AU-10 Audit and Accountability

Non-Repudiation

High Risk Moderate Medium Cost

AU-10 requires providing irrefutable evidence that an individual (or process acting on behalf of an individual) has performed particular system actions — protecting against false denial of those actions. In healthcare, non-repudiation underpins break-glass reviews, order authenticity, disclosure investigations, and privileged change accountability. Shared logins destroy AU-10; strong identity, signed actions, and protected audit trails build it.

Control Objective

Ensure critical actions affecting ePHI can be reliably attributed to a unique individual with integrity-protected evidence that resists repudiation.

Implementation Guidance

  1. Eliminate shared accounts for clinical and administrative ePHI systems (IA-2/AC-2).
  2. Bind privileged and clinically significant actions to unique IDs with timestamps and source context.
  3. Protect audit logs from alteration (AU-9); consider WORM/SIEM immutability for high-value logs.
  4. Use digital signatures or application-level signing for orders, consents, and high-risk approvals where systems support it.
  5. For break-glass, require justification capture tied to the user identity.
  6. Extend non-repudiation expectations to BA platforms via contract and configuration review (SA-9).
  7. Test attribution during investigations: can you prove who exported a chart?
  8. Train workforce that credentials equal identity — sharing passwords voids accountability culture.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Disputed medication order

E-signature and audit trail show the ordering clinician and time; AU-10 evidence resolves the dispute without relying on memory.

Alleged inappropriate chart access

Unique login plus integrity-protected EHR audit log supports a PS-8 investigation the user cannot credibly deny.

Shared 'nurse station' EHR login retired

After moving to individual badges/MFA, non-repudiation for disclosures and amendments becomes enforceable.

Best Practices

  • Unique IDs everywhere ePHI is accessed.
  • Integrity protection on audit evidence.
  • Application e-sign for critical acts.
  • Break-glass with identity + reason.
  • Ban shared clinical logins.
  • Verify attribution in tabletop investigations.

Common Gaps & Violations

  • Departmental shared passwords.
  • Audit logs editable by the same admins they watch.
  • No user attribution on batch interfaces.
  • Break-glass without identity binding.
  • Paper 'someone signed it' without system evidence.

Required Documentation

  • Non-repudiation / accountability standard
  • List of actions requiring strong attribution
  • Audit integrity controls description
  • E-signature / order authentication configs
  • Sample investigation using attributed logs

How to Test & Validate

  1. Attempt to identify shared accounts in EHR; require remediation.
  2. Verify privileged actions are attributable in logs.
  3. Confirm audit log integrity controls (AU-9 linkage).
  4. Review break-glass events for user + reason.
  5. Trace one disclosure investigation to attributed evidence.

Audit Considerations

Without non-repudiation, sanctions and incident narratives collapse. Assessors probe shared accounts and weak audit integrity as AU-10 failures in practice.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — mechanisms to record and examine activity in systems containing ePHI.
  • 164.312(c) Integrity — protect ePHI from improper alteration; attribution supports integrity investigations.
  • 164.312(d) Person or Entity Authentication — authentication is a prerequisite to non-repudiation.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — review of records depends on reliable attribution.

Compliance Tips

  • Prioritize killing shared EHR logins before buying exotic signing tech.
  • Store security logs in a role-separated SIEM.
  • Include AU-10 scenarios in privacy investigation SOPs.

Frequently Asked Questions

Is MFA the same as non-repudiation?

MFA strengthens authentication; non-repudiation also needs reliable binding of actions to that identity and protected evidence.

Do HL7 interface accounts break AU-10?

Service accounts should map to owning teams/processes with compensating controls; human actions must still be uniquely attributable.

How does AU-10 relate to AU-2/AU-12?

AU-2/AU-12 define what is logged and how; AU-10 focuses on the strength of attribution / non-denial for those actions.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-10
  • Related controls: AU-2, AU-9, AU-12, IA-2, AC-2, PS-8

Need Help Implementing AU-10?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.