Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Operations · Compliance Evidence & Records

When someone asks you to prove it, how much do you have to reconstruct?

The question is almost never whether the practice did the work. It is whether the practice can produce what the work generated — and do it this week rather than after a month of archaeology.

Included in Basic·Starting at $39/mo

HIPAA mapping

Where this fits in the Security Rule.

4 provisions this capability contributes to, each with the specific Compliance Evidence & Records behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.310(d)

Device and media controls

Implements policies for receipt, removal, and disposal of hardware and electronic media. Validated file handling extends the control to the document layer.

§164.312(c)(1)

Integrity

Implements policies to protect ePHI from improper alteration or destruction. Keeping superseded versions rather than overwriting them, and recording who changed what, are the integrity controls for documents held here. ePHI in your EHR, imaging and backups is outside this system and still yours to protect.

§164.316(b)(1)

Documentation standards

Policies and procedures must be documented. The repository is purpose-built for the documentation requirement.

§164.316(b)(2)

Time limit

Requires retention of the subpart's documentation for six years from creation or last effective date. Keeping superseded versions rather than overwriting them is what makes that datable at all — the clock often runs from a version the current file replaced.

What it does

Evidence should be a by-product, not a project.

An investigator, a payer, an acquirer or a partner's security review asks the same thing in different words: show me. Show me the policy that was in force in March. Show me that this person was trained before they touched a record. Show me the agreement with that vendor. Show me what you did about the incident. A practice that did all of it well and kept none of it together is in nearly the same position as one that did none of it.

The reason that happens is not carelessness. It is that evidence gets generated in one place and stored somewhere else, by a person who has to remember to move it. Policies live in a folder, training certificates arrive by email, the agreement is in somebody's downloads, the incident notes are in a notebook. Each step is small, and the whole thing fails quietly.

Here the evidence lands where it was produced. A policy adopted in Policies & Procedures is held with its versions and the audit trail behind them. A training completion is recorded against the person who did it, with the time and the score. An agreement — issued here or uploaded from a vendor — is a record with a state. An incident carries its own documentation. Nobody has to remember to file anything, which is the mechanism and the whole of the argument.

That is a different thing from a document store, even though it holds documents. A shared drive will keep whatever you put in it. What it will not do is fill itself while you work.

How it works

6 mechanisms keep Compliance Evidence & Records working.

01

Documents, not executables.

The repository takes the formats compliance documentation actually comes in — PDFs, office documents, spreadsheets, images of diagrams and signed pages. It is a document store rather than general file hosting, and the narrower scope is deliberate.

02

The modules file for you.

This is not a filing cabinet you have to remember to use. A policy adopted in Policies & Procedures, an agreement executed or uploaded against a vendor, a training certificate produced when someone finishes a module, the assessment answers, the documentation attached to an event — they land here because the module that produced them puts them here. The documents most often missing at audit are precisely the ones a person had to decide to save.

03

Versions accumulate rather than overwrite.

Uploading a revised document creates a new version and keeps the previous one. This is the behavior the six-year documentation rule actually needs, because §164.316(b)(2) runs from creation or last effective date — which is a question about the earlier version, not the current one.

04

One place to answer “show me”.

The value is not that documents are stored. It is that when the request arrives — and it arrives as a payer questionnaire long before it arrives as an investigation — the answer is one place rather than four people's recollections. Practices routinely pay someone to assemble this after the fact. Assembling it as you go costs nothing extra, because the work was being done anyway.

05

A document that knows where it came from.

Each document carries its own history: when it arrived, when it was revised, and by whom. During an audit the provenance is often the point — a policy dated three days before the request reads differently from one dated two years earlier and revised twice since.

06

Cross-module integration.

Documents are not a siloed feature. Policies in the Policies module use Record Management. BAA uploads in Workforce use Record Management. Training certificate exports from Workforce Training use Record Management. The repository is the document substrate the platform shares.

Who this is for

Built for the practices that need it most.

Practices using shared drives for compliance.

Migration is straightforward — upload existing documents in batches, the platform validates and versions them. After a weekend's work, the shared-drive chaos is replaced with a structured record that supports the rest of the platform.

Practices managing multiple document types.

P&P documents, BAAs, training records, SRA reports, audit responses, breach documentation. Practices accumulate substantial compliance document inventory. Keeping it all in one structured place pays off when any of it needs to be found.

Practices preparing for audit.

When OCR or an auditor requests specific documents, response time is the difference between calm and crisis. Record Management indexes everything; “show me our most recent SRA” or “show me the BAA with vendor X as of 2024” are one-click queries.

Practices with consultants.

Consultants typically need access to your compliance documents. Record Management's role-scoped sharing lets consultants see exactly what they need without inheriting access to documents outside their scope.

What you get

6 outcomes you’ll feel in week one.

No shared-drive chaos.

Structured, indexed, queryable document repository.

Versions kept, not replaced.

The current document is unambiguous; the earlier one is still there.

A document store, deliberately.

Compliance formats, not general file hosting.

Document-level audit.

Who, what, when on every interaction.

Per-office storage tracking.

Visibility without surprises.

Datable for §164.316(b)(2).

Retention runs from a version you can still produce.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

What file types are accepted?
PDF, DOCX, XLSX, common image formats (PNG, JPG), CSV, and a few sector-specific formats. Executable files, scripts, and other formats outside the standard document set are rejected.
How much storage do I get?
Allocations are sized for typical practice document volumes and most independent practices use a fraction of theirs. If you approach the limit, the dashboard surfaces it before it becomes a problem.
Can I delete documents?
Documents in active compliance contexts (current policies, adopted BAAs, current training records) are retention-locked, because §164.316(b)(2) requires six-year retention of the documentation the Security Rule calls for and these are that documentation. Documents in non-compliance contexts (drafts, working notes, superseded internal documents) can be deleted with audit logging.
What about version comparison?
The platform supports inline version comparison for text-based documents. For PDFs and binary formats, side-by-side viewing is available; programmatic diffing is not.
Are documents encrypted?
Yes. Documents are encrypted at rest and in transit. Documents belong to the office that uploaded them, and access follows the same role boundaries as the rest of the platform.
Can I bulk-upload?
Yes. The platform supports bulk upload for migration scenarios — ZIP archives are extracted, files are individually validated, and metadata is captured per file.

What it does not do.

  • Compliance artifacts, not patient records — Patient Management is a different capability
  • No tamper-evidence or immutability claim without implementation evidence

The compliance record where compliance can find it.

Most practices migrate from shared drives to structured records inside a weekend. The platform takes over forward.