Audit trail

Activity logs and audit trail

Most clinic disputes are not about what the system shows now. They are about what it showed last Tuesday and who changed it. The log answers that without anyone having to remember.

Invoice #292 createdDr. Fatimah Al-Kafi · Riyadh Branch
Appointment movedRoom 3 → Room 2 · Arwa Idrees
Price changedPeel course · $4,000 → 4,600
Patient merged#P-00073 ← #P-00219
Session completedLaser 3 of 6 · derma

The state now, and how it got there

Current state tells you where things ended up. The log tells you how they got there — the discount that was applied, the invoice that was edited, the appointment that moved.

  • Every create, edit and delete recorded
  • Before and after values, not just the fact of a change
  • Discounts, write-offs and price overrides called out
  • Deleted records recoverable rather than gone
  • Filterable by user, branch, date and record type
The Medicolize activity log, recording every change with the user who made it and the time it happened

A name against every change

A change without a name against it is not an audit trail. Every entry carries the user, the time and the device.

  • Named user against every action
  • Timestamp and branch
  • Device and session where relevant
  • Actions taken on behalf of another user made explicit
  • Export for an external auditor

Who read what, not only who changed it

Who logged in, from where, and what they looked at matters as much as what they changed — particularly for records that are confidential by nature.

  • Sign-ins, failures and lockouts
  • Access to restricted clinical records recorded
  • Permission changes logged as events
  • Bulk exports flagged
  • Retention long enough to be useful in a dispute

Who reads the log

Rarely, and usually at a bad moment — which is exactly when it needs to be complete.

Owners

What changed, who changed it, and whether it was authorised.

Compliance

An access trail for confidential records, exportable.

Managers

Discounts and overrides, without accusing anyone of anything.

Trust versus a trail

Nobody wants to need this. Everyone eventually does.

The way it is done now

  • Changes nobody can trace
  • Deleted records simply gone
  • Discounts argued about
  • No record of who read what
  • A dispute resolved by seniority

With Medicolize

  • Every change attributed and timed
  • Recoverable, and logged
  • Recorded with who approved them
  • Access to restricted records logged
  • A dispute resolved by the log
Questions

Audit trail — what clinics ask

How long are logs kept?

Long enough to be useful in a dispute, and exportable if a clinic needs to retain them for longer under local rules.

Does it record who viewed a record, or only who changed it?

Both, for records marked confidential. For ordinary records, changes are logged and access is not, which keeps the log readable.

Can a deleted record be recovered?

Yes. Deletion is a state rather than a removal, and restoring is itself logged.

Can we give an auditor access without giving them the clinic?

Yes, through a role that can read the log and nothing else.

Put Audit trail in front of your own week

Half an hour on your own services, packages and price list. Someone calls you back within a day.

Book a demo WhatsApp