When OSHA issues a citation, a lawsuit is filed, or an insurance claim is opened, your safety records stop being paperwork and become legal evidence. Deleting, modifying, or losing those records — even by accident during a routine office cleanup — can trigger spoliation sanctions: an adverse-inference instruction to the jury, evidence thrown out, or a larger penalty. The duty to preserve attaches the moment you reasonably anticipate litigation, which for a construction employer is often the day the citation lands.
HazComFast's Legal Hold locks the relevant records the instant a legal event triggers, so nothing is lost or altered while the matter is open.
At a glance: The duty to preserve attaches once litigation is reasonably anticipated — often the day an OSHA citation lands, which also starts the 15-working-day contest clock (1903.17). A legal hold locks relevant records so they can't be deleted or edited (even by admins) and overrides normal retention (1910.1020: employment + 30 yrs; 1904.33: 5 yrs). A legal hold locks safety records the moment litigation is reasonably anticipated, preventing spoliation sanctions, and it overrides normal OSHA retention schedules so a held record cannot be deleted even after its retention date passes.
The moment records become evidence
A held record can't be deleted even after its normal 1910.1020 / 1904.33 retention date passes — and the 15-working-day contest clock (1903.17) starts the same day.
What a legal hold must preserve
A legal (or litigation) hold is a directive to preserve all documents that may be relevant to a proceeding. In construction safety, that usually means:
- SDS access and read-proof confirmations,
- Training records and sign-in sheets,
- Near-miss and incident reports,
- Inspection records and corrective actions,
- Equipment inspection histories,
- Permit records (hot work, confined space, excavation),
- Chemical inventory changes.
Why paper systems fail a legal hold
| Risk | Paper records | HazComFast Legal Hold |
|---|---|---|
| Accidental deletion | Files tossed during cleanup | Locked records cannot be deleted by any user |
| Modification | Entries altered after the fact | Every change is logged with the user who made it |
| Loss | Water, fire, theft | Cloud + local backups with redundancy |
| Incomplete preservation | Hard to find all relevant records | System-wide search flags everything in scope |
| Chain of custody | Hard to prove authenticity | Timestamped, user-attributed audit logs |
The 15-day clock: why timing is everything
Under 29 CFR 1903.17, an employer who wants to contest a citation has 15 working days from receiving it to notify the OSHA Area Director in writing. Miss that window and the citation and its penalty become a final order — no review, no negotiation. That same 15-day period is when your defense is built, and it depends entirely on records that must not change underneath you.
- Day 1 — citation received → activate the legal hold.
- Days 1–3 — the system identifies and locks every relevant record.
- Days 3–10 — review the locked records to build the defense.
- Days 10–15 — generate a citation-defense package from the locked set.
- Contest or abate — the locked records serve as evidence throughout.
Without a hold, records from the citation period can be overwritten or deleted during normal operations — quietly destroying the defense you are trying to build.
How the hold works
Trigger — a manager specifies which record types the hold covers (incident reports, training records, SDS documents, permits…), the reason (citation, lawsuit, claim), and the custodian. Identify — every record of the covered types falls under the hold, organization-wide. Lock — a held record cannot be deleted; the refusal comes from the database, not the screen, and a deletion attempt made through the application is logged as blocked with its reason. Monitor and release — a dashboard shows active holds; the custodian releases the hold when the matter closes, and the release is logged.
How to test whether a hold actually locks anything
Most safety software sells legal hold as a checkbox. Here is the test that separates a lock from a label, and you can run it on any product — ours included:
- Place a record under hold, then try to delete it from the normal screen. Every vendor passes this step; the delete button greys out or an error appears. This proves nothing yet.
- Now bypass the screen. Have someone with API access send the delete request directly to the backend — every modern SaaS has one, and opposing counsel's discovery expert knows it. If the record disappears, the hold was enforced by the user interface alone, and the interface is not where your data lives.
- Check the trail. Now make the same attempt through the application and look for a log entry recording who tried, when, and why it was refused, written by the system rather than by an optional client call that a crashed browser tab would silently skip. Do not expect the refused API call of step 2 to leave that line: a database that refuses a delete rolls the whole transaction back, journal entry included, so the trail is proven on the application path.
- Check what expiry does. Set a hold's end date in the past and try the delete again. On some systems a lapsed date quietly stops protecting. A hold should keep protecting until a person explicitly releases it. An expired date is a reminder to review; nothing should open on its own.
We ran this test against HazComFast ourselves during acceptance testing on August 19, 2026: the direct API delete comes back refused by the database across the 23 record tables a hold can cover, a refusal that by its transactional nature leaves no journal line of its own; the blocked attempt through the application writes a blocked line with its reason to an audit log that itself accepts no edits or deletions; a hold past its end date keeps refusing until explicitly released; and deleting the entire organization while a hold is active is refused too. And the other side of the test matters just as much: releasing the hold genuinely releases, and a legitimate deletion then goes through — with a required reason, logged. A lock that can never open isn't a control, it's a malfunction.
And so you hear it from us rather than discover it: the lock is on deletion. Field-level edit protection on held records is enforced by the application, not yet by the database layer.
How it fits OSHA's retention duties
A legal hold sits on top of — and overrides — your normal retention schedule:
- 29 CFR 1910.1020(d): employee exposure and medical records are kept for the duration of employment plus 30 years. (See the deep dive on 30-year record retention.)
