EHR upgrade disables audit API
Ingest volume drops to zero at 02:00. AU-5 silence alert pages on-call; settings restored before morning clinics open — avoiding a full day of unlogged chart access.
AU-5 requires alerting designated personnel within an organization-defined time period in the event of an audit logging process failure, and taking additional organization-defined actions (such as shutting down, overwriting oldest records, or stopping system functions). In healthcare, a quiet log pipeline during a ransomware event or insider browsing spree is itself an incident.
Detect audit generation, transport, or storage failures quickly; notify the right people; and execute predefined actions so ePHI activity is not invisibly unlogged.
How this control shows up in healthcare and HIPAA-covered environments.
Ingest volume drops to zero at 02:00. AU-5 silence alert pages on-call; settings restored before morning clinics open — avoiding a full day of unlogged chart access.
Collectors reject events. AU-5 triggers capacity response and temporary filter of low-value noise while preserving ePHI access and admin events.
Forwarding had failed for 12 hours unnoticed historically. New AU-5 heartbeats would have exposed the gap before encryption started.
Auditors increasingly ask how you know logging is working today. AU-5 evidence is alerts, on-call records, and playbooks — not a hope that disks never fill.
How this NIST control supports HIPAA Security Rule expectations.
Rarely practical for patient care. Define proportionate actions — alert, failover, restrict admin functions — and document clinical safety tradeoffs.
No. Include application-level audit disable and shipping failures.
Organization-defined personnel — typically SOC plus system owners for tier-1 clinical systems.
Related controls that commonly accompany AU-5.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.