Practices do not stay on paper because they prefer paper. They stay because of one unanswered question: can I actually throw it away afterwards?
Nobody wants to spend a fortnight scanning eight years of files, shred the originals, and then be asked for a record in a complaint two years later that a court decides does not count. So the filing cabinet stays, and the practice runs two systems, and the migration never happens.
The answer is more interesting than a straight yes, and understanding it properly is what unblocks the whole project.
What the law actually says about scanned records
There is no UK statute that makes a scan automatically equivalent to an original. If someone told you there was, they were simplifying.
What exists instead is BS 10008, the British Standard for Evidential Weight and Legal Admissibility of Electronic Information. It exists precisely so organisations can destroy paper originals with confidence. Under it, originals can be securely destroyed after scanning provided a "true copy" is produced under a documented, authorised procedure.
The operative concept is evidential weight, not admissibility. A scanned record is admissible. The question a court asks is how much weight to give it, and that depends on whether you can demonstrate the scan was produced under a controlled process you actually followed. A properly scanned record with an audit trail carries substantial weight. A pile of phone photographs in a folder carries very little.
For practical purposes this means: you can go digital and destroy the paper, provided you can describe your process and show you followed it. Write the process down before you start scanning, not afterwards. It is a page of A4 and it is the entire difference.
If you are working in or alongside NHS services, digitisation projects are also assessed against DCB 0129, the NHS clinical risk management framework. Most private MSK practices will not be caught by this, but it is worth knowing the phrase if a commissioner asks.
Digitising is a deletion opportunity, not just a scanning project
This is the point most migration guides miss, and it saves more time than anything else here.
You have retention periods. In England and Wales, adult records are kept eight years from last contact; in Scotland, six; records for children and young people until their 25th birthday or eight years from last contact, whichever is later. Our retention guide has the full table.
Apply those dates to a paper archive and a meaningful proportion of it should already be gone. Every file past its retention date is not an asset you need to migrate. It is a liability you are supposed to have destroyed, and scanning it is the expensive way to carry on breaking the rules.
So the first job is not scanning. It is sorting into three piles:
- Active caseload. Anyone seen in the last 12 to 18 months. This migrates first and properly
- Within retention, inactive. Keep, but you do not need it in the system on day one
- Past retention. Destroy securely, and record that you did
That third pile is usually larger than people expect, and working through it is the most valuable afternoon of the whole project.
What UK GDPR adds once records become digital
Digitising does not create new obligations exactly, but it makes several existing ones enforceable in a way a filing cabinet never did. Health data is Article 9 special category data, and our GDPR guide covers the full picture. Three things change specifically at migration.
Records become searchable, which cuts both ways. A subject access request against a paper archive is a person with a highlighter. Against a digital system it is a query. That is enormously better for you, and it also removes any excuse for missing the one-month deadline.
Access control becomes real. A cabinet is either locked or it is not. A digital system can distinguish between what your receptionist sees and what only the treating practitioner sees. If your software does not support note visibility tiers, you have lost something in the move. Atlacare enforces three levels, patient-visible, internal, and confidential, with confidential notes restricted to the treating practitioner and the owner.
Retention becomes automatable, so failing to automate it looks worse. Nobody manually deletes a discharged patient's file eight years later. The whole reason paper archives become indefinite retention is that the deletion step depends on a human remembering in 2034. A system that tracks last-contact dates and applies a retention rule is doing the one part of compliance that is genuinely hard for a person to do reliably.
The consent trap
This is where migrations most often go wrong, and it is worth slowing down for.
Your historic patients consented to treatment, in a paper world, probably by signing a form or simply by attending. What most of them did not do is give you a documented, GDPR-shaped marketing consent, because when they first attended, nobody was asking that way.
When those records land in a new system, the temptation is to mark everyone as consented, because the alternative looks like losing your entire mailing list. Do not do this. Recording a consent that was never given is worse than having no record, because now you have created a false audit trail, and you will rely on it to send marketing you were not entitled to send.
The correct handling is to record what actually happened: consent obtained offline, on a date, in a form that predates your current process. Atlacare's import wizard captures exactly this, marking imported patients with an OFFLINE consent status rather than silently defaulting them to consented. It is less flattering and it is accurate, which is the point. You can then re-consent the ones you want to market to, deliberately, and leave clinical care unaffected, because treatment does not run on consent as its lawful basis anyway.
The practical sequence
1. Write your scanning procedure first. One page. What gets scanned, at what resolution, who checks it against the original, how the checked scan is named and stored, when the original is destroyed, and who authorised the whole thing. This is what gives your records evidential weight later.
2. Sort into the three piles above. Destroy the past-retention pile securely and log it.
3. Pick your system before you scan anything. Scanning into a folder structure and then migrating again is doing the job twice. Look for note visibility tiers, retention handling, an audit log, and an import route that does not require you to hand-type demographics.
4. Migrate demographics by data entry or import, not by scanning. This is the distinction that halves the work. A scanned PDF of a patient's details is an image. It is not searchable, it does not populate a recall, and it cannot be exported later. Names, dates of birth, contact details, GP details and consent status should go in as structured data, even if the clinical history goes in as an attached scan.
If you are coming from another system rather than paper, this is a file export rather than typing. Atlacare's import wizard has presets for Cliniko, Jane, WriteUpp, Carepatron and Pabau, auto-maps the columns, and does fuzzy practitioner matching so "Dr S. Patel" and "Sarah Patel" resolve to the same person. Coming from paper, you will be typing the active caseload, which for most solo practices is a few hundred records and two or three evenings.
5. Scan clinical history and attach it to the right patient. Active caseload first. The inactive-but-within-retention pile can be scanned in batches over following months, or left in secure storage until its retention date passes, which is a legitimate choice and much cheaper.
6. Run both systems for a fortnight. Not longer. A short overlap catches what you forgot; a long overlap becomes permanent and you end up maintaining two systems forever.
7. Then destroy the paper, securely and in line with the procedure you wrote in step one. Cross-cut shredding or a certified destruction service. Keep the certificate.
What to do with the paper you keep
Some practices choose to retain originals in secure off-site storage rather than destroying them, at least for a transitional period. That is a perfectly reasonable belt-and-braces position, and if it is what it takes to get you to move, take it.
Just put a date on it. "We will review the boxes in twelve months" turns into a unit you are still renting in 2032 and quietly still holding records you should have destroyed. Storage is not neutral. Data you hold is data you are responsible for.
The honest summary
Digitising is not primarily a technology project. It is a decision about which records you should still be holding, a page of written procedure so scans carry weight, and then a fortnight of unglamorous typing.
The legal blocker most practices think they face is not really there. You can destroy the paper. You just have to be able to say, credibly, how it was scanned and who checked it.
Sources: BS 10008, Evidential Weight and Legal Admissibility of Electronic Information. NHS DCB 0129 clinical risk management framework. UK GDPR and Data Protection Act 2018. Retention periods per the NHS Records Management Code of Practice.
This guide is general information about record-keeping practice, not legal advice. If a specific record is likely to be disputed, take advice on it.
Related: UK GDPR for physiotherapists · How long do I need to keep physiotherapy patient records? · Practice management software for physiotherapists
