MyHealthVault policy

Data deletion

Effective October 11, 2026 · Version 2026-10-11

Delete from account settings

Signed-in users can open Settings, export their information if desired, and use the permanent deletion form. The request requires the current password, an explicit confirmation phrase, and MFA verification when MFA is enabled.

What the workflow removes

The workflow first revokes active doctor links, then removes private uploaded files, patient profile information, records, medications, conditions, reminders, visits, caregiver permissions, access history, consent receipts, notification subscriptions, and the authentication account.

Failure safety

If private files cannot be inventoried or removed, account deletion stops rather than leaving inaccessible orphan health documents. Active sharing is revoked before destructive cleanup begins. Operational failures generate privacy-safe security alerts without medical content.

Backups and legally required retention

Production backup expiration, billing records, fraud-prevention records, legal holds, and jurisdiction-specific retention must be documented in the final retention schedule. Backup copies should expire automatically and must not be restored into active use after a valid deletion request except where legally required.