AU-2 Audit and Accountability

Audit Events

High Risk Moderate Medium Cost

AU-2 requires the organization to identify the types of events that the system is capable of logging, coordinate logging content with other related repositories, specify which events to log for each system, and review/update the event list periodically — especially after major system changes or security incidents. It answers: what must we capture to investigate ePHI access and security events?

Control Objective

Define a living list of security- and privacy-relevant events that systems with ePHI (and supporting infrastructure) must generate so investigations and compliance reviews are possible.

Implementation Guidance

  1. Inventory logging capabilities of EHR, IdP, VPN, email, endpoints, firewalls, and key SaaS under BAAs.
  2. Define required events: logon success/failure, logoff, privilege use, admin config changes, ePHI view/create/update/print/export, break-glass, failed authorization, remote access, and malware alerts.
  3. Coordinate so the same incident can be reconstructed across IdP + EHR + network logs.
  4. Publish the event list in a logging standard; map each event to systems that must produce it.
  5. Review the list at least annually and after incidents, EHR go-lives, or new remote access methods.
  6. Exclude noisy low-value events that drown analysts — document why.
  7. Ensure BA systems that create/receive ePHI have contractually required audit events.
  8. Tie AU-2 selections to AU-3 (content), AU-12 (generation), and AU-6 (review).

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Chart snooping investigation

A celebrity patient alleges workforce browsing. Because AU-2 required EHR 'view' events on charts, compliance can pull who opened the record and when — without AU-2 those views might never have been selected for logging.

Ransomware timeline

Security needs to know the first privileged logon and lateral tool use. AU-2 ensures endpoint process-create and VPN logon events are in scope for clinical workstations — not only firewall denies.

New telehealth platform

A telehealth SaaS is added. AU-2 review updates the event list to include recording access, session join, and export events before go-live.

Best Practices

  • Maintain a master audit event catalog by system tier.
  • Prioritize ePHI access and privileged change events.
  • Revisit after every major clinical system change.
  • Align with HIPAA audit control expectations and IR needs.
  • Do not confuse 'system can log' with 'we configured it to log.'
  • Include cloud admin and SaaS audit events in scope.

Common Gaps & Violations

  • Default EHR audit settings never reviewed after install.
  • Only authentication failures logged — not successful ePHI views.
  • No update to event lists after adding VPN or new EHR modules.
  • BA portals with no agreed audit events.
  • Logging everything raw with no catalog or ownership.

Required Documentation

  • Audit event selection standard (AU-2 catalog)
  • System-to-event mapping matrix
  • Annual review records / change tickets updating events
  • BA audit-event requirements excerpts
  • Coordination notes across log sources

How to Test & Validate

  1. Compare EHR audit config to the AU-2 catalog for required events.
  2. Generate a test ePHI view and confirm an event is produced.
  3. Generate an admin config change and confirm logging.
  4. Review last catalog update date vs recent system changes.
  5. Sample one BA system for required event availability.

Audit Considerations

Assessors ask which events you chose and why. Show the catalog and proof systems actually emit those events — selection without generation fails AU-2/AU-12 together.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — hardware, software, and procedural mechanisms that record and examine activity in systems containing ePHI.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — procedures to regularly review records of information system activity.
  • 164.308(a)(5)(ii)(C) Log-in Monitoring — monitoring log-in attempts depends on selecting those events.
  • 164.316 Policies and procedures / documentation — retain documentation of logging decisions.

Compliance Tips

  • Put AU-2 catalog updates on the EHR change-control checklist.
  • Start from investigation scenarios (snooping, ransomware, lost device) and work backward to required events.
  • Keep the catalog short enough to operate — depth over dump.

Frequently Asked Questions

Is AU-2 the same as enabling audit logs?

No. AU-2 is selecting which events matter. AU-12 is ensuring the system generates them; AU-3 defines record content; AU-6 covers review.

How often should we update the event list?

At least annually and whenever major systems, remote access, or incidents change your monitoring needs.

Do we need every mouse click?

No. Focus on security- and privacy-relevant events that support investigations and HIPAA activity review.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-2
  • NIST SP 800-92 Guide to Computer Security Log Management
  • HIPAA §§ 164.312(b), 164.308(a)(1), 164.308(a)(5)
  • Related controls: AU-3, AU-6, AU-12, SI-4

Need Help Implementing AU-2?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.