Access & action audit trail (HipaaAuditMiddleware). No PHI is present in this log — each entry
records only the request line (user, role, action, method, path, status), never a request body or query
string, and any PHI-bearing value is pseudonymized server-side (PSN-…) before it is
returned. Export (JSON / CSV / PDF) requires the manage_audit permission.