/
Configure Dermi Atlas Professional's audit logging features to track system activity, monitor access, and support regulatory compliance requirements.
Audit logging is a critical feature for maintaining accountability and visibility into how patient data is accessed. Dermi Atlas Professional includes a configurable logging system that tracks user activity, system access, and data operations.
This data is essential for security incident investigations and is often a requirement for healthcare privacy compliance (such as HIPAA and PIPEDA).
Dermi Atlas Manager allows administrators to configure the depth of logging based on storage capacity and compliance needs. Sign-in, account security, and administration events are recorded at both levels; the level governs clinical events only.
Essential logging captures high-level security events with minimal impact on storage.
Events captured:
Best for: Practices with limited storage capacity or lower regulatory reporting requirements.
Comprehensive logging, the shipped default, provides a granular audit trail of almost all user interactions within the system.
Events captured:
Best for: Practices subject to strict audit requirements (e.g., HIPAA) or those requiring detailed forensic data in the event of an incident.
Activity is recorded per feature, so a specific area of the record can be isolated later. Full body photography is one example: sessions and the lesion records documented within them are logged under a Full Body resource type that the patient log view can filter on.
Illustrative demo with synthetic data. Learn more
Audit logging is configured globally via the Dermi Atlas Manager desktop application, in the Settings group of the Administration area. That area is locked at every launch and is opened by entering the admin passphrase set on the host computer, so the logging level, the deletion policy, and the retention period cannot be changed from a clinician's browser session. See Atlas Manager Administration.
To change the logging level:
Note: Changes to logging levels apply to future events only. Previously recorded logs retain their original detail.
Audit logs are stored in the local database. Each entry typically contains:
A deployment holds one practice team, and every member of it works on the same clinical records. The actor recorded on each entry is therefore what attributes an action to a person: the entry names the account that performed it, and that attribution stays in the log after the member leaves the team.
Users can view their own security history to verify their account integrity:
Clinical actions related to a specific patient record are viewable within the patient record:
The drawer holds the team's trail for that patient. Every member opens the same entries, each entry names the member who performed the action beneath its time, and the reader's own entries carry the suffix "(You)". Entries written by another member are shown without that member's IP address and device details.
Action, Resource, Member, and Period filters combine, so a dense history can be narrowed to the events under review. On a team with a single member, the member names and the Member filter are not shown.
Illustrative demo with synthetic data. Learn more
Illustrative demo with synthetic data. Learn more
Under the Essential level no new clinical entry is recorded; a drawer with nothing to list reports that audit logging is set to Essential, and entries recorded earlier under Comprehensive still list.
Sign-in and administrative activity on the deployment is read from the Administration Activity card in Dermi Atlas Manager, under the Deployment heading of the Administration area: every member's sign-ins and account security events, and every administrative action, newest first. Clinical activity is not listed there. The card is described in Atlas Manager Administration.
Illustrative demo with synthetic data. Learn more
For an audit that spans every patient, the complete record is the system backup. Since audit logs are stored locally, they are included in the system backups created from Backup Management in Dermi Atlas Manager.
How audit logs are handled during deletion depends on the Data Deletion Policy configured in Dermi Atlas Manager. Under the default Standard policy, the historical logs for a deleted record are removed at the time of deletion and a single deletion event is retained for the configured retention period; the Recoverable policy retains the full log history for that period instead. The default retention period is 120 months (10 years), which sits above common US and Canadian record-retention expectations. Records involving minors may require extended retention under applicable provincial or state law.
Administrators can configure the retention period through Dermi Atlas Manager:
Important: Changes to the retention period are applied retroactively to all existing deleted records and their associated audit logs. Reducing the retention period may cause previously deleted records to be permanently removed sooner, so a reduction requires typing the confirmation phrase "REDUCE RETENTION PERIOD" before it is applied. Extending the period will delay their removal.
For targeted removal of specific records, see Configuring Data Retention for Deleted Records.
Deleting an account on a deployment removes the person, not the practice's records. Patient records, images, and the clinical activity log belong to the team and stay in place, and the entries the departing member wrote keep naming that account as the actor, so the audit trail remains complete. What is removed with the account is its own account and authentication history, which is marked to expire at the end of the configured retention period rather than immediately. The account is also dropped from the assignment list of every patient it was assigned to.
Removing a member in Dermi Portal ends that person's access at the deployment's next check-in and likewise leaves everything they documented with the team; disabling the account under Administration => User Accounts in Dermi Atlas Manager ends it immediately. Neither deletes clinical data.
The only action that removes clinical data and the clinical activity log from a deployment is the Deployment Purge in Dermi Atlas Manager, described in Atlas Manager Administration. It is permanent, it keeps the accounts and the sign-in and administration activity log, and there is no software mechanism to reverse it. Maintaining system backups through Dermi Atlas Manager is the only way to preserve data ahead of it.
The Data Deletion Policy, configured in Dermi Atlas Manager, determines how audit logs are handled when patients, entries, or images are deleted:
Recommendation: For strict compliance environments, the Recoverable or Standard Data Deletion Policy is preferred to maintain a historical record of access, even after data is deleted.
Your feedback helps us improve our documentation
Contact our support team for personalized help
All demonstrations, screenshots, and media on this page use synthetic data only. No real patient information is shown.
The following are synthetic and do not correspond to real patients:
Media is provided solely to illustrate platform functionality and workflows.