AU-7 Audit and Accountability

Audit Reduction and Report Generation

Medium Risk Moderate Medium Cost

AU-7 requires providing audit record reduction and report generation capabilities that support on-demand analysis and after-the-fact investigations, without altering original audit records. Raw multi-gigabyte EHR and IdP dumps are useless to privacy investigators who need a filtered report of who opened a specific MRN last week.

Control Objective

Give authorized reviewers tools to reduce, filter, and report on audit data quickly for operational monitoring and ePHI access investigations while preserving original records.

Implementation Guidance

  1. Deploy SIEM/EHR audit tools that filter by user, patient/MRN, time range, event type, workstation, and success/failure.
  2. Build saved reports: VIP chart access, mass export, break-glass, privileged changes, terminated-user activity.
  3. Ensure reduction/reporting is read-only against originals (WORM or immutable store + working copies).
  4. Grant report capabilities to compliance/privacy and SOC roles under least privilege (AU-9).
  5. Support export formats suitable for case files (CSV/PDF) with integrity hashes when needed.
  6. Tune parsers so healthcare-specific fields (MRN, encounter, department) are first-class filters.
  7. Document how to run standard investigation reports within an SLA (e.g., same business day).
  8. Periodically validate reports still work after EHR or SIEM upgrades.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Celebrity patient complaint

Privacy needs all workforce views for one MRN across 72 hours. AU-7 report finishes in minutes instead of manual EHR console clicking — original logs remain intact.

Ransomware forensics

IR reduces endpoint and VPN logs to the first privileged lateral movement window and generates a timeline report for leadership and counsel.

Monthly access anomaly pack

Compliance runs an AU-7 saved search for after-hours bulk exports and attaches the PDF to the AU-6 review record.

Best Practices

  • Saved investigation playbooks/reports.
  • Never modify original audit events when reporting.
  • Role-based access to reduction tools.
  • Healthcare field-aware filters (patient, department).
  • Test reports after platform upgrades.
  • Measure time-to-report for privacy cases.

Common Gaps & Violations

  • Logs retained but only searchable by raw grep on appliances.
  • Reports that rewrite or delete source events.
  • Privacy staff cannot run queries without IT for every case.
  • No standard VIP or export report templates.
  • Broken dashboards ignored for months.

Required Documentation

  • Audit reduction and reporting procedure
  • Standard report catalog (privacy + security)
  • Tool access roles for investigators
  • Proof of original-record integrity controls
  • Sample redacted investigation reports

How to Test & Validate

  1. Run a patient-centric access report for a test MRN; verify completeness vs source.
  2. Confirm originals unchanged after report generation.
  3. Time a standard privacy report against SLA.
  4. Verify least-privilege access to reporting tools.
  5. Re-validate saved reports after a recent upgrade.

Audit Considerations

HIPAA activity review is judged partly on whether you can produce meaningful reports. AU-7 is the capability that turns AU-6 ambition into evidence packets.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.308(a)(1)(ii)(D) Information System Activity Review — regular review implies usable reduction/reporting.
  • 164.312(b) Audit Controls — examine activity; tools must support examination.
  • 164.528 Accounting of Disclosures — some accounting processes rely on reportable event histories.
  • 164.308(a)(6) Security Incident Procedures — investigations need timely audit reporting.

Compliance Tips

  • Publish a short menu of standard reports privacy can run solo.
  • Keep a redacted sample pack ready for assessors.
  • Pair AU-7 filters with AU-3 field quality — bad content breaks reports.

Frequently Asked Questions

Is a SIEM required for AU-7?

Any capability that reduces and reports without altering originals can work; SIEM/EHR audit modules are common in healthcare.

Can we summarize away detailed events?

Summaries are fine for dashboards, but retain originals for investigations per AU-9/AU-11.

How does AU-7 relate to AU-6?

AU-6 is the review process; AU-7 is the technical reduction/reporting capability reviewers use.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-7
  • NIST SP 800-92
  • Related controls: AU-6, AU-3, AU-9, AU-11, IR-4

Need Help Implementing AU-7?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.