Audit logs are a critical – not to mention required – way for your company to monitor activity on your network. A newsletter on the importance of importance of HIPAA logging requirements states this:1
“Audit logs are records of events based on applications, user, and systems. Audit trails involve audit logs of applications, users, and systems. Audit trails’ main purpose is to maintain a record of system activity by application process and by user activity.”
Why are audit controls so important?
Whether this traffic is from an employee or another source, these logs are vital to protecting the information your organization holds. Keeping these logs is an important risk management measure.
A federal grand jury indicted a former MedStar Ambulance paramedic on counts of identity theft and fraud. He altered patient records as part of a scheme to steal narcotics from a local hospital from January 2013 to May 2015.2 The paramedic was finally caught after someone discovered his logs had various irregularities compared to the corresponding hospital records.
This incident highlights just how important it is to maintain and regularly monitor detailed logs. HIPAA log retention is also crucial; if the hospital had not archived the logs, investigators could not have found the incriminating records. HIPAA log retention requirements mandate that entities store and archive these logs for at least six years, unless state requirements are more stringent.
What HIPAA Security Rule Mandates
45 C.F.R. § 164.312(b) (also known as HIPAA logging requirements) requires Covered Entities and Business Associates to have audit controls in place.
These organizations must implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information (ePHI).1
Information systems include all electronic devices and applications used within your company’s network (e.g. smartphones, computers, emails, file sharing application, internal server).
In plain English, HIPAA auditing requirements call for organizations to regularly review network activity and device usage.
Whether you are a medical or dental practice, health insurance agency, or an employee of an organization that manages health records, you need to record and review audit logs to stay compliant with HIPAA and protect the information you maintain.
Creating a log is not as complicated as it seems. You can follow a HIPAA audit log template for your records.
Your Audit Logs Should Include This Information:
- Risk Assessments and Risk Analyses (Risk Assessments are performed proactively; Risk Analyses, retroactively, after an incident)
- Authorizations for the Disclosure of PHI
- Disaster Recovery and Contingency Plans
- Business Associate Agreements
- Information Security and Privacy Policies
- Employee Sanction Policies
- Incident and Breach Notification Documentation
- Complaint and Resolution Documentation
- Physical Security Maintenance Records
- IT Security System Reviews (including new procedures or technologies implemented)
- Logs Recording Access to and Updating of PHI (Application Processes and any user activity, including denial of access)
Examples of this kind of activity include:
- When workforce members log in
- The number of failed login attempts on a computer
- The last time you conducted a software update
- Who downloaded a new program, the name of the program, and when
- When passwords were changed, and by whom
- Who logged into HR systems at a certain time
- What information was accessed by the person who logged in
This extends beyond your electronic systems. If you use paper files to store information, keep a log of employee access. These logs should also include information about when the files leave the file room. We suggest requiring employees to “sign files out.”
Log repairs to any physical assets. You should also keep track of
Many of the software systems you currently use already have the ability to keep detailed logs of activity. Your IT department should consolidate these logs so they are easy to review.
In the event of a security incident, audit trails and logs should be reviewed as soon as possible. This will help you determine if there is tampering with the information. Outside of cybersecurity incidents, audit trails can help you identify flaws in your network before things go wrong. This process will also help you make sure applications are performing as intended.
How to Maintain Compliance with HIPAA
Keeping detailed logs is the first step toward HIPAA compliance. Consider implementing the following three steps to protect your business.
First, create detailed policies and procedures around audit handling.
Second, educate staff on changes in procedures.
Third, keep up-to-date with regular reviews of audit logs and audit trails.
You should also be prepared to keep these logs for a minimum of 6 years as is required for HIPAA Compliance. These logs should be stored in a raw format for at least six (6) months to one (1) year. After that, you can store these logs in a compressed format.
In conclusion, a HIPAA compliance service (like us) provides helpful guidance on establishing the logs that will help you monitor your network. Our HIPAA Prime™ program is a turn-key solution that helps you build a robust compliance program from the ground up. With the right documents in place, your staff can safeguard PHI from internal and external attempts to compromise the data.