AU-6 Audit and Accountability

Audit Review, Analysis, and Reporting

High Risk Moderate Medium Cost

AU-6 requires reviewing and analyzing system audit records on an organization-defined frequency for indications of unusual activity, reporting findings to defined personnel, and adjusting review levels when indications of increased risk appear. Selecting and generating logs is wasted effort without scheduled human or automated review — the heart of HIPAA information system activity review.

Control Objective

Ensure audit records are routinely examined, correlated, and escalated so inappropriate ePHI access, attacks, and misconfigurations are found and reported in time to respond.

Implementation Guidance

  1. Define review cadences: continuous/automated alerting for high-risk events; daily/weekly analyst review; monthly compliance chart-access audits.
  2. Assign owners: security ops for threat detection; compliance/privacy for snooping and minimum-necessary reviews.
  3. Use SIEM or EHR audit tools to alert on VIP chart access, mass exports, after-hours admin changes, and repeated auth failures.
  4. Correlate across IdP, EHR, email, and endpoint sources for higher-fidelity detection.
  5. Document findings, tickets, and outcomes — reviews without records do not satisfy auditors.
  6. Increase review intensity after incidents, terminations, or threat intel spikes.
  7. Report metrics to leadership (open investigations, mean time to review).
  8. Include BA-provided audit extracts in the review program where ePHI is processed externally.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

VIP patient privacy round

Compliance runs weekly AU-6 reviews of who accessed board-member charts. An unnecessary view by registration staff triggers sanctions investigation — demonstrating activity review beyond security malware alerts.

Mass export at 2 a.m.

SIEM alerts on an unusual EHR export volume. AU-6 process pages on-call, revokes sessions, and opens IR — automated analysis plus human reporting.

Post-termination access spike

After a layoff, review frequency for privileged and remote logs increases for two weeks, catching a disabled account that was re-enabled in error.

Best Practices

  • Combine automated detection with scheduled privacy audits.
  • Record every review cycle (even 'no findings').
  • Tune alerts to reduce ignored noise.
  • Escalate with clear severity and owners.
  • Feed lessons back into AU-2 event selection.
  • Protect reviewers' access to audit data (least privilege).

Common Gaps & Violations

  • Logs retained but never reviewed.
  • SIEM alerts ignored (alert fatigue).
  • Only IT security reviews — no privacy chart-access audits.
  • No documentation of weekly/monthly reviews.
  • Review frequency never increases after incidents.

Required Documentation

  • Audit review and reporting procedure (AU-6)
  • Review schedule and RACI
  • Alert use-cases / correlation rules list
  • Sample review reports and tickets
  • Escalation matrix to IR and privacy

How to Test & Validate

  1. Inspect evidence of the last 4 review cycles (dates, reviewer, outcomes).
  2. Trigger a synthetic alert and confirm reporting path.
  3. Sample a privacy audit of EHR access for a test patient.
  4. Verify increased review was documented after a recent change/incident.
  5. Confirm BA audit extracts are reviewed when required.

Audit Considerations

HIPAA assessors specifically look for regular activity review evidence. A SIEM alone is not enough without proof humans analyze and report findings on a defined frequency.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1)(ii)(D) Information System Activity Review — regularly review audit logs, access reports, and security incident tracking.
  • 164.312(b) Audit Controls — recording activity must be paired with examination.
  • 164.308(a)(6) Security Incident Procedures — review findings often feed incident response.
  • 164.308(a)(5)(ii)(C) Log-in Monitoring — review of log-in attempts is an AU-6 use case.

Compliance Tips

  • Keep a simple monthly compliance packet: dates reviewed, tools used, findings, tickets.
  • Separate 'security monitoring' and 'privacy access audit' checklists so neither is skipped.
  • Retune alerts quarterly so AU-6 stays usable.

Frequently Asked Questions

Does automated SIEM alerting satisfy AU-6 by itself?

It helps, but you still need defined frequencies, human analysis/reporting, and evidence — especially for HIPAA activity review.

How often is 'regular' review?

Define it risk-based in policy (e.g., continuous alerts + weekly privacy sampling + monthly privileged review) and follow it.

Who should review EHR chart access?

Typically compliance/privacy with IT support — not only SOC analysts looking for malware.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-6
  • NIST SP 800-92
  • HIPAA §§ 164.308(a)(1)(ii)(D), 164.312(b)
  • Related controls: AU-2, AU-3, AU-7, IR-4, SI-4

Need Help Implementing AU-6?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.