# 0013 — Signed clinical notes are versioned, never rewritten

**Status:** Accepted · 2026-08-02

## Context

The clinical note is the single most consequential record in the system. When a
complaint, a claim or a coroner's inquiry looks at a case, the first question is
not what the record says now — it is *what did the record say at the time the
decision was made*, and *was anything changed afterwards, by whom, and why*.

An `UPDATE` on a note table makes that question permanently unanswerable. Worse,
it makes an honest correction indistinguishable from a cover-up, which harms the
clinician who made the correction in good faith.

The obvious response — treat every save as an immutable version — has its own
failure mode. A clinician correcting a typo mid-sentence should not generate a
legal amendment. Systems that do this train people to compose the note in a text
editor and paste it in when finished, which destroys the contemporaneous timing
the record existed to capture.

## Decision

A line between **draft** and **signed**.

**Draft** is working material. It is editable in place, by its author only, and
is not part of the record. No versions, no reasons, no ceremony.

**Signing** is an attestation. Only the author can make it — no permission
grants the right to sign in somebody else's name. From that moment the text is
fixed.

**Amending** a signed note writes a **new row** with the next version number,
`supersedes_id` pointing back, and a mandatory reason of at least ten
characters. The superseded row is left byte-for-byte intact and marked
`amended`, with `superseded_by_id` pointing forward. Both directions are stored
so the chain walks either way in a single indexed lookup.

Amendment is deliberately open to another clinician, not just the author: a
colleague correcting a factual error on the record is legitimate, and the
amendment carries their name and their stated reason.

**Retraction** marks `entered_in_error` with a reason. The row stays and the
text stays. "Recorded then retracted" and "never recorded" are different
clinical facts, and only the first can explain a decision made that day.

**Enforcement is at the model, not only the service.** `EncounterNote::save()`
throws if the body of a non-draft note is dirty, and `delete()` throws
unconditionally. The service is not the only thing that can reach a model — an
importer, a console command, a future API controller and a well-meaning refactor
all go through `save()`, and a rule that lives in one calling path protects one
calling path.

**Nothing new can be added to a closed encounter.** Notes appearing hours after
a consultation ended are a well-known pattern in records that end up in front of
a lawyer. Amending an existing note remains possible and leaves a dated,
reasoned trail.

## Consequences

**Good.** The record can always be reconstructed as of any date. An honest
correction is visibly an honest correction. The version history is shown inline
on the consultation screen rather than buried in an audit view nobody opens —
"what did this say before?" is a question clinicians ask in the room.

**Bad.** The notes table grows with every amendment and never shrinks. At clinic
volumes this is nothing; the alternative loses information that cannot be
recovered at any price.

**Bad.** Rendering a note's history has to be done from the versions already
loaded, not by walking the relation — otherwise a consultation with four
twice-amended notes costs twelve extra queries per page. `chainFrom()` takes the
pool explicitly and the caller must supply it. This was caught by
`preventLazyLoading` rather than by review, which is the argument for having it
switched on in development.

**Honest limit.** `saveQuietly()` and `forceFill()` still reach the row, and
anyone with database credentials can rewrite it directly. This is a guardrail
against ordinary mistakes, not a claim of tamper-proofing. The hash-chained
audit trail ([ADR 0005](0005-tamper-evident-audit-trail.md)) is what covers the
rest, and it records the prior text on every amendment independently of the
chain.

## Related

The same principle, applied more simply, governs allergies, conditions,
medications and diagnoses ([ADR 0010](0010-clinical-records-are-append-only.md)).
Notes get full versioning because their content is long-form clinical reasoning;
the others only need a status, because a retracted allergy has nothing to
supersede.
