Implement ATNA audit logging for PHI access events in an IHE-compliant system

domain: profiles.ihe.net · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Construct an AuditMessage XML document conforming to DICOM Supplement 95 / RFC 3881 structure for each auditable event, identifying the EventIdentification (eventActionCode, eventDateTime, eventOutcomeIndicator)
  2. Populate the ActiveParticipant elements for the human requestor (with userId and network access point), the process performing the action, and the destination system
  3. Add a ParticipantObjectIdentification element for the patient (ParticipantObjectTypeCode=1, Role=1) with the patient identifier, and a second element for the document or study accessed
  4. Transmit the audit message to the ATNA Audit Repository using either syslog over TLS (RFC 5425) on port 6514 or the DICOM STOW method, depending on the repository's supported transport
  5. Verify the repository acknowledges receipt and implement local buffering so audit messages are not lost if the repository is temporarily unavailable

Known gotchas

Related routes

Implement HIPAA-compliant audit logging for PHI access in a FHIR agent pipeline
fhir · 6 steps · unrated
implement HIPAA-compliant audit logging for a health application
hipaa-compliance · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans