Records are kept to show that requirements have been met and that the quality management system is operating effectively. A documented procedure sets the controls needed for identifying, storing, securing and keeping the integrity of records, for retrieving them, for how long they are retained and for their disposition. The organization defines and applies ways of protecting confidential health information held in records, in line with the regulatory requirements that apply. Records must stay legible, easy to identify and retrievable, and any change to a record must remain identifiable. The organization keeps records for no less than the device lifetime the organization has defined, or longer where regulatory requirements say so, and in any case for no less than two years after the organization released the device.
This control maps to 9 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 9 it maps to, and the evidence behind each claim, over MCP and REST.