Where consult audio goes:
retention and deletion

How long the recording should live after the note is drafted, what deletion has to mean across backups and devices, the questions to put to a vendor, and how to answer a patient who asks.

An ambient scribe records the consult so it can draft the note, which makes the recording the most sensitive artefact the tool ever touches. What happens to that audio after the draft exists is a question every practice should be able to answer precisely. This guide covers retention windows, genuine deletion, backups, Australian privacy law, and the conversations with vendors and patients that follow.

A recording microphone in shallow focus beside a bright window

The recording is an input to the note

An ambient AI scribe listens to the consult, produces a transcript, and drafts the note, letter or summary from it. The audio exists to make that draft possible. Once the clinician has read the draft, corrected it and signed it into the practice's clinical system, the signed note is the clinical record of the encounter. Nothing the scribe produces becomes a record until that review and signature happen.

The recording sits in a different category from the note. It contains everything said in the room, including small talk, interruptions and the voices of anyone else present. It was never written to be read by the next treating clinician, and it is far harder to search, correct or redact than a structured note. For those reasons most vendors and most practices treat consult audio as transient working material.

That framing decides everything else in this article. If the audio is a working input, the useful questions become how long it needs to exist, what legitimate purposes it serves during that time, and how it is destroyed at the end. These questions apply to any AI scribe, whichever vendor a practice chooses.

Retention windows in practice

Vendors handle audio retention in a few recognisable patterns. Some transcribe in near real time and hold audio only for the moments needed to process it. Some keep the recording for a short, fixed window measured in hours or days so the clinician can replay a passage while reviewing the draft. Some let the practice or hospital set the window itself. And some keep audio indefinitely unless somebody remembers to delete it.

A short, defined window is easy to defend. It lets a clinician check the draft against what was actually said, and it gives the practice a way to resolve a query about the note before it is signed. Once the note is signed, the legitimate reasons to hold raw audio fall away quickly. Indefinite retention creates the largest risk surface a scribe can have: a growing archive of highly sensitive recordings that someone must secure, catalogue, produce on request and eventually destroy.

What matters most is that the window is written down, agreed with the practice and enforced by the system. A vendor who says the equivalent of "we usually delete it" is telling you that deletion depends on a person remembering. A retention period you can point to in a contract or a configuration screen is one that happens by design.

What deletion has to mean

Deletion is where vague language does the most damage. Many systems soft delete by default: the recording disappears from view but remains recoverable by an administrator for some period. Hard deletion removes the data from live systems so it cannot be restored through the application. When a vendor says audio is deleted, ask which of these they mean, who could recover a soft-deleted recording, and for how long.

Backups are the second half of the answer. A recording removed from live systems will usually persist inside encrypted backups until those backups expire. That is normal and acceptable when the backup cycle is defined, reasonably short, and stated to you plainly. What you want in writing is the timing of primary deletion, the age-out period for backups, and confirmation that restoring from a backup will never quietly resurrect audio the practice deleted.

There are usually more copies than the obvious ones. Recordings may be buffered on the clinician's phone or desktop before upload, held briefly by the transcription pipeline, or referenced in logs. A credible vendor can walk you through the whole life of a recording, from the moment of capture to the moment the last backup containing it expires. If they cannot describe that path, they do not fully control it.

Where Australian privacy law sits

A recording of a consultation is health information, which the Privacy Act 1988 treats as sensitive information carrying the strongest protections in the Act. Australian Privacy Principle 11 requires reasonable steps to secure it, and APP 11.2 requires an organisation to take reasonable steps to destroy or de-identify personal information once it is no longer needed for a permitted purpose. Audio kept past its usefulness is therefore a compliance question as well as a security one.

Record retention laws pull in the other direction, and it is worth being precise about what they cover. Health records legislation in New South Wales, Victoria and the ACT generally requires the clinical record to be kept for seven years from the last entry for adults, and until age 25 for records made when the patient was a child. Those obligations attach to the record the clinician signs. They do not require the raw audio to be kept.

Read together, the two regimes suggest a clean workflow: sign the note, retain the note for as long as record-keeping law requires, and destroy the audio once it has served its purpose. A practice that chooses to keep recordings long term should understand what it is taking on. Retained audio becomes part of the health information the practice holds, subject to access requests, secure storage and eventual destruction obligations of its own.

Questions to put to a vendor

The broader security conversation with a vendor covers encryption, access control and assurance. On audio specifically, a handful of direct questions will tell you most of what you need to know.

A real answer names systems, settings and timelines. A weak answer talks about commitment to privacy and offers no numbers. If the audio answers are vague, treat that as a finding in itself.

  • What is the default retention period for consult audio, and where is it documented?
  • Can our practice set or shorten that period, and does the system enforce it automatically?
  • When audio is deleted, is that a hard deletion? Who could recover it afterwards, and for how long?
  • How long do encrypted backups hold a deleted recording before they expire?
  • Are recordings ever cached on the clinician's device before upload, and when are those copies removed?
  • Is consult audio ever used to train or improve your models, and can we decline that in writing?
  • If we leave the service, how do export and purge work, and in what order?
  • Will you confirm in writing when deletion of our data has completed?

How aurii handles consult audio

This section is about our product. Everything above is not.

Consult audio in aurii is captured and transcribed inside Australia, and everything the service holds (audio, transcripts, drafts and backups) is encrypted and stays in the country, with the primary in Sydney and an encrypted geo-redundant copy in Melbourne. Each record is encrypted individually, with keys held in Australian Key Vault, and each practice's data is isolated from every other tenant.

The audio exists to draft the documentation, and its retention follows the configuration agreed with the practice or hospital, so the window is a written setting rather than a habit. Nothing becomes a clinical record until a clinician has reviewed and signed it. The signed documents, together with an append-only, tamper-evident audit of every action, are retained to meet record-keeping obligations.

Deletion is treated as a completed process. Ask for data to be purged and it is removed from live systems, with encrypted backups ageing out on a defined cycle. At offboarding, export comes first so the practice's records leave in a usable form, and the purge follows on the practice's instruction.

When a patient asks about the recording

Patients who ask about the recording usually want four things: who will hear it, how long it is kept, whether they can say no, and whether saying no changes their care. Plain answers work best, and the practice should agree on them before the first consult is recorded rather than improvising in the room.

A workable script covers the essentials in a few sentences. The recording is used by software to draft the note. The doctor reads and corrects that draft before anything goes into the record. The audio is deleted after a set period, and the practice can say what that period is. The patient can decline, and if they do, the clinician documents the consult the way they always have. Knowing who at the vendor could access a recording, and under what conditions, is part of the practice's homework before offering that script.

Patients sometimes ask for a recording to be deleted after the consult. In most configurations the honest answer is that it will be deleted on schedule shortly anyway, and you can tell them exactly when. Where a recording still exists, honouring the request is straightforward because the clinical record is the signed note, and deleting the audio does not change it. Recording the consent conversation itself in the note closes the loop.

Common questions

The signed clinical note is the record, and record-keeping obligations attach to it. If a practice retains the audio, that audio becomes health information the practice holds and must manage, including for access requests and eventual destruction. Most workflows avoid this by deleting audio once the note is signed.

It varies by vendor and configuration. Some never store audio beyond processing, some hold it for hours or days to support the clinician's review, and some let the practice set the window. What matters is that the period is documented, agreed and enforced by the system, so ask for it in writing.

Encrypted backups commonly hold data until the backup itself expires, so a deleted recording can persist for the length of the backup cycle. That is acceptable when the cycle is defined and the vendor confirms that restoring from backup will not resurrect deleted audio. Ask for the age-out period in writing.

Yes, and honouring the request is usually easy. In most configurations the audio is already scheduled for deletion shortly after the note is signed, and the practice can tell the patient exactly when. Deleting the audio does not affect the signed note, which remains the clinical record.

Only if the contract permits it, and the contract should say so plainly. Ask the vendor directly whether audio or transcripts feed model training or improvement, and get the answer, including any opt-out, in writing before recording a single consult.

This is general information about audio retention and deletion, not clinical or legal advice. More guides sit on the resources hub. If your practice needs a question answered before it adopts AI documentation, tell us and we will write it: hello@aurii.com.au.

Read first.
Then see it on your own round.

You do not have to take any of this on faith. Request access, bring a real consult, and watch the note, letters and discharge come out the other end, yours to correct and sign.

hello@aurii.com.au

Stay in the loop.

Leave your email and we'll be in touch. No spam, unsubscribe any time.