If you’re a practising therapist, whether you’re working in acupuncture, massage, cupping, or another complementary therapy, good record-keeping isn’t paperwork for its own sake. It’s part of safe, professional practice, and it’s what stands between you and serious trouble if a client ever makes a complaint or a claim.
Here’s a clear, practical guide to what you need to record, why it matters, and how long to keep hold of it.
What Counts as a Client Record
A client record is anything you hold that relates to an individual client and their treatment. That includes:
- Contact and identifying details
- Relevant medical and lifestyle history
- Consent forms
- Notes from each consultation, including the treatment given
- Any unusual reactions or adverse events
- Correspondence with the client about their care
As a general rule, records should be detailed enough to reconstruct what happened in a session, including the date of consultation, the therapy or treatment provided, and any notes on medical history relevant to that treatment.
What Doesn’t Count as a Client Record
Personal musings that you scribble down, including working out diagnostics before they are transferred to the client records. These can be kept securely in personal notes for reference or disposed of after treatment.
Why Record Keeping Matters
It protects your clients. Accurate, up-to-date notes let you and any other practitioner involved in a client’s care understand their history, track how they’re responding to treatment, and spot any warning signs early.
It protects you. If a client ever raises a complaint or brings a claim against you, your records are often the first and most important evidence you have. Full, accurate and contemporaneous notes give your insurer the best chance of defending you against allegations of negligence or injury, and this holds true even when you’ve done nothing wrong.
It’s a condition of your insurance. Most professional indemnity insurers require you to keep consultation records as a condition of cover. If your notes don’t meet the standard your policy requires, you could find your insurance doesn’t respond when you need it most.
It’s a legal requirement. Under UK GDPR, client records are personal data, and you have a legal duty to handle that data properly, including deciding, documenting, and sticking to a sensible retention period.
How Long Should You Keep Records?
This is the question practitioners ask most often, and the honest answer is that there isn’t one single legal number written down anywhere. UK GDPR doesn’t set a fixed retention period for any type of data. Instead, it puts the responsibility on you to decide a period that’s justified by your purpose for holding it, and to document that decision.
That said, in practice there’s a strong consensus across the sector:
We recommend 7 years. Most professional indemnity insurance policies have a limit of liability of 6 years, matching the standard limitation period for civil claims in England and Wales. We recommend keeping records for 7 years, adding a year’s buffer on top of that limit. This extra year allows for the time it can take a client to raise an issue, and for any claim to be formally processed once it’s made, so your records are still there and complete when they’re needed most.
Records for children and young people need to be kept much longer. Because minors have longer to bring a claim once they reach adulthood, retention periods for their records are typically measured from their 18th birthday rather than from the date of treatment, and should run for at least 7 years from that point.
Check your specific insurance policy. Insurers vary in what they require, and your policy is a contract, so its terms take priority over any general guidance.
These are minimums, not maximums. If a client’s case was complex, involved a higher level of risk, or is connected to an ongoing complaint or investigation, keep the records for as long as that risk remains live, and don’t destroy anything relevant to an open complaint or legal proceedings.
Storing and Disposing of Records Securely
Holding records for the right length of time is only half the job. You also need to store them securely for as long as you keep them, whether they’re on paper or digital, and dispose of them securely once the retention period ends. Deleting or shredding records once they’re no longer needed isn’t optional under GDPR. Keeping data indefinitely, “just in case,” is itself a compliance risk, since the law requires you to hold personal data for no longer than you can justify.
A Simple Checklist
- Record every consultation in enough detail to reconstruct what happened
- Check your insurance policy’s specific retention requirement
- Default to seven years for adult clients, extended for children and young people
- Keep hold of anything connected to an open complaint or claim, however old
- Store records securely, and destroy them securely once the retention period is up
- Write your retention policy down, so it’s consistent and defensible
Good record keeping takes a few extra minutes at the end of each session. Set the habit early in your career, and it will quietly protect both your clients and you for years to come.
Author – Michelle Bebbington – Course Coordinator and Assessor
References
Balens, Record Keeping: what every health and wellbeing practitioner needs to know – balens.co.uk/educational-resources/record-keeping-what-every-health-and-wellbeing-practitioner-needs-to-know
Federation of Holistic Therapists, Insurance – fht.org.uk/insurance
Howden Group, Guidance for Therapists on Note and Record Keeping – howdengroup.com/uk-en/therapist-note-keeping
Information Commissioner’s Office, Principle (e): Storage limitation – ico.org.uk
