EPPA Audit Log Retention and Export Expectations¶
EPPA audit rows are append-only clinical workflow records. They identify the authenticated practitioner, organization, action, target type/id, request time, IP address, user agent, and a small JSON metadata allowlist.
Audit metadata must not include raw radiographs, marker coordinate payloads, MAT payloads, secrets, tokens, passwords, or unnecessary patient identifiers. Patient and study target IDs should be added only after LABIS signs off on the stable patient/study persistence identifiers.
LABIS sign-off items before production:
- Retention period for clinical audit logs, including legal and research-policy requirements.
- Export format and access controls for compliance review.
- Authorized roles for audit export and review.
- Procedure for documenting exceptional deletions required by law while preserving audit integrity.