Operations · Compliance Evidence & Records
When someone asks you to prove it, how much do you have to reconstruct?
The question is almost never whether the practice did the work. It is whether the practice can produce what the work generated — and do it this week rather than after a month of archaeology.
HIPAA mapping
Where this fits in the Security Rule.
4 provisions this capability contributes to, each with the specific Compliance Evidence & Records behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.
§164.310(d)Device and media controls
Implements policies for receipt, removal, and disposal of hardware and electronic media. Validated file handling extends the control to the document layer.
§164.312(c)(1)Integrity
Implements policies to protect ePHI from improper alteration or destruction. Keeping superseded versions rather than overwriting them, and recording who changed what, are the integrity controls for documents held here. ePHI in your EHR, imaging and backups is outside this system and still yours to protect.
§164.316(b)(1)Documentation standards
Policies and procedures must be documented. The repository is purpose-built for the documentation requirement.
§164.316(b)(2)Time limit
Requires retention of the subpart's documentation for six years from creation or last effective date. Keeping superseded versions rather than overwriting them is what makes that datable at all — the clock often runs from a version the current file replaced.
What it does
Evidence should be a by-product, not a project.
An investigator, a payer, an acquirer or a partner's security review asks the same thing in different words: show me. Show me the policy that was in force in March. Show me that this person was trained before they touched a record. Show me the agreement with that vendor. Show me what you did about the incident. A practice that did all of it well and kept none of it together is in nearly the same position as one that did none of it.
The reason that happens is not carelessness. It is that evidence gets generated in one place and stored somewhere else, by a person who has to remember to move it. Policies live in a folder, training certificates arrive by email, the agreement is in somebody's downloads, the incident notes are in a notebook. Each step is small, and the whole thing fails quietly.
Here the evidence lands where it was produced. A policy adopted in Policies & Procedures is held with its versions and the audit trail behind them. A training completion is recorded against the person who did it, with the time and the score. An agreement — issued here or uploaded from a vendor — is a record with a state. An incident carries its own documentation. Nobody has to remember to file anything, which is the mechanism and the whole of the argument.
That is a different thing from a document store, even though it holds documents. A shared drive will keep whatever you put in it. What it will not do is fill itself while you work.
How it works
6 mechanisms keep Compliance Evidence & Records working.
Documents, not executables.
The repository takes the formats compliance documentation actually comes in — PDFs, office documents, spreadsheets, images of diagrams and signed pages. It is a document store rather than general file hosting, and the narrower scope is deliberate.
The modules file for you.
This is not a filing cabinet you have to remember to use. A policy adopted in Policies & Procedures, an agreement executed or uploaded against a vendor, a training certificate produced when someone finishes a module, the assessment answers, the documentation attached to an event — they land here because the module that produced them puts them here. The documents most often missing at audit are precisely the ones a person had to decide to save.
Versions accumulate rather than overwrite.
Uploading a revised document creates a new version and keeps the previous one. This is the behavior the six-year documentation rule actually needs, because §164.316(b)(2) runs from creation or last effective date — which is a question about the earlier version, not the current one.
One place to answer “show me”.
The value is not that documents are stored. It is that when the request arrives — and it arrives as a payer questionnaire long before it arrives as an investigation — the answer is one place rather than four people's recollections. Practices routinely pay someone to assemble this after the fact. Assembling it as you go costs nothing extra, because the work was being done anyway.
A document that knows where it came from.
Each document carries its own history: when it arrived, when it was revised, and by whom. During an audit the provenance is often the point — a policy dated three days before the request reads differently from one dated two years earlier and revised twice since.
Cross-module integration.
Documents are not a siloed feature. Policies in the Policies module use Record Management. BAA uploads in Workforce use Record Management. Training certificate exports from Workforce Training use Record Management. The repository is the document substrate the platform shares.
Who this is for
Built for the practices that need it most.
Practices using shared drives for compliance.
Migration is straightforward — upload existing documents in batches, the platform validates and versions them. After a weekend's work, the shared-drive chaos is replaced with a structured record that supports the rest of the platform.
Practices managing multiple document types.
P&P documents, BAAs, training records, SRA reports, audit responses, breach documentation. Practices accumulate substantial compliance document inventory. Keeping it all in one structured place pays off when any of it needs to be found.
Practices preparing for audit.
When OCR or an auditor requests specific documents, response time is the difference between calm and crisis. Record Management indexes everything; “show me our most recent SRA” or “show me the BAA with vendor X as of 2024” are one-click queries.
Practices with consultants.
Consultants typically need access to your compliance documents. Record Management's role-scoped sharing lets consultants see exactly what they need without inheriting access to documents outside their scope.
What you get
6 outcomes you’ll feel in week one.
No shared-drive chaos.
Structured, indexed, queryable document repository.
Versions kept, not replaced.
The current document is unambiguous; the earlier one is still there.
A document store, deliberately.
Compliance formats, not general file hosting.
Document-level audit.
Who, what, when on every interaction.
Per-office storage tracking.
Visibility without surprises.
Datable for §164.316(b)(2).
Retention runs from a version you can still produce.
What file types are accepted?
How much storage do I get?
Can I delete documents?
What about version comparison?
Are documents encrypted?
Can I bulk-upload?
What it does not do.
- Compliance artifacts, not patient records — Patient Management is a different capability
- No tamper-evidence or immutability claim without implementation evidence
Continue exploring
Related features in the platform.
Operations
HIPAA Foundations Training
HIPAA training inside the platform, with every completion recorded as it happens. The first documentation an auditor asks for, produced by doing the training rather than assembled afterwards.
Learn moreDefense
ePHI Audit
The question after an incident is never abstract. It is whether one named person opened one named record on one particular afternoon, and whether you can show it.
Learn moreIntelligence
Audit Replay TimelineIn development
In development. The evidence it would read — who opened what, when, and what state changed around it — is being recorded today; assembling it into a sequence on demand is the part we are building.
Learn moreThe compliance record where compliance can find it.
Most practices migrate from shared drives to structured records inside a weekend. The platform takes over forward.
