See every read of protected health information in your organization — for periodic review, or to answer someone asking who has accessed their record.
Before you start
The View Access Logs right to view; the separate Export Access Logs right to export.
Steps
- Go to Settings → System Security → PHI Access Audit.
- Four stat tiles summarize activity: Total accesses, Denied attempts, Platform staff access, Exports.
- Filter by Member ID, Record type (Lead, Contact, Document, Loan File, and more), Record ID, Access type (View/List/Search/Download/Export/Disclose), Outcome (Allowed/Denied), Accessed by (Any / Platform staff / your workforce), and a date range.
- Rows are visually flagged — Denied attempts (red) outrank everything else, then Platform staff access (amber), then Bulk actions like downloads/exports/disclosures (blue).
- Switch the timestamp column between your local timezone and UTC using the toggle at the top — switch to UTC before quoting a timestamp in a report, to keep it unambiguous.
To see who accessed one specific record
Rather than filtering this whole grid, open that record directly and choose Access history from its menu — you'll land on the same audit view scoped to just that record, titled "Who has accessed this record". This is the exact accounting an individual is entitled to request.
To export
Click Export accounting (requires the separate Export Access Logs right). If the export can't be written to the audit trail itself, it's refused rather than silently succeeding — nothing is disclosed if that happens.
Related articles
Other guides that answer questions close to this one.
The PHI Access Audit
Every read of protected health information anywhere in KamoCRM is recorded as a PHI access record: who (actor), what kind of access (view, list, search, download, export, or disclose), on what record (one of 17 tracked…
What Turning On PHI Handling Does
The PHI compliance boundary is a tenant-wide switch: turn it on when an organization handles protected health information and Kamo acts as its business associate under HIPAA. While it's on, the platform refuses every…
How to Turn PHI Handling On or Off
Audience correction: unlike everything else in this Security section, this is not something any organization admin — including a full Administrator role — can reach or perform. The tab itself is only visible to platform…