EHR upgrade silently disables detailed audit
After a version upgrade, chart-view logging defaults off. AU-12 monitoring detects a drop in audit volume and change control restores the required generation settings before an assessment.
AU-12 requires the information system to provide audit record generation capability for the events defined in AU-2 at organization-defined information system components, allow designated personnel to select which events are audited, and generate audit records for those events. If AU-2 is the shopping list, AU-12 is making sure the cash register actually prints receipts.
Guarantee that selected systems technically generate the required audit records continuously — not merely that logging is mentioned in a policy.
How this control shows up in healthcare and HIPAA-covered environments.
After a version upgrade, chart-view logging defaults off. AU-12 monitoring detects a drop in audit volume and change control restores the required generation settings before an assessment.
Laptop EDR logs stop reaching the SIEM for a whole clinic subnet. Heartbeat/silence alerts under AU-12 operations restore forwarding — preserving ransomware visibility.
SSO sign-ins existed in the IdP console but were never shipped to the SIEM. AU-12 implementation adds API export so AU-6 reviewers can actually analyze workforce authentication.
Assessors distinguish "we intend to log" from "show me today's records." AU-12 evidence is live configuration plus freshly generated sample events.
How this NIST control supports HIPAA Security Rule expectations.
AU-2 selects which events; AU-12 ensures components generate those audit records and that authorized staff can manage selection.
Centralization is best practice for AU-6 review and retention, though AU-12 itself focuses on generation capability at components.
Document compensating controls (proxy logs, DLP, procedural reviews) and risk-accept or replace — do not pretend generation exists.
Related controls that commonly accompany AU-12.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.