Curaeon Help Centre / KB-100
Open in the Help Centre →  ·  All topics
KB-100Security & privacyHow-to
Draft. This article is awaiting technical review and may change — if anything here conflicts with advice from our team, follow the team.

Keep the audit log for accreditation: the yearly archive, the copies beside the backups, and removing months past the period

Know what Curaeon already does to keep the audit log, what your practice's own procedure has to add, and how a month is removed once it is older than the period — so the policy you quote at accreditation is the one the software enforces.

Before you start

An administrator's task, in two places: Settings → Audit log (the strip and Download year) and Settings → Records retention → The audit log (the period and the months past it). The weekly warnings on the strip — a chain that does not hold, a restored backup, a check not running — are covered in KB-064 — Sign off the weekly Security review, and act on alerts and audit-log check warnings; this article is about keeping the log, not checking it.

What Curaeon does by itself

What your procedure has to add

  1. Keep the second backup location off the server, and encrypted like every other place a backup is kept (KB-067 — Set up nightly backups, a second copy and a monthly restore drill).
  2. Write down the anchor now and then. The strip on the Audit log shows the last record sealed and the start of its fingerprint. Noting both on the weekly sign-off gives the practice an anchor nobody with access to the server can change: a log rewritten afterwards cannot end on that fingerprint at that record.
  3. Take a year for the practice's own archive. On the Audit log, choose the year and Download year. The file can be checked on any machine, against nothing but itself and a fingerprint you wrote down, with curaeon-api verify-archive <file>; the arithmetic is plain SHA-256, so a practice can recompute the chain without us. Taking the file is recorded in the log.

Set a longer period

Settings → Records retention → The audit log states the period and when the first month reaches it. Change sets a longer one; seven years is the floor and cannot be lowered.

Settings → Records retention → The audit log: the period the log is kept, the date the first month reaches it, and Change beside it.
Settings → Records retention → The audit log: the period the log is kept, the date the first month reaches it, and Change beside it.

Remove months past the period

Nothing ages out by itself. When whole months are older than the period, the same section lists each one and what stops it going.

  1. Read what stops a month: not sealed or not archived yet (run Check now on the Audit log), the archive files missing from the backup folder, or a patient it names being on legal hold.
  2. Choose Remove months and enter your password. It cannot be undone.
  3. Afterwards the month is listed under Removed, and the removal is recorded in the Audit log.

Three things to know before you do:

At accreditation, the manual's "Keeping the audit log" section can be quoted as it stands; add the practice's own lines — where the second copy lives, who notes the anchor, who may remove months, and how long the archive files are kept.

Still stuck? Raise a ticket at support.curaeon.com.au or call 1300 XXX XXX. If your clinic can't see patients right now, call and choose option 1. Support is staffed Monday to Friday, 8:00–18:00 Sydney time; outside those hours a call or text to the same number is answered on a best-effort basis.