Data retention is the boring-but-critical side of compliance. FrontDesk ships sensible defaults that meet HIPAA, GDPR, and CCPA out of the box, and gives you levers to tighten or relax them based on your jurisdiction and policies.
Default retention periods
| Data type | Healthcare org | Non-healthcare |
|---|---|---|
| Call recordings (audio) | 7 years | 1 year |
| Call transcripts | 7 years | 1 year |
| Patient records | Indefinite | Indefinite |
| Appointments | Indefinite | Indefinite |
| SMS messages | 7 years | 1 year |
| Audit log | 6 years | 1 year |
| Voicemail audio | 1 year | 90 days |
Healthcare defaults are set to match HIPAA's 6-year minimum for records of disclosures plus a 1-year buffer. Non-healthcare defaults match common state-law minimums.
Change retention periods
- Open Settings → Compliance → Data Retention.
- For each category, choose from the dropdown (30 days, 90 days, 1 year, 3 years, 7 years, indefinite).
- Click Save.
For healthcare orgs the dropdown won't let you go below HIPAA minimums (6 years for audit). For all orgs, lengthening retention takes effect immediately; shortening retention triggers a background cleanup over the next 24 hours.
Per-patient deletion (right to be forgotten)
When a patient invokes their GDPR, CCPA, or HIPAA right to deletion:
- Open Patients → search the patient → click their row.
- Click the ⋯ menu → Delete Patient Data.
- Confirm by typing the patient's name.
What happens:
| Data | After deletion |
|---|---|
| Name, phone, email | Replaced with hashed values (e.g., Patient-a3f8b1) |
| Call recordings | Audio files deleted from S3 |
| Transcripts | Personally identifying content scrubbed |
| Appointments | Kept (anonymized) for your business records |
| Audit log entry | Records that the deletion happened, who requested it, and when |
The operation is irreversible. We retain the audit-log entry for the deletion itself even after the data is gone — required for your compliance records.
Automated cleanup
A background job runs daily and deletes data that has exceeded its retention period. You'll see line items in your audit log:
[2026-01-15 02:00] System auto-deleted 247 call recordings older than 7 years (retention policy)
[2026-01-15 02:01] System auto-deleted 1,892 SMS messages older than 7 years
Export all your data
Want an offline copy of your data — before shortening retention, or if you're leaving the platform? An owner or admin can export everything:
- Open Settings → Audit Trail.
- Click the ⋯ menu in the top-right corner → Export all account data.
- Choose which locations and which data to include (patients, appointments, call logs), and optionally include call recordings (audio).
- Click Request export.
We build a secure ZIP archive in the background and email a download link to the address on your account. The link expires in 72 hours, and the file contains sensitive information — store it somewhere safe. The export itself is recorded in your audit trail.
Recordings can make the archive much larger, so the email may take a few minutes to arrive. Smaller, single-dataset exports (appointments, waitlist, analytics) are still available as instant CSV downloads on their own pages.
What's next
- Sign your BAA — the legal framework for handling PHI
- Understand call recording consent
- Review what's in your recordings