{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Record Keeping and Documentation Policy
1. Purpose
This policy ensures that {{org_field_name}} maintains accurate, comprehensive, and up-to-date records in compliance with the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and CQC Fundamental Standards. Good record-keeping supports safe, effective, and person-centred care while ensuring compliance with legal, regulatory, and organisational requirements. It also provides a reliable source of evidence in case of any legal, regulatory, or internal investigations, protecting the interests of people we support, staff, and the organisation.
This policy also supports compliance with Regulation 17 (Good governance), including the requirement to maintain securely an accurate, complete and contemporaneous record for each person using the service, including the care and treatment provided and decisions taken in relation to that care and treatment. Records must be sufficiently detailed to evidence safe care, continuity, decision-making, and outcomes, and to demonstrate compliance during internal audits and CQC assessment activity.
2. Scope
This policy applies to all staff members responsible for recording, maintaining, and managing documentation related to people we support, staff, and organisational operations at {{org_field_name}}. It covers all forms of records, including paper-based and electronic records. It ensures that all records are handled responsibly and that proper measures are in place for data protection, accessibility, and retention.
3. Related Policies
- Good Governance Policy (CH04) ensures overall organisational compliance and accountability.
- Person-Centred Care Policy (CH07) ensures records reflect the needs, choices, and preferences of people we support.
- Confidentiality and Data Protection (GDPR) Policy (CH34) governs the security and lawful handling of records.
- Safeguarding Adults from Abuse and Improper Treatment Policy (CH13) ensures accurate documentation of safeguarding concerns.
- Safe Care and Treatment Policy (CH11) supports the accurate recording of health and safety measures and risk assessments.
4. Policy Statement
{{org_field_name}} is committed to ensuring that all records are accurate, timely, complete, and securely maintained. Proper documentation enhances care quality, supports staff decision-making, protects legal interests, and ensures accountability. Record-keeping is a fundamental aspect of service provision and must be completed diligently to uphold care quality and meet regulatory requirements.
5. Principles of Record Keeping All records must be:
- Accurate and factual – Records should be an objective account of care delivered, free from speculation or personal opinion.
- Timely and up to date – Entries must be made as soon as possible after an event or action, avoiding retrospective amendments unless properly noted.
- Legible and clear – Handwritten records must be readable, using black ink, with correct spelling and grammar.
- Comprehensive and complete – No important details should be omitted, and all records should contain adequate information for future reference.
- Confidential and secure – Adherence to GDPR and Data Protection Act 2018 is mandatory, ensuring personal information is protected from unauthorised access.
- Person-centred – Records must reflect the preferences, needs, and wishes of people we support, ensuring a holistic approach to documentation.
- Retrievable – Records must be stored systematically for ease of access and auditing, ensuring they are available when required for care provision, regulatory inspection, or legal purposes.
- Contemporaneous – Records must be completed at the time of the event or as soon as practicable, and must clearly identify any late entry as “Late Entry”, including the date/time of the event and the date/time the entry is made.
- Attributed – Every entry must include the full name, role/designation, and signature or authenticated e-signature, plus the date and time of the entry.
- Objective and professional – Records must separate facts, clinical/care observations, and opinions, and must avoid emotive or judgmental language.
- Standard abbreviations only – Only abbreviations approved by the organisation may be used; unclear abbreviations must be avoided.
- Correcting errors (paper and electronic) – Records must never be altered in a way that obscures the original entry. Paper corrections must be made with a single line through the error, marked “error”, then dated, timed and signed/initialled. Correction fluid must not be used. Electronic records must retain an audit trail and any correction must be made as an addendum that is dated/timed and attributed.
- Decision recording – Records must clearly document key decisions, the rationale, who was involved (including the person and/or representative), and any agreed actions and review dates.
6. Types of Records Maintained
- Care Records: Including care plans, risk assessments, daily notes, medication administration records (MAR), and incident reports, all of which provide a comprehensive record of the support provided.
Duty of Candour records (Regulation 20) – where a notifiable safety incident occurs, records must include the verbal notification, facts known at the time, an apology, support offered, investigation/enquiries and outcomes, and copies of all written correspondence, all kept securely.
- Medical and Health Records: Documentation from GPs, hospitals, district nurses, and other healthcare professionals involved in a person’s care.
- Safeguarding records (Regulation 13) – concerns, immediate actions taken, referrals made, strategy/discussion outcomes, risk management actions, communication with the person/representatives (where appropriate), multi-agency decisions, and learning outcomes, with clear dates/times and attribution.
- Staff Records: Training, supervision, DBS checks, and employment records to ensure compliance with recruitment and employment standards.
- Health and Safety Records: Risk assessments, equipment maintenance logs, and accident/incident reports to ensure a safe working environment.
- Financial Records: Where the organisation manages finances for people we support, clear documentation is kept to ensure transparency and prevent financial abuse.
7. Responsibilities of Staff
- Registered Manager: Ensures compliance with record-keeping regulations and audits records regularly to maintain accuracy and completeness.
- Care Staff: Maintain up-to-date and accurate care records for people we support, ensuring that all actions and observations are clearly recorded.
