Disputed medication order
E-signature and audit trail show the ordering clinician and time; AU-10 evidence resolves the dispute without relying on memory.
AU-10 requires providing irrefutable evidence that an individual (or process acting on behalf of an individual) has performed particular system actions — protecting against false denial of those actions. In healthcare, non-repudiation underpins break-glass reviews, order authenticity, disclosure investigations, and privileged change accountability. Shared logins destroy AU-10; strong identity, signed actions, and protected audit trails build it.
Ensure critical actions affecting ePHI can be reliably attributed to a unique individual with integrity-protected evidence that resists repudiation.
How this control shows up in healthcare and HIPAA-covered environments.
E-signature and audit trail show the ordering clinician and time; AU-10 evidence resolves the dispute without relying on memory.
Unique login plus integrity-protected EHR audit log supports a PS-8 investigation the user cannot credibly deny.
After moving to individual badges/MFA, non-repudiation for disclosures and amendments becomes enforceable.
Without non-repudiation, sanctions and incident narratives collapse. Assessors probe shared accounts and weak audit integrity as AU-10 failures in practice.
How this NIST control supports HIPAA Security Rule expectations.
MFA strengthens authentication; non-repudiation also needs reliable binding of actions to that identity and protected evidence.
Service accounts should map to owning teams/processes with compensating controls; human actions must still be uniquely attributable.
AU-2/AU-12 define what is logged and how; AU-10 focuses on the strength of attribution / non-denial for those actions.
Related controls that commonly accompany AU-10.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.