Practice archive
Take the complete record of the practice out as machine-readable files with an index of every part and original document, a manifest and a validation report.
Settings → Practice archive produces the whole record of the practice for a closure or a change of software: every table as JSON Lines parts, an index listing every part and every original document with its size and SHA-256 digest, a manifest that names the index, and a validation report that recounts every table after the export. Owners and anyone allowed to export data can request, download and acknowledge an archive.
Request an archive
Click Request archive and keep the page open. The archive is produced in short steps by the page itself: each step writes a few parts to the practice's clinical storage and the page shows how many tables are written so far. One archive is produced at a time. Closing the page pauses the archive where it is; opening it again, from any owner's browser, resumes it. Earlier completed archives stay listed and downloadable in full.
The archive is written to the same encrypted clinical storage as patient documents and copied to the backup account like any other document. The archive's own files and bookkeeping are not part of the record: they never appear in the tables they list.
Parts are sized by bytes, not by rows: a part closes at 8 MiB, and a single row wider than that — a long clinical note, say — makes a part of its own. No table, note or number of parts is too large for an archive to finish.
Download
A completed archive shows its Manifest and validation report and one or more Index files. Each Download opens a one-minute signed link. Open Parts to read the index: every table part with its row count, size and digest, then every original document of the practice — radiographs, consents, letters, invoices and the rest — with its id, type, size, owner and digest. Every download is written to the activity log.
Original files are listed and downloadable through the archive, not embedded in its parts. Download the originals while the account is live: once the practice is purged they are gone with everything else.
The manifest (format: smileline-practice-archive/2) names the practice, the
generation, the cut-off time, every table with its row and part counts, the
index files with their digests, and the total number and size of original
documents. It also lists the tables it leaves out under omitted: platform
machinery such as delivery lanes, work leases, budgets and payment-provider
receipts, which the practice's own role cannot read, and the archive's own
bookkeeping. Each index file and each part is one JSON object per line; parts
use the database's own column names. A reader verifies an archive from the
outside in: the manifest's digest, then each index file against the manifest,
then each part and each original against the index.
The validation report lists for each table the rows exported and the rows live when the archive closed, flags any table that moved in between, and records the practice's lifecycle when the archive was requested and when it completed.
Acknowledge
Acknowledge as received is offered only for the closure record: an archive whose every table recounted complete, requested and completed while the practice was in its closing period — when the app refuses new writes, so nothing can change underneath it. An archive produced while the practice was still active, or during which a table changed, stays a downloadable snapshot and says so; request a new one once the practice is closing. The acknowledgement records who confirmed receipt and when; it is the practice's evidence that the record left in full.
Work arriving from a connected system while the practice is closing — a change from the practice software, a remittance or an acknowledgement from the insurance clearinghouse — waits in the review queue instead of posting, and posts by itself if the practice is reopened.
After closure
When the closing period ends and the practice moves to purging, every clinical document it still holds — patient files, staff records, account statements, the archives themselves, and documents already deleted — enters custody. A document in custody keeps its own retention date and the identity of its owner (the patient's name, date of birth and chart number, the account or staff member's name), so the practice's other records can be purged around it. The acknowledged archive's generation is stamped on every document at that moment: it records which archive the practice closed under.
Custody is not a copy of the archive. A document is deleted only after its own retention date, with no legal hold on it and with both its copies verified, and a legal hold on a patient keeps matching that patient's documents after the patient's own record is gone.
Custody ends when the last document has been deleted. Each document in custody is deleted only under a disposition reference from counsel, recorded by Smileline on the practice's behalf once its retention date has passed; the documents are then removed from both the primary and the backup copy. When none remains, Smileline writes a permanent record of the closure — when custody began and ended, how many documents it held, the archive generations the practice acknowledged, the reference, and a digest of every deletion and copy record — and removes the practice entirely. That record is what an enquiry about the closed practice can be answered from. A practice that holds no clinical file at all finishes custody on its own, with a count of nought and no disposition reference: there was nothing to dispose of.