AU-1 Audit and Accountability Policy and Procedures

Audit and Accountability Policy and Procedures

High Risk Moderate Low Cost

AU-1 requires audit and accountability policy and procedures that address purpose, scope, roles, management commitment, coordination, and compliance, plus procedures to implement the Audit and Accountability family. For HIPAA, AU-1 sets governance for audit controls — who reviews EHR access logs, how long logs are kept, and how integrity of audit trails is protected when investigating snooping or breach scope.

Control Objective

Establish policy and procedures that define logging, protection, retention, review, and response expectations for systems that create, receive, maintain, or transmit ePHI.

Implementation Guidance

  1. Publish AU-1 policy covering EHR, IdP, VPN, HIE gateways, imaging, and privileged admin activity.
  2. Define event types of interest: access, create/update/delete of ePHI, exports, admin changes, failed logons.
  3. Assign roles for log administration, review, and investigation (security, privacy, HIM).
  4. Set retention aligned to HIPAA and investigation needs (often ≥6 years for related documentation; system logs per risk).
  5. Require clock sync, access restriction on log stores, and tamper-evident storage where feasible.
  6. Document review cadence and escalation to IR when anomalies appear.
  7. Review policy annually and after SIEM/EHR audit-config changes.
  8. Coordinate with AU-2 through AU-12 operational procedures.

Real-World Use Cases

How this control shows up in healthcare and HIPAA-covered environments.

VIP chart snooping allegation

AU-1 procedures name privacy as reviewer of EHR access reports and define evidence handling so HR/legal receive intact audit extracts.

Cloud EHR audit API change

Vendor alters available events; AU-1-driven review updates logging procedures and retention jobs before the old feed goes dark.

Ransomware scoping

Policy requires privileged authentication and backup-admin logs be in scope for IR — not only clinical chart opens.

Best Practices

  • Explicit ePHI systems inventory for logging scope.
  • Separate duties: admins who manage logs vs subjects of monitoring.
  • Retention and protection stated in policy.
  • Review procedures linked to privacy investigations.
  • Annual AU-1 review with config drift checks.
  • Cover medical devices and interfaces where feasible.

Common Gaps & Violations

  • Logging enabled but no policy on review ownership.
  • Audit trails overwritten in weeks with no risk basis.
  • EHR logs exist; IdP and VPN ignored.
  • Staff can alter or delete their own audit records.
  • Policy copied from generic IT without healthcare events.

Required Documentation

  • Audit and accountability policy (AU-1)
  • Logging/review/retention procedures
  • System logging scope inventory
  • Roles for audit review and escalation
  • Policy review and approval records

How to Test & Validate

  1. Verify AU-1 policy is current and approved.
  2. Sample an ePHI system for logging aligned to policy.
  3. Confirm retention settings match stated periods.
  4. Review evidence of scheduled log/access reviews.
  5. Test that audit stores are access-controlled.

Audit Considerations

HIPAA § 164.312(b) audit controls are frequently tested. AU-1 shows leadership defined what “reasonable” logging and review means for your environment.

HIPAA Mapping

How this NIST control supports HIPAA Security Rule expectations.

  • 164.312(b) Audit Controls — hardware, software, and/or procedural mechanisms that record and examine activity in systems with ePHI.
  • 164.308(a)(1) Risk Analysis / Risk Management — logging scope should reflect assessed risks (snooping, insider, malware).
  • 164.308(a)(6) Security Incident Procedures — audit data supports incident detection and response.
  • 164.316 Policies and procedures — document and maintain audit policy and procedures.

Compliance Tips

  • Maintain a logging coverage matrix: system → events → retention → reviewer.
  • Align AU-1 retention language with legal hold procedures.
  • Require change tickets when audit logging is disabled anywhere.

Frequently Asked Questions

Must every medical device send logs to SIEM under AU-1?

Policy should risk-rank devices; prioritize networked devices that store/process ePHI and document compensating reviews where full SIEM ingest is impractical.

How does AU-1 differ from AU-2?

AU-1 is the governing policy/procedures; AU-2 selects auditable events operationally under that policy.

Are privacy access reports enough?

They are necessary for EHR snooping use cases but AU-1 should also cover infrastructure, identity, and export channels.

References & Resources

  • NIST SP 800-53 Rev. 5 — AU-1
  • HIPAA § 164.312(b)
  • Related controls: AU-2, AU-3, AU-6, AU-9, IR-4

Need Help Implementing AU-1?

Our auditors map NIST SP 800-53 controls to your HIPAA Security Rule program — policies, technical evidence, and audit readiness.