Security, privacy and audit requirements · C0905
Would the system detect snooping and unusual access patterns?
Designed, not yet built
Short answer
The audit part of the specification (REQ-4505) says audit analytics must detect snooping (VIP, coworker, neighbor, family), volume anomalies, off-hours access and repeated denials, producing review items with SLA. No. The specification describes it, but the pilot does not include it. Acceptance check: seeded snooping scenarios detected in test.
This is designed, not built.
- Specification item
- REQ-4505
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Could a patient see who has looked at their record? Pilot
- How long would audit records be kept? Designed
- Can an outside auditor read the audit trail, and is their own access logged? Pilot
- Can anyone edit or delete audit records once written? Pilot
See it in context: Audit · Search the help center · Ask a question