AU-16 Audit and Accountability

Cross-Organizational Audit Logging

Medium Risk Moderate Medium Cost

AU-16 employs methods for coordinating audit information among external organizations when audit information is transmitted across organizational boundaries. HIEs, EHR hosts, and clearinghouses often hold pieces of an access story that a covered entity must assemble during investigations.

Control Objective

Coordinate and protect audit information exchanged with external healthcare organizations and BAs for defined events involving ePHI.

Implementation Guidance

  1. Identify partners that generate audit data for your ePHI (EHR host, HIE, BA processors).
  2. Define methods: secure API, SIEM share, periodic evidence packages, BA incident clauses.
  3. Protect audit in transit and at rest (SC-8, AU-9).
  4. Negotiate retention and response times in BAAs/contracts.
  5. Test joint investigation playbooks annually.
  6. Minimize PHI inside shared audit payloads when possible.
  7. Track chain of custody for external audit exports.
  8. Align with CA-3 interconnection agreements.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Hosted EHR access investigation

Suspicious chart access spans CE and SaaS host; AU-16 methods pull host audit into the CE SIEM under the BAA within the SLA.

HIE disclosure dispute

Patient disputes an HIE query; coordinated audit from HIE and local EHR reconstructs the access path.

Clearinghouse anomaly

Billing BA provides filtered audit extracts for a suspected insider using coordinated logging methods.

Best Practices

  • Put audit-sharing in BAAs.
  • Prefer automated secure feeds.
  • Protect shared audit like ePHI when it contains identifiers.
  • Test joint IR.
  • Define SLAs for evidence.
  • Minimize unnecessary identifiers in shared logs.

Common Gaps & Violations

  • BAAs silent on audit access.
  • Emailing raw logs unencrypted.
  • No tested method to obtain host audits.
  • Unlimited third-party log retention visibility without agreement.
  • Ignoring HIE audit coordination.

Required Documentation

  • Cross-org audit coordination standard (AU-16)
  • Partner inventory and methods
  • BAA/contract clauses
  • Sample coordinated investigation
  • Protection controls for shared audit

How to Test & Validate

  1. Request a test audit package from a key BA; measure time/quality.
  2. Verify transport encryption.
  3. Review BAA language for audit cooperation.
  4. Tabletop a multi-party access investigation.
  5. Confirm local correlation IDs match partner events.

Audit Considerations

AU-16 is about methods and agreements—not only wishing partners would send logs someday.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(b) Business Associate Contracts — cooperation including security incident and documentation needs.
  • 164.312(b) Audit Controls — audit mechanisms may span hosted systems.
  • 164.308(a)(6) Incident Response — cross-org events need coordinated evidence.
  • 164.314 BA requirements — ensure satisfactory assurances include audit support.

Compliance Tips

  • Add audit evidence SLAs to strategic BAAs.
  • Prefer customers of hosted EHR get immutable audit export rights.
  • Keep a partner audit contact roster.

Frequently Asked Questions

Does AU-16 require real-time SIEM sharing?

Methods are organization-defined; real-time is ideal but secure periodic packages may suffice if risk-accepted.

Can we share full audit freely?

Share per agreement and minimum necessary; audit can contain ePHI.

Related to AU-6?

AU-6 is review; AU-16 enables cross-boundary coordination of the audit information itself.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-16
  • Related controls: AU-6, AU-7, CA-3, SA-9

Need Help Implementing AU-16?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.