Audit Controls
Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
Implementation Guidance
What to record:
• Authentication events — successes, failures, lockouts and password changes
• Access to ePHI records, including read access, with the user, subject record, timestamp and source
• Creation, modification, deletion and export of ePHI
• Bulk queries, report generation, printing and downloads
• Privileged and administrative actions, including changes to accounts and permissions
• Changes to the audit configuration itself, and any attempt to disable or clear logs
• Remote access sessions, VPN connections and API activity
What to do with it:
- Define who reviews logs, how often, and what triggers escalation, then evidence that it happens
- Automate detection for the patterns that matter: same-surname access, VIP record access, access outside working hours, bulk export, repeated authorisation failures
- Centralise logs off the originating host so a compromised system cannot erase its own trail
- Protect log integrity with append-only or write-once storage and restricted access
- Set retention to at least six years where the log evidences compliance activity, per 164.316(b)(2)
- Record each review: who reviewed, what period, what was found and what action followed
Note the relationship with 164.308(a)(1)(ii)(D): the information system activity review specification requires regular review of audit logs, access reports and incident tracking reports. The two standards are tested together.
Required Documentation
• Log review procedure naming the reviewer role, frequency and escalation path
• Inventory of systems holding ePHI, each mapped to its logging configuration
• Audit log configuration evidence per system, including which event types are captured
• Completed log review records with reviewer, date, period covered, findings and actions
• Alert rule definitions and the tuning history behind them
• Log retention and protection standard, including integrity controls
• Records of any log-related incident and its investigation
• Evidence that audit configuration changes are themselves logged and approved
Best Practices
• Automate the detection patterns that matter clinically: same-surname lookups, VIP records, employee self-access, out-of-hours access and bulk export
• Make log review a scheduled, evidenced task with a named owner rather than an aspiration
• Tune alerts deliberately — unreviewable alert volume is functionally the same as no monitoring
• Synchronise time across all systems via NTP so timelines hold up under investigation
• Use append-only or write-once storage for audit data, and restrict access to it
• Retain compliance-relevant logs for six years to align with 164.316(b)(2)
• Report review metrics to leadership so the activity is visible and resourced
• Include cloud services, APIs and database administration tools in log coverage
Common Violations
• Read access to ePHI not captured, so inappropriate record lookups are invisible
• No documented review procedure, reviewer or frequency
• Log review evidenced only by a signature with no record of what was examined
• Logs stored only on the originating host, where an attacker can delete them
• Retention set to weeks or months, so investigations and audits have nothing to examine
• Privileged users able to alter or clear logs without trace
• Unsynchronised clocks making cross-system correlation unreliable
• Cloud services, APIs and database tools excluded from logging entirely
• Alert volume so high that alerts are routinely ignored
Testing Procedures
• Verify read access to ePHI is captured, not only writes — this is the most common gap
• Generate a test access event and confirm it appears in the log with user, record, timestamp and source
• Attempt to modify or delete a log entry as a privileged user and confirm the attempt is prevented or recorded
• Inspect completed review records and confirm they show genuine examination rather than a signature
• Trace a sample alert from trigger through investigation to documented outcome
• Confirm retention meets policy by retrieving a record from the earliest retained period
• Check that clocks are synchronised across systems so events can be correlated
• Verify logs are stored off the originating host and are access-restricted
• Confirm audit configuration changes are logged and require approval
Implementation Resources
Download expert-developed templates and checklists to implement this control:
Quick Facts
Related Controls
Explore other controls in the Technical Safeguards category.
Transmission Security
Implement technical security measures to guard against unauthorized access to ePHI that is being transmitted over an electronic communications…
Access Control
Implement technical policies and procedures for electronic information systems that maintain ePHI to allow access only to those persons or software…
Integrity
Implement policies and procedures to protect ePHI from improper alteration or destruction.
Need Help Implementing This Control?
Our certified HIPAA experts can help you implement this control correctly and efficiently.