Security, privacy and audit requirements · C0903
Can anyone edit or delete audit records once written?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. In the pilot: Per-clinic SHA-256 hash chain (tamper-evident, verify endpoint, edit/delete/reorder detected in tests); not WORM storage. REQ-4503 says audit storage must be append-only with WORM tier and no update or delete interface for any role. Its acceptance check: attempted update fails and is itself audited.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-4503
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How would audit records be chained, batched and anchored to the ledger? Designed
- Could a patient see who has looked at their record? Pilot
- Would the system detect snooping and unusual access patterns? Designed
- Which events does the audit trail record, and what does each entry contain? Pilot
See it in context: Audit · Search the help center · Ask a question