Phase 9: Archive & Protect
Applies to: All staff responsible for closing engagement records, managing retained data, responding to patient rights requests, or overseeing secure disposal of patient engagement materials
Sequence note: Phases 0-4 sequential; phase 10 anytime; not all phases apply
What you'll learn
- Apply the correct retention period for each document type - consent forms, executed contracts, financial records, recordings, screening notes, and audit logs - as set out in the data retention schedule
- Execute secure disposal through cryptographic erasure or certified destruction, documenting every deletion event and obtaining vendor disposal confirmation where applicable
- Close engagement records completely, fulfill patient rights requests within the 30-day target, and feed post-engagement findings into the continuous improvement cycle
Lesson
Step 1 - Review the Data Retention Schedule
Before closing an engagement, confirm the required retention period for every document type created during the program. The schedule specifies: consent forms must be retained for the program duration plus 6 years; executed contracts for 6 years post-termination; financial records (W-9s and payments) for 7 years; recordings for selected participants for 6 years from program completion; screening notes for non-selected participants must be destroyed within 90 days; and audit logs and incident records for a minimum of 6 years.
Source: slide 32 - FINAL - Assembled Intelligence - Data Retention Schedule V3
Retention Periods Are Mandatory Minimums - Do Not Delete Early
Retention periods are regulatory floors, not targets. Destroying records before the required period expires - whether by oversight or to save storage space - is a compliance violation. Screening notes for non-selected participants are the sole exception: those must be destroyed within 90 days, not retained longer than that period.
Source: slide 32 - PHI Handling and HIPAA Safeguards_Final_8-2026
Step 2 - Execute Secure Deletion
When a retention period expires, data must be destroyed using cryptographic erasure or certified physical destruction. You must document every deletion event recording what was deleted, when, the method used, and who performed the deletion. Where a vendor is responsible for disposal, you must obtain written disposal confirmation from them before the file can be considered closed.
Source: slide 32 - FINAL - Assembled Intelligence - Data Retention and Disposal Policy
Secure Disposal Only - No Unverified or Informal Deletion
Deleting files from a shared drive, emptying a recycle bin, or asking a vendor verbally to dispose of data does not satisfy the secure disposal requirement. Only cryptographic erasure or certified destruction qualifies. If a vendor performs disposal, a written confirmation must be obtained and filed. Do not mark a disposal task complete until that confirmation is in hand.
Source: slide 32 - FINAL - Assembled Intelligence - Data Retention and Disposal Policy
Step 3 - Close the Engagement Record
Mark the engagement as complete with a closure date. Perform a final reconciliation of all files against the engagement checklist to confirm nothing is missing, mis-filed, or pending action before the record is considered closed.
Source: slide 33 - Operational Governance Addendum_Final_8-2026
Step 4 - Communicate Patient Rights
Patients retain rights over their stored data after engagement close. They may request copies of stored documents, corrections to inaccurate documents, or deletion of their data (subject to regulatory retention requirements that may override deletion requests). All such requests must be fulfilled within 30 days.
Source: slide 33 - FINAL - Assembled Intelligence - Data Subject Rights and SAR Procedure
Patient Rights Requests - 30-Day Fulfillment Target Is Non-Negotiable
When a patient submits a request for copies, corrections, or deletion of their data, the 30-day fulfillment target is a compliance deadline, not a service level aspiration. A deletion request does not override mandatory regulatory retention periods - if a record must be kept by law, document why the deletion cannot be fully honored and communicate that reason to the patient within the same 30-day window.
Source: slide 33 - FINAL - Assembled Intelligence - Data Subject Access Request (DSAR) Policy
Step 5 - Conduct Post-Engagement Debrief
After closing the record, conduct a structured debrief to review what worked, what did not, and any compliance close-calls encountered during the engagement. Feed findings into the continuous improvement cycle: Capture, Assess, Implement, Communicate.
Source: slide 33 - Operational Governance Addendum_Final_8-2026
Scenario
You are closing out a patient engagement. The program ended 95 days ago. While reconciling files, you find: (1) screening notes for three patients who were not selected for the program; (2) a message from the cloud storage vendor saying they have cleared the associated storage bucket but you have not yet received written confirmation; (3) an email from one of the selected patients asking for a copy of their stored consent form - the request arrived 28 days ago and has not yet been fulfilled.
The screening notes for non-selected participants have been in storage for 95 days. The retention schedule requires destruction within 90 days for this document type. What is the correct action?
Incorrect. Screening notes for non-selected participants have a 90-day destruction requirement, not a 6-year retention period. Retaining them beyond 90 days is a compliance violation.
Correct. The 90-day destruction requirement has passed. The correct action is immediate secure disposal via cryptographic erasure or certified destruction, with the deletion event fully documented including what was deleted, when, the method, and who performed it.
Incorrect. Deferring to a future review cycle extends a compliance violation that is already active. Secure disposal must happen now, not at the next scheduled review.
Incorrect. Deleting files from a shared drive does not satisfy the secure disposal requirement. Only cryptographic erasure or certified physical destruction qualifies.
The vendor says they cleared the storage bucket verbally, but you have not received written disposal confirmation. Can you mark the vendor disposal task as complete?
Incorrect. Verbal confirmation does not satisfy the disposal documentation requirement. Written confirmation from the vendor is required.
Incorrect. Obtaining written confirmation is your organization's responsibility and cannot be discharged by informal vendor communication. The obligation does not transfer until proper documentation is in hand.
Correct. Vendors must provide written disposal confirmation. You may not mark the disposal complete until that written confirmation is received and filed.
Incorrect. Vendor-performed disposal is permitted, but it requires written confirmation. Self-destruction is not required if a vendor handled it - the written confirmation is what is required.
The patient's request for a copy of their consent form arrived 28 days ago and has not been fulfilled. What must you do?
Correct. The 30-day fulfillment target is a compliance deadline. With 2 days remaining, you must fulfill the request immediately to avoid a violation.
Incorrect. The 30-day fulfillment target is a compliance deadline, not a flexible service aspiration. Missing it is a compliance violation.
Incorrect. Standard patient rights requests such as a copy request do not require legal escalation before fulfillment. Initiating escalation would likely cause the deadline to be missed.
Incorrect. Deferring to a quarterly cycle would miss the 30-day deadline. The request must be fulfilled within the compliance window.
Knowledge Check
Select an answer to see feedback. This is practice - it does not affect your score.
Screening notes for patients who were not selected for the program must be destroyed within how many days?
Incorrect. 30 days is the patient rights fulfillment target, not the screening notes destruction requirement.
Incorrect. 6 years from program completion is the retention period for recordings of selected participants, not for screening notes of non-selected participants.
Correct. Screening notes for non-selected participants must be destroyed within 90 days, per the PHI Handling SOP (Section 14).
Incorrect. 7 years is the retention period for financial records such as W-9s and payments.
Which two methods are acceptable for secure deletion of retained data?
Correct. Cryptographic erasure is an approved secure deletion method.
Correct. Certified physical destruction is an approved secure deletion method.
Incorrect. Deleting files from a shared drive does not meet the secure disposal standard.
Incorrect. Emptying a recycle bin does not constitute cryptographic erasure or certified destruction and does not satisfy the secure disposal requirement.
A patient submits a request for copies of their stored documents. What is the fulfillment target?
Incorrect. 7 business days is not the stated fulfillment target for patient rights requests.
Correct. Patient rights requests - including requests for copies, corrections, or deletion - must be fulfilled within 30 days of the request.
Incorrect. The fulfillment target is 30 days, not 60.
Incorrect. Patient rights requests must be fulfilled within 30 days, not deferred to a scheduled review.
Key Controls Recap
- [RULE] Retention Periods Are Mandatory Minimums - Do Not Delete Early
- [WATCH OUT] Secure Disposal Only - No Unverified or Informal Deletion
- [WATCH OUT] Patient Rights Requests - 30-Day Fulfillment Target Is Non-Negotiable
You've completed the Phase 9 learning module.
Return to Dayforce and take the Phase 9 quiz.