Sheet W-04 · Confidential records — isolation and audit · Healthcare
Prototype- Goes in
- A session note, in a practice that cannot treat records casually
- What we built
- Per-tenant scoping, encrypted notes, and an append-only audit trail
- Comes out
- A record whose history can be shown rather than asserted
- The line it does not cross
- A correction is a new entry. Nothing is overwritten.
Note 1 · The constraint
An independent practice carries a documentation burden but cannot accept a tool that treats patient records casually. The interesting question is not whether a model can draft a note. It is whether the surrounding system can prove who saw what, and when.
Note 2 · What we built
Per-tenant scoping so one practice can never read another, encrypted session notes, and an append-only audit trail where corrections are added rather than overwritten. This is a prototype: it demonstrates the design, and its stored state is simulated rather than a production database.
Note 3 · What transfers
The same design applies wherever confidentiality is a contractual obligation — legal files, HR records, financial casework, anything covered by a data processing agreement.
- Stage
- Prototype. Storage simulated.
- Audit model
- Append-only
- Isolation
- Per-tenant scoping
- Not claimed
- Production security