Records management policy
Document control
- Policy owner: Steve Creighton, Head of Information Governance and Data Protection Officer
- Corporate lead: Executive director of finance and resources
- Document version: V4
- Date approved by Clinical and Corporate Policies Group (CCPG): 1 April 2024
- Date ratified by Trust Leadership team: 17 April 2024
- Date issued: June 2024
- Next review date: April 2027
- Policy number: PL325
Executive summary
This policy ensures that Leeds Community Healthcare NHS Trust will meet records management standards and regulatory requirements, for patient, staff and corporate data. The policy is supplemented by guidance which directs staff to their individual responsibilities.
Compliance with this policy also ensures that the trust is compliant with the current Data Protection Legislation, Freedom of Information Act 2000 and the Access to Health Records Act 1990.
Equality analysis
Leeds Community Healthcare NHS Trust’s vision is to provide the best possible care to every community. In support of the vision, with due regard to the Equality Act 2010 General Duty aims, Equality Analysis has been undertaken on this policy and any outcomes have been considered in the development of this policy.
Table of content
- Introduction
- Aims and objectives
- Definitions
- Responsibilities
- Statutory and regulatory requirements of records management
- Records and information lifecycle management and principles relating to good records management
- Records management best practice and professional obligations
- Record retention schedules
- Record access arrangements
- Responsibility for inactive records
- Risk assessments
- Training needs
- Approval and ratification process
- Dissemination and implementation
- Associated documents
- References
- Appendices
1. Introduction
This policy provides the basis for managing records and information at Leeds Community Healthcare (LCH) NHS Trust. This includes paper, electronic, health, staff and administrative records. It is supported by guidance which ensures LCH remains compliant with the NHS regulatory and statutory frameworks.
2. Aims and objectives
LCH is committed to effective records management in line with the Records Management Code of Practice 2021, both clinical and non-clinical information, including health and staff data.
The CoP and records management contributes to patient care and business processes by effectively managing the information created by LCH. Robust records management delivers benefits for LCH, which include better use of staff time and more efficient use of physical space and information stored electronically.
This policy contains actions necessary to comply with national standards for record keeping; these include from the Care Quality Commission, National Health Service Resolutions and Data Security and Protection Toolkit.
3. Definitions
Records management describes the process which records are managed through their lifecycle from creation and storage to final destruction or permanent place of deposit (refer to appendix A). Throughout the lifecycle all records will be kept under secure conditions and access will only be to those with a legitimate right of access. Refer to appendix B for Retention Periods for Records.
A record The International Standard for Records Management ISO 15489-1:2016 defines a record as “Information created, received, and maintained as evidence by an organization or person in the transaction of business, or in the pursuance of legal obligations, “regardless of media”.’
This policy aligns with the requirements of ISO 15489 wherever appropriate
4. Responsibilities
All staff employed by LCH must work in concordance with the Leeds Safeguarding Multi-agency policies and procedures and local guidelines in relation to any safeguarding concerns they have for service users and the public with who they are in contact.
The following roles are responsible for delivering and achieving records management standards;
The trust board is ultimately responsible for ensuring that records management function is addressed.
Chief executive has overall accountability for records management within the trust as the accountable officer, the role provides assurance, through a Statement of Internal Controls, that all risks to the organisation, including those relating to the management of records are effective and mitigated.
Director of finance and resources has the lead responsibility for the records management policy and for ensuring that this is implemented and becomes an active document.
Information Governance Group will approve guidance and procedures related to records management recommended by the head of information governance and data protection officer. This is the sub-group with delegated duties to deal with information governance and overall records management issues and reports to the Audit Committee.
Caldicott Guardian is the medical director; this is an advisory role and has responsibility for protecting the confidentiality of patient information and ensuring it is shared appropriately and securely. The Caldicott Guardian is supported by the trust’s Data Protection and Information Governance team who provides service level support and assurance on delegated Caldicott tasks.
Head of information governance and data protection officer has responsibility for the operational development and maintenance of the records management policy. Additional responsibilities include ensuring this policy complies with legal and regulatory edicts, providing learning and development with key learning points and monitoring compliance to assess overall effectiveness. The head of information governance and data protection officer will give advice and guidance to inform staff of their obligations relating to records management.
Heads of service are responsible for records and information created by their staff. Heads of service are also responsible as information asset owners (IAO). An IAO is obliged to enforce policies and procedures locally relating to information management and give assurances to the SIRO that they are being met. This includes an annual audit of information assets, removable media and data flow mapping.
All staff are responsible for ensuring they comply with this policy and local guidance where this exists. Staff are also directed by their professional codes of practice which may also include guidance on record keeping (please see section 6). Staff must report all incidents involving records via the Datix incident reporting system, this includes the loss of or missing records.
5. Statutory and regulatory requirements of records management
- LCH is subject to several statutory and legislative requirements. The head of information governance and data protection officer can issue guidance and procedural notes to meet these requirements. Any procedures and guidance are approved by the Information Governance Group.
- LCH, as an NHS body created by statute, is subject to the Freedom of Information Act 2000 (FOI) and the Public Records Act 1958. The Code of Practice issued under Section 46 of the Freedom of Information Act 2000 directs public bodies how to conduct records management for the purposes of information availability. The Public Records Act is regulated by the Information by the Ministry of Justice.
- The UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA) (“Data Protection Legislation”) requires LCH to ensure that personal data is managed within statutory and legislative boundaries. These include keeping personal data for only as long as it is necessary and enforcing appropriate technical measures to keep relevant records secure. The Freedom of Information Act 2000 (FOIA)The GDPR or DPA are regulated by the information commissioner.
- The Department of Health and Social Care requires NHS records for staff and patients to be managed according to the Records Management Code of Practice 2021.
- All patient records and staff records are regarded as confidential and must be marked confidential and their access limited to those with a legitimate right of access. Sensitive business records and those subject to further controls before release must be marked as restricted. Records not marked might be assumed to be unclassified and open to access. LCH patient records must be managed according to regulatory standards for records to ensure quality and appropriate secure storage and access. Refer to section 6.
- ISO 15489-1:2016 defines the concepts and principles from which approaches to the creation, capture and management of records are developed.
6. Records and information lifecycle management and principles relating to good records management
Records and information management play an integral role within LCH as it underpins effective information usage within our organisation and externally to patients and suppliers. The law requires certain records to be kept for a defined retention period. The diagram below describes more about each of the 5 steps in the records lifecycle.

Stage 1: Creation and receipt
This part of the life cycle is when we put pen to paper, make an entry into a database or start a new electronic document. It can be created internally or received from an external source.
Stage 2: Distribution
Distribution is making the information available internally or externally once it is created or received.
Stage 3: Use
This occurs when records are used on a day-to-day basis for patient care, to support staff management, to help generate organisational decisions, document further action or support other LCH operations.
Stage 4: Maintenance
Maintenance occurs when records are not used on a day-to-day basis and are stored in a records management system. Even though they are not used on a day-to-day basis, they will be kept for legal or financial reasons until they have met their retention period. This phase includes filing, transfers and retrievals. The information may be retrieved during this period to be used as a resource for reference or to aid in a business decision.
Stage 5: Disposition
Disposition occurs when a record is less frequently accessed, has no more value to LCH or has met its assigned retention period (and may become a risk if held). It is then reviewed and if necessary, destroyed using appropriate confidential destruction techniques. Not all records will be destroyed once the retention period has been met. Any records that have historical value to LCH will be retained for 20 years and sent to an official Place of Deposit, where they will be kept for the future of the organisation and may never be destroyed. This is the final phase of a records lifecycle. Contact the Data Protection and Information Governance department for advice if unsure if the records held have historical value.
Of note- some records may also be held beyond their retention period if there is a legal hold placed upon them, for instance if they fall under the scope of an enquiry.
7. Records management best practice and professional obligations
At all stages throughout the records management lifecycle it is of paramount importance to ensure that “best practice” is adhered to.
Staff who are registered to a professional body, such as the General Medical Council (GMC), Nursing and Midwifery Council (NMC) or Social Work England will be required to adhere to record keeping standards defined by their registrant body. This is designed to guard against professional misconduct and to provide high quality care in line with the requirements of professional bodies.
The Academy of Medical Royal Colleges (AoMRC) generic medical record keeping standards were prepared for use in the NHS, primarily in acute settings but the standards are useful for all health and care settings. The AoMRC notes that a medical record, whether paper or digital, must adhere to certain record keeping standards. The Royal College of Nursing has produced guidance on abbreviations and other short forms in patient or client records.
