Chart snooping investigation
A celebrity patient alleges workforce browsing. Because AU-2 required EHR 'view' events on charts, compliance can pull who opened the record and when — without AU-2 those views might never have been selected for logging.
AU-2 requires the organization to identify the types of events that the system is capable of logging, coordinate logging content with other related repositories, specify which events to log for each system, and review/update the event list periodically — especially after major system changes or security incidents. It answers: what must we capture to investigate ePHI access and security events?
Define a living list of security- and privacy-relevant events that systems with ePHI (and supporting infrastructure) must generate so investigations and compliance reviews are possible.
How this control shows up in healthcare and HIPAA-covered environments.
A celebrity patient alleges workforce browsing. Because AU-2 required EHR 'view' events on charts, compliance can pull who opened the record and when — without AU-2 those views might never have been selected for logging.
Security needs to know the first privileged logon and lateral tool use. AU-2 ensures endpoint process-create and VPN logon events are in scope for clinical workstations — not only firewall denies.
A telehealth SaaS is added. AU-2 review updates the event list to include recording access, session join, and export events before go-live.
Assessors ask which events you chose and why. Show the catalog and proof systems actually emit those events — selection without generation fails AU-2/AU-12 together.
How this NIST control supports HIPAA Security Rule expectations.
No. AU-2 is selecting which events matter. AU-12 is ensuring the system generates them; AU-3 defines record content; AU-6 covers review.
At least annually and whenever major systems, remote access, or incidents change your monitoring needs.
No. Focus on security- and privacy-relevant events that support investigations and HIPAA activity review.
Related controls that commonly accompany AU-2.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.