/
Configure Dermi Atlas Professional's audit logging features to track system activity, monitor access, and support regulatory compliance requirements.
Audit logging is a critical feature for maintaining accountability and visibility into how patient data is accessed. Dermi Atlas Professional includes a configurable logging system that tracks user activity, system access, and data operations.
This data is essential for security incident investigations and is often a requirement for healthcare privacy compliance (such as HIPAA and PIPEDA).
Dermi Atlas Manager allows administrators to configure the depth of logging based on storage capacity and compliance needs.
Essential logging captures high-level security events with minimal impact on storage.
Events captured:
Best for: Practices with limited storage capacity or lower regulatory reporting requirements.
Comprehensive logging, the shipped default, provides a granular audit trail of almost all user interactions within the system.
Events captured:
Best for: Practices subject to strict audit requirements (e.g., HIPAA) or those requiring detailed forensic data in the event of an incident.
Activity is recorded per feature, so a specific area of the record can be isolated later. Full body photography is one example: sessions and the lesion records documented within them are logged under a Full Body resource type that the patient log view can filter on.
Illustrative demo with synthetic data. Learn more
Audit logging is configured globally via the Dermi Atlas Manager desktop application.
To change the logging level:
Note: Changes to logging levels apply to future events only. Previously recorded logs retain their original detail.
Audit logs are stored in the local database. Each entry typically contains:
Users can view their own security history to verify their account integrity:
Clinical actions related to a specific patient record are viewable within the patient record:
The drawer carries Action, Resource, and Period filters that combine, so a dense history can be narrowed to the events under review.
Illustrative demo with synthetic data. Learn more
For comprehensive audits or incident response, administrators rely on the system database. Since audit logs are stored locally, they are included in the system backups created from Backup Management in Dermi Atlas Manager.
How audit logs are handled during deletion depends on the Data Deletion Policy configured in Dermi Atlas Manager. Under the default Standard policy, the historical logs for a deleted record are removed at the time of deletion and a single deletion event is retained for the configured retention period; the Recoverable policy retains the full log history for that period instead. The default retention period is 120 months (10 years), which sits above common US and Canadian record-retention expectations. Records involving minors may require extended retention under applicable provincial or state law.
Administrators can configure the retention period through Dermi Atlas Manager:
Important: Changes to the retention period are applied retroactively to all existing deleted records and their associated audit logs. Reducing the retention period may cause previously deleted records to be permanently removed sooner, so a reduction requires typing the confirmation phrase "REDUCE RETENTION" before it is applied. Extending the period will delay their removal.
For targeted removal of specific records or other manual database operations, see Configuring Data Retention for Deleted Records.
Account deletion always permanently removes all patient data and associated audit logs belonging to that account, regardless of the configured Data Deletion Policy. There is no software mechanism to recover a deleted account or its audit history. Maintaining system backups via Dermi Atlas Manager is the only way to preserve this data.
The Data Deletion Policy, configured in Dermi Atlas Manager, determines how audit logs are handled when patients, entries, or images are deleted:
Recommendation: For strict compliance environments, the Recoverable or Standard Data Deletion Policy is preferred to maintain a historical record of access, even after data is deleted.
Your feedback helps us improve our documentation
Contact our support team for personalized help
All demonstrations, screenshots, and media on this page use synthetic data only. No real patient information is shown.
The following are synthetic and do not correspond to real patients:
Media is provided solely to illustrate platform functionality and workflows.