Security, privacy and audit requirements · C0904
Could a patient see who has looked at their record?
In the pilot (v0.2.0, synthetic data)
Short answer
REQ-4504 is a top-priority requirement for all three tiers: audit must provide a patient-facing accounting-of-disclosures and access-history view without exposing workforce personal data beyond profile rules. The pilot covers part of this. The rest is designed, not built. What v0.2.0 does today: Per-patient access report for privacy staff; not patient-facing. To verify it, the specification says report matches underlying audit.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-4504
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Can anyone edit or delete audit records once written? Pilot
- Would the system detect snooping and unusual access patterns? Designed
- How long would audit records be kept? Designed
- How would audit records be chained, batched and anchored to the ledger? Designed
See it in context: Audit · Search the help center · Ask a question