Skip navigation

Good Practice: When Your Client Wants You to Destroy Their Health Information

“A client wants us to destroy all of their client records at our clinic, as they are currently undergoing an issue with identity theft, what do we do?”

The College of Physiotherapists of Alberta has many resources related to privacy, including the Privacy Guide. All resources are designed to help physiotherapists comply with the legislation that applies to their practice. However, sometimes we get questions that aren’t quite covered in the Privacy Guide. This article is based on a question that was submitted by three different physiotherapists over the span of a couple of weeks. 

Scenario

Client X comes into your practice and tells you they have been involved in a situation involving identity theft or financial fraud. They are very worried about their health and financial information being compromised further. Client X may or may not blame you as the source of the privacy breach, but they are adamant they want all their information removed from your systems. 

Before we address this scenario, let’s do a quick review of the Standards of Practice and some privacy basics you should know regarding health information. 

The Standards of Practice

The Privacy and Record Retention Standard (2026) includes requirements that the physiotherapist:

  • Complies with the requirements of the Health Information Act (HIA), Health Information Regulation (HIR) and other privacy legislation relevant to their practice.
  • Protects the privacy of health information in all environments, regardless of the format of information collection.
  • Accesses only relevant individually identifying health information when providing physiotherapy services for the client.
  • Employs appropriate administrative, physical, and technical safeguards to prevent unauthorized access, use, modification, disclosure, or destruction of health information throughout the health information lifecycle.

Privacy Basics

Physiotherapists are custodians under the HIA. As a result, the health information physiotherapists collect, use, and disclose for purposes established in Section 27 of the HIA is subject to the provisions of that Act. 

The HIA allows for sharing of information within the “circle of care” without direct client consent. Anything outside of the “circle of care” like disclosure to a lawyer or insurer requires client consent. 

According to the Health Information Regulation (HIR), “A custodian must designate an individual who is responsible for the overall security and protection of health information in the custody or under the control of the custodian,” (HIR, Section 8(2)), sometimes referred to as a privacy officer. This privacy officer is responsible for overseeing adherence to the HIA, including developing and enforcing privacy policies and the organization’s collection or privacy statement. The Privacy Officer should be the person responding to the client in our scenario.

Within larger public institutions, (e.g., hospitals or continuing care centres), the organization is the custodian; the physiotherapist can direct the client to the organization’s privacy officer. In smaller practice settings, the physiotherapist may or may not be the custodian, and the privacy officer may be the physiotherapist or another individual designated by the custodian to fulfill the role. It is essential to clarify what your privacy role is within the practice setting. If you don’t have documentation designating you as an affiliate to a custodian, you are the custodian. 

Privacy policies and your collection notice help to clearly communicate the steps you are taking to meet your regulatory and legislated requirements. With these in place, you may not have to respond to many questions regarding the privacy of health information in your practice. This could help foster feelings of trust between you, your clinic/facility and the client. 

It is also a good idea to review contracts with third party organizations that provide you with information systems or information technology services. Do contract terms comply with the requirements of the HIA? Did contractors sign a confidentiality agreement as part of their contract? Is there a risk that contractors or your affiliates are not following your privacy policies? Contact  your Electronic Medical Record (EMR) provider to discuss the steps they have in place to ensure your client’s data is protected, including both health information and financial data. The answers to these questions may help to address client concerns about the security of their health information. 

Back to Our Scenario – The client who wants you to destroy the health information you have about them.

Now that we have reviewed some privacy basics and posed some questions for consideration, we will get back to answering the question posed at the top of this article. 

The first step would be to speak with your client to get a better sense of what is driving their request.

Do they feel you are the source of the breach?

Someone within the practice, typically the privacy officer, needs to investigate their concern. If it becomes apparent that you are the cause of the breach, then you will need to take responsibility. Someone in the practice environment erred. You must contact your privacy officer to notify them of the issue. The privacy officer may need to contact the Office of the Information and Privacy Commissioner (OIPC), depending on the nature of the breach and risk of harm related to the breach. Details of when you need to report a privacy breach can be found in the Privacy Guide for Alberta Physiotherapists (2026) and Health Information Act Policies and Procedures for Alberta Physiotherapist Custodians (2026).

Do they feel you are not providing adequate stewardship over their information?

Maybe they don’t think you are the source of a breach but are concerned that you are not protecting their private information. Does your client understand the steps you take to protect their personal information? You should have this information readily available for the person asking you to destroy the records. You can also direct them to your privacy officer or sit with them and take them through the measures you have in place to protect their health information. This would include: 

  • The policies and procedures listed in your collection notice - highlighting how their data is used and secured, and requirements that apply to access to health information by others and use of information by you and your colleagues.
  • Physical controls that are currently in place such as lock and key type safeguards for paper charts, computers, and the office.
  • Technical controls such as how your EMR functions, login and password use, protection of their data, encryption and data loss prevention. 

If the client is satisfied with the steps you have taken, they may still request you destroy their records to limit their perceived risk. Remember, identity theft and credit card fraud can be extremely stressful events, and we should be empathetic to what they are going through. 

If the client is still requesting that you destroy their records, then we move onto the next phase of the discussion which hovers primarily around you as a regulated health professional and your duty to maintain health records.

You have the tricky job now of balancing what the client wants and what you must do to fulfill your professional obligations regarding documentation and record keeping. The authority to approve the destruction of health records is derived from a governing body or health professional body, such as the CPTA. 

The Documentation Standard includes the requirement that physiotherapists retain client records for 10 years. This retention period is established so that you can respond to information requests from clients and third parties and address any future malpractice or conduct concerns that may arise. The retention period is set at 10 years because that is the time limit for a person to bring forward a civil claim against another party. As a regulated health professional, you are required to adhere to the Standards of Practice, which means that between the Standards of Practice and the potential need to respond to a civil claim, you have a legal and business purpose to retain the client’s record. 

The client cannot direct the destruction of their health information.

If you can't delete the entire client record, what can you do?

It is important to take into consideration the client’s expressed wishes regarding what happens to their health information (including their registration information). You most likely can expunge their credit card information if the client has been discharged. If they are a current client and continuing treatment at your clinic, you can discuss alternate forms of payment if needed. However, in both cases, you still need to retain financial records as part of the client record. This would be necessary for chart or insurance audits so you can match clinical records with billing records. 

When it comes to other personal registry information (name, date of birth, phone number, email), there needs to be a balance between complying with the client’s request and making sure that sufficient information is retained so that you can confidently identify the record and who it pertains to. Since you need to retain client records for 10 years, you must think about what you would need to identify the client and their record in the future. The typical standard used by accrediting bodies is to employ two unique identifiers to identify an individual and mitigate against errors when dealing with two people with similar names (e.g., full legal name and date of birth, or legal name and health-care number). 

If the therapeutic relationship has come to an end, it is unlikely that you have a legitimate need to contact the client via phone or email; therefore, it is not unreasonable to remove or redact that information from the record at their request.

Hopefully, after you have discussed your regulatory requirements and privacy safeguards in place to protect private information with the client they will understand what you can and cannot do and you can mutually agree on a course of action. If you are not able to resolve the matter, you may want to contact a lawyer, the HIA help desk, or the Office of the Information and Privacy Commissioner (OPIC) for advice.

HIA Help Desk: 780-427-8089

OPIC: Edmonton 780-422-6860 and Calgary 403-297-2728 

The College of Physiotherapists of Alberta’s Practice Advisor is also here to help you navigate challenging situations related to privacy or the other Standards of Practice. Contact them at professionalpractice@cpta.ab.ca

Page updated: 16/09/2026