aestheticlinic

Help centre

Erasing a patient's data, and what is kept

When a patient asks you to delete their data, the app does it in one action and tells you exactly what happened. It is owner-only, and it is not the tool for tidying your list: archiving is for that.

How to do it

  1. Open the patient, go to the Details tab and scroll to Danger zone.
  2. Press Erase patient data.
  3. Type the patient's name to confirm, then press Erase permanently.

This cannot be undone.

The app decides which of two things happens

You do not choose, and neither do we. The outcome comes from the record itself:

  • No signed-off clinical record. The patient is deleted outright, and everything hanging off them goes with them.
  • Any signed-off clinical record. The patient is anonymised instead. Every identifying detail is cleared, their photos and documents are deleted, and the signed clinical record itself is kept, with nothing in it that says who it belonged to.

That second case is not us being awkward. UK clinical records carry retention obligations that outlast a patient's preference, and anonymising the record is the correct answer to both duties at once. Your DPA says the same thing.

What is removed

  • Their contact and demographic details, appointments, messages, forms and payments.
  • Their photos and documents, the files themselves and not just the rows.
  • Their entries in your audit trail, including the ones written about their appointments, photos and payments rather than only about the patient record. Deleting audit entries is the one documented exception to an otherwise append-only trail, because the right to erasure outranks our own logging.
  • Their marketing record with Mailchimp, if you have that connected, which is dealt with first because the email address is the only thing Mailchimp knows them by.
  • Their patient portal login, if the account is not shared. If the same login is also a staff account or another patient record, it is unlinked and left alone rather than deleted, because deleting it would take a colleague's account with it.

What is kept, and why

  • A signed-off clinical record, stripped of identifiers, in the anonymise case above.
  • The photograph a locked treatment map was drawn on. The doses on a map are stored as positions on that image and a signed record can never be re-mapped, so removing the photograph would leave the record claiming injections over a picture that is not there, permanently. It is a deliberate decision, it is reported to you by name, and if a patient specifically asks about it, tell us and we will deal with it case by case.
  • Some security and sign-in records held outside the application. These are stated as retained rather than quietly kept.

Read the confirmation, and keep it

The result is not a description of the feature, it is a report of what actually happened on that patient: how many photo files went, how many document files, any treatment-map photo retained and against which record, how many audit entries were scrubbed, and what became of the portal login. If a file could not be removed it says so rather than pretending otherwise.

That report is what to quote if you are writing back to the patient. Quote it rather than describing the process from memory.

Closing your own clinic account

That is a different thing and lives at Settings > Data & export > Close your account, with an optional erasure request. Take an export of everything first: see One-click full export.

Back to help centre