Export event without patient context
EHR logs say UserX exported a report but not which patients. AU-3 remediation enables detailed export auditing so compliance knows the census list scope.
AU-3 requires audit records to contain information establishing what type of event occurred, when it occurred, where it occurred, the source of the event, the outcome, and the identity of any individuals or subjects associated with the event. Thin logs that only say "error" without user or object identity fail both NIST and practical HIPAA investigations.
Ensure every required audit event carries enough fields to answer who did what to which ePHI or system object, when, from where, and whether it succeeded.
How this control shows up in healthcare and HIPAA-covered environments.
EHR logs say UserX exported a report but not which patients. AU-3 remediation enables detailed export auditing so compliance knows the census list scope.
Legacy VPN logged only public IPs. After IA/AU hardening, records include unique user ID + device posture — enough to support incident timelines.
IdP uses email; EHR uses short username; timestamps differ by minutes. AU-3 + identity mapping + clock sync make cross-system investigation possible.
Auditors open sample audit records. If they cannot identify the user, object, time, and result, AU-3 (and HIPAA audit usefulness) is not met.
How this NIST control supports HIPAA Security Rule expectations.
For ePHI access events, some durable patient object reference is usually required to investigate. Protect audit repositories accordingly.
No. Priority is metadata; AU-3 needs identity, object, time, source, and outcome in the record.
AU-2 selects events; AU-3 defines what each selected event record must contain.
Related controls that commonly accompany AU-3.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.