# Protect data and use the audit trail

> Apply consent, least privilege, and traceable workflows to sensitive clinic operations.

Canonical URL: https://provider.peptiq.io/help/security-and-audit

## Protect patient information

- Use individual accounts and protect authentication factors; complete email MFA when your organization requires it.
- Access only patients associated with the selected clinic and only for legitimate work.
- Respect the patient’s active consent scopes on every clinical surface.
- Do not paste sensitive patient data into unapproved support channels or external tools.
- Patient detail reads are rate limited; repeated bulk scraping triggers alerts.

## Understand audit evidence

The console records access and operational events with context such as organization, actor, patient, resource, action, and time. Organization admins page the dashboard access audit log and filter by team member, resource, action, and date. Those filters use stored metadata, not patient names or note text. Audit data helps investigate who accessed or changed information, but it does not replace your organization’s complete compliance program.

1. Identify the patient, actor, resource, and time window under review.
2. Preserve relevant identifiers and avoid altering the affected workflow.
3. Escalate suspected inappropriate access through your security process.
4. Use the Security & Compliance footer link for platform security information.

## Export and copy protections

> **No bulk export workflow**  
> The Provider Console does not provide PDF generation or a general PHI export. Follow approved clinic and support procedures for records requests.

- Patient roster tables disable text selection and hide from browser print to reduce casual copying.
- Rate limits apply to patient detail API reads per staff member per hour.
- MFA may be required before clinical panels load when your organization enables it.
- Settings and grant changes are recorded in the settings audit trail.

- [Verify with email MFA](https://provider.peptiq.io/help/mfa-email-verification)
- [Settings audit trail](https://provider.peptiq.io/help/settings-audit-trail)
