Security controls · C0155
Does the audit log store patient data?
Designed, not yet built
Short answer
The design keeps personal content out of logs and uses pseudonymous identifiers. A build test is specified to fail if a log schema holds restricted fields.
This is designed, not built.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Can a patient see the access history for their record? Designed
- Are reads audited or only writes? Designed
- Can auditors look without changing things? Designed
- Is there an immutable copy of the audit log? Designed
See it in context: Audit and tamper evidence · Search the help center · Ask a question