VIP patient privacy round
Compliance runs weekly AU-6 reviews of who accessed board-member charts. An unnecessary view by registration staff triggers sanctions investigation — demonstrating activity review beyond security malware alerts.
AU-6 requires reviewing and analyzing system audit records on an organization-defined frequency for indications of unusual activity, reporting findings to defined personnel, and adjusting review levels when indications of increased risk appear. Selecting and generating logs is wasted effort without scheduled human or automated review — the heart of HIPAA information system activity review.
Ensure audit records are routinely examined, correlated, and escalated so inappropriate ePHI access, attacks, and misconfigurations are found and reported in time to respond.
How this control shows up in healthcare and HIPAA-covered environments.
Compliance runs weekly AU-6 reviews of who accessed board-member charts. An unnecessary view by registration staff triggers sanctions investigation — demonstrating activity review beyond security malware alerts.
SIEM alerts on an unusual EHR export volume. AU-6 process pages on-call, revokes sessions, and opens IR — automated analysis plus human reporting.
After a layoff, review frequency for privileged and remote logs increases for two weeks, catching a disabled account that was re-enabled in error.
HIPAA assessors specifically look for regular activity review evidence. A SIEM alone is not enough without proof humans analyze and report findings on a defined frequency.
How this NIST control supports HIPAA Security Rule expectations.
It helps, but you still need defined frequencies, human analysis/reporting, and evidence — especially for HIPAA activity review.
Define it risk-based in policy (e.g., continuous alerts + weekly privacy sampling + monthly privileged review) and follow it.
Typically compliance/privacy with IT support — not only SOC analysts looking for malware.
Related controls that commonly accompany AU-6.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.