, and managed-cloud or on-premise deployment choices. See the CliniKite feature overview, security and data approach, and patient-data ownership checklist.
Those capabilities can support a clinic's retention process.
CliniKite's current public pages do not claim that the product automatically determines every legally applicable retention period, resolves deletion requests, or certifies a clinic's compliance. The clinic still needs an approved policy based on its services, jurisdiction, professional obligations, and qualified advice.
Before purchase, ask CliniKite or any other vendor to demonstrate the exact record lifecycle that applies to your clinic.
Conclusion
Medical record retention is not one number and it is not a storage setting.
A workable policy connects record type, retention reason, responsible person, access workflow, correction method, backup treatment, disposal approval, and audit evidence.
Start by inventorying the records the clinic creates. Separate clinical, identity, financial, pharmacy, consent, communication, and security records. Verify the requirements that apply to the clinic's state and services. Then test whether the software can retrieve, correct, export, protect, and dispose of each category without destroying clinical history.
The objective is not to keep everything forever or delete everything at the first possible date. It is to preserve the right information for the right reason and remain able to explain every important decision.
Questions clinics ask
Frequently asked questions
How long should a private clinic keep medical records in India?
There is no single reliable period for every clinic and every record category. The NMC's 2002 rule expressly mentions three years for indoor-patient records, while clinic, state, pharmacy, diagnostic, contractual, dispute, and other requirements may affect different records. Obtain qualified advice for the clinic's actual services.
Does the three-year NMC rule apply to every OPD record?
The wording of the cited NMC provision refers to indoor patients. It should not be presented as a universal permission to delete every OPD record after three years.
Must patient records be supplied within 72 hours?
The NMC's 2002 regulations state that requests from patients, authorised attendants, or involved legal authorities should be acknowledged and records supplied within 72 hours. The clinic should verify how this applies to the particular request and jurisdiction.
Can a patient ask a clinic to delete a medical record?
A patient may request correction or deletion, but the clinic must assess the specific record, applicable law, clinical purpose, and any required retention. Removing a communication preference is different from destroying an issued prescription or required financial record.
Can medical records be retained electronically?
The Information Technology Act provides a framework for satisfying certain retention requirements electronically when records remain accessible, accurate, and attributable. The clinic should still verify whether any particular rule requires another form.
Is a backup enough for medical record retention?
No. A backup supports recovery. A retained record must also be searchable, readable, attributable, exportable, and governed by access and disposal rules.
Evidence used
Sources and claim notes
- NMC Code of Medical Ethics Regulations, 2002
Supports the indoor-patient three-year provision, 72-hour record-request provision, medical-certificate register, and encouragement of computerisation.
- NMC rules and regulations index
Confirms that the 2023 Registered Medical Practitioner Professional Conduct Regulations are listed with an amendment keeping them in abeyance.
- Clinical Establishment standards for clinics and polyclinics
Supports statements about OPD, procedure, referral and emergency records, patient registration, and documented assessment in the relevant clinic category.
- MoHFW EHR Standards for India, 2016
Supports electronic health-record integrity, access controls, audit trails, user identification, and attributable record actions.
- Information Technology Act, 2000
Supports the conditions under which electronic records can satisfy applicable retention requirements.
- Digital Personal Data Protection Act, 2023
Supports the future framework for correction, erasure, security, processing purpose, and legally necessary retention.
- DPDP commencement notification, G.S.R. 843(E)
Supports the phased commencement dates and confirms that sections 3 to 17 are in the eighteen-month cohort.
- Digital Personal Data Protection Rules, 2025
Supports the corresponding phased commencement of the operational Rules.
- CliniKite features
Supports current product claims about longitudinal records, roles, prescriptions, exports, billing, pharmacy, and deployment.
- CliniKite security
Supports current statements about deployment choice, role-based access, attributable activity, data export, and external data paths.
A useful next step
Review CliniKite's security and data approach
Bring the real clinic workflow, current plan and people who run the day. We will show the connected path and its limits clearly.
This guide explains how to separate retention, access, correction, archival, backup, and deletion. It provides operational guidance for evaluating software. It does not prescribe a universal legal retention period.