Security, privacy and audit requirements · C0901
Which events does the audit trail record, and what does each entry contain?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. Pilot detail: Per-clinic SHA-256 hash chain (tamper-evident, verify endpoint, edit/delete/reorder detected in tests); not WORM storage. For reference, REQ-4501 (a top-priority requirement, all three tiers) says every access, change, print, export, consent, authentication, admin, alert and break-glass event must generate an audit record with actor, role, terminal, purpose, patient pseudonym, object type, action, outcome, time and correlation id. Check: audit schema validation; 100% of covered actions produce a record in test.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-4501
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How would audit records be chained, batched and anchored to the ledger? Designed
- Can anyone edit or delete audit records once written? Pilot
See it in context: Audit · Search the help center · Ask a question