Skip to guide content
Browse all guides
Reports & complianceAll rolesChiefs & admins

HIPAA access and audit history

Understand protected sessions, idle expiration, audit evidence, and safe shared-device use.

7 minVerified guidanceReviewed Jul 13, 2026Synthetic examples only
HIPAA security settings showing verification and protected-session controls
Clinical records require a short-lived HIPAA session in addition to sign-in.View full size(opens in a new tab)

Understand the two security layers

Your account session identifies you. A separate short-lived HIPAA session is required before protected clinical records can be opened.

HIPAA security settings showing verification and protected-session controls
Clinical records require a short-lived HIPAA session in addition to sign-in.View full size(opens in a new tab)

Unlock with your own verification method

Use the available password or configured PIN verification. Never approve another person’s protected access from your session.

Expect idle and hard expiration

The HIPAA session locks after inactivity and has an absolute lifetime. Re-verify when prompted rather than attempting to bypass the lock.

Configure a Quick PIN only for yourself

When the option is available, use Account → HIPAA to configure your own Quick PIN after password verification. Treat the PIN like a credential and never use another person’s PIN.

Review audit evidence

Authorized admins use Admin → Audit Log to review bounded activity evidence. Use exports only for an approved compliance purpose and store them according to department policy.

Leave shared devices safely

Close protected records and sign out when leaving a shared workstation. Do not rely on closing a browser tab as the only security action.

Keep support material free of protected information

These examples use synthetic records. Never capture or send patient information, passwords, API keys, access tokens, or real incident details when asking for help.