# AI evidence and retention matrix

Use the record type to choose a retention owner and rationale. The example deliberately avoids assigning an invented organisation-wide retention period.

Synthetic records and evaluation plan. No production event, six-year prompt policy or completed deletion is asserted.

Source: https://aona.ai/resources/guides/hipaa-ai-audit-evidence-retention/
Sources checked: 2026-09-21

## A record has a purpose

### TEST-AI-001

Synthetic sensitive-input check

Note: Observed outcome: not run

### Policy reference

Identify the version that should apply

### Review reference

Record who examined the actual evidence

| Record | Evidence purpose | Retention decision |
| --- | --- | --- |
| Security event: synthetic upload | Which application, policy and action were involved? | Security and privacy owners define the period and supported fields. |
| Policy version and required procedure | What rule and procedure were in effect? | Apply the Security Rule documentation requirement where applicable. |
| Activity-review record | Who reviewed the defined event scope and what followed? | Determine whether it is required Security Rule documentation and apply the relevant rule. |
| Underlying patient record | Clinical or administrative source of the input. | Use the medical-record and other applicable requirements, not the event-log default. |
| Exported event copy | Investigation or reporting in another system. | Assign the receiving owner and its access, retention and preservation rules. |
| Record subject to preservation | Evidence relevant to a specific dispute or investigation. | Resolve the preservation obligation before routine deletion. |

## Review checklist

- [ ] Define event semantics
  Identify what an action value proves and which unsupported or unobserved paths it does not cover.
- [ ] Record the retention rationale
  Distinguish required policy documentation from prompt content, operational events and exported copies.
- [ ] Compare source and export
  Run an authorised synthetic test and record actual fields, timestamp behaviour and access boundaries.

## Included example files

- hipaa-ai-evidence-retention.md
- hipaa-ai-evidence-retention.csv

## Source references

- HHS: Summary of the HIPAA Security Rule: https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html (2026-09-21)
- HHS: Guidance on risk analysis: https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
