The Audit Trail is a running, tamper-evident record of everyone who touches patient information in FrontDesk. HIPAA's Security Rule requires this kind of access logging, and FrontDesk records it automatically — you don't have to switch anything on.
Open it from Settings → Audit Trail.
What's logged
Every entry captures who did what, and when:
- User & email — the team member who took the action
- Action — a view, an update, or an export
- Resource & patient — what was accessed
- Time & IP address — when and from where
- Outcome — whether it succeeded
Actions fall into three groups, color-coded in the list:
| Group | Examples |
|---|---|
| Views | Opening a record, searching, listening to a recording, reading a transcript, a client signing in to the portal |
| Updates | Creating or changing a record, signing a note, granting portal access, telehealth events (links sent, joins, admits, removals, ending) |
| Exports | Exporting, downloading, printing, sharing, and disclosures made under a release |
Clinical records have their own resource types — clinical notes, psychotherapy notes, treatment plans, outcome measures, and releases of information — so you can see exactly who opened a chart. Emergency "break the glass" access to a psychotherapy note is logged with the reason given. Entries are kept for seven years.
Find what you're looking for
- Tabs — filter to All, Views, Updates, or Exports.
- Date range — Last 7 days, 30 days, 90 days, or All time.
- Search — narrow by name or resource.
Entries are grouped by day so you can scan activity date by date.
Export the log
- Export CSV — download the current audit log (with time, user, email, action, resource type, patient, IP, and outcome) for your own records or an auditor.
- Disclosure report for a patient — type a patient's name to download a CSV of every logged access to their information, for a patient-rights request. A patient's formal accounting of disclosures under a release lives on their Records tab; see Discharge and records release.
- Export all account data — owners and admins can request a full export across chosen locations and data types: clients, appointments, clinical records (notes, treatment plans, outcome measures, releases, disclosures), billing (charges, payments, invoices, superbills, payment plans), intake forms and consents, messages, providers and services, and call logs, with optional call-recording audio and a chart PDF per client. FrontDesk builds a secure ZIP in the background and emails a download link that expires in 72 hours. The export itself is recorded in the audit trail. See Data retention and deletion.
Good to know
- It can't be edited. The trail is a record of what happened; entries aren't editable.
- It supports patient-rights requests. When you delete or export a patient's data, that action is logged here too.