Administration & Security

Security, Access Control & Audit Logs

Understand Medaius enterprise security standards, clinic workspace isolation, role-based access control, session protection, and compliance audit logging.

Medaius Clinical Team
Last updated: September 2026

Medaius is built upon strict healthcare data protection and compliance principles, meeting modern standards for patient privacy, workspace isolation, and clinical accountability. This guide explains how access controls operate and how administrators review workspace audit logs.


1. Clinic Workspace & Data Privacy Isolation

Medaius is designed with strict organization-level data isolation:

  • Dedicated Clinic Workspaces: All patient records, clinical encounters, appointment schedules, and financial transactions belong exclusively to your registered clinic organization.
  • Enterprise Data Protection: Clinic data is completely isolated. Only verified staff members authenticated into your clinic workspace are permitted to view or manage your organization's records.

2. Granular Access Control (Role-Based Permissions)

Within an organization, clinic administrators control which team members can view or modify specific categories of data:

  • Role Permissions: Permissions map directly to discrete clinical and administrative functions (e.g., only authorized clinicians can view clinical SOAP notes, and only cashier roles can view or modify billing invoices).
  • Care Team Scoping: Patient charts can be restricted to members of the primary care team. Clinicians outside the assigned care circle cannot view sensitive patient history without an authorized and logged emergency override.

3. Session Security & Workstation Protection

To prevent unauthorized access from unattended workstations in busy clinics:

  • Automatic Workstation Locking: Inactive workstations automatically lock or log out after a configurable idle duration.
  • Encrypted Session Management: User sessions are protected with encrypted, modern authentication safeguards that refresh securely, protecting against unauthorized access.

4. User Activity Audit Logs

To maintain strict healthcare accountability, all administrative, diagnostic, and clinical actions are logged in real time:

  1. Navigate to Settings > Audit Logs (restricted to Administrator roles).
  2. The audit log dashboard visualizes all events across the clinic workspace:
    • User Logins: Timestamp, location details, and authentication status.
    • Chart Views: Identifies precisely who accessed a patient electronic record and when.
    • Profile Modifications: Tracks demographic, scheduling, and system configuration edits.
  3. Search and filter logs by staff member, event type, or date range for compliance reporting.

5. Clinical Document Immutability & Addenda

Clinical records are protected against retroactive alteration and tampering:

  • Draft Versioning: While notes remain in Draft status, revisions are tracked in chronological version histories.
  • Signed Immutability: Once an attending clinician signs and finalizes a clinical encounter, the record is locked permanently as an official read-only document.
  • Addendum System: If corrections or late-arriving diagnostic findings must be added to a finalized chart, clinicians create a timestamped, signed Addendum. The addendum is preserved alongside the original note, protecting the historical integrity of the medical record for healthcare compliance.

Was this page helpful?

Help us improve our clinical documentation with your quick feedback.