Security, privacy and audit requirements · C0906
How long would audit records be kept?
Designed, not yet built
Short answer
How would it be tested? The specification says retention config cannot go below profile value. That is the check for REQ-4506: audit retention must meet the longest applicable profile requirement; HIPAA documentation retention is 6 years (to be verified). Not yet. It is designed in the specification and not built in the pilot.
This is designed, not built.
- Specification item
- REQ-4506
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Would the system detect snooping and unusual access patterns? Designed
- Can an outside auditor read the audit trail, and is their own access logged? Pilot
- Could a patient see who has looked at their record? Pilot
See it in context: Audit · Search the help center · Ask a question