Skip to content

Procedure

Export and exit

Steps for exporting a hospital's data from Pensieve, the formats produced, and how a clean exit hands the record back to the hospital.

A hospital keeps its own data within reach at every stage. During the term it exports whenever it wants, with no notice and no fee. On exit it receives a full copy of everything it put in and everything the Platform generated about it, in standard formats, before Pensieve deletes its own copies to a published schedule.

Export during the term

A hospital's own users export its data from the Platform at any time, self-service, without asking Pensieve. The export is not gated on a ticket, an approval, an invoice or a notice period, and it carries no fee for the standard formats. A hospital that can export on an ordinary working afternoon for no reason is a hospital that is not locked in.

Data is never held hostage

Export proceeds regardless of a commercial dispute, of termination, and of non-payment. A disputed invoice, a termination for the hospital's own breach, and a termination for Pensieve's breach all leave the export rights untouched. Pensieve pursues an unpaid invoice through the remedies in its agreement, not by withholding a hospital's records, because those records are the evidence for the care the hospital has given and holding them back would create a patient-safety problem to win a payment argument.

What an export contains

Everything the hospital put in, and everything the Platform generated about it. The clinical record that Atlas holds travels as HL7 FHIR R4 resource bundles, the money that Vault runs travels as structured extracts, imaging travels as DICOM, and the one audit trail travels with them so the records keep their evidentiary integrity. A data dictionary and per-file checksums accompany every delivery, so the receiving team can load the export and verify it rather than take it on trust. The same export mechanism produces the downtime pack a hospital keeps for use when the link to the Platform is down. The pack lands on storage the hospital nominates and administers, so the hospital holds that copy rather than Pensieve.

ContentFormat
Clinical records: encounters, notes, orders, results, medication administration, allergies, vital signsHL7 FHIR R4 resource bundles, with a structured CSV or JSONL extract alongside
ImagesDICOM, with the accompanying study and series metadata
Billing, inventory, workforce and master dataStructured CSV or JSONL
Documents the Platform generated, such as reports and lettersPDF, with the structured data they were generated from
The audit trail: record access, amendments with prior values, disclosuresStructured JSONL
A data dictionaryDescribes each file, each column, each code system in use and each identifier

The exit sequence

On termination the process runs in a fixed order, with a named owner and an artefact at each step. The trial export at step three is the one that finds a problem while there is still time to fix it.

  1. 1

    Notice and an exit contact

    The hospital gives written notice of termination and names the person who will run the exit on its side.

  2. 2

    The exit plan

    Within five business days of notice, Pensieve issues an exit plan that names the export scope, the formats, the dates, the receiving system where it is known, and the named owners on both sides.

  3. 3

    A trial export the hospital verifies

    Before the termination date, Pensieve produces a trial export and the hospital verifies it against a sample of its own records.

  4. 4

    The full export

    Within ten business days of the termination effective date, Pensieve delivers the full export to the hospital's nominated secure destination, with checksums and the data dictionary.

  5. 5

    The retrieval window

    For sixty days from the termination effective date the hospital verifies the export and may request further exports.

  6. 6

    The deletion instruction

    On the hospital's written confirmation, or at the end of the retrieval window, the hospital issues a deletion instruction.

  7. 7

    Deletion from live systems

    Within thirty days of the deletion instruction, Pensieve deletes the data from the live systems: the database, object storage, the secret store and caches.

  8. 8

    Destruction of the downtime pack

    The hospital destroys any downtime pack held at its own sites and confirms that it has done so. The pack sits on storage the hospital administers, so the hospital carries out this step itself, and its confirmation is what the Certificate of Deletion records for the pack.

  9. 9

    Deletion from backups

    The tenant's key is destroyed first, after which any residual copy is cryptographically unrecoverable, and the backup sets then expire on their rotation, within ninety days of the live deletion.

  10. 10

    The Certificate of Deletion

    Within ten business days of the backup deletion completing, Pensieve issues a signed Certificate of Deletion recording what was deleted, from where and when, together with what statutory retention leaves behind.

Deletion, stated accurately

Deletion from live systems is prompt. Deletion from backups is not instantaneous, and Pensieve states the mechanism rather than an assurance. Pensieve does not restore, edit and re-write a backup set to remove one tenant, because that would compromise the backups protecting every other hospital. Instead the tenant's data encryption key is destroyed, which makes that tenant's data in any backup unrecoverable, and the backup sets then expire on their normal rotation, within ninety days of the live deletion. The Certificate of Deletion records the key-destruction date and the date the last backup set expired.

The honest sentence about backups

A vendor that claims data is deleted from backups the instant a contract ends either keeps no backups or is not describing what happens. Pensieve states the actual period and the order of events, key destruction first and expiry second, so a hospital can weigh the residual exposure for itself.

In DM-3 Customer cloud and DM-4 On-premise, exit is structurally simpler, because the data already sits in the hospital's own cloud project or on its own hardware. The hospital revokes Pensieve's access, Pensieve hands over the infrastructure-as-code and the runbooks, and Pensieve deletes nothing in the hospital's environment because it holds nothing there. The Certificate of Deletion then covers only any copies Pensieve held in its own systems, of which there are none beyond support correspondence.

Does a hospital have to be leaving to export?

No. The self-service export runs at any time during the term, with no notice and no fee for the standard formats. Leaving is one reason to export, not the only one.

Is the audit trail part of the export?

Yes. The one audit trail is included, so record access, amendments with their prior values, and disclosures travel with the records they describe.

Can a dispute or an unpaid invoice delay the export?

No. Export proceeds regardless of a dispute, of termination, and of non-payment.

Read where each class of data physically sits in where data lives, how long each record class is kept in retention, and which store is the authority for each record in the system of record.