- 29 CFR 1904.33: the OSHA 300, 300A, and 301 forms are kept for five years following the year they cover.
- A record under legal hold cannot be deleted even after it reaches its normal expiration date.
Read the underlying access-and-retention rule on the Access to Employee Exposure and Medical Records (1910.1020) page, and know your penalty exposure in the 2026 penalty schedule.
Lock the record before it can quietly disappear
When a citation or claim lands, the defense depends on records that can't change underneath you. HazComFast holds relevant records the moment you trigger it — no deletion or edit, every attempt logged — and rolls the locked set into a citation defense package. Estimate the exposure, then keep the evidence intact on trial.
The hub & related: OSHA recordkeeping — 300, 300A & 301 · 30-Year Record Retention: OSHA 1910.1020 · How to Contest an OSHA Citation · The OSHA Citation Defense Package · Read-Proof SDS Confirmation · How long to keep each OSHA record
Sources & verification (retention re-read 2026-10-08 on the eCFR, title 29 up to date as of 2026-10-06; the rest verified 2026-07-17 against osha.gov): the 15-working-day contest window per 29 CFR 1903.17; retention per 29 CFR 1910.1020(d) and 29 CFR 1904.33. Spoliation and legal-hold duties arise under the Federal Rules of Civil Procedure and case law, not OSHA. General guidance, not legal advice.
Frequently Asked Questions
What is a legal hold, and why does it matter for safety records?
A legal hold (or litigation hold) is a directive to preserve every document that may be relevant to a legal proceeding — an OSHA contest, a lawsuit, or an insurance claim. Once you reasonably anticipate litigation, the duty to preserve attaches, and if relevant safety records are then deleted or altered, even accidentally during routine cleanup, a court can sanction the party that lost them. Note where the duty comes from, because it changes who you argue with: spoliation is a matter of civil procedure and case law, not of OSHA. What OSHA sets is the floor underneath it. 29 CFR 1910.1020(d) tells each employer to 'assure the preservation and retention of records,' with each employee exposure record preserved 'for at least thirty (30) years' under (d)(1)(ii), and 29 CFR 1904.33(a) says you 'must save the OSHA 300 Log, the privacy case list (if one exists), the annual summary, and the OSHA 301 Incident Report forms for five (5) years following the end of the calendar year that these records cover.' A hold is what keeps a record past those dates and out of the routine cleanup that would otherwise be allowed.
How long do I have to contest an OSHA citation?
15 working days from the day you receive the citation. Under 29 CFR 1903.17, an employer who intends to contest must notify the OSHA Area Director in writing within that window, or the citation and penalty become a final order not subject to review. The moment a citation arrives is the moment to trigger a legal hold on every record from that inspection period.
How long must OSHA safety records be kept?
It depends on the record. Employee exposure and medical records must be kept for the duration of employment plus 30 years under 29 CFR 1910.1020(d). OSHA Form 300, 300A, and 301 recordkeeping forms must be retained for five years following the year they cover under 29 CFR 1904.33. A legal hold overrides these schedules: a held record cannot be deleted even after it reaches its normal expiration date.
Can a record under legal hold be deleted?
No. Deletion of a held record is refused by the database itself, not by the application's screens — so the refusal holds even against a direct API call, and an administrator account has no way around it. The dates that refusal protects are OSHA's own: 29 CFR 1910.1020(d) requires the employer to assure preservation and retention, (d)(1)(ii) keeps each employee exposure record at least thirty years, and 29 CFR 1904.33(a) keeps the 300 Log, the privacy case list, the annual summary and the 301 forms five years past the calendar year they cover. A deletion attempt made through the application is written to the audit log as blocked, with the user's identity and a timestamp, and the audit log itself accepts no edits or deletions. That preserves the chain of custody you need to prove the record is authentic.
Can a legal hold be scoped to specific workers or jobsites?
A hold is scoped by record type: you choose which categories it covers — incident reports, training records, SDS documents, permits — and every record of those types is then protected across the organization. That is the same unit OSHA uses: 29 CFR 1904.33(a) names record TYPES — the 300 Log, the privacy case list, the annual summary, the 301 forms — and 29 CFR 1910.1020(d) sets its periods by category of record, not by employee or by site. It cannot be narrowed to one worker, one jobsite, or a date range. In practice that breadth works in your favor: preservation duties are read broadly by courts, and a hold carved too finely is exactly how a relevant record slips through and becomes a spoliation problem. The custodian (often legal counsel) releases the hold when the matter concludes, and the release is logged.
How do I verify that my software's legal hold actually locks anything?
Run the test on a record whose loss would actually cost you: one of the employee exposure records 29 CFR 1910.1020(d)(1)(ii) keeps for at least thirty years, or one of the forms 29 CFR 1904.33(a) keeps for five. Then don't take the lock icon's word for it — test the layer underneath the screen. Have someone with API access attempt to delete a held record directly, bypassing the application. If the record disappears, the 'lock' was a label painted on the interface, and it will not survive contact with a determined litigant's discovery expert. A real hold is enforced where the data lives: the database refuses the delete no matter which client asked.
OSHA figures and citations here come from our regulatory source-of-truth modules, last checked against the eCFR, OSHA.gov, and the Federal Register on October 5, 2026. Last reviewed August 26, 2026.
About This Article
Published by: HazComFast
Published: February 26, 2026
Last Updated: August 26, 2026
This content is for informational purposes only and does not constitute legal advice.
