prime-simplereport
prime-simplereport copied to clipboard
[SPIKE] Investigate logs and analytics for patient and test data retention.
Description
As SimpleReport, we do not want to retain any logs or analytics that include Patient or Test information after 30 days.
Ask
Please investigate what changes need to be made to decrease the retention of those types of logs or analytics and summarize the work that will be needed. Examples of types data that will need to be deleted are:
- Any patient related information (ex. name, phone number, ethnicity, etc.). Please see this section of the product brief for a more exhaustive list.
- Any test result related information (ex. conditions, result, symptoms, etc). Please see this section of the product brief for a more exhaustive list.
Some examples of places to investigate are:
- Splunk
- Logs in Azure
The above list came up in a quick brainstorm and may not be exhaustive.
Additional context
- Product Brief > As SimpleReport, I don’t want to keep user or test data for more than 30 days
- @mpbrown has done very related work in this issue.
- It is worth mentioning that we will still be tracking some test data, namely the LOINC code, as metadata. If this is of interest or concern to this ticket @mpbrown has more information.
- Product PoC: @mindyatwork
Because we're storing metadata, the scope of what we can keep has changed.
Here's the current source of truth for what we're keeping and not keeping.