AU-14 Audit and Accountability

Session Audit

High Risk Moderate High Cost

AU-14 provides the capability to capture, record, and log all content of organization-defined sessions, remotely view sessions in real time, and/or remotely replay sessions. In healthcare, privileged EHR admin, PAM, and remote vendor sessions are prime candidates so investigators can see what changed—not only that a login occurred.

Control Objective

Enable session capture/view/replay for defined high-risk sessions that can create, modify, or exfiltrate ePHI.

Implementation Guidance

  1. Scope sessions: PAM admin, EHR security console, VPN vendor access, break-glass.
  2. Deploy session recording via PAM/VDI where feasible.
  3. Protect recordings as sensitive audit media (AU-9).
  4. Limit who can view/replay; log viewer access.
  5. Align retention with investigation and legal needs.
  6. Notify users of monitoring per policy/workforce notice.
  7. Test replay during IR tabletop.
  8. Exclude ordinary clinical charting if risk analysis scopes only privileged sessions—document the boundary.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Vendor PACS admin weekend

OEM engineer works through PAM with full session recording; later dispute over a route change is resolved by replay.

Break-glass EHR elevation

Emergency admin session is recorded and reviewed within 24 hours under AU-14 procedures.

Real-time SOC view

SOC watches a suspicious privileged session live and terminates when mass export begins.

Best Practices

  • Prefer PAM-brokered recording.
  • Protect recording storage.
  • Scope privileged sessions first.
  • Legal/privacy notice to workforce.
  • Test replay in IR drills.
  • Do not over-collect ordinary clinician sessions without need.

Common Gaps & Violations

  • Logging logons only, no content.
  • Recordings on unprotected shares.
  • Unlimited viewer access.
  • Vendors on unrecorded RDP.
  • Claiming AU-14 without any replay capability.

Required Documentation

  • Session audit standard (AU-14)
  • In-scope session types
  • PAM/recording configuration evidence
  • Retention and access controls
  • Sample replay investigation

How to Test & Validate

  1. Conduct a test privileged session; confirm recording exists.
  2. Replay and verify content fidelity.
  3. Confirm unauthorized staff cannot access recordings.
  4. Review retention settings.
  5. Verify vendor access path is in scope.

Audit Considerations

AU-14 evidence is recordings and controlled replay—not only SIEM login events.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — record and examine activity in systems with ePHI.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — session content supports reviews.
  • 164.308(a)(6) Incident Response — session replay aids investigations.
  • 164.312(a) Access Control — accountability for privileged use.

Compliance Tips

  • Start with PAM for EHR and infrastructure admins.
  • Put session review SLAs on break-glass use.
  • Mention workforce monitoring notice in onboarding.

Frequently Asked Questions

Must every clinician session be recorded?

AU-14 is organization-defined; most hospitals scope privileged/vendor sessions first.

Is keystroke logging required?

Capability typically includes session content; implement via PAM/VDI tools appropriate to risk and law.

How related to AU-2?

AU-2 defines auditable events; AU-14 adds session capture/view/replay capabilities.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-14
  • Related controls: AU-2, AU-9, AC-2, IA-2

Need Help Implementing AU-14?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.