AU-13 Audit and Accountability

Monitoring for Information Disclosure

High Risk Moderate Medium Cost

AU-13 monitors for evidence of unauthorized disclosure of organizational information at organization-defined frequency and using defined sources/methods. Healthcare programs watch for leaked charts on paste sites, misplaced files on public cloud, and abnormal outbound transfers of ePHI.

Control Objective

Detect unauthorized disclosure of ePHI and related sensitive healthcare information through continuous or periodic monitoring of defined sources.

Implementation Guidance

  1. Define disclosure monitoring sources: DLP alerts, cloud public-share scans, dark-web/brand monitoring, media, BA incident feeds.
  2. Set frequency and owners (SOC vs privacy).
  3. Alert on public links to files with MRNs or clinical content.
  4. Correlate with AU-6 and IR-4 for confirmed leaks.
  5. Include workforce social media and misdirected email patterns where feasible.
  6. Cover research preprint and conference materials for PHI slips.
  7. Document monitoring limitations honestly.
  8. Retain investigation evidence per policy.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Public S3 bucket with imaging exports

Cloud posture scan finds a public object with study metadata; AU-13 monitoring triggers IR and BA notification review.

Paste site credential dump

Brand monitoring finds staff email/password lists; SOC assumes possible EHR reuse and forces resets.

Misdirected ROI email trend

DLP shows recurring external sends of full records; privacy investigates disclosure patterns under AU-13.

Best Practices

  • Combine technical DLP with open-source monitoring.
  • Clear ownership privacy vs SOC.
  • Feed confirmed events to IR.
  • Include cloud public exposure.
  • Train workforce on accidental disclosure.
  • Measure time-to-detect.

Common Gaps & Violations

  • Only monitoring firewalls, not disclosure channels.
  • Ignoring public cloud shares.
  • No owner for brand/leak monitoring.
  • Alerts without IR linkage.
  • Research publications unchecked for PHI.

Required Documentation

  • Disclosure monitoring standard (AU-13)
  • Source and frequency matrix
  • Alert/IR playbooks
  • Sample findings and tickets
  • Residual coverage gaps

How to Test & Validate

  1. Plant a safe test public share; confirm detection.
  2. Review last quarter disclosure alerts.
  3. Verify IR tickets for confirmed events.
  4. Check cloud public-access findings closed.
  5. Sample BA incident intake for disclosure themes.

Audit Considerations

AU-13 is about discovering disclosures—not only preventing them. Show monitoring sources and response samples.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1) Risk Analysis — undiscovered disclosures increase breach impact.
  • 164.308(a)(6) Incident Response — detected disclosures must enter IR.
  • 164.312(b) Audit Controls — mechanisms that examine activity supporting disclosure detection.
  • 164.400 Breach Notification — timely detection supports notification duties.

Compliance Tips

  • Put public-cloud exposure on the weekly SOC checklist.
  • Pair AU-13 with DLP and CASB where licensed.
  • Brief executives on monitoring blind spots.

Frequently Asked Questions

Is AU-13 the same as SI-4?

Related. SI-4 is broader system monitoring; AU-13 focuses on unauthorized information disclosure evidence.

Must we buy dark-web monitoring?

Risk-based; document chosen sources and gaps.

Does this cover intentional insider theft?

It helps detect after-the-fact disclosure indicators; pair with AU-6 and AC-23.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-13
  • Related controls: AU-6, SI-4, IR-4, AC-6

Need Help Implementing AU-13?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.