Configure Dermi Atlas Professional's audit logging features to track system activity, monitor access, and support regulatory compliance requirements.
Audit logging is a critical feature for maintaining accountability and visibility into how patient data is accessed. Dermi Atlas Professional includes a configurable logging system that tracks user activity, system access, and data operations.
This data is essential for security incident investigations and is often a requirement for healthcare privacy compliance (such as HIPAA and PIPEDA).
Dermi Atlas Manager allows administrators to configure the depth of logging based on storage capacity and compliance needs.
Essential logging captures high-level security events with minimal impact on storage.
Events captured:
Best for: Practices with limited storage capacity or lower regulatory reporting requirements.
Full logging provides a granular audit trail of almost all user interactions within the system.
Events captured:
Your feedback helps us improve our documentation
Contact our support team for personalized help
Best for: Practices subject to strict audit requirements (e.g., HIPAA) or those requiring detailed forensic data in the event of an incident.
Audit logging is configured globally via the Dermi Atlas Manager desktop application.
To change the logging level:
Note: Changes to logging levels apply to future events only. Previously recorded logs retain their original detail.
Audit logs are stored in the local database. Each entry typically contains:
Users can view their own security history to verify their account integrity:
Clinical actions related to a specific patient are viewable within the patient record:
For comprehensive audits or incident response, administrators rely on the system database. Since audit logs are stored locally, they are included in all System Backups generated by Dermi Atlas Manager.
When a user or patient record is deleted, associated audit log entries are retained for 10 years (120 months) by default to satisfy both US (HIPAA) and Canadian (PHIPA/CPSO) compliance requirements. Records involving minors may require extended retention under applicable provincial or state law.
Administrators can configure the retention period through Dermi Atlas Manager:
Important: Changes to the retention period apply only to records deleted after the setting is saved. Previously deleted records retain the retention period that was in effect at the time of their deletion.
For manual cleanup of records before their scheduled expiration, see Configuring Data Retention for Deleted Records.
Recommendation: For strict compliance environments, "Soft" or "Regular" deletion is often preferred to maintain a historical record of access, even after data is deleted.