{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Compliance with the Records Management Code of Practice for Health and Social Care 2022 and Welsh Care Service Record-Keeping Requirements Policy

1. Purpose

The purpose of this policy is to ensure that {{org_field_name}} creates, maintains, uses, stores, shares, retains, archives and securely disposes of records in accordance with the legal and regulatory requirements applicable to care home services in Wales.

{{org_field_name}} will comply with the Regulation and Inspection of Social Care (Wales) Act 2016 and the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, including in particular Regulations 47, 59 and 78 and Schedule 2 to the Regulations. The organisation will also have regard to the statutory guidance issued by the Welsh Ministers for service providers and responsible individuals.

Where applicable to the service, its commissioning arrangements or the records concerned, {{org_field_name}} will also follow the Records Management Code of Practice for Health and Social Care 2022 for Wales. The Code applies to records within NHS Wales and adult social care and public health functions commissioned or delivered by local authorities and may also apply to independent providers undertaking NHS or commissioned health and social care functions.

Records containing personal data or special category personal data will be processed in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018, as amended, the common law duty of confidentiality where applicable, and other applicable information-governance legislation. The Freedom of Information Act 2000 will be applied only where {{org_field_name}}, or the information held by it, falls within the scope of that legislation or where information is held on behalf of a public authority to which the Act applies.

The objectives of this policy are to ensure that records are accurate, complete, current, secure, accessible to authorised persons when required, capable of being audited, retained for the appropriate period and disposed of securely when there is no longer a lawful reason to retain them. Records must support safe and effective care, protect the rights and well-being of individuals, provide evidence of the care and support delivered and enable {{org_field_name}}, the Responsible Individual and the Registered Manager to demonstrate compliance with regulatory requirements.

2. Scope

This policy applies to all staff at {{org_field_name}}, including employees, agency workers, contractors, volunteers, and anyone with access to care records, including visiting professionals. It covers all types of records: resident care records, medication charts, risk assessments, clinical notes, financial documentation, staffing and HR files, incident logs, safeguarding records, and records related to quality assurance and governance. It applies regardless of format, whether handwritten, typed, scanned, or stored digitally.

3. Related Policies

This policy should be read in conjunction with:
CHW34 – Confidentiality and Data Protection (GDPR) Policy
CHW04 – Good Governance Policy
CHW11 – Safe Care and Treatment Policy
CHW24 – Management of Accidents, Incidents, and Near Misses Policy
CHW13 – Safeguarding Adults from Abuse and Improper Treatment Policy
CHW27 – Staff Supervision, Training, and Development Policy

4. Policy Details

4.1 Welsh Records Management and Regulatory Framework

{{org_field_name}} will manage records in accordance with the record-keeping requirements that apply to regulated care home services in Wales.

The primary regulatory requirements for the regulated service are the Regulation and Inspection of Social Care (Wales) Act 2016 and the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended. Regulation 59 requires the service provider to keep and maintain the records specified in Schedule 2, to ensure records relating to individuals are accurate and up to date, to keep all records securely, to make arrangements for their continued security if the service closes, to make records available to Care Inspectorate Wales on request and to meet the statutory retention and access requirements.

Where applicable to the records concerned or to the organisation’s NHS Wales or local-authority commissioning arrangements, {{org_field_name}} will also apply the Records Management Code of Practice for Health and Social Care 2022 for Wales. Where the Code specifies a retention period longer than the minimum period required by the Regulated Services Regulations, the longer applicable period will be followed where there is a lawful, contractual or regulatory basis for doing so.

No provision in this policy may be interpreted as reducing or replacing a specific requirement imposed by Welsh legislation or by the conditions of {{org_field_name}}’s registration with Care Inspectorate Wales.

4.2 Roles and Responsibilities

The service provider has overall responsibility for ensuring that effective record-management arrangements are established and maintained and that the records required by Regulation 59 and Schedule 2 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, are kept for the service.

The Responsible Individual is responsible for ensuring that effective systems are in place for keeping records and for ensuring the accuracy and completeness of records required under Regulation 59. The Responsible Individual must obtain assurance that these systems operate effectively and must consider the findings of record audits as part of the statutory quality-of-care review arrangements.

The Registered Manager is responsible for the day-to-day implementation of this policy within the service. This includes ensuring that records are created and maintained appropriately, that access is restricted to authorised persons, that staff understand their responsibilities, that deficiencies are addressed promptly and that required records are available for inspection.

The Data Protection Officer, where {{org_field_name}} is required to appoint one or has voluntarily appointed one, is:

{{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}.

The Data Protection Officer provides advice and oversight in relation to applicable data-protection requirements. Appointment of a Data Protection Officer does not remove the statutory accountability of the service provider or Responsible Individual.

All staff, agency workers, contractors and volunteers who create, use or have authorised access to records are responsible for ensuring that information they record is accurate, complete, factual, timely, relevant and handled securely. Staff must protect records against unauthorised access, disclosure, alteration, loss or destruction and must immediately report actual or suspected information-security incidents in accordance with this policy.

4.3 Creation, Accuracy, Completeness and Amendment of Records

All records must be accurate, complete, factual, relevant, timely and written or entered in a clear and professional manner. Records relating to individuals must be kept accurate and up to date.

Entries in care and support records must, where applicable, include:

Records must be completed as soon as reasonably practicable following the care, support, intervention, event or decision to which they relate.

Records must not be falsified, backdated, overwritten or altered in a manner that conceals the original entry. Where a correction or subsequent amendment is necessary, the original information must remain identifiable and the correction must show, as appropriate, the date of the amendment, the person making the amendment and the reason for the change.

For paper records, an incorrect entry must remain legible and must normally be corrected by drawing a single line through the incorrect information, entering the correct information and adding the date and initials or signature of the person making the correction. Correction fluid, erasure or any other method that obscures the original entry must not be used.

Electronic record systems must use individual user credentials and must provide an audit trail capable of identifying who created, viewed or amended a record and when the relevant action occurred. Staff must not share individual passwords or access credentials.

4.4 Records Required, Retention and Archiving

{{org_field_name}} will keep and maintain all records required by Regulation 59 and Schedule 2 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.

For all regulated services, the required records include, where applicable:

As a care home service, {{org_field_name}} must additionally maintain, where applicable:

All records must be stored securely and must be made available to Care Inspectorate Wales when requested.

4.5 Secure Storage and Access Controls

Paper records are stored in locked areas with restricted staff access. Electronic records are stored on secure, encrypted systems with password protection, user authentication, and audit logging. Staff access is based on role and need-to-know principles. Mobile devices used for accessing records are protected by PINs, antivirus software, and secure connections. Records must not be left unattended in public areas or visible on computer screens. Any unauthorised access attempt is treated as a data breach and investigated.

4.6 Review and Secure Disposal of Records

Records must not be destroyed merely because a stated minimum retention period has expired. At the end of the applicable retention period, the record must be reviewed to determine whether there remains a legal, regulatory, contractual, safeguarding, clinical, operational or evidential reason for continued retention.

No record may be destroyed where it is, or may reasonably be expected to become, relevant to:

Where destruction is authorised, it must be carried out securely and in a manner appropriate to the sensitivity and format of the information.

Paper records containing confidential or personal information must be destroyed by secure confidential-waste arrangements, such as cross-cut shredding or an appropriately controlled confidential destruction service.

Electronic records must be securely deleted so that they are no longer available for ordinary operational use and are dealt with in accordance with the organisation’s approved technical, backup and retention arrangements. Records must not simply be deleted from a live system while uncontrolled copies remain elsewhere.

A destruction record must be maintained showing, as a minimum:

The destruction log must not reproduce unnecessary confidential information from the records that have been destroyed.

4.7 Access to Records, Information Sharing and Transfers

Individuals who use the service must be able to access records about themselves in accordance with applicable law and must be made aware that they can access those records. {{org_field_name}} will provide information about how an individual, or a person lawfully acting on their behalf, can request access.

Requests for access to personal data will be handled in accordance with the UK GDPR and Data Protection Act 2018, including the applicable requirements concerning identity verification, third-party information, exemptions and statutory response times.

Records and personal information will only be shared where there is an appropriate lawful basis and, where special category personal data is involved, an appropriate condition permitting that processing. Consent will be obtained where consent is the relevant lawful basis, but staff must not assume that consent is required for every lawful disclosure.

When information is shared with NHS Wales services, local authorities, other care providers or other authorised persons or bodies, {{org_field_name}} will ensure that the disclosure is necessary, proportionate and limited to information relevant to the purpose for which it is being shared.

Appropriate secure methods must be used when transferring confidential information. The method selected must take account of the sensitivity and volume of the information and may include appropriately secured email, approved secure information-sharing systems or encrypted media.

Where appropriate, a record of the disclosure or transfer must be retained, including:

Where an individual moves to another care provider or health setting, information necessary to support safe continuity of care must be transferred securely and lawfully. The transfer of information does not automatically authorise destruction of the provider’s own records; records must continue to be retained for the period required by Regulation 59 and any other applicable legal or contractual requirement.

Where {{org_field_name}} provides a care home service wholly or mainly for children, records must be delivered to the placing authority where Regulation 59 requires this when the service ceases to be provided to the child.

4.8 Personal Data Breaches, Information-Security Incidents and Regulatory Notification

Any actual or suspected loss, destruction, alteration, unauthorised disclosure of, or unauthorised access to personal data or confidential records must be reported immediately in accordance with {{org_field_name}}’s internal incident-reporting arrangements and escalated to the Data Protection Officer or other designated information-governance lead.

The organisation will take immediate and proportionate action to contain the incident, preserve relevant evidence, establish what information and individuals are affected, assess the likely consequences and reduce the risk of further harm.

All personal data breaches must be documented, whether or not they are ultimately reportable to the Information Commissioner’s Office.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} will notify the Information Commissioner’s Office without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach. Where notification is made later than 72 hours, the reasons for the delay must be documented and provided where required.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, those individuals will also be informed without undue delay unless an applicable statutory exception applies.

A personal data breach is not automatically a Care Inspectorate Wales notification. The service provider and Responsible Individual must separately assess whether the circumstances are a notifiable event under Regulation 60 and Schedule 3, Regulation 84 and Schedule 4, or any other applicable CIW notification requirement. Where a CIW notification is required, it must be made without delay, in writing and in the manner and form required by CIW, unless the relevant provision specifies a different timescale.

The organisation will maintain a record of information-security incidents and personal data breaches, including the facts of the incident, its effects, the risk assessment, decisions about notification, remedial action taken and lessons learned.

4.9 Staff Training and Monitoring

All staff receive mandatory training on data protection, confidentiality, and records management at induction and annually thereafter. Training includes practical guidance on secure handling, record-keeping standards, data sharing, and breach prevention. Competency is assessed through supervision, audits, and periodic spot checks. Any staff found to be in breach of this policy may be subject to disciplinary procedures in line with CHW31.

4.10 Monitoring, Audit and Continuous Improvement

{{org_field_name}} will operate an effective system for monitoring the quality, accuracy, completeness, security and accessibility of records.

Record audits must include an appropriate sample of the records required under Regulation 59 and Schedule 2 and must be capable of identifying omissions, incomplete documentation, inaccurate or untimely records, inappropriate amendments, access-control concerns and failures to comply with required retention or record-keeping arrangements.

The Registered Manager must ensure that identified deficiencies are addressed promptly and that any required corrective action, staff support, supervision, retraining or system improvement is implemented.

The Responsible Individual must ensure that effective systems are in place for the keeping of records and for ensuring the accuracy and completeness of records required by Regulation 59.

As part of the Responsible Individual’s statutory quality-of-care review, which must take place as often as required and at least every six months, the Responsible Individual must consider the outcome of audits of the accuracy and completeness of records. Relevant findings, trends, risks and improvement actions must contribute to the assessment of the quality and safety of the service.

Where record audits identify a risk to an individual’s safety, well-being or rights, or indicate a possible breach of legislation or a notifiable event, the matter must be escalated without delay and dealt with under the appropriate safeguarding, incident, data-protection, governance or CIW notification arrangements.

4.11 Service Closure, Transfer or Change of Provider

Where the regulated service closes, ceases operating, transfers to another provider or undergoes another organisational change affecting responsibility for records, {{org_field_name}} must ensure that records continue to be kept securely and remain retrievable for the applicable statutory retention period.

Before any closure or transfer, the service provider and Responsible Individual must identify:

Where a commissioner lawfully directs the transfer of records to a successor provider, {{org_field_name}} will ensure that the transfer is documented and undertaken securely.

Where a care home service provided wholly or mainly for children ceases to be provided in respect of a child, the child’s records must be delivered to the placing authority where required by Regulation 59.

Records must not be abandoned, made inaccessible or destroyed solely because {{org_field_name}} ceases to provide the service.

5. Policy Review

This policy will be reviewed annually or earlier if there are updates to legislation, national guidance (including updates to the NHS Records Management Code of Practice), or in response to audit findings, data breaches, or feedback from CIW. It forms part of {{org_field_name}}’s overarching commitment to high-quality governance, transparency, and information security.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *