Skip to main content
Information Access Log provides a record of when and by whom a resident’s protected health information (PHI) was accessed or disclosed. HIPAA § 164.528 gives individuals the right to request this accounting.

Where to find it

Open a resident’s profile and select the Disclosures tab.
Access to the Disclosures tab requires Administrator role in the default permission matrix. Administrators can grant Managers access from Settings → Role Permissions.

What is tracked

The log pulls from the facility-wide Activity logs and filters to actions directly tied to this resident. Tracked events include: Covered entities include: resident profile, medical data, medications, documents, care plans.

Date range filter

Use the From and To date filters to narrow results. ImaraCare retains this data for up to 6 years from creation, consistent with HIPAA record retention requirements.

Responding to a disclosure request

When a resident (or their representative) requests an accounting:
  1. Open their profile → Disclosures tab
  2. Apply the date range the resident requested (up to 6 years back)
  3. Review entries for any disclosures other than treatment, payment, or healthcare operations (TPO) — those are exempt from the required accounting under § 164.528(a)(1)(i)
  4. Prepare a written response documenting the non-TPO disclosures
ImaraCare captures internal system access events. External disclosures made outside the platform (faxes, verbal, paper) must be recorded separately in your facility’s disclosure log.
See HIPAA compliance for the full HIPAA feature map.