Month-end chart audit spike
Compliance enables detailed VIP auditing for a board member admission. Volume doubles; AU-4 headroom and alerts prevent the SIEM index from filling and rotating away the week of interest.
AU-4 requires allocating audit log storage capacity to support AU-2 event logging and configuring auditing to reduce the likelihood of capacity being exceeded. Hospitals generate heavy EHR view traffic, VPN sessions, and endpoint telemetry — undersized stores lead to overwritten evidence just when a privacy investigation or breach timeline needs it.
Provision and monitor enough durable storage (and retention windows) so required ePHI-system audit records are not lost to disk-full conditions or premature overwrite.
How this control shows up in healthcare and HIPAA-covered environments.
Compliance enables detailed VIP auditing for a board member admission. Volume doubles; AU-4 headroom and alerts prevent the SIEM index from filling and rotating away the week of interest.
EDR log ingest grows overnight. Capacity planning under AU-4 expands hot retention before agents are told to truncate locally.
Application server audit partition hits 100% and logging stops. Proper AU-4 sizing plus AU-5 alerting would have paged storage admins hours earlier.
Assessors ask whether logs can survive for the stated retention period under real load. Gaps during a known incident window are treated as serious control failures.
How this NIST control supports HIPAA Security Rule expectations.
No. It requires capacity allocated to support selected logging and practices that avoid unexpected exhaustion.
Only if sampling still meets AU-2 requirements and investigation needs — do not silently thin ePHI access evidence.
AU-4 reduces the chance of failure; AU-5 defines what to do when auditing still fails.
Related controls that commonly accompany AU-4.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.