- Data Protection Officer: Oversees confidentiality and GDPR compliance, ensuring data security and appropriate access control measures are in place.
- Clinical Staff: Ensure that medical records are accurate and up to date, following professional and legal standards for healthcare documentation.
- Administrative Staff: Maintain staff records, employment documents, and organisational documentation to support compliance and operational efficiency.
8. Electronic Records Management
- Secure Systems: Only approved software and encrypted devices must be used for electronic records, ensuring data security and protection from breaches.
- Access Control: Staff must use unique passwords and follow role-based access permissions, limiting access to only those who require it for their duties.
- Audit Trails: Digital systems must log all changes to records, providing transparency and accountability for any amendments or updates made.
- Data Backups: Regular backups of digital records must be performed to prevent data loss due to system failures, cyber incidents, or accidental deletions.
- Device and session security – All devices used to access records must have automatic screen-lock, strong passwords, and up-to-date security patches/anti-malware.
- Secure transfer of information – Personal data must only be shared using approved secure methods (e.g., encrypted email/secure portals). Records must not be transferred via unencrypted personal email accounts or consumer messaging apps.
- Printing controls – Printing of personal records must be minimised; any printed records must be collected immediately and stored/disposed of securely.
- Business continuity – The service must maintain tested arrangements for system outages so staff can access essential information and continue safe care, with controlled later transcription into the main record.
9. Confidentiality and Data Protection
- All records must be stored securely in accordance with the Data Protection Act 2018 and GDPR, ensuring that personal and sensitive information is protected from unauthorised access.
- Only authorised personnel should have access to records, ensuring compliance with privacy and confidentiality regulations.
- Any actual or suspected data breach (loss, unauthorised access, disclosure, alteration or destruction) must be reported immediately to the Data Protection Officer and recorded as an incident. The DPO will assess risk, take containment action, and ensure any required notifications are made (including to affected individuals and regulators where applicable).
9.1 Information sharing and lawful disclosure
Information sharing must be lawful, necessary, proportionate and recorded. Where information is shared without consent (for example safeguarding, serious risk, or statutory requests), the record must document the legal basis, what was shared, with whom, why, and the outcome.
9.2 Access to records (Subject Access / representatives)
Access requests – People we support (or their authorised representative) may request access to their records. Requests must be logged immediately and managed in line with the organisation’s information rights procedure, including identity/authority checks, redaction of third-party information where required, and timely response.
9.3 Duty of Candour (Regulation 20) – Documentation requirements
Where a notifiable safety incident occurs, the Registered Manager (or delegate) must ensure the duty of candour process is followed and fully documented. Records must include:
- the date/time the incident was identified and initial actions taken to keep the person safe;
- the date/time of the verbal notification, who was present, the facts known at that time, and an apology;
- support offered to the person and/or relevant person;
- investigation/enquiries undertaken, outcomes, and learning actions;
- written follow-up notification and a copy of all correspondence, stored securely.
All duty of candour documentation must be filed so that it is retrievable for audit and CQC review.
10. Record Retention and Disposal
- Records are retained in line with the Records Management Code of Practice for Health and Social Care (2021) and the adult social care retention guidance, ensuring minimum retention periods are met and extended where there is a clear justification (for example ongoing investigations, safeguarding, complaints, or litigation).
- People We Support Records: Retained for eight years after their last contact with the service to support care continuity and regulatory compliance.
- Staff Records – Staff records (including recruitment, right to work, checks and core employment documentation) are retained in line with the adult social care retention schedule. As a minimum, statutory records are retained for at least six years, however key staff records and significant training evidence may need to be retained for longer in accordance with the retention schedule adopted by the organisation.
- Safeguarding and serious incident records – Safeguarding records are retained in line with the organisation’s retention schedule and will be retained for longer where required (for example where the safeguarding matter constitutes a serious incident, forms part of a complaint, or may reasonably lead to legal proceedings). Where multiple retention periods apply, the longest relevant retention period will be used.
- Secure Disposal: Paper records must be shredded, and digital records must be permanently deleted in line with GDPR guidelines to protect confidentiality.
11. Auditing and Compliance
- Regular internal audits are conducted to evidence effective governance under Regulation 17, including checks on accuracy, completeness, contemporaneous recording, secure storage, decision/consent documentation, MAR documentation, incident recording, and actioning of identified shortfalls, with clear audit outcomes, responsible persons, and timescales for improvement.
- CQC inspections may review record-keeping practices as part of governance checks, ensuring that documentation supports the delivery of high-quality care.
- Audit results are reviewed, and any identified gaps or issues are addressed through training and process improvements to enhance documentation practices.
12. Training and Awareness
- All staff receive mandatory training on record-keeping, data protection, and documentation best practices, ensuring they understand their responsibilities.
- Additional training is provided for staff using electronic records systems, ensuring they can competently navigate and maintain digital records.
- Refresher training is scheduled annually to keep staff updated on legal and regulatory changes, ensuring continuous improvement in record-keeping practices.
13. Policy Review
This policy will be reviewed annually or sooner if changes in CQC regulations, GDPR, or operational needs require an update. Any amendments will be communicated to all staff to ensure ongoing compliance and best practices in record-keeping.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.