Auditing

Mon, October 5, 2026

Compliance

Audit Trails for Every Patient Record

Astral automatically keeps a chronological record of who accessed patient information, what changed, and when. Your organization can request an audit report at any time to support HIPAA and GDPR compliance, internal reviews, or a patient's request.

Auditing runs quietly in the background of every session, with nothing to set up and no extra steps for your team. The records themselves are designed to protect privacy, so they never become a second copy of your patients' data.

At a glance

Separate audit trails for access, changes, and sign-ins
3
Names or email addresses written to audit logs
0
Minimum retention of archived audit logs
6 years
To deliver an audit report once a request is acknowledged
48–72 hours

What Astral Records

Every audit entry belongs to one of three trails, each kept in its own log. Together they let you reconstruct what happened to any record, by whom, and in what order.

Access Trail

Each time a patient record is viewed, retrieved, or exported, Astral logs which record was opened, which fields it contained, and who opened it. Exports of patient lists and downloads of patient documents are recorded as their own action.

What each entry contains
  • The type and identifier of the record
  • The names of the fields involved, never their contents
  • The action performed: view or export
  • A pseudonymized user identifier and a SHA-256 hash of the user's email address
  • The organization identifier
  • The IP address and browser user agent
  • A unique request identifier that links every entry produced by the same action
  • A timestamp

Modification Trail

Every creation, update, and deletion of patient information is logged with the fields that changed and their previous and new values, giving you the complete change history of each record.

What each entry contains
  • The type and identifier of the record
  • The fields that were created, updated, or deleted
  • The previous and new values, each individually encrypted
  • The action performed: create, update, or delete
  • A pseudonymized user identifier and a SHA-256 hash of the user's email address
  • The organization identifier
  • The IP address and browser user agent
  • A unique request identifier that links every entry produced by the same action
  • A timestamp

Authentication Trail

Sign-ins, failed sign-in attempts, failed two-step authentication codes, sign-outs, password changes and resets, and email address changes are all logged, so unusual account activity stands out.

What each entry contains
  • The event: sign-in, failed attempt, sign-out, password reset or change, or email change
  • For failed attempts, a hash of the email address that was entered, so repeated attempts on one account can be linked without storing the address
  • A pseudonymized user identifier and a SHA-256 hash of the user's email address
  • The organization identifier
  • The IP address and browser user agent
  • A unique request identifier that links every entry produced by the same action
  • A timestamp

How Auditing Helps Your Organization

An audit trail is only useful if it answers real questions. Astral's is built to answer the ones clinics, patients, and regulators actually ask.

Answer Patients with Facts

When a patient asks who has seen their file, you can answer precisely, which supports their right of access under GDPR and HIPAA.

Investigate Incidents Quickly

If something looks wrong, timestamps and request identifiers let you reconstruct exactly what happened, in order, across all three trails.

Demonstrate Compliance

Regulators, auditors, and insurers expect evidence that access to health information is controlled and reviewed. An audit report gives you that evidence.

Strengthen Internal Oversight

Periodic reviews of access patterns help supervisors confirm that clinicians and assistants only open the records their role requires.

Discourage Improper Access

Knowing that every access is recorded is one of the most effective deterrents against browsing patient files out of curiosity.

Always On, on Every Plan

Auditing is part of the platform itself, not an add-on. There is nothing to enable, and it does not slow down or change how your team works.

Requesting an Audit Report

Organizations can request a copy of, or a report derived from, the audit trail data of their own organization at any time: for a given period, a given team member, or a given patient.

  1. Send a written request

    Write to us from your organization's account, stating the period, the people, or the records the report should cover.

  2. Acknowledgement

    We confirm receipt of your request within two business days.

  3. Delivery

    The report is delivered within 48 to 72 hours of acknowledgement. For requests of exceptional scope, we tell you the expected timeline up front.

Reports only ever contain records belonging to your organization and its patients, never data from other clients.

Private by Design

An audit log that copied patient data would become a new risk of its own. Astral's audit trails record what happened without revealing who the people involved are or what the records say.

