For administrators

Retention and audit basics

What's logged, for how long, and how to review it.

The audit trail

Every access to patient data and every write-back attempt is captured in an append-only audit log, alongside infrastructure-level audit logging at the platform layer. Consent attestations, note edits, action decisions, and write-back attempts are all recorded with the acting user, the encounter, and a timestamp.

Accounts with the Auditor or TenantAdmin role can query audit events; this is currently an API-level capability rather than a dedicated screen in the app — ask your Fieldnote contact for an export if you need one for a compliance review.

Retention

Retention periods for recordings, transcripts, notes, and audit events are set out in the full privacy policy, not duplicated here — see Legal: Privacy Policy. Treat that document, not this page, as authoritative if the two ever appear to differ.

Requesting an audit export

Contact support with the date range and encounters or providers in scope — see Getting support.