Every read of PHI is logged with the actor, the timestamp, the system that performed the read, and the purpose. Logs are immutable and retained for seven years.
We monitor for anomalous access patterns and we surface alerts to a small security team that triages them within the workday.
We make the same logs available to customers through their audit dashboard. They can see exactly who at Curee touched their data and why.
