Verify your history
Who this page is for: the practice manager or auditor asking “prove it” - which is exactly the right question to ask of an audit trail.
The design goal is that the practice can verify its own history without trusting us, and keeps that ability after leaving. The connected build has not yet met that full goal, so Refera blocks real-data activation until a tenant-verifiable artifact is deployed and proved.
What verification does
Section titled “What verification does”Verification walks the chain event by event, recomputing each seal from the event content plus the previous seal and comparing it with the stored value. If an event was altered, inserted or removed, the walk stops matching at that point.
Automated tests use fictional events and unkeyed SHA-256, so the release suite can recompute the chain. Production writes use HMAC-SHA256 with a server-held secret. That prevents an attacker with database write access from silently re-sealing altered events, but a third party cannot recompute the production HMAC from an export unless Refera also supplies a tenant-safe verification artifact. The shared server secret is never exported.
The current trust boundary
Section titled “The current trust boundary”- Private release check: independently recomputable unkeyed SHA-256 over patient-free events.
- Connected product: server-verifiable keyed HMAC chain; the authenticated export carries events and chain heads but not the HMAC secret.
- Real-data activation: fail-closed until original-document retention/retrieval/export, restore/readback and an independently tenant-verifiable chain artifact are deployed and evidenced in the authorised activation record.
The current deployment also does not claim a daily write-once anchor.
After leaving
Section titled “After leaving”The structured export includes the available event history and chain heads in machine-readable form. It does not currently make a production HMAC chain independently verifiable from that file alone. A tenant cannot be activated for real data until the source-document lifecycle checks prove the missing portable verification artifact and offboarding readback path.
The exact event sequence and language boundary are documented on Chain of custody.
Did this answer your question?
Thanks - that helps us make these docs better.
Refera tracks referral admin only. It does not triage patients.
Examples are fictional and contain no patient information. Practice staff approve every external action. Refera never auto-sends or independently contacts patients.
Refera homeStart account setupOpen ReferaPrivacyTerms
[email protected]AI-assisted product and setup support. For a person, use the contact form or email.