HIPAAmart

Security safeguards · 7 min read

HIPAA Audit Controls

Create useful, reviewable records of activity in systems that contain or use ePHI.

Reviewed August 2026

Definition

Audit controls are mechanisms that record and examine activity in information systems containing or using ePHI.

In practice

  • A record-access report supports a privacy investigation when it includes user, patient record, timestamp, and action context.
  • Cloud audit logs can complement application logs but do not replace them.

Who this applies to

  • Application and infrastructure owners
  • Security operations and privacy teams
  • Business associates operating systems on behalf of covered entities

What the rule asks for

  • Identify relevant systems and activity to record.
  • Protect log integrity and access.
  • Define review, retention, alerting, and investigation practices based on risk.

How teams put it into practice

  • Write down what events answer who, what, when, where, and outcome questions.
  • Centralize or correlate high-value logs while preserving source context.
  • Exercise an investigation using real records and document gaps.

Common mistakes

  • Logging everything without a review plan.
  • Allowing administrators to alter or delete their own audit trail.
  • Ignoring SaaS, support, and API activity.

Questions that come up

How long must HIPAA logs be kept?

HIPAA has documentation retention requirements and organizations should also consider applicable system, incident, contractual, and state-law needs; define a documented retention schedule rather than guessing one universal period.

References