Skip to main content
Use case · Healthcare

Health-Records Chain of Custody

A tamper-evident, hash-linked record of every AI-agent read and write to a patient record, so a health system can prove who, or what, touched a record and why.

The risk

What an ungoverned agent gets wrong here.

When an AI agent reads or writes a patient record, a health system needs to answer a simple question with certainty: who, or what, touched this record, when, and why? Ordinary application logs do not carry that weight. They can be edited, they rarely tie an action to a specific agent and its authorizing operator, and they cannot prove they were not altered after the fact. As agents increasingly touch records directly, the gap between what happened and what can be proven becomes a legal and clinical liability. Chain of custody closes it: an unbroken, tamper-evident history of every agent access to a record.

Without governance

Where it goes wrong.

01

A disputed change

A record shows an altered medication entry. Was it a clinician, an agent, or an error? Standard logs cannot prove which, or rule out that the log itself was edited after the incident.

02

The breach investigation with a gap

After a suspected inappropriate access, investigators need an unbroken account of every touch on the affected records. The existing logs have gaps and no integrity guarantee, so the investigation cannot reach a defensible conclusion.

03

Attribution to the wrong actor

An agent's action is recorded against a shared service account, so the record trail points at a system rather than the operator who authorized the agent to act.

04

Evidence that will not hold up

In a compliance review or legal matter, the health system offers its access logs as evidence, but cannot demonstrate the logs are complete and unaltered, so their evidentiary value collapses.

With Agentomy

How Agentomy governs it.

01

Capture every touch

Every agent read and write to a patient record is recorded as an event (the agent, the authorizing operator, the record, the action, the timestamp, and the reason), with no path for an agent to act on a record off the record.

02

Hash-link the chain

Each event is cryptographically hash-linked to the one before it, so any later edit, deletion, or insertion breaks the chain and is detectable. The history is tamper-evident by construction, not by policy.

03

Attribute to a person, not a script

Every agent action ties back to a named operator and an authorization tier, so the trail points at who stood behind the agent, never at an anonymous shared account.

04

Produce the custody record on demand

For any patient record, export a complete, verifiable custody history, readable in plain English, for a breach investigation, a compliance review, or a legal request.

Frameworks

Maps to what you answer to.

Agentomy does not certify you. It gives you the enforcement and the audit trail these frameworks ask for, so readiness is something you can show rather than assert.

HIPAAthe US Health Insurance Portability and Accountability Act protecting patient health information; its accounting-of-disclosures and audit-control requirements are exactly what a verifiable custody record answers21 CFR Part 11the US FDA rule (Title 21 of the Code of Federal Regulations, Part 11) for trustworthy electronic records and signatures; the hash-linked, attributable trail provides the record integrity and traceability it calls forHITRUSTthe Health Information Trust Alliance common security framework health systems certify against; the custody record supplies readiness evidence you can map to its audit-logging controls
See it in the record

Every action, logged and provable.

A tamper-evident, hash-linked trail of every governance decision for this workload: what an agent did, under whose authorization, and why. Plain-English reasons for every allow and deny, exportable to the framework your auditors care about.

Agentomy Command CenterFilter Health-Records Chain of Custody
  • 100% Integrity
  • 44,097 Blocks
  • SHA-256 hash-linked
Audit trail: one tamper-evident block per governance decision, hash-linked to the one before it
BlockTimestampAgentActionTierHash
44,097Today 12:42:08clinical-research-agentdata_access_requestEvaluatorf6fb236d15ca4d56
44,096Today 12:41:54patient-intake-agentoutput_validationAnalyst114028b1f26d3b9d
44,095Today 12:41:37supplier-review-agentpolicy_checkBuilderc9637ea14d36a174
44,094Today 12:40:58claims-extract-agentbehavior_driftOperator53935fd9bc1620ad
44,093Today 12:40:21consent-draft-agenthalt_initiatedStrategist04be10ba09ad3ad9
44,092Today 12:39:46care-report-agentprompt_reviewEvaluator114b932d9eaebb4f
Governance events today: 12,842Demo environment
Illustrative interface with sample data, in the shipped Command Center’s structure. Not a customer environment and not a live feed.

Ready to govern your agents?