Know Who Accessed
Every Patient Photo
CureCast records every view, download, and share across patient records and clinical photos, with staff account, device, IP address, and timestamp.
CureCast records every view, download, and share across patient records and clinical photos, with staff account, device, IP address, and timestamp.
Reviewed by the CureCast team · Last updated 31st August 2026
CureCast’s audit trail records the staff account or login associated with an action, what they did, which patient was involved where applicable, the device and IP address used, and when it happened. You can filter the activity by staff or login, event, patient, device, IP address, and date range.Access to view or export audit logs is controlled by administrator permission. Audit-log entries cannot be edited or deleted by clinic users or CureCast after they are recorded.
CureCast records defined patient and file activity, including patient record views, file downloads, file shares, file edits, file deletions, and bulk downloads.
Questions about patient information come up. An employee’s access is questioned. A patient asks who has seen their photos. A download looks unfamiliar.
When that happens, you should be able to look back and see what actually took place.
CureCast provides an audit trail that records key activity across patient information and clinical photos.
An employee is suspected of accessing a patient’s information without authorization. Review the recorded activity. Filter by staff member, patient, event, or date to see what was recorded during the period in question. This is also useful for investigating a suspected privacy incident more broadly: the log shows recorded access, downloads, shares, devices, IP addresses, and timestamps. The log shows what happened. It does not determine whether the access was appropriate or whether an incident is reportable. That judgment stays with the practice and its advisers.
Every entry identifies the staff account that performed the action. Individual logins are enforced for US, UK, EU and Australian accounts, so each entry is attributable to a named person.
A patient asks who accessed their clinical photos. Look up the recorded photo activity for that patient. The log identifies the individual staff account associated with each recorded event, along with the device, time, and action taken.
A practice wants to know whether someone downloaded or shared a patient’s photo. Downloads and shares are recorded events. Bulk downloads are also recorded, giving the practice visibility into large-scale file activity, including the associated staff or login, device, IP address, patient context where applicable, and time.
CureCast records defined activity across patient records, files, before/after, albums, selected clinical modules, logins, exports, and consent workflows.
Each recorded event includes the same core details, shown in plain columns in the admin panel.
Recorded audit activity can remain searchable by device information even after the related device record is expired or deleted from the Devices screen.
Scrolling through every event isn’t practical once a practice has real activity history. The audit log can be filtered by staff or login, event, patient, device, IP address, and date range.
For example, if you need to review activity involving one patient during a specific week, select the patient and set the date range. The log narrows to just that activity, including everything recorded for that patient across the selected period. Filtering by device or IP address works the same way, useful if you’re tracing activity back to a specific machine or connection rather than a specific person.
Audit logs contain sensitive information about patient records, clinical photos, staff activity, devices, and IP addresses. Access to audit logs is controlled by permission.
Administrators can view audit logs. They can also grant audit-log access to specific authorized staff members when appropriate for the practice’s workflow.
Audit-log entries cannot be edited or deleted by clinic users. After an event is recorded, clinic staff and administrators cannot change or remove the entry through CureCast, regardless of their permission level.
Authorized administrators and staff members with audit-log permission can select a custom date or month range, apply the available audit-log filters, and export the matching recorded activity in CSV or PDF format. This makes it easier to export a specific patient, staff member, device, event type, incident period, or monthly activity record without exporting the entire log at once.
CureCast retains audit history for up to six years, subject to the retention arrangement applicable to your account.
CureCast’s audit-log retention is based on the applicable local compliance requirements and the retention arrangement for the clinic’s account.
Retention requirements may differ by country, emirate, healthcare authority, contract, internal policy, or legal obligation. For example, a clinic may require a longer retention period than the default arrangement available for another market.
Before onboarding, clinics should confirm the retention period required for their jurisdiction and agree on the appropriate retention arrangement with CureCast. If your practice has a specific retention requirement, contact CureCast before onboarding to confirm whether it’s available for your account.
An audit trail is one part of a HIPAA-compliant workflow, not the whole of it.
The audit log tells you what happened. Staff access controls determine what can happen in the first place, this page covers who should be allowed to access patient information.
The audit trail records available device context for recorded events. Device management gives practices visibility into device records associated with their account.
CureCast is built to support HIPAA-compliant workflows. Your practice remains responsible for its own compliance obligations, including how it uses this information.
CureCast records photo activity, including views, downloads, and shares, together with the staff account associated with the event. Individual staff logins are enforced for US, UK, EU and Australian accounts, so the associated staff member can always be identified.
Yes. Filter the audit log by staff member or login to see their recorded activity.
Yes. File downloads and shares are recorded events, including bulk downloads.
Yes. Authorized users can filter recorded activity by patient, staff or login, event, device, IP address, and date range.
Retention depends on the applicable local compliance requirements and the retention arrangement for the clinic’s account. Contact CureCast before onboarding to confirm whether the retention period required by your jurisdiction is available.
Yes. Clinic staff and administrators cannot edit or delete recorded audit-log entries through CureCast, regardless of their permission level.
Yes. Authorized administrators and staff members with audit-log permission can select a custom date or month range, apply available filters, and export matching audit activity in CSV or PDF format.

Discuss how CureCast fits into your clinical photo workflow, from capturing and organizing patient photos to securely managing them across your practice.
Prefer email? [email protected]