Keep the audit log for accreditation: the yearly archive, the copies beside the backups, and removing months past the period
Know what Curaeon already does to keep the audit log, what your practice's own procedure has to add, and how a month is removed once it is older than the period — so the policy you quote at accreditation is the one the software enforces.
Before you start
An administrator's task, in two places: Settings → Audit log (the strip and Download year) and Settings → Records retention → The audit log (the period and the months past it). The weekly warnings on the strip — a chain that does not hold, a restored backup, a check not running — are covered in KB-064 — Sign off the weekly Security review, and act on alerts and audit-log check warnings; this article is about keeping the log, not checking it.
What Curaeon does by itself
- Keeps every record for at least seven years and never removes one automatically. A child's record is kept until they turn 25, and the log is not held to that by itself — set a longer period, or keep a legal hold on the patient, where you want the two to match (KB-066 — Keep, hold or destroy patient records past retention).
- Writes once, never changes. The database refuses any change or removal, and a production server runs under a login that cannot switch that refusal off.
- Seals each record into a chain within about a minute and checks the chain nightly at 02:30. The records sealed that day are copied, with a checksum, into
audit/<practice>/inside the backup folder, and to the second backup location when one is set. Once an hour the last record sealed and its fingerprint go toanchors.login the same folder.
What your procedure has to add
- Keep the second backup location off the server, and encrypted like every other place a backup is kept (KB-067 — Set up nightly backups, a second copy and a monthly restore drill).
- Write down the anchor now and then. The strip on the Audit log shows the last record sealed and the start of its fingerprint. Noting both on the weekly sign-off gives the practice an anchor nobody with access to the server can change: a log rewritten afterwards cannot end on that fingerprint at that record.
- Take a year for the practice's own archive. On the Audit log, choose the year and Download year. The file can be checked on any machine, against nothing but itself and a fingerprint you wrote down, with
curaeon-api verify-archive <file>; the arithmetic is plain SHA-256, so a practice can recompute the chain without us. Taking the file is recorded in the log.
Set a longer period
Settings → Records retention → The audit log states the period and when the first month reaches it. Change sets a longer one; seven years is the floor and cannot be lowered.

Remove months past the period
Nothing ages out by itself. When whole months are older than the period, the same section lists each one and what stops it going.
- Read what stops a month: not sealed or not archived yet (run Check now on the Audit log), the archive files missing from the backup folder, or a patient it names being on legal hold.
- Choose Remove months and enter your password. It cannot be undone.
- Afterwards the month is listed under Removed, and the removal is recorded in the Audit log.
Three things to know before you do:
- A month runs by Coordinated Universal Time, so in Australia it ends in the morning of the 1st, and the few rows either side go with the neighbouring month.
- The Audit log, access reports and staff activity reports no longer show that month. The rows about a destroyed patient record go when their month does.
- A month less than seven years old can never be removed, whatever the setting says — the database refuses it. Curaeon opens and checks the archive file before it removes anything; keep that file, and its off-site copy, for as long as your own procedure says.
At accreditation, the manual's "Keeping the audit log" section can be quoted as it stands; add the practice's own lines — where the second copy lives, who notes the anchor, who may remove months, and how long the archive files are kept.
Still stuck? Raise a ticket at support.curaeon.com.au or call 1300 XXX XXX. If your clinic can't see patients right now, call and choose option 1. Support is staffed Monday to Friday, 8:00–18:00 Sydney time; outside those hours a call or text to the same number is answered on a best-effort basis.
Related articles
- KB-064 — Sign off the weekly Security review, and act on alerts and audit-log check warnings — Sign off the weekly Security review, and act on alerts and audit-log check warnings
- KB-066 — Keep, hold or destroy patient records past retention — Keep, hold or destroy patient records past retention
- KB-067 — Set up nightly backups, a second copy and a monthly restore drill — Set up nightly backups, a second copy and a monthly restore drill