Web-forensics use case
Acquire evidence from healthcare and patient portals
Eviquire can preserve authorized information displayed through a healthcare or patient web portal, including patient and provider context, appointments, communications, prescriptions, test-result presentation, billing and downloadable documents. This is a narrowly scoped web-interface acquisition and is not a substitute for a certified health record, direct clinical-system export, imaging-system acquisition or provider audit evidence.
What this use case means
Eviquire can preserve authorized information displayed through a healthcare or patient web portal, including patient and provider context, appointments, communications, prescriptions, test-result presentation, billing and downloadable documents. This is a narrowly scoped web-interface acquisition and is not a substitute for a certified health record, direct clinical-system export, imaging-system acquisition or provider audit evidence.
Patient portals summarize and transform information from multiple clinical and billing systems, release results at different times and present dates according to organizational rules. Records are exceptionally sensitive and can concern third parties. Collection must be tightly authorized, minimized and separated from medical interpretation.
Common situations
When this workflow is useful
- Authorized medical, insurance, employment, negligence, complaint or identity investigations
- Preserving portal messages, appointments, results or documents before access changes
- Documenting exactly what an authorized patient, proxy or staff role could see
Recommended process
A documented acquisition workflow
- Confirm authority and necessity
Identify patient, proxy or staff authority, record categories, dates, purpose, exclusions, retention and permitted reviewers.
- Record account relationship
Preserve provider organization, portal, role, proxy status, locale, timezone and navigation without collecting authentication secrets.
- Acquire selected records
Document encounter or message context, displayed results, prescriptions, appointments, billing and release status only within scope.
- Preserve authorized documents
Download relevant reports, statements and correspondence in supplied formats and retain their portal relationship.
- Secure and qualify
Hash originals, restrict access, record unavailable clinical context, and obtain certified provider records when required.
Technical guidance
Conditions that affect patient-portal acquisition
Confirm these points during a short pre-acquisition validation on the authorized workstation.
Portal summary versus clinical record
Patient views can omit internal notes, preliminary data, metadata and corrections.
- Describe the view accurately.
- Do not claim completeness.
- Request certified records for authoritative use.
Proxy and account role
A patient, guardian, proxy and clinician may see different information and release timing.
- Record the access relationship.
- Avoid collecting other family members.
- Do not infer hidden content is absent.
Health-data security
Results, diagnoses, identifiers and messages require heightened confidentiality and may create urgent risks if disclosed.
- Use strict need-to-know access.
- Encrypt transfer and storage.
- Redact only on controlled derivatives.
Reviewable output
What the evidence package should explain
Portal and role context
Provider, portal, patient or proxy relationship, selected record and navigation.
Displayed health record
Authorized messages, appointments, prescriptions, results, billing and release presentation.
Supplied documents
Relevant authorized reports and statements preserved with hashes.
Restricted review package
Acquisition activity, time, limitations, access and custody records.
The exact artifacts depend on the source, plan, configuration, authority, and investigation. A report should identify what was and was not collected.
Professional considerations
Authority, proportionality, and limitations
- Obtain specific authority and apply health-data, professional-secrecy, privacy and retention requirements.
- Do not publish or broadly disclose identifiable health information.
- Eviquire preserves presentation; qualified clinicians and authoritative records support medical interpretation.
Important: Eviquire supports a documented technical process. It does not establish identity, truth, culpability, infringement, or admissibility, and it does not replace legal advice or a validated organizational procedure.
Standards and primary guidance
Online evidence procedures should be validated for the organization and matter. Useful starting points include SWGDE guidance for acquiring online content, ISO/IEC 27037:2012, and NIST digital-evidence resources.
Frequently asked questions
Is a patient-portal capture a certified medical record?
No. It records what the portal displayed; obtain certified provider records where required.
Can proxy access be documented?
Yes, without exposing credentials, and only within the proxy’s lawful authority.
Can test results be preserved?
Yes when authorized, together with release and portal context.
Does Eviquire interpret medical findings?
No. Medical interpretation belongs to qualified professionals.
How should the package be shared?
Only through approved encrypted, access-controlled and audited channels.
Who uses this workflow?
Relevant professional roles
This acquisition workflow is commonly relevant to these teams. The appropriate authority, scope, procedure, and review requirements still depend on the matter.
Forensic experts
Acquire online evidence with technical context, integrity verification, custody records, and reporting.
See role-specific guidance →Law firms
Preserve websites and online content for litigation, disclosure, legal holds, and expert review.
See role-specific guidance →In-house legal teams
Preserve early evidence for disputes, compliance, legal holds, and outside-counsel review.
See role-specific guidance →HR and due-diligence teams
Preserve relevant online material for employment, compliance, fraud, and diligence matters.
See role-specific guidance →