AU-12 Audit and Accountability

Audit Generation

High Risk Moderate Medium Cost

AU-12 requires the information system to provide audit record generation capability for the events defined in AU-2 at organization-defined information system components, allow designated personnel to select which events are audited, and generate audit records for those events. If AU-2 is the shopping list, AU-12 is making sure the cash register actually prints receipts.

Control Objective

Guarantee that selected systems technically generate the required audit records continuously — not merely that logging is mentioned in a policy.

Implementation Guidance

  1. For each AU-2 event, identify the component that must generate it (EHR app, database, IdP, OS, firewall).
  2. Enable vendor audit features and confirm they are writing to an immutable or access-controlled store.
  3. Provide admin capability to tune which events are audited without vendor code changes where supported.
  4. Forward logs to a central SIEM/repository with reliable transport (TLS, buffering, alerts on silence).
  5. Monitor for log generation failure (agent down, disk full, API audit disabled after upgrade).
  6. Cover all tiers that matter: clinical apps, identity, remote access, endpoints holding ePHI caches, and privileged jump hosts.
  7. Document how designated personnel change audit selection (change control).
  8. Retest generation after patches and EHR module activations.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

EHR upgrade silently disables detailed audit

After a version upgrade, chart-view logging defaults off. AU-12 monitoring detects a drop in audit volume and change control restores the required generation settings before an assessment.

Endpoint agents stop forwarding

Laptop EDR logs stop reaching the SIEM for a whole clinic subnet. Heartbeat/silence alerts under AU-12 operations restore forwarding — preserving ransomware visibility.

Cloud IdP audit not exported

SSO sign-ins existed in the IdP console but were never shipped to the SIEM. AU-12 implementation adds API export so AU-6 reviewers can actually analyze workforce authentication.

Best Practices

  • Alert on logging pipelines going quiet.
  • Dual-write or centralize so local disk failure is not total loss.
  • Lock down who can disable auditing.
  • Include generation checks in go-live and upgrade tests.
  • Verify BA SaaS can export audit records you depend on.
  • Treat audit configuration as a monitored security control.

Common Gaps & Violations

  • Policy lists events; production logging still on defaults.
  • Logs only on the app server local disk with no forwarding.
  • No alarm when audit logging stops.
  • Only one admin knows how to enable EHR audit flags.
  • Components in AU-2 catalog never configured (VPN, email, SaaS).

Required Documentation

  • Audit generation configuration baselines per system
  • Log forwarding architecture diagram
  • Evidence of enabled audit settings (screenshots/exports)
  • Monitoring for logging failure
  • Change procedure for altering audited events

How to Test & Validate

  1. Enable a lab event, generate it, confirm a new record appears centrally.
  2. Temporarily stop a forwarder in test; confirm silence alert.
  3. Verify designated admins can adjust audited events per procedure.
  4. After a patch in test, re-confirm required events still generate.
  5. Sample components from the AU-2 matrix for active generation.

Audit Considerations

Assessors distinguish "we intend to log" from "show me today's records." AU-12 evidence is live configuration plus freshly generated sample events.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — systems containing ePHI must have mechanisms that record activity.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — cannot review what was never generated.
  • 164.316(b) Documentation — retain implementation evidence of audit mechanisms.
  • 164.308(a)(8) Evaluation — periodic evaluation should confirm logging still functions.

Compliance Tips

  • Add a 'logging still on' checkbox to every EHR upgrade template.
  • Monitor audit EPS (events per second) baselines per source.
  • Keep a break-glass path to re-enable auditing if a vendor toggle is switched off.

Frequently Asked Questions

How is AU-12 different from AU-2?

AU-2 selects which events; AU-12 ensures components generate those audit records and that authorized staff can manage selection.

Is forwarding to a SIEM required?

Centralization is best practice for AU-6 review and retention, though AU-12 itself focuses on generation capability at components.

What if a legacy system cannot log required events?

Document compensating controls (proxy logs, DLP, procedural reviews) and risk-accept or replace — do not pretend generation exists.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-12
  • NIST SP 800-92
  • HIPAA §§ 164.312(b), 164.308(a)(1)(ii)(D)
  • Related controls: AU-2, AU-3, AU-6, AU-9, SI-4

Need Help Implementing AU-12?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.