Further information about professional standards for records can be obtained from your relevant professional body. The main standard setting bodies in health and social care in England are:
- Academy of Medical Royal Colleges
- British Medical Association
- General Medical Council
- Health and Care Professions Council
- Royal College of Midwives
- Royal College of General Practitioners
- Royal College of Nursing
- Royal College of Obstetricians and Gynaecologists
- Royal College of Pathologists
- College of General Dentistry
- Pharmaceutical Services Negotiating Committee
- Royal College of Physicians
- Social Work England
There are also organisations that provide advice specifically to records managers and archivists. These are:
- The Federation for Informatics Professionals
- The National Archives
- The Archives and Records Association
- The Institute of Health Records and Information Management
- Information and Records Management Society
8. Record retention schedules
Keeping unnecessary records wastes staff time, uses up valuable space and incurs unnecessary costs. It also imposes a risk liability when it comes to servicing requests for information made under Data Protection Legislation or the Freedom of Information Act 2000. Moreover, compliance with these acts means that, for example, personal data must not be kept longer than is necessary for the purposes, for which it was collected (GDPR Article 5 (e)).
Records should only be destroyed in accordance with the LCH’s Records Retention and Disposal Schedule, appendix B. It can be a personal criminal offence to destroy requested information under either the Data Protection Act 2018 (Chapter 6: Enforcement, sections 170 to 173) or the Freedom of Information Act 2000 (Part 8 Section 77). Therefore, clear and appropriate destruction must take place in accordance with proper retention procedures.
The ICO Code of Practice on Records Management, issued under Section 46 of the Freedom of Information Act 2000, requires that records disposal ‘is undertaken in accordance with clearly established policies that have been formally adopted’.
The NHS Records Code of Practice provides extensive advice on retention schedules for many different types of records including health records, staff records and corporate records, and is used to inform the LCH Business and Corporate Records Retention Schedule.
The Business and Corporate Records Retention Schedule is a key component of LCH’s information compliance and allows it to standardise its approach to retention and disposal.
The recommended retention periods shown on the Business and Corporate Records Retention Schedule apply to the official or master copy of the records. Any duplicates or local copies made for working purposes should be kept for the shortest period of time as possible. Duplication should be avoided unless absolutely necessary. It should be clear who is responsible for retaining the master version of a record this is maintained as part of the Information Asset Register and copies should be clearly marked as such to avoid confusion.
Some types of records which may be created and kept locally are the responsibility of the local department, but may be found under a different function on the retention schedule: for example where recruitment is carried out by departments, the department shall be responsible for ensuring the disposal of the records relating to unsuccessful candidate, this type of record is listed under Human Resources in the retention schedule.
The difficulty of removal or deletion of records from the trust’s Electronic Patient Records systems (EPRs) is recognised, these EPRs are not designed to appropriately manage retention schedules and allow the removal of records.
It is to be noted that the published record retention schedules for records should be regarded as minimum retention periods, and this must be balanced with the caveats above regarding storage limitation.
9. Record access arrangements
There are a range of statutory provisions that give individuals the right of access to information created or held by LCH such as a Data Subject Access request which allows individuals to find out what personal data is held about them, or a request made under the Freedom of Information Act 2000 which gives the public the right of access to information held by public authorities.
Any access granted to records should always follow the appropriate procedure.
9.1 Record disclosure
There are a range of statutory provisions that limit, prohibit or set conditions in respect of the disclosure of records to third parties, and similarly a range of provisions that require or permit disclosure.
Only certain staff members have the authority, which is dictated by their role, to disclose records. Staff members with this authority should make a record of any copies of records they have disclosed, and to whom.
9.2 Record closure
Records should be closed, for example, made inactive and transferred to secondary storage as soon as they have ceased to be in active use other than for reference purposes, in the case of paper corporate records.
If a record is deleted or destroyed once its retention period has been reached, then a Records Disposal Certificate must be completed and saved in order to prove that the record existed, met its retention and was then disposed of.
9.3 Record appraisal
Appraisal refers to the process of determining whether records are worthy of permanent archival preservation, as certain records created by LCH may be of historical interest to The National Archives. For further advice contact the Data Protection and Information Governance department.
The purpose of the appraisal process is to ensure the records are examined at the appropriate time to determine whether or not they are worthy of archival preservation, whether they need to be retained for a longer period as they are still in use, or whether they should be destroyed.
It is the responsibility of the staff member who is leaving their current post or the organisation, and their line manager, to identify as part of the exit procedure specific records that should be retained in line with LCH’s Business and Corporate Record Retention Schedule.
9.4 Record transfer
Records selected for archival preservation and no longer in regular use by LCH should be transferred to an archival institution, for example a ‘Place of Deposit’. This must be approved by The National Archives and have adequate storage and public access facilities.
Following implementation of the Constitutional Reform and Governance Act 2010, in particular Part 6: Public Records and Freedom of Information, non-active records are required to be transferred no later than 20 years from the creation date of the record, as required by the Public Records Act 1958.
The head of information governance and data protection officer will identify LCH’s Place of Deposit and assist in the transfer of those records identified.
9.5 Record disposition
Disposal is the implementation of appraisal and review decisions, and the term should not be confused with destruction. A review decision may result in the destruction of records but may also result in the transfer of custody of records, or movement of records from one system to another.
Records should not be kept longer than is necessary and should be disposed of at the right time. Unnecessary retention of records consumes time, space and equipment use, therefore disposal will aid efficiency.
Unnecessary retention may also incur liabilities in respect of the Freedom of Information Act 2000 and Data Protection Legislation. If LCH continues to hold information which we do not have a need to keep, we would be liable to disclose it upon request. Data Protection Legislation also advises that we should not retain personal data longer than is necessary.
9.6 Records security: Work base, home working agile working
All person identifiable data or commercially sensitive data must be saved with appropriate security measures.
Staff must not use home email accounts or private computers to hold or store any sensitive records or information which relates to the business activities of LCH.
Removable Media should be LCH owned and encrypted by IT. Ideally, personal confidential data should not be stored on any removable media, however if there is no other option ensure this data is stored on a corporate encrypted device and deleted once transferred to identified secure area folder.
When printing paper records, especially sensitive documents, ensure appropriate measures have been taken in collecting all documents immediately after printing.
LCH has an information handling procedure (IG-007) in order to ensure that staff are aware how to receive personal information in a secure manner at a protected point.
In non-clinical areas, each department should have at least one designated safe haven contact point. Ideally, all information transmitted to the organisation should pass to these contact points. Clinical environments should operate in accordance with safe haven principles and the organisation should operate safe haven procedures for all flows of person identifiable information.
When routinely transferring personal or special category data, ensure security measures and precautions have been actioned by the sender and receiver. A robust contract or Information Sharing Agreement should be in place detailing responsibilities if the information is being transferred to a third party. Please contact the Data Protection and Information Governance department for more advice.
10. Responsibility for inactive records
Records that are no longer used must also be managed until they are not needed for patient care, business need or statutory retention.
Records that are no longer required will be destroyed appropriately aligned to the Records Management Code of Practice 2021. Confidential destruction of records includes using the designated shredding bins for on-site shredding. For digital media the Computer Helpdesk will take ownership of the media and arrange for it to be crushed by a service accredited to the appropriate destruction standards. Inactive records will be held securely, stored and managed to restrict access to only those who have a legitimate right to see them. This will ensure that an integral, authentic, reliable and usable record is maintained.
Where local conditions cannot be maintained to appropriate standards, the records must be moved to a place where they meet standards, refer to Corporate and Retention Schedules appendix B for further guidance.
11. Risk assessments
This policy requires any non-compliance to be risk assessed and incidents to be reported where they occur. Where the guidance issued by the head of information governance and data protection officer cannot be implemented, the service or department must escalate this risk of non-compliance and is entered onto the service or departments risk register.
Non-compliance with this policy must be reported as an incident via the Datix® reporting system. The learning must be communicated to staff through the most appropriate communication channels. These include staff meetings, staff briefings or intranet notice. Additional training may also be identified.
12. Training needs
For staff training refer to the statutory and mandatory training policy (including training needs analysis). Course details are available on the intranet.
The head of information governance and data protection officer delivers bespoke training to individual services to meet their needs as and when requested. Training will cover the organisation’s policies, guidance and specific areas directed by NHS Resolution and the Care Quality Commission in respect of records management if required.
13. Approval and ratification process
The policy has been approved by the Clinical and Corporate Policies Group and ratified by Trust Leadership team (TLT) behalf of the board.
14. Dissemination and implementation
Dissemination of this policy will be via the Clinical and Corporate Policy Group to services and made available to staff via the intranet.
Implementation will require:
- directors, heads of service and general managers to ensure staff have access to this policy and understand their responsibilities for implementing it into practice
- the head of information governance and data protection officer will provide appropriate support and advice to staff on the implementation of this policy.
15. Review arrangements
This policy will be reviewed in three years following ratification by the author or sooner if there is a local or national requirement.
16. Associated documents
The following policies are associated with effective records management:
- PL316 Confidentiality Code of Conduct
- PL301 Information governance policy and framework
- PL378 Data protection policy
- PL370 Internet policy
- PL350 Network security policy
- IG-007 Information handling procedure
- PL341 Waste management policy
17. References
- Care Quality Commission
- Care Quality Commission: Essential Standards of Quality and Safety 2009
- Records Management Code of Practice 2021
- Freedom of Information Act: Section 46 Code of Practice
Statute and legislation
- Data Protection Act 2018
- Freedom of Information Act 2000
- Freedom of Information Act 2000
- Human Rights Act 1998
- Access to Health Records Act 1990
- Public Records Act 1958
- Regulation (EU) 2016/679 of the European Parliament and of the Council (“UK GDPR”)
- The Health and Social Care Act 2012
Other resources
- Data Security and Protection toolkit
- NHS Resolutions
- NHS England Accessible Information Standard
- ISO 15489-1:206 Information and documentation Records management Part 1: Concepts and principles
Specific codes of practice for professional and registered bodies
- Academy of Medical Royal Colleges
- British Medical Association
- General Medical Council
- Health and Care Professions Council
- Royal College of Midwives
- Royal College of General Practitioners
- Royal College of Nursing
- Royal College of Obstetricians and Gynaecologists
- Royal College of Pathologists
- College of General Dentistry
- Pharmaceutical Services Negotiating Committee
- Royal College of Physicians
- Social Work England
- The Federation for Informatics Professionals
- The National Archives
- The Archives and Records Association
- The Institute of Health Records and Information Management
- Information and Records Management Society
18. Appendices
18.1 Appendix A Patient records management
Managing patient held health records
Prior to creating a new patient health record the relevant patient registration system must be checked to ensure the patient does not already have health records. This will ensure a complete record of the patient’s record of care is available, and also serve to minimise risk and duplication.
When a new health record is created, an entry must be made into the relevant registration system so all staff are aware of this. They must be securely contained in a folder, with the outside marked confidential with the patient’s name and NHS
number.
The creation and format of paper clinical records must include the following elements:
Bound and stored so that loss of documents is minimised, additional information securely fastened to the clinical records:
- Health practitioners use the approved LCH documentation when completing clinical records.
- A designated section on the front of the records for recording alert notices such as hypersensitive reactions, special conditions for retention of records (for example, because patient is taking part in a clinical trial).
- Clear structure and be divided into sections, for example, medication section.
- Instructions for filing printed on the inside of the Health Record or on any dividers being used where these have been agreed.
- Flaps or pockets only used for the storage of patient labels not for filing.
- A medication list detailing all prescribed items completed for relevant patients.
All records must be completed contemporaneously in line with professional and organisational standards. This may be achieved in a variety of ways according to the nature of the record held by the service, for example, entering information into electronic system at the time of the intervention or immediately on return to base or completing patient held records at time of intervention. If the record is not available, interventions undertaken must be recorded via means agreed within service and added to the record as soon as this becomes available. All entries should be timed, dated and signed.
Tracking records
Paper records are either: in the base or department, patient’s home, with a staff member, or in archive.
Each service must have a registration system as a means of identifying where the record is at any given time (this may be paper based or electronic). Examples of processes which may be used are:
- A tracking book which includes information (date, time and name of staff) when the record is removed and returned from the base.
- Assigning the records by caseload to a staff member who takes full responsibility until the patient is discharged.
- Using electronic systems to identify which staff member has the paper record through the last entry.
For more detail on tracking and the information that must be recorded refer to the IG-007 information handling procedure.
Process for retrieving records
Records will either be in the base, with another team or staff member or in commissioned storage. In the first instance, the electronic record can be used to
determine where a record is located. If the record is with another team they are requested to provide the record. Where local records indicate the patient file is in storage they can be retrieved through contacting the records centre.
18.2 Appendix B Clinical and non-clinical retention schedule
As records retention schedules may be subject to change, or specific types of records subject to legal holds due to enquiries etc , it is recommended that the current version of the NHS Records Codes of practice is consulted prior making decisions regarding the retention of records whether they are health records, staff records or corporate records.