CareBand × Regis Healthcare — Patent Positioning & Technology Alignment Review

Export full PDF

C — Positioning Modules

Audit, Compliance & Evidence Generation

Most systems can show that a record was opened. Far fewer can show why a particular attribute was released to a particular person for a particular purpose.

Access log versus disclosure record

Conventional access log

  • User opened resident record
  • Timestamp
  • System or module used

Answers who opened the file. Does not establish what was seen, or on what basis.

Disclosure-decision record

  • Attributes released and suppressed
  • Purpose and authority relied upon
  • Policy applied and access expiry

Answers what was released, to whom, why, and under which rule.

Recorded fields (illustrative)

Individual identified
Requester identity
Requester role and authority
Relationship to the individual
Asserted purpose
Location or point of care
Device and trust status
Jurisdiction
Policy version applied
Attributes released
Attributes suppressed
Form of release (identifiable, pseudonymised, aggregate)
Consent or authority basis
Access start and expiry
Emergency override flag

Illustrative CareBand record model — not a representation of current Regis logging.

Why this is commercially valuable

Regis publishes corporate governance material describing oversight, risk and compliance structures, and its privacy policy commits to controlling access and protecting information handled by service providers. Official Regis source Privacy and governance source

  • Supports incident investigation and complaint response with concrete evidence.
  • Supports regulatory and accreditation review.
  • Supports breach assessment by establishing what was actually exposed.
  • Difficult and expensive to retrofit once a clinical platform is in production.
Evidence of appropriate disclosure is itself an asset in a regulated environment — and it is produced as a by-product of making the decision explicitly in the first place.

Sources referenced on this page