Privacy complaint arrives nine months later
A patient alleges snooping during a prior admission. AU-11 cold archive still holds EHR view events; without it, the organization cannot confirm or refute.
AU-11 requires retaining audit records for an organization-defined period consistent with records retention policy to support after-the-fact investigations and meet regulatory/organizational requirements. Healthcare organizations often need months to years of EHR access logs for privacy complaints, payer disputes, and breach timeline reconstruction — far beyond default 30-day SIEM tiers.
Define, implement, and enforce retention periods for audit records from ePHI systems so evidence remains available for investigations, reviews, and legal holds without unauthorized early destruction.
How this control shows up in healthcare and HIPAA-covered environments.
A patient alleges snooping during a prior admission. AU-11 cold archive still holds EHR view events; without it, the organization cannot confirm or refute.
IdP logs retained only 30 days frustrate timeline work. Retention policy expands privileged and remote-access logs to meet investigation norms.
Finance wants 15-day hot retention. AU-11 governance requires privacy/security sign-off; compromise moves older ePHI access logs to cheaper searchable archive instead of delete.
Assessors compare stated retention to what systems actually keep. Mismatch — especially losing ePHI access history — is a common HIPAA audit-control finding.
How this NIST control supports HIPAA Security Rule expectations.
HIPAA does not set a single universal audit-log day count; define periods risk-based and retain documentation per 164.316. Many orgs choose multi-year EHR access log retention.
Yes if retrieval meets investigation SLAs and protections (AU-9) still apply.
Retention goals drive required storage capacity; they must be planned together.
Related controls that commonly accompany AU-11.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.