hipaa.systems
Security Rule · 45 CFR 164.312(b), 164.308(a)(1)(ii)(D)

Audit controls and activity logs

Systems holding ePHI must record activity so you can review who accessed what. When choosing a tool, check that you — not only the vendor — can see sign-ins and access to records, and for how long.

Checked 2026-10-05Sources 3

Audit controls and activity logs at a glance

HIPAA audit controls are the mechanisms that record and let you examine activity in systems containing electronic protected health information. The Security Rule requires them under 45 CFR 164.312(b), together with a regular review of system activity such as audit logs and access reports. When choosing a tool, check that you as the customer can see sign-in and access logs, for long enough to investigate an incident.

Rules45 CFR 164.312(b) and 164.308(a)(1)(ii)(D)
StatusRequired
What to logSign-ins, access to and sharing of PHI, admin changes
Must alsoRegularly review the logs
Check in toolsCustomer-visible logs, retention period, export

The audit controls standard (164.312(b)) requires “hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information”. It works together with a required administrative specification: regularly reviewing records of system activity such as audit logs, access reports and security incident tracking (164.308(a)(1)(ii)(D)).

Why logs matter in practice

Logs are what let you answer the questions that follow any incident: who opened this mailbox, when was this file shared, from which device did someone sign in. Without them, a suspected incident often has to be treated as a breach because you cannot show the information was not accessed.

What to check when choosing a tool

  • Sign-in logs: successful and failed sign-ins, with time, user and location or IP.