Security & Compliance

Clinic Audit Logs: How to See Who Changed What in a Patient Record

Antony Dick·Founder & CEO, CuraVerto·3 September 2026·6 min read

Every clinic eventually has the same argument. A bill total is lower than expected. A patient's phone number changed. A prescription was approved by someone who was not the treating doctor. Without a record of who did what and when, the argument is settled by whoever is most senior or most persuasive. An audit log settles it with facts. This post explains what an audit trail should capture in a clinic, what CuraVerto's audit log actually records today, how it connects to the accountability ideas in India's Digital Personal Data Protection Act 2023, and what it does not do.

What an audit log is, and what it is not

An audit log is a chronological record of actions taken in the system: who acted, what they did, to which record, and when. It is different from the clinical record itself. A patient chart tells you what the doctor found. An audit log tells you who touched the chart, and what it looked like before and after. It is also different from a backup: a backup restores data, an audit log explains how the data got into its current state.

Three places a clinic needs it most

Patient records
Edits to demographics, medical history and prescriptions. If a doctor disputes what is on a prescription, or a patient asks who accessed their file, the log is the evidence.
Money
Discounts, credit bills, and billing changes. Most billing disputes inside a clinic are really questions of who applied what and when.
Access and permissions
Who was given the ability to do what. Our role-based access post covers the permission model itself; the audit trail is how you check it was used as intended.

What CuraVerto's audit log records

CuraVerto writes audit entries to a dedicated audit table, one row per action. Each row carries the clinic (tenant), the acting user, an action name in capitals such as PATIENT_UPDATE, the type of record affected and its identifier, a details field, the request's IP address and browser user agent where the request is available, and a timestamp. Where a route supplies before and after snapshots, the details field holds both, so a reviewer can see the old value next to the new one.

Actions that CuraVerto's code audits today include patient creation and updates, changes to a patient's medical or intake information, transfers of a patient between branches, prescription submission, approval and rejection, granting and revoking prescription delegation, staff discounts, credit bills, and changes to a doctor's commission. The list is not exhaustive of every click in the product, and we would rather you know that than assume it.

Append-only at the database level

An audit log that an administrator can quietly edit is worth little. In CuraVerto, the audit table has database triggers that reject any update or delete of an existing row, raising an error that says audit rows are immutable. Corrections are made by adding a new entry, not by changing an old one. That protects the trail from accidental edits and from casual tampering through the application. It is not a claim of protection against someone with direct administrative access to the database itself, which is a different threat and is handled by access controls on the infrastructure.

Viewing the log

A clinic administrator can open the activity log for their own clinic and filter by event type, acting user, action text, record type and date range, with newest entries first. The view is scoped to that clinic's tenant, so one clinic never sees another's entries. On CuraVerto, Audit Logs is a Plus plan feature at ₹49,999 per year excluding GST, and is not listed on Essential at ₹9,999 or Pro at ₹24,999.

How this relates to the DPDP Act, and where to be careful

The DPDP Act 2023 places obligations on a Data Fiduciary, which includes a clinic that decides why and how patient data is processed. Being able to show what happened to personal data, and who did it, supports the accountability the Act expects, for example when responding to a patient's request or investigating an incident. An audit log is a useful piece of evidence for that. It is not, on its own, compliance. Consent, notice, retention, breach handling and processor agreements are separate obligations that no log can satisfy. For a full walkthrough, see the DPDP post below, and take the free readiness check to see where your own clinic stands.

Honest limits

  • Coverage follows the code: only actions that the software audits appear, so ask a vendor which actions are covered, not just whether a log exists.
  • In CuraVerto, a failed audit write is recorded in the server log but does not block the clinical or billing action it belongs to, by design, so that a fault in logging never stops patient care. That trade-off favours availability over completeness.
  • A log shows what was done through the software. It cannot show what someone read over a colleague's shoulder or copied from a printout.

Frequently asked questions

What does CuraVerto's audit log record?
Each entry records the clinic, the acting user, an action name, the type and identifier of the affected record, a details field that holds before and after snapshots where the action supplies them, the IP address and browser user agent where available, and a timestamp.
Can an administrator edit or delete audit entries?
Not through CuraVerto. The audit table rejects updates and deletes of existing rows at the database level, so a correction appears as a new entry rather than a change to an old one.
Which CuraVerto plan includes Audit Logs?
Audit Logs is a Plus plan feature at ₹49,999 per year excluding GST. It is not listed on the Essential plan at ₹9,999 or the Pro plan at ₹24,999.
Does an audit log make a clinic DPDP compliant?
No. It helps a clinic show who did what to personal data, which supports accountability, but DPDP compliance also covers consent, notice, retention, breach response and processor arrangements. CuraVerto's audit log is one supporting tool, not a compliance certificate.
Related reading

Frequently asked questions

See who changed what, without asking around

CuraVerto's Audit Logs record who acted, on which record and when, in an append-only trail your clinic administrator can filter. It is part of the Plus plan at ₹49,999 per year excluding GST.

See CuraVerto pricing →Check your clinic's DPDP readiness freeChat on WhatsApp

Prefer not to use WhatsApp? Leave your number and we will call.

We use your name, clinic and number only to contact you about CuraVerto. See our privacy policy.

More from the blog

Security & Compliance
Do You Need DLT Registration for WhatsApp Reminders in India? (2026)
Security & Compliance
Schedule H and H1 Compliance for Digital Prescriptions in India
Security & Compliance
Role-Based Access in Clinic Software: Who Should See What (India, 2026)