Version 2026.05.1
Data Retention Disclosure
This disclosure explains the principles ScoliBase and ScoliBase Connect use to retain account, operational, healthcare-related, brace-tracking, security, and audit data, including backup and legal-hold considerations.
Retention Principles
ScoliBase and ScoliBase Connect retain information for as long as reasonably necessary to provide and administer the applicable services, support care coordination, maintain account functionality, protect security, satisfy audit and compliance requirements, resolve disputes, maintain backups, and comply with legal obligations.
Retention periods may differ depending on the type of information, the purpose for which it was collected, the applicable healthcare relationship, contractual requirements, and applicable law.
ScoliBase Connect Data
Information associated with ScoliBase Connect may include account identifiers, patient or guardian associations, brace wear sessions, manually entered wear time, brace wear history and progress, notes entered by users, authentication information, and application security or operational records.
Brace-tracking information associated with a ScoliBase account may be retained as part of the broader ScoliBase record or healthcare-related workflow and may remain available after an individual mobile session or application installation ends.
Categories of Information
Retention may vary by record type, including account records, patient and guardian information, protected health information (PHI), brace-tracking records, clinical or care-coordination information, appointment records, messaging records, uploaded files, support records, security events, authentication records, audit logs, analytics or performance records, and backups.
Healthcare and PHI Records
Healthcare-related information and PHI may be subject to retention requirements established by healthcare organizations, applicable federal or state law, professional or regulatory requirements, payer requirements, contractual obligations, or other healthcare record retention standards.
As a result, deletion of a ScoliBase account or ScoliBase Connect application access may not require or permit deletion of healthcare records that must otherwise be retained.
Account Closure and Deletion Requests
Where permitted, users may request closure or deletion of certain account information through available account, support, or privacy channels.
A deletion request does not necessarily result in deletion of every record associated with the user. Information may be retained when necessary for healthcare recordkeeping, legal compliance, security, fraud prevention, audit requirements, dispute resolution, enforcement of agreements, or other lawful purposes.
Deletion and Backups
When information is deleted from active systems, copies may remain for a limited period in backups, disaster-recovery systems, operational replicas, cached systems, security records, or archival environments until the applicable retention or backup cycle expires.
Backup copies are generally maintained for recovery, security, and continuity purposes and may not be immediately accessible for individual record deletion.
Security and Audit Records
Security logs, authentication records, audit trails, access history, and related records may be retained independently of other account information when reasonably necessary to investigate security events, demonstrate compliance, detect unauthorized activity, or preserve the integrity of ScoliBase systems.
De-Identified and Aggregated Information
Information that has been appropriately de-identified or aggregated so that it is no longer reasonably associated with an identifiable individual may be retained for analytics, research, operational improvement, security, statistical analysis, or other lawful purposes, subject to applicable requirements.
Legal Hold Exceptions
Information may be retained longer than an otherwise applicable retention period when reasonably necessary for litigation holds, investigations, regulatory inquiries, audits, legal claims, preservation requests, or comparable legal and compliance obligations.
Information subject to a legal hold will generally not be deleted until the hold or preservation obligation has been released.
Third-Party Service Providers
Vendors and service providers supporting ScoliBase or ScoliBase Connect may retain information according to contractual requirements, security obligations, backup practices, and applicable law. Where appropriate, ScoliBase requires service providers to protect information and limit its use to authorized purposes.
Changes to Retention Practices
Retention practices may be updated when services, operational needs, healthcare requirements, contractual obligations, or applicable laws change. Material changes may be reflected in an updated version of this disclosure.
Contact
Questions regarding retention, deletion requests, or information associated with ScoliBase or ScoliBase Connect should be directed to the designated ScoliBase privacy or support contact channels published by the organization.
