Celebrity patient complaint
Privacy needs all workforce views for one MRN across 72 hours. AU-7 report finishes in minutes instead of manual EHR console clicking — original logs remain intact.
AU-7 requires providing audit record reduction and report generation capabilities that support on-demand analysis and after-the-fact investigations, without altering original audit records. Raw multi-gigabyte EHR and IdP dumps are useless to privacy investigators who need a filtered report of who opened a specific MRN last week.
Give authorized reviewers tools to reduce, filter, and report on audit data quickly for operational monitoring and ePHI access investigations while preserving original records.
How this control shows up in healthcare and HIPAA-covered environments.
Privacy needs all workforce views for one MRN across 72 hours. AU-7 report finishes in minutes instead of manual EHR console clicking — original logs remain intact.
IR reduces endpoint and VPN logs to the first privileged lateral movement window and generates a timeline report for leadership and counsel.
Compliance runs an AU-7 saved search for after-hours bulk exports and attaches the PDF to the AU-6 review record.
HIPAA activity review is judged partly on whether you can produce meaningful reports. AU-7 is the capability that turns AU-6 ambition into evidence packets.
How this NIST control supports HIPAA Security Rule expectations.
Any capability that reduces and reports without altering originals can work; SIEM/EHR audit modules are common in healthcare.
Summaries are fine for dashboards, but retain originals for investigations per AU-9/AU-11.
AU-6 is the review process; AU-7 is the technical reduction/reporting capability reviewers use.
Related controls that commonly accompany AU-7.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.