VIP chart snooping allegation
AU-1 procedures name privacy as reviewer of EHR access reports and define evidence handling so HR/legal receive intact audit extracts.
AU-1 requires audit and accountability policy and procedures that address purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to implement the Audit and Accountability family. For HIPAA, AU-1 sets governance for audit controls — who reviews EHR access logs, how long logs are kept, and how integrity of audit trails is protected when investigating snooping or breach scope.
Establish policy and procedures that define logging, protection, retention, review, and response expectations for systems that create, receive, maintain, or transmit ePHI.
How this control shows up in healthcare and HIPAA-covered environments.
AU-1 procedures name privacy as reviewer of EHR access reports and define evidence handling so HR/legal receive intact audit extracts.
Vendor alters available events; AU-1-driven review updates logging procedures and retention jobs before the old feed goes dark.
Policy requires privileged authentication and backup-admin logs be in scope for IR — not only clinical chart opens.
HIPAA § 164.312(b) audit controls are frequently tested. AU-1 shows leadership defined what “reasonable” logging and review means for your environment.
How this NIST control supports HIPAA Security Rule expectations.
Policy should risk-rank devices; prioritize networked devices that store/process ePHI and document compensating reviews where full SIEM ingest is impractical.
AU-1 is the governing policy/procedures; AU-2 selects auditable events operationally under that policy.
They are necessary for EHR snooping use cases but AU-1 should also cover infrastructure, identity, and export channels.
Related controls that commonly accompany AU-1.
Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.