Pseudonymized Identities

Users appear in audit logs only as a system identifier and a one-way SHA-256 hash of their email address. Linking an entry to a person requires identity data that is kept separately, encrypted, and access-controlled.

Encrypted Change History

The previous and new values in the modification trail are encrypted one by one before they are written, so the history of a record stays as confidential as the record itself.

Fields, Not Contents

The access trail names the fields a record contained without copying them, which is enough to establish exactly what was exposed.

Kept Apart from Your Data

Audit logs are stored separately from the application database, encrypted at rest, and reachable only by authorized personnel. No one using the platform, administrators included, can edit or delete an entry.

What Is Covered

Auditing is attached to the data itself rather than to individual screens, so every path to a record is captured, background processes included. Actions performed by automated processes are attributed to the system rather than to a person.

  • Patient profiles and emergency contacts
  • Medical, surgical, and allergy history
  • Psychiatric history and hospitalizations
  • Mental health and substance use history
  • Family, sibling, and child details
  • Legal and referral information
  • Evaluations and assessments
  • Consultations and clinical notes
  • Patient documents
  • EMDR targets and readings
  • Appointments and attendance
  • Tasks

Changes are also tracked for user accounts, team invitations, role assignments, calendar integrations, and billing details.

Storage and Retention

Audit logs follow a fixed lifecycle, from the moment an event happens to the end of its retention period.

  1. Recorded

    Entries are written as events happen, in a daily log file for each trail.

  2. Archived weekly

    Every week, logs are moved to dedicated, encrypted archival storage. Each file is verified on arrival before the original is removed.

  3. Retained for six years

    Archived logs are kept for at least six years from their creation, in line with HIPAA documentation retention requirements.

  4. Securely deleted

    Once the retention period ends, archived logs are securely deleted.

For Compliance Officers

Astral's audit trails are designed around the following regulatory requirements:

HIPAA · 45 CFR § 164.312(b)
Audit controls: mechanisms that record and examine activity in information systems containing protected health information.
HIPAA · 45 CFR § 164.308(a)(6)
Security incident procedures: identifying, responding to, and documenting suspected security incidents.
HIPAA · 45 CFR § 164.502(b)
Minimum necessary standard, reflected in audit entries that identify fields without copying their contents.
HIPAA · 45 CFR § 164.530(j)
Retention of required documentation for six years.
GDPR · Article 5(1)(c)
Data minimisation, through pseudonymized identities in every audit entry.
GDPR · Articles 5(2) and 24
Accountability: being able to demonstrate compliance with the data protection principles.
GDPR · Article 28(3)(h)
Processors make available the information needed to demonstrate compliance, and allow for and contribute to audits.
GDPR · Article 32
Security of processing, including the pseudonymisation and encryption of personal data.
GDPR · Articles 33 and 34
Breach notification, supported by records that establish what was accessed, when, and by whom.

Under these frameworks, Astral acts as a business associate (HIPAA) and a data processor (GDPR) on behalf of your organization. Our audit commitments, including report timelines and retention periods, are set out in our Business Associate Agreement.

Frequently Asked Questions

Can I find out who viewed a specific patient's record?

Yes. The access trail records every view and export of a patient record. Request an audit report for that patient and period, and we will provide each access with the person and the date and time.

Do audit logs contain patient information?

Audit entries identify records by system identifiers and name the fields involved. The previous and new values kept in the change history are individually encrypted, and no user names or email addresses are ever written in plain text.

Can anyone edit or delete audit entries?

No one using Astral can, administrators included. Entries are written automatically, stored apart from the application data, and reachable only by authorized Astral personnel.

How long are audit logs kept?

At least six years from the date they are created, after which they are securely deleted.

Who can request an audit report?

Any organization using Astral can request reports covering its own team members, patients, and records. Requests are made in writing and answered within the timelines described above.

Does auditing make my practice HIPAA or GDPR compliant?

Audit controls are one of the safeguards both regulations require, and Astral provides them out of the box. Compliance remains a shared responsibility: as the covered entity or data controller, your organization decides who may access what and reviews the activity Astral records.

Want to know how Astral protects the data itself?

Read about our security