Insider tries to delete EHR audit
A tech with DB rights attempts to purge view history after improper access. AU-9 immutable forward-to-SIEM copy remains, enabling sanctions and showing why local-only logs fail.
AU-9 requires protecting audit information and audit logging tools from unauthorized access, modification, and deletion, and backing up audit records to a physically different system or system components. Attackers and malicious insiders often wipe logs after browsing celebrity charts or deploying ransomware — unprotected audit stores erase the HIPAA investigation trail.
Keep audit records and logging tooling confidential, integrity-protected, and recoverable so ePHI activity evidence remains trustworthy and available to authorized reviewers only.
How this control shows up in healthcare and HIPAA-covered environments.
A tech with DB rights attempts to purge view history after improper access. AU-9 immutable forward-to-SIEM copy remains, enabling sanctions and showing why local-only logs fail.
Secondary object-lock bucket in another account still holds 30 days of IdP and EHR audits for counsel — backup to a different system component pays off.
Helpdesk staff can search all patient-identified audit events. AU-9 remediation restricts raw search to SOC/privacy and provides redacted report roles.
If privileged users can edit the only copy of audit evidence, accountability collapses. Assessors look for independent, protected log repositories.
How this NIST control supports HIPAA Security Rule expectations.
Not always, but you must protect against unauthorized modification/deletion — immutability is a strong pattern for high-risk ePHI environments.
Often yes. Protect audit stores with safeguards comparable to other ePHI repositories.
AU-9 protects the records; AU-11 defines how long to keep them.
Related controls that commonly accompany AU-9.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.