Exports and leaving
Who this page is for: the practice manager doing diligence on the exit before signing the entry - the right order.
Data portability is separate from subscription-cancellation wording. This page distinguishes the self-service export available now from the complete evidence path that must be deployed and proven before real-data activation. Cancellation and closure follow the accepted terms and the authenticated process described below.
What exports now
Section titled “What exports now”An authenticated owner can download one tenant-scoped JSON file at no export charge. It contains:
- practice, member, channel and notification settings;
- every structured referral record available to that tenant; and
- every available hash-chained event, including the terms-acceptance history.
The first-50 capture allowance never blocks reading or export. Platform credentials,
session material and other tenants are excluded. The response is no-store and downloads
as an attachment. Before either the JSON or complete evidence response begins, Refera must
append a keyed event to that tenant’s export audit. It records the authenticated business
account, role, format and complete-tenant scope, but no patient, referral, source-document,
request-body or network data. If the audit append fails, the export fails closed.
Complete evidence package
Section titled “Complete evidence package”The complete evidence implementation adds a private ZIP containing the sanitized tenant
JSON, every referral projection and sealed event log, each exact inbound source envelope,
decoded original PDF/image attachments, verification instructions and manifest.json.
Every listed file has an independently reproducible SHA-256 digest. The package deliberately
does not contain the server HMAC key.
Object-Locked source-archive storage is deployed in AWS Sydney. Complete source retention, authenticated retrieval, GuardDuty handling, readback, migration and export remain unavailable until the lifecycle is proven end to end. The Settings control fails closed until those proofs pass. A legacy referral without a provable exact original makes the complete package unavailable rather than receiving invented evidence.
The sealed history travels
Section titled “The sealed history travels”The JSON export includes the available hash-chained event history in a documented format, so the practice keeps the sequence and chain heads. Production chains use a server-held HMAC key; the current JSON is not independently verifiable from the file alone. Refera does not export a shared server secret. The evidence manifest lets the practice verify file bytes and source-to-referral bindings; keyed event-seal verification stays on the authenticated Refera verifier. See Verify your history for the exact verification boundary.
Controlled closure on exit
Section titled “Controlled closure on exit”An owner can record a closure request only after verifying a passkey within the previous five minutes. Email links, authenticator codes and recovery codes cannot authorise it. The request is sealed, versioned and handed to Refera operations through a durable retryable queue. No browser button immediately deletes health records.
The controlled states are requested, verified, approved, export ready, scheduled and completed. Rejected and failed are explicit stop states; they do not silently advance. Refera verifies authority, records approval, proves the export package, records the governing retention reference and reaches the scheduled time before completion. Until completion, workspace access and the ABN claim remain unchanged.
There is no automatic or contractual completion deadline encoded in the product. The durable operations alert is not proof that a review or closure has happened, and the only enforced timing rule is that completion cannot occur before the recorded scheduled time. Status updates report the actual sealed state rather than an estimated deletion date.
Completion closes workspace discovery and access and releases the tenant-owned ABN uniqueness claim. It does not delete the tenant record, sealed events, source-document evidence or executed agreement. Those remain under the recorded retention policy, and any later disposal needs its own approved process. Source-archive retention is not an automatic legal deletion rule. Production uses one encrypted, pooled DynamoDB table with tenant-partitioned access; Refera does not claim a separate per-practice encryption key or instant cryptographic erasure.
Why this is also a retention argument
Section titled “Why this is also a retention argument”The things that make practices stay should still be useful: a history that accumulates and cannot be recreated after the fact, and intelligence that deepens with every month of referrals counted at the door. Structured export and a controlled closure path keep those reasons to stay, not barriers to leaving.
Did this answer your question?
Thanks - that helps us make these docs better.
Refera tracks referral admin only. It does not triage patients.
Examples are fictional and contain no patient information. Practice staff approve every external action. Refera never auto-sends or independently contacts patients.
Refera homeStart account setupOpen ReferaPrivacyTerms
[email protected]AI-assisted product and setup support. For a person, use the contact form or email.