Hosted EHR access investigation
Suspicious chart access spans CE and SaaS host; AU-16 methods pull host audit into the CE SIEM under the BAA within the SLA.
AU-16 employs methods for coordinating audit information among external organizations when audit information is transmitted across organizational boundaries. HIEs, EHR hosts, and clearinghouses often hold pieces of an access story that a covered entity must assemble during investigations.
Coordinate and protect audit information exchanged with external healthcare organizations and BAs for defined events involving ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
Suspicious chart access spans CE and SaaS host; AU-16 methods pull host audit into the CE SIEM under the BAA within the SLA.
Patient disputes an HIE query; coordinated audit from HIE and local EHR reconstructs the access path.
Billing BA provides filtered audit extracts for a suspected insider using coordinated logging methods.
AU-16 is about methods and agreements—not only wishing partners would send logs someday.
How this NIST control supports HIPAA Security Rule expectations.
Methods are organization-defined; real-time is ideal but secure periodic packages may suffice if risk-accepted.
Share per agreement and minimum necessary; audit can contain ePHI.
AU-6 is review; AU-16 enables cross-boundary coordination of the audit information itself.
Related controls that commonly accompany AU-16.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.