AU-9 Audit and Accountability

Protection of Audit Information

High Risk Moderate Medium Cost

AU-9 requires protecting audit information and audit logging tools from unauthorized access, modification, and deletion, and backing up audit records to a physically different system or system components. Attackers and malicious insiders often wipe logs after browsing celebrity charts or deploying ransomware — unprotected audit stores erase the HIPAA investigation trail.

Control Objective

Keep audit records and logging tooling confidential, integrity-protected, and recoverable so ePHI activity evidence remains trustworthy and available to authorized reviewers only.

Implementation Guidance

  1. Store audit data separately from production EHR app servers with strict ACLs and MFA admin access.
  2. Prefer append-only / WORM / object-lock retention for tier-1 investigation stores.
  3. Limit who can query raw logs; use AU-7 reports with least privilege for privacy analysts.
  4. Monitor for audit deletion, index drops, or permission changes — alert as high severity.
  5. Back up audit repositories to a different system/account boundary; test restores.
  6. Harden SIEM and log forwarders like Tier-0 assets (patching, MFA, jump hosts).
  7. Encrypt audit data at rest and in transit; treat MRNs in logs as sensitive.
  8. Separate duties so the person administering production EHR is not sole owner of immutable audit stores.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

Insider tries to delete EHR audit

A tech with DB rights attempts to purge view history after improper access. AU-9 immutable forward-to-SIEM copy remains, enabling sanctions and showing why local-only logs fail.

Ransomware hits the SIEM

Secondary object-lock bucket in another account still holds 30 days of IdP and EHR audits for counsel — backup to a different system component pays off.

Over-broad SIEM access

Helpdesk staff can search all patient-identified audit events. AU-9 remediation restricts raw search to SOC/privacy and provides redacted report roles.

Best Practices

  • Immutable or strongly integrity-protected stores.
  • Tier-0 hardening for logging infrastructure.
  • Dual custody / separation of duties.
  • Encryption and strict query ACLs.
  • Off-system backups with restore tests.
  • Alert on audit tampering attempts.

Common Gaps & Violations

  • Admins with full rights to delete their own audit trails.
  • Logs only on the same server being investigated.
  • SIEM open to too many IT staff.
  • No backup of audit indices.
  • Unencrypted log channels across networks.

Required Documentation

  • Audit information protection standard
  • Access control lists / roles for log systems
  • Immutability or integrity control evidence
  • Audit backup and restore procedures
  • Tamper-alert configurations

How to Test & Validate

  1. Attempt unauthorized delete/modify in test; confirm denial and alert.
  2. Verify production admins cannot unilaterally wipe central audit copies.
  3. Restore a sample audit backup successfully.
  4. Review SIEM user list for least privilege.
  5. Confirm encryption in transit to collectors.

Audit Considerations

If privileged users can edit the only copy of audit evidence, accountability collapses. Assessors look for independent, protected log repositories.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — recorded activity must remain available for examination.
  • 164.312(a) Access Control — limit who can access audit repositories containing ePHI identifiers.
  • 164.312(c) Integrity — protect ePHI (including in logs) from improper alteration/destruction.
  • 164.308(a)(1)(ii)(D) Information System Activity Review — reviews require trustworthy records.

Compliance Tips

  • Forward EHR audits off-box before local retention ends.
  • Put SIEM admin through the same privileged access workstation controls as domain admin.
  • Include audit-store access in quarterly access reviews.

Frequently Asked Questions

Does AU-9 require write-once media?

Not always, but you must protect against unauthorized modification/deletion — immutability is a strong pattern for high-risk ePHI environments.

Are logs containing MRNs ePHI?

Often yes. Protect audit stores with safeguards comparable to other ePHI repositories.

How does AU-9 relate to AU-11?

AU-9 protects the records; AU-11 defines how long to keep them.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-9
  • NIST SP 800-92
  • Related controls: AU-6, AU-7, AU-11, AC-3, AC-6, CP-9

Need Help Implementing AU-9?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.