Public S3 bucket with imaging exports
Cloud posture scan finds a public object with study metadata; AU-13 monitoring triggers IR and BA notification review.
AU-13 monitors for evidence of unauthorized disclosure of organizational information at organization-defined frequency and using defined sources/methods. Healthcare programs watch for leaked charts on paste sites, misplaced files on public cloud, and abnormal outbound transfers of ePHI.
Detect unauthorized disclosure of ePHI and related sensitive healthcare information through continuous or periodic monitoring of defined sources.
How this control shows up in healthcare and HIPAA-covered environments.
Cloud posture scan finds a public object with study metadata; AU-13 monitoring triggers IR and BA notification review.
Brand monitoring finds staff email/password lists; SOC assumes possible EHR reuse and forces resets.
DLP shows recurring external sends of full records; privacy investigates disclosure patterns under AU-13.
AU-13 is about discovering disclosures—not only preventing them. Show monitoring sources and response samples.
How this NIST control supports HIPAA Security Rule expectations.
Related. SI-4 is broader system monitoring; AU-13 focuses on unauthorized information disclosure evidence.
Risk-based; document chosen sources and gaps.
It helps detect after-the-fact disclosure indicators; pair with AU-6 and AC-23.
Related controls that commonly accompany AU-13.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.