# AI evidence and retention matrix

Synthetic records and evaluation plan. No production event, six-year prompt policy or completed deletion is asserted.

Use the record type to choose a retention owner and rationale. The example deliberately avoids assigning an invented organisation-wide retention period.

| Record | Evidence purpose | Retention decision |
| --- | --- | --- |
| Security event: synthetic upload | Which application, policy and action were involved? | Security and privacy owners define the period and supported fields. |
| Policy version and required procedure | What rule and procedure were in effect? | Apply the Security Rule documentation requirement where applicable. |
| Activity-review record | Who reviewed the defined event scope and what followed? | Determine whether it is required Security Rule documentation and apply the relevant rule. |
| Underlying patient record | Clinical or administrative source of the input. | Use the medical-record and other applicable requirements, not the event-log default. |
| Exported event copy | Investigation or reporting in another system. | Assign the receiving owner and its access, retention and preservation rules. |
| Record subject to preservation | Evidence relevant to a specific dispute or investigation. | Resolve the preservation obligation before routine deletion. |

## Review steps

- Define event semantics: Identify what an action value proves and which unsupported or unobserved paths it does not cover.
- Record the retention rationale: Distinguish required policy documentation from prompt content, operational events and exported copies.
- Compare source and export: Run an authorised synthetic test and record actual fields, timestamp behaviour and access boundaries.

## Synthetic event specification

Event reference: TEST-AI-001
Input: an invented administrative note
Application: named by the evaluator before the test
Policy: sensitive-input test policy
Intended outcome: the agreed policy action
Observed outcome: not run
Raw patient content required in the event: no real patient data in this fixture

This is an evidence specification, not a representation of an Aona export schema. Map it to fields actually supported by the selected configuration.

## Source and scope

Guide: https://aona.ai/resources/guides/hipaa-ai-audit-evidence-retention/

Source check: 21 September 2026. General information; no professional approval or installed-product result is represented.

- HHS: Summary of the HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- HHS: Guidance on risk analysis: https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
