PatientSwaps
  • Home
  • Why PatientSwaps
  • How It Works
  • Pricing
  • Legal
  • Login
  • Schedule a Demo

Data Retention Schedule

Effective March 24, 2026  |  Last Updated July 17, 2026

IMPORTANT: PatientSwaps Role Under HIPAA
PatientSwaps operates as a Business Associate under HIPAA (45 C.F.R. Parts 160 and 164), not as a Covered Entity. PatientSwaps is a healthcare technology platform that provides algorithmic bed-matching and transfer matching software for senior care facilities. PatientSwaps is not a healthcare provider, patient broker, placement service, medical advisor, or care coordinator. This Data Retention Schedule governs how long PatientSwaps retains different categories of data collected or processed through the platform.

1. Purpose & Scope

This Data Retention Schedule describes the retention periods for all categories of data processed by the PatientSwaps platform, including Protected Health Information (PHI), facility operational data, de-identified records, and financial data.

Retention periods are determined by the following factors:

  • HIPAA requirements for Business Associates (45 C.F.R. § 164.530(j) — 6 years for policies, procedures, and documentation)
  • Colorado state record retention requirements
  • Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) — data minimization and purpose limitation
  • Anti-Kickback Statute (42 U.S.C. § 1320a-7b) and Colorado Anti-Kickback Law (C.R.S. § 24-31-809) — documentation of fee structures, technology services agreements, and commercial reasonableness
  • IRS requirements for financial and tax records
  • Legitimate business operational needs

2. Data Retention Schedule

2.1 Protected Health Information (PHI)

PHI is stored exclusively in systems covered by a Business Associate Agreement (BAA). Systems that are not BAA-covered never receive PHI — only de-identified operational data.

Data CategoryExamplesRetention PeriodDisposal Method
PHI Patient Transfer RecordsPatient names linked to facility assignments, transfer dates, matching results6 years from transfer completionSecure deletion with audit log
PHI Clinical Communication EmailsEmails between facilities containing patient-identifiable transfer details6 years from communication dateSecure deletion with audit log
PHI HIPAA Consent & BAA RecordsSigned BAAs, HIPAA authorizations, consent forms6 years from termination of agreement or last service date, whichever is laterSecure deletion with audit log

2.2 Facility Information

Business information about facility clients. Facility names, contacts, and operational details are business data (not PHI).

Data CategoryExamplesRetention PeriodDisposal Method
FAC Facility Profile DataFacility name, address, contact person, phone, email, bed count, payer types acceptedDuration of active subscription + 3 yearsStandard deletion
FAC Facility Account CredentialsLogin emails, portal access credentialsDuration of account + 1 yearSecure deletion
FAC Facility Marketing LeadsNames, emails, facility info from cold outreach or demo requests2 years from last engagement, or upon opt-outDeletion from all systems

2.3 De-Identified Operational Data

De-identified data compliant with HIPAA Safe Harbor (45 C.F.R. § 164.514(b)). Contains no direct patient identifiers.

Data CategoryExamplesRetention PeriodDisposal Method
OPS Swap Records (De-Identified)Swap IDs (SW-###), status, facility names, dates, bed counts6 years from swap completionStandard deletion
OPS Matching Query LogsQuery counts per facility, tier usage, capacity tracking3 yearsAutomated purge
OPS Platform AnalyticsOccupancy metrics, payer mix data, swap chain statistics (aggregated)Indefinite (aggregated, non-identifiable)N/A — no individual identifiers
OPS Automation LogsAutomation scenario execution logs, webhook payloads (de-identified IDs only)30 days (platform default), extended logs retained for 2 yearsAutomatic platform purge / manual deletion

2.4 Financial & Billing Records

Data CategoryExamplesRetention PeriodDisposal Method
FIN Platform Subscription PaymentsPayment-processor customer IDs, subscription IDs, payment amounts, tier levels7 years (IRS requirement)Per payment-processor policies / standard deletion
FIN Subscription InvoicesPlatform subscription charges, tier upgrade records7 yearsSecure deletion
FIN Technology Services AgreementsFacility contracts with pricing, tier selection, included query allowancesDuration of agreement + 6 yearsSecure deletion with audit log

2.5 Legal & Compliance Records

Data CategoryExamplesRetention PeriodDisposal Method
Business Associate AgreementsBAAs with facility clients6 years from termination (HIPAA requirement)Secure deletion with audit log
HIPAA Policies & ProceduresPrivacy policies, security procedures, breach response plans6 years from date superseded or last effectiveSecure archival then deletion
AKS Compliance DocumentationFee structure documentation, FMV opinions, legal opinion letters, commercial reasonableness analysesIndefinite (retain for duration of business operations + 10 years)Secure archival
Audit LogsPHI access logs, system access records, data modification logs6 yearsSecure deletion
Breach NotificationsBreach investigation records, notification documentation, corrective actions6 years from breach resolutionSecure deletion with audit log
Data Subject RequestsAccess, deletion, correction requests under CPA/CCPA3 years from request fulfillmentSecure deletion

3. Retention Principles

3.1 Minimum Necessary Standard

PatientSwaps applies the HIPAA minimum necessary standard to data retention. Data is retained only as long as necessary to fulfill the purpose for which it was collected, comply with legal obligations, or meet legitimate business needs. When retention periods expire, data is promptly disposed of using the designated method.

3.2 Data Minimization

Consistent with the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.), PatientSwaps limits the collection and retention of personal data to what is adequate, relevant, and reasonably necessary for the specified purposes.

3.3 De-Identification Preference

Where feasible, PatientSwaps converts PHI to de-identified format under HIPAA Safe Harbor (45 C.F.R. § 164.514(b)) when the identifiable form is no longer required. De-identified data may be retained for longer periods for platform analytics, occupancy trend analysis, and network improvement without the risks associated with identifiable data.

3.4 Clinical Decision Firewall

PatientSwaps does not retain clinical acuity data, diagnosis codes, treatment plans, or clinical notes. The matching algorithm uses only operational factors (bed availability, payer acceptance, geographic proximity, timing). Any clinical data inadvertently received is deleted within 72 hours and logged as an incident.

3.5 Legal Hold Override

If PatientSwaps receives a litigation hold, government investigation notice, or audit notification, the scheduled disposal of relevant data will be suspended until the hold is released. The PatientSwaps Privacy Contact is responsible for implementing and communicating legal holds.

4. Disposal Methods

Method Description Used For
Secure Deletion with Audit Log Permanent deletion from all systems (including backups within 90 days) with written record of deletion event, data categories destroyed, date, and authorizing party. PHI, HIPAA documentation, BAAs, AKS records
Secure Deletion Permanent deletion from all systems. No recovery possible after 90-day backup cycle. Facility PII, financial records, account data
Standard Deletion Deletion from primary systems. May persist in automated backups per platform retention. De-identified operational data, non-sensitive records
Automated Purge System-managed expiration per platform settings (e.g., a rolling 30-day log window). Automation logs, temporary processing data

5. Facility Rights & Individual Rights

5.1 Facility Data Rights

Facility clients may request:

  • Data Export: A complete export of all facility data held by PatientSwaps, in a portable format.
  • Data Deletion: Deletion of facility data upon subscription termination, subject to legal retention requirements.
  • Access Logs: Records of who accessed facility-related data and when.

5.2 Individual Rights (Colorado Privacy Act / CCPA)

Individuals whose data is processed through the platform have the right to:

  • Access: Request confirmation of whether PatientSwaps processes their personal data and obtain a copy.
  • Deletion: Request deletion of personal data, subject to HIPAA and other legal retention requirements.
  • Correction: Request correction of inaccurate personal data.
  • Data Portability: Obtain personal data in a portable, readily usable format.
  • Opt-Out: Opt out of the processing of personal data for targeted advertising, sale, or profiling. PatientSwaps does not sell personal data or engage in targeted advertising.

To exercise any of these rights, contact: privacy@careswaps.com

Note on PHI Retention: Certain health information may be subject to minimum retention requirements under HIPAA (6 years for Business Associate documentation). If deletion is requested and a legal obligation requires continued retention, PatientSwaps will notify the requesting party of the specific obligation and the expected date when deletion can occur. Access to such data will be restricted to the minimum necessary during the extended retention period.

6. Review & Updates

This Data Retention Schedule is reviewed at least annually and updated to reflect changes in legal requirements, business operations, or data processing activities. Material changes will be communicated via the PatientSwaps website and, where required, by direct notice to affected facility clients.

Questions about this schedule should be directed to: privacy@careswaps.com

7. Governing Law

This Data Retention Schedule is governed by the laws of the State of Colorado, including the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.), the Colorado Anti-Kickback Law (C.R.S. § 24-31-809), and applicable provisions of HIPAA (45 C.F.R. Parts 160 and 164) and the Anti-Kickback Statute (42 U.S.C. § 1320a-7b). In the event of a conflict between this schedule and applicable law, the law controls.

PatientSwaps

  • Home
  • Why PatientSwaps
  • Pricing

Legal

  • Terms of Service
  • Privacy Policy
  • About Our HIPAA Role
  • Data Retention
  • Cancel Subscription

Contact

  • privacy@careswaps.com
  • Fort Collins, Colorado
  • HIPAA Business Associate

Resources

  • For Families
  • Contact Support

Technology Platform Disclaimer: PatientSwaps is a healthcare technology platform providing algorithmic bed-matching and transfer matching software. PatientSwaps is not a healthcare provider, patient broker, placement service, medical advisor, or care coordinator. All transfer decisions are made independently by licensed clinical staff at participating facilities based on their independent clinical judgment. Platform subscription fees are for technology services and are not conditioned on referral volume or transfer outcomes.

© 2026 CareSwaps, LLC d/b/a PatientSwaps. All rights reserved. | Terms | Privacy | About Our HIPAA Role | Data Retention

This site uses analytics cookies (Google Analytics) to understand how visitors use our platform. No health information is collected through cookies. See our Privacy Policy for details.