Chain of custody
Who this page is for: the practice manager who needs the audit trail to hold up, and the IT contact who wants to know how the sealing actually works.
Every event at the front door - a referral received, a document captured, an acknowledgement approved, a card filed - is recorded as an event and hash-chained with SHA-256 the moment it is written. Each event’s seal covers the event before it, so the whole history forms one unbroken chain: change any event after the fact and every seal from that point on stops matching.
How the verification test works
Section titled “How the verification test works”An automated test uses four fictional events for one referral, hash-chained with SHA-256. The test verifies the chain, tampers with a copy of one event and verifies again. The break must appear at the exact changed event. The product uses the same seal code, while connected production writes add a server-held HMAC key.
A typical chain for one referral:
- referral received - fax via fax-to-email
- captured - text extracted, source excerpt and attachment metadata recorded
- acknowledgement approved - staff sign-off recorded
- filed - ready-to-enter card completed
The language discipline
Section titled “The language discipline”The property is tamper-evident, and the word is chosen with care. No system can stop every alteration in principle; what the chain shows is where a recomputed chain stops matching. Production events use a server-held HMAC key. Refera has versioned, Object-Locked source-archive storage in AWS Sydney. That infrastructure alone is not a complete source-document lifecycle. Real-referral activation remains blocked until every inbound path proves archive-before-extraction, source integrity binding, authenticated retrieval and readback, complete export, retention and disposal handling, restore, and legacy migration behaviour end to end. The evidence ZIP’s manifest makes file digests and the source-to-referral binding customer-checkable, while keyed event-seal verification stays on the authenticated Refera verifier because the shared HMAC secret is never exported.
Whose evidence it is
Section titled “Whose evidence it is”The audit trail is the practice’s evidence, not just ours. If a referral is ever questioned - by a referrer, a regulator, an insurer - the practice holds dated, tamper-evident history of what arrived and what was done. The private release chain is independently recomputable; portable production verification remains unavailable until its fail-closed checks pass. The exact boundary is on Verify your history.
Did this answer your question?
Thanks - that helps us make these docs better.
Refera tracks referral admin only. It does not triage patients.
Examples are fictional and contain no patient information. Practice staff approve every external action. Refera never auto-sends or independently contacts patients.
Refera homeStart account setupOpen ReferaPrivacyTerms
[email protected]AI-assisted product and setup support. For a person, use the contact form or email.