Export an audit trail
Export the access events of a period as a signed evidence pack. An auditor verifies it offline, with no enrolled device.
Who can do this: a person entitled to Export. The pack is served to that person alone.
The samples use the allowed helper from Access decisions.
1. Export the pack
Choose one scope: the whole tenant, one or more datasets, or one patient.
const pack = await allowed(await client.evidence.export({ datasets: ['encounters'] }, { from, to }));let pack = try await allowed(client.evidence.export(.datasets(["encounters"]), from: from, to: to))val pack = allowed(client.evidence.export(ExportScope.Datasets(listOf("encounters")), from = from, to = to))| Scope | TypeScript |
|---|---|
| Whole tenant | { tenant: true } |
| Datasets | { datasets: ['encounters'] } |
| One patient, an accounting of disclosures | { subject: medicalRecordNumber } |
2. Save the bytes
Hand the file to the auditor through your own channel.
if (pack) await writeFile(`evidence-${pack.packId}.sealdhealthcare`, await pack.bytes());if let pack { try await writeFile("evidence-\(pack.packId).sealdhealthcare", await pack.bytes()) }pack?.let { writeFile("evidence-${it.packId}.sealdhealthcare", it.bytes()) }3. Verify the pack
The auditor calls verifyPack on the SDK, without a Client.
const verification = await sealdhealthcare.verifyPack(bytes);if (!verification.verified) return render(verification.failure);renderEvents(verification.events, verification.controlStatus);let verification = try await sealdhealthcare.verifyPack(bytes)guard verification.verified else { return render(verification.failure) }renderEvents(verification.events, verification.controlStatus)val verification = sealdhealthcare.verifyPack(bytes)if (!verification.verified) return render(verification.failure)renderEvents(verification.events, verification.controlStatus)failure names the first check that failed.
Next
- Evidence and audit for resolving refs and every
PackEventfield.