How long you must keep a patient record in Australia
There is no single national retention period for health records in Australia. There is a federal privacy regime that says you must not keep personal information longer than you need it, and state legislation that sets minimum periods for health records — and in two states those periods are explicit.
The practical answer for a dental practice is two clocks, and you keep the record until the later of them expires.
The two clocks
Seven years from the last service. This is the standard set by NSW's Health Records and Information Privacy Act 2002 and by Victoria's Health Records Act 2001. In states without their own private-sector health records statute, it is the accepted professional standard and the figure your indemnity insurer will expect.
Until the patient turns 25, where they were under 18 at the time of the service. Both Acts state this separately, and it is the clock most often missed — because it is the one that cannot be computed from the treatment date alone.
Whichever expires later is the one that governs.
Why the second clock catches people out
Consider a child treated at five years old.
A flat seven-year rule expires when they are twelve. The correct period runs until they are twenty-five. That is a thirteen-year gap, and a system configured with a single retention period will quietly destroy the record in the middle of it.
The destruction is automated, silent, and irreversible. Nobody discovers it until the record is asked for — which, in the situation where a paediatric record matters, is usually the worst possible moment.
This is the single most common retention configuration error we have seen, and it is entirely a consequence of software that models retention as one number.
Keeping records too long is also a failure
It is tempting to conclude that the safe answer is to keep everything forever. It is not.
Australian Privacy Principle 11.2 requires an entity to destroy or de-identify personal information once it is no longer needed for a permitted purpose. Indefinite retention is a failure to comply, not a cautious reading of the rules.
There is a practical argument too. Every record you hold is a record you can lose. A practice sitting on twenty-five years of history it had no obligation to keep has enlarged the consequences of a breach for no benefit — and under the Notifiable Data Breaches scheme, the size of that breach is the thing you will be explaining.
What "the record" includes
Broader than most practices assume. It is not only the clinical notes:
- Clinical notes and their amendment history
- Radiographs and clinical photography
- Medical history and consent forms
- Treatment plans presented, accepted and declined
- Correspondence with the patient and with specialists
- Referrals in and out
If it informed a clinical decision, or evidences one, it is part of the record.
What to actually do
Write down the periods you are applying, and the reason. If you cannot say which rule sets your retention period, you cannot defend the decision when it is questioned.
Check whether your system can express "the later of two dates". Many cannot. If yours only supports a single number of years from a treatment date, your paediatric records are on the wrong clock right now.
Do not run an automated destruction sweep you have not had reviewed. Deletion is the one operation with no undo. Run it in report-only mode first, read what it proposes to destroy, and have the periods confirmed by somebody qualified before it ever runs for real.
Check the state you practise in. NSW and Victoria legislate explicitly. The others rely on the federal regime plus professional standards, and the answer is usually the same — but "usually" is doing work in that sentence, and your practice is the one that wears it.
This is general information about record-keeping obligations, not legal advice. Retention periods are set by legislation that varies between states and changes over time. Before configuring automated destruction of patient records, get the periods confirmed by a lawyer who practises in health privacy.