When the user is building, validating, or auditing a computer system that creates, modifies, maintains, archives, retrieves, or transmits electronic records or applies electronic signatures in an FDA-regulated (GxP) context. Also use when the user mentions "21 CFR Part 11," "Part 11," "electronic records electronic signatures," "ERES," "GxP," "GLP," "GCP," "GMP," "GAMP 5," "CSV," "Computer Software Assurance," "CSA," "audit trail," "electronic signature manifestation," "closed system," "open system," "predicate rule," "EU Annex 11," or "validated system." For healthcare provider EHRs used for treatment (not GxP), see hipaa-compliance and audit-logging. For HITRUST or HIPAA generally, see hipaa-compliance.
When the user wants to design, build, audit, or remediate accessibility for healthcare apps and patient-facing systems. Also use when the user mentions "WCAG," "WCAG 2.2," "WCAG 3.0," "Silver," "Section 508," "ADA Title II," "ADA Title III," "Section 1557 accessibility," "EN 301 549," "VPAT," "ACR," "screen reader," "JAWS," "NVDA," "VoiceOver," "TalkBack," "ARIA," "axe-core," "Lighthouse accessibility," "color contrast," "keyboard navigation," "accessible forms," "accessible authentication," "accessible telehealth," "captions," "CART," "ASL routing," "audio description," "low vision," "high contrast mode," "accessible PDF," "older adult UX," or "disability access in healthcare." For plain language and reading level, see health-content-writing. For outreach orchestration, see patient-engagement.
When the user is designing, implementing, or reviewing audit logging for PHI access — including the HIPAA §164.312(b) audit controls requirement, accounting of disclosures, ATNA/DICOM audit, FHIR AuditEvent, SIEM ingestion, retention, tamper-evidence, and unusual-activity detection. Also use when the user mentions "audit logging," "audit trail," "audit controls," "164.312(b)," "164.308(a)(1)(ii)(D)," "accounting of disclosures," "164.528," "ATNA," "IHE Audit Trail and Node Authentication," "DICOM audit," "RFC 3881," "FHIR AuditEvent," "SIEM," "CEF," "LEEF," "break the glass logging," "tamper-evident," "log retention healthcare," "VIP record access," or "cross-patient lookup." For the regulatory basis, see hipaa-compliance. For the cybersecurity program, see healthcare-cybersecurity. For PHI controls, see phi-handling.