# 0010 — Clinical records are retracted, never deleted

**Status:** Accepted · 2026-08-02

## Context

An allergy, a diagnosis or a medication gets onto a patient record and later
turns out to be wrong — recorded against the wrong patient, mistyped, or
disproved. The obvious interface is a delete button.

After an adverse reaction, the first question anyone asks is "was this allergy on
the record at the time?". A deleted row makes that unanswerable. "Recorded and
later retracted" and "never recorded" are different clinical facts, and the
difference is exactly what a complaint, an incident review or a claim turns on.

## Decision

`PatientAllergy`, `PatientCondition` and `PatientMedication` override `delete()`
to throw. There is no destroy route and no delete button anywhere in the module.

Retraction is a status change to `entered_in_error`, and a reason is mandatory
for that transition and optional for every other. The entry stays on the record,
struck through, with who recorded it, who retracted it, when, and why. The
`ClinicalRecordStatus` enum draws the distinction the rest of the system needs:
`isCurrent()` for "describes the patient now", `isClinicallyRelevant()` for
"may influence a decision" — a resolved condition is history worth reading, an
entry made in error must never drive a warning or a dose.

Emergency contacts are deliberately excluded and remain soft-deletable. A contact
is demographic data that goes stale, not a clinical finding, and removing an
ex-partner from an emergency contact list is a reasonable request.

## Consequences

**Good.** The record can always answer what was known and when. The guard is at
the model, so it holds for the API, an importer and a future mobile client, not
just the screens we have written.

**Bad.** The problem list grows monotonically and needs filtering in the
interface rather than pruning in the data. Acceptable — the volume is small and
the alternative loses information that cannot be recovered.

**Consequence worth stating.** A patient exercising a right to erasure cannot be
served by deleting rows here. That is a deliberate, separately reviewed process
with clinical-retention law on the other side of it, not a button on a record
screen — and the same reasoning applies to the patient record itself, which is
archived rather than removed because encounters, prescriptions and invoices point
at it.

## Related

The absence of an allergy record is displayed as explicitly as its presence. A
blank space reads as "no known allergies" when it usually means "nobody has
asked", so the banner says which one it is.
