Back to editorials

Lead Opinion

Health

Healthcare incident reports should be legally preserved in full

After inquiry testimony that an NHS trust wanted about 4,000 reports removed or deleted, the case for a legal duty to preserve internal safety records is no longer abstract, it is about whether patients and investigators can ever know what went wrong.

Portrait of Mira Solenne

By Mira Solenne / The Regulator / 1188 words

Editorial illustration for "Healthcare incident reports should be legally preserved in full"

The policy question sounds administrative until you place it next to the facts. At a formal inquiry, an NHS manager testified that he believed a trust wanted around 4,000 reports removed or deleted. He described the trust as panicking. He also said he was discouraged from raising concerns about staff rota issues. Those details turn a dry records debate into a patient safety test. When an organization under pressure can destroy internal incident reports and safety documentation, it can also erase patterns of risk, frustrate accountability, and deprive patients, families, staff, regulators, and future investigators of the evidence needed to understand harm.

That is why healthcare organizations should be legally required to preserve all internal incident reports and safety documentation. Not because every piece of paper is sacred, and not because regulation is an end in itself, but because preservation is the minimum guardrail in a sector where foreseeable harm is measured in injuries, deaths, missed warnings, and repeated mistakes.

The best argument for this legal duty begins with a simple institutional truth. Safety culture is most fragile precisely when an organization feels threatened. That is when reputational anxiety, litigation fear, staffing strain, and leadership self protection can overwhelm candor. The fact sheet captures that moment in one word, panicking. If the legal status of records is discretionary in calm times and fragile in crisis, then the system is backwards. The moment you most need a reliable documentary trail is the moment an organization has the strongest incentive to make it disappear.

Preservation matters for three distinct reasons. First, it protects the evidentiary record. Incident reports, rota concerns, near miss logs, internal safety reviews, and related documentation often reveal chronology, recurrence, and management knowledge. A single report may look minor. Four thousand reports may show a pattern. Second, preservation enables learning. Healthcare does not improve only by celebrating best practice. It improves by tracing small failures before they become fatal ones. Third, preservation supports due process. A formal inquiry cannot fairly test what happened if the underlying records can be curated by the very institution whose conduct is in question.

Opponents raise serious objections, and they deserve a serious answer. One concern is that a legal requirement to preserve all internal incident reports will chill reporting. If every document may later be scrutinized by regulators, lawyers, or the public, staff and managers may write less, report less, or sanitize what they say. That is not a frivolous point. Defensive documentation is real. Organizations do respond to legal incentives. A bad preservation regime could produce bland templates, euphemism, and paperwork designed to protect the institution rather than illuminate the risk.

But that objection fails for a practical reason and a moral one. Practically, the alternative is worse. If fear of scrutiny justifies allowing deletion, then the institutions most likely to suppress evidence are rewarded for their own vulnerability to embarrassment. Morally, patient safety cannot depend on the hope that private actors will voluntarily preserve damaging information when no law requires them to do so. The answer to chilled reporting is not permissive destruction. It is better whistleblower protection, clearer reporting standards, fair treatment of good faith reporting, and penalties for retaliation or tampering.

A second objection is that preserving all incident reports and safety documentation is too broad. Why keep every minor concern, duplicated note, or superseded version? Why not preserve only serious incidents, root cause analyses, and records tied to major harm? This is the strongest narrowing argument, because it recognizes the need for retention while warning against a costly data hoard.

There is some truth here. Not every document has equal value. Retention rules should include sensible records management, indexing, access controls, privacy protection, and defined archival practices. Hospitals and trusts should not be left with chaotic digital closets that make retrieval impossible. But the proposed narrowing still puts too much faith in ex ante classification. What counts as minor is often known only in hindsight. A rota complaint dismissed as operational noise may later explain fatigue, missed observations, or unsafe staffing. A cluster of near misses may matter precisely because they are numerous, not individually catastrophic. Once you authorize selective preservation based on internal judgments of significance, you recreate the same discretion that panic can corrupt.

A third objection is more theoretical. Some critics say the real answer is not a legal mandate but a more resilient information architecture, perhaps decentralized, cryptographically verifiable, and auditable, so records cannot be quietly altered or deleted. In the long run, that may be a valuable design direction. An immutable audit trail is attractive for exactly the reasons this debate exists.

But as a response to the present policy question, it is incomplete. A technical system is not self executing law. Someone must still define what gets recorded, who has access, how privacy is protected, what counts as tampering, and what sanctions follow. More importantly, patients cannot wait for a future ideal architecture while current organizations retain the practical power to destroy records. The legal duty to preserve is not an alternative to better systems. It is the baseline condition that makes any trustworthy system possible.

This is where the precautionary principle properly applies. The burden should fall on those who argue against preservation to show that the absence of a legal duty will not foreseeably enable harm. The fact pattern here does the opposite. We already have sworn testimony describing an alleged desire to remove or delete thousands of reports and discourage internal concerns. That is not speculative abuse. It is evidence that, under pressure, document handling can become part of the safety failure itself.

There is also a broader consumer protection issue. Patients enter healthcare systems with radical information asymmetry. They do not know internal staffing pressures, incident trends, or whether warnings were raised and ignored. Families trying to understand a death or injury are often dependent on institutional candor they cannot compel. In that setting, record preservation is not bureaucratic excess. It is one of the few mechanisms that limits the power imbalance between large healthcare organizations and the people affected by their mistakes.

The legal requirement should be robust, but it need not be crude. It can coexist with confidentiality protections, patient privacy rules, retention schedules for access versus archive, and sanctions calibrated to intentional deletion, concealment, or retaliation. It can distinguish preservation from public disclosure. It can support frontline candor rather than punish it. What it cannot do is leave the existence of the safety record to institutional convenience.

The central question is not whether preserving all internal incident reports creates administrative work. It will. The question is whether healthcare organizations should be allowed to decide, especially during a crisis, which records of their own failures survive. After hearing testimony about a trust that allegedly wanted about 4,000 reports removed or deleted, and a manager discouraged from raising rota concerns, the answer should be no.

A healthcare system that cannot reliably keep its own safety record is asking the public for trust without offering traceability. That is not a safety culture. It is a memory hole with patients inside it. The law should close it.