AU-11 Audit and Accountability

Audit Record Retention

High Risk Moderate Medium Cost

AU-11 requires retaining audit records for an organization-defined period consistent with records retention policy to support after-the-fact investigations and meet regulatory/organizational requirements. Healthcare organizations often need months to years of EHR access logs for privacy complaints, payer disputes, and breach timeline reconstruction — far beyond default 30-day SIEM tiers.

Control Objective

Define, implement, and enforce retention periods for audit records from ePHI systems so evidence remains available for investigations, reviews, and legal holds without unauthorized early destruction.

Implementation Guidance

  1. Set retention by log class: ePHI access/audit trails, privileged/admin, authentication, network, endpoint — document periods in policy.
  2. Align with legal/compliance (often multi-year for clinical access audits) and with AU-4 capacity reality.
  3. Implement technical retention locks; restrict who can shorten retention.
  4. Support legal hold overrides that suspend deletion for cases/breaches.
  5. Tier storage (hot search vs cold archive) but keep retrieval SLAs usable for privacy.
  6. Cover BA-exported audits you rely on — contract for retention or pull copies in-house.
  7. Dispose securely after retention ends (MP-6 style for media).
  8. Review retention annually with counsel/privacy — update after incidents that proved gaps.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Privacy complaint arrives nine months later

A patient alleges snooping during a prior admission. AU-11 cold archive still holds EHR view events; without it, the organization cannot confirm or refute.

Breach counsel requests 180-day auth history

IdP logs retained only 30 days frustrate timeline work. Retention policy expands privileged and remote-access logs to meet investigation norms.

SIEM cost-cutting proposal

Finance wants 15-day hot retention. AU-11 governance requires privacy/security sign-off; compromise moves older ePHI access logs to cheaper searchable archive instead of delete.

Best Practices

  • Written retention schedule by log type.
  • Technical enforcement, not honor system.
  • Legal hold process.
  • Archive with defined restore SLA.
  • Contractual BA retention or local copies.
  • Secure deletion after expiry.

Common Gaps & Violations

  • Default vendor retention never reviewed.
  • Policy says years; SIEM keeps weeks.
  • No legal hold capability.
  • BA SaaS audits expire before you notice.
  • Deletion jobs run without compliance approval.

Required Documentation

  • Audit record retention schedule
  • Linkage to enterprise records policy
  • Technical retention configuration evidence
  • Legal hold procedure
  • BA audit retention requirements

How to Test & Validate

  1. Compare SIEM/EHR retention settings to the written schedule.
  2. Retrieve a sample event older than hot-tier age from archive.
  3. Verify users cannot unilaterally shorten retention.
  4. Review a legal hold example or test hold.
  5. Sample BA audit availability vs contract.

Audit Considerations

Assessors compare stated retention to what systems actually keep. Mismatch — especially losing ePHI access history — is a common HIPAA audit-control finding.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — retain the ability to examine activity over relevant periods.
  • 164.316(b)(2) Documentation — retain documentation for six years from creation or last effective date (policy retention culture informs operational evidence practices).
  • 164.308(a)(1)(ii)(D) Information System Activity Review — historical reviews and investigations need retained records.
  • 164.528 Accounting of Disclosures — retention of disclosure-related records may intersect with audit histories.

Compliance Tips

  • Publish a one-page retention matrix (source × days/years × store).
  • Never cut retention in a cost ticket without privacy sign-off.
  • Prove restore from cold storage once per year.

Frequently Asked Questions

Does HIPAA mandate a specific audit log retention period?

HIPAA does not set a single universal audit-log day count; define periods risk-based and retain documentation per 164.316. Many orgs choose multi-year EHR access log retention.

Can hot SIEM retention be short if cold archive is long?

Yes if retrieval meets investigation SLAs and protections (AU-9) still apply.

How does AU-11 relate to AU-4?

Retention goals drive required storage capacity; they must be planned together.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-11
  • NIST SP 800-92
  • HIPAA §§ 164.312(b), 164.316
  • Related controls: AU-4, AU-9, AU-6, MP-6, SI-12

Need Help Implementing AU-11?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.