Legal

Audit Logs and Access Control Policy

What we record, who can access it, and how long we keep it

Maatla Healthcare (Pty) Ltd · CIPC registered, South Africa
Version 1.0 · Effective date: TODO: insert effective date

1. Introduction

This policy explains what audit logs are, what actions we record, who can access them, and how long we keep them. It applies to all users of Maatla Facilities.

In this document, we, us, our and Maatla refer to Maatla Healthcare (Pty) Ltd. You and your refer to the clinic, pharmacy or healthcare network using Maatla Facilities.

2. What Are Audit Logs

An audit log is a record of who did what, when, and from where on Maatla Facilities. Audit logs allow us to track access to patient data, identify unusual activity, support investigations, and meet compliance requirements.

3. What We Log

Maatla records the following actions in our audit logs:

  • Staff login and logout: when a staff member signs in or out, including date, time, IP address and browser.
  • Patient record viewed: when a staff member opens a patient's record, including which patient, which staff member, and when.
  • Patient data edited or updated: when any change is made to a patient’s record (e.g., medication added, notes updated, status changed), including what was changed, who changed it, and when.
  • Reminder sent: when a reminder is triggered and sent to a patient, including which patient, message type, delivery channel (WhatsApp or SMS), and timestamp.
  • Patient added to system: when a new patient is loaded into Maatla Facilities, including facility staff member who added them and timestamp.
  • Patient deleted or deactivated: when a patient record is deleted or deactivated, including by whom and when. Hard deletions are final and logged.
  • Staff access or permissions changed: when a staff member’s role or permissions are updated, including what permissions were changed, by whom, and when.
  • SMS credits purchased or used: when credits are bought or consumed, including amount, cost, and timestamp.
  • Export request: when a facility or staff member requests to export patient data, including what data was requested and by whom.
  • Account access change: when new staff members are invited to the facility account or existing staff are removed.

4. Access to Audit Logs

4.1 Maatla access. Maatla uses audit logs internally for security monitoring, compliance audits, and breach investigations. Only authorized Maatla staff with a specific compliance or security role can access facility audit logs.

4.2 Facility access. A facility may request access to their own audit logs by emailing info@maatlahealthcare.com. To request audit logs, provide:

  • Your facility name and account email.
  • The date range you want (e.g., "January 2024" or "January 1 to January 31").
  • A clear business reason for the request (e.g., "staff accountability," "compliance review," "investigating a data concern").

4.3 Maatla discretion. Maatla will review the request and may:

  • Provide the full audit log in the requested timeframe.
  • Provide a redacted log that hides sensitive information (e.g., IP addresses, detailed system errors).
  • Ask you to sign a confidentiality agreement before releasing logs.
  • Decline the request if Maatla reasonably believes it is for an improper purpose.

4.4 What we do not share. Maatla will redact or withhold:

  • Audit logs of other facilities.
  • Logs involving direct-registered patients (patients who registered with Maatla, not your facility).
  • Internal Maatla security logs, system errors, or vulnerability information.
  • Information about other Maatla staff members' access to your data.

4.5 Patients’ right to their logs. Patients can request a record of who accessed their personal information by emailing info@maatlahealthcare.com. Maatla will provide this upon verification of identity.

5. Facility Role-Based Access Control

Maatla Facilities supports the following roles, each with specific permissions:

5.1 Admin

  • Permission: full access to the facility account, including all patient records, staff management, reporting and deletion.
  • Can: view all patients, send reminders, edit patient data, invite/remove staff, change staff permissions, view analytics, purchase SMS credits, export patient data, delete patient records.
  • Cannot: access other facilities' data or Maatla system settings.
  • Audit log visibility: can view the facility's own audit logs upon request.

5.2 Manager

  • Permission: operational oversight without the ability to delete data.
  • Can: view all patients, send reminders, edit patient data, invite/remove staff, manage permissions, view analytics, purchase SMS credits.
  • Cannot: delete patient records, access financial records, or change admin settings.
  • Audit log visibility: can view the facility's own audit logs upon request.

5.3 Pharmacist

  • Permission: patient care and collection management.
  • Can: view all patients, send reminders, edit patient notes and collection dates, mark collections as completed.
  • Cannot: delete patients, add/remove staff, purchase credits, or view financial records.
  • Audit log visibility: cannot directly access audit logs.

5.4 Nurse

  • Permission: limited to assigned patients only.
  • Can: view only their assigned patients, send reminders, add notes, mark collections.
  • Cannot: view all patients, delete records, or manage staff.
  • Audit log visibility: cannot access audit logs.

5.5 Data Officer

  • Permission: compliance and data management.
  • Can: view audit logs, handle data export requests, process patient deletion requests, respond to data subject rights requests.
  • Cannot: view patient clinical data, send reminders, or manage staff.
  • Audit log visibility: can view facility's own audit logs.

6. Role Assignment and Removal

6.1 Assignment. The facility Admin assigns roles to staff members. Role assignment is logged in the audit trail.

6.2 Least privilege principle. Each staff member must be assigned only the role and permissions necessary for their job. Over-provisioning (giving more access than needed) is prohibited.

6.3 Prompt removal. When a staff member leaves or changes role, their access must be removed or downgraded immediately. Delayed removal is a compliance failure and may result in account suspension.

6.4 Shared logins prohibited. Staff members must not share login credentials. Each person must have their own account. Shared logins are impossible to audit and are a security risk.

7. Audit Log Retention

7.1 Retention period. Audit logs are retained for as long as necessary to meet legal and compliance requirements. Maatla typically retains audit logs for a minimum of one year and a maximum of three years, depending on the type of log and applicable law.

7.2 Deletion after retention. Once the retention period expires, audit logs are permanently deleted unless there is an ongoing investigation, legal hold, or regulatory requirement to keep them longer.

7.3 Breach or incident investigation. If a security incident or breach is reported, relevant audit logs are retained for the duration of the investigation and for as long as required by law, which may be longer than the standard retention period.

8. Audit Log Security

Audit logs themselves contain sensitive information (staff identities, patient data, access patterns). Maatla protects audit logs by:

  • Storing them in encrypted, access-controlled systems.
  • Limiting access to authorized Maatla staff only.
  • Monitoring access to audit logs.
  • Retaining them only as long as necessary.

9. Patient Data Ownership and Facility Responsibility

Once a facility uploads patient data to Maatla Facilities, that data is processed by Maatla in accordance with our Privacy Policy and Terms and Conditions. However:

9.1 Facility responsibility. You (the facility) remain responsible for:

  • Having valid consent to load the patient's data.
  • Ensuring the data is accurate and up to date.
  • Complying with privacy laws that apply to your jurisdiction.
  • Notifying the patient of any breach or unauthorized access.

9.2 Patient access rights. Patients retain their right to access, correct, or request deletion of their personal information. Requests can be made to either your facility (the uploader) or to Maatla at info@maatlahealthcare.com.

10. Data Export and Portability

10.1 Facility export. A facility can request an export of their complete patient database (names, contact details, collection history, notes) at any time. To request an export, email info@maatlahealthcare.com with your facility name and account email.

10.2 Patient export. A patient can request an export of their own records by emailing info@maatlahealthcare.com. Maatla will provide the export in a machine-readable format within 30 days.

10.3 Direct-registered patients. Patients who registered directly with Maatla (not through a facility) cannot be exported by a facility without the patient’s written consent.

11. Patient Deletion

11.1 Who can delete. Only Maatla staff (specifically the Data Officer or Admin role) can delete patient records. Facility staff cannot delete patients directly.

11.2 How to request deletion. To request deletion of a patient record, the facility must email info@maatlahealthcare.com with:

  • The facility name and account email.
  • The patient's name and contact number.
  • A clear reason for deletion (e.g., "patient requested," "moved to another facility," "no longer a client").

11.3 Soft vs. hard delete. Maatla may soft-delete a patient (hide them from active lists but retain data) or hard-delete (permanently remove all records) depending on the reason and legal requirements. Hard deletions are final and cannot be reversed.

11.4 Data retention after deletion. Deleted patient data is retained in secure backups for a limited time (typically 90 days) to allow recovery if a deletion was made in error. After that period, the data is permanently deleted.

12. Monitoring and Investigation

12.1 Unusual activity. Maatla monitors audit logs for unusual activity, such as:

  • Access from unusual IP addresses or at unusual times.
  • Bulk deletion of patient records.
  • Rapid repeated access to sensitive records.
  • Failed login attempts.

12.2 Investigation. If unusual activity is detected, Maatla may contact the facility to clarify or may temporarily limit access while investigating.

12.3 Cooperation. If Maatla investigates a suspected breach or misuse, the facility agrees to cooperate by answering questions and providing information about staff members and access patterns.

13. Changes to This Policy

Maatla may update this policy at any time by publishing a new version on our website. Changes take effect from the moment of publication. By continuing to use Maatla Facilities, you accept the updated policy.

14. How to Contact Us

For questions about audit logs or access control: