Skip to content

Implement API Logging #15

@suhasramanand

Description

@suhasramanand

Log all API requests involving ePHI.

Acceptance criteria

  • Log: timestamp, client ID, endpoint, response code, data accessed
  • Do not log actual ePHI in logs
  • Retain API logs for minimum 6 years
  • Real-time alerting for anomalous patterns

Source: § 4.1.2

Covered entities MUST log all API requests involving ePHI.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions