Definition
Audit controls are mechanisms that record and examine activity in information systems containing or using ePHI.
In practice
- A record-access report supports a privacy investigation when it includes user, patient record, timestamp, and action context.
- Cloud audit logs can complement application logs but do not replace them.
Who this applies to
- Application and infrastructure owners
- Security operations and privacy teams
- Business associates operating systems on behalf of covered entities
What the rule asks for
- Identify relevant systems and activity to record.
- Protect log integrity and access.
- Define review, retention, alerting, and investigation practices based on risk.
How teams put it into practice
- Write down what events answer who, what, when, where, and outcome questions.
- Centralize or correlate high-value logs while preserving source context.
- Exercise an investigation using real records and document gaps.
Common mistakes
- Logging everything without a review plan.
- Allowing administrators to alter or delete their own audit trail.
- Ignoring SaaS, support, and API activity.
Questions that come up
How long must HIPAA logs be kept?
HIPAA has documentation retention requirements and organizations should also consider applicable system, incident, contractual, and state-law needs; define a documented retention schedule rather than guessing one universal period.
References
- Audit controls guidance HHS Office for Civil Rights