Inspector Mode and medical records isolation

A read-only inspector view that exposes only the documents an OSHA, FTC, or state mortuary board investigator is entitled to see, with medical records stored in independently-keyed encrypted storage that the inspector view cannot reach.

When an investigator arrives, the last thing you want is to log them into the live owner account. Inspector Mode hands the investigator an iPad in a contained, read-only view of exactly the documents they are entitled to see, with medical records firewalled at the storage layer.

What inspectors can see

  • Written programs (Formaldehyde Compliance, Bloodborne Pathogens Exposure Control Plan, HazCom, Respiratory Protection, Emergency Action), with version history.
  • Training transcripts per employee.
  • SDS library and chemical inventory.
  • Formaldehyde exposure monitoring results (sampling dates, results, sampling method, affected employee, respiratory protection in use).
  • Hep B vaccination status (vaccinated / declined / pending) for each covered employee.
  • FTC price lists (GPL, CPL, OBCPL) with effective dates and version history.
  • Fire extinguisher monthly inspection log.
  • PDF export of any individual record or the full inspection packet.

What inspectors cannot see

  • Underlying medical questionnaire content. The owner-director sees physician opinions only; the questionnaire content lives in independently-keyed encrypted storage that no inspector role can access.
  • Employee personal data beyond what regulatory access requires.
  • Pricing of services to families, billing, or financial records unrelated to the FTC price lists.

Medical records isolation

Medical questionnaire content is stored in a separate object store under a separate KMS key. The primary database holds only opaque pointers. Even at the database level, the questionnaire payload is unreadable. A compromised application server cannot reveal the underlying answers, only confirm that a record exists.

Audit log

Every state change and every medical-record read is logged with actor, timestamp, IP address, and the version hash of the document affected. The log is retained for the life of the funeral home account and is available for export.

Inspector Mode is available now on all plans. Medical records isolation is built into the platform and applies to every funeral home regardless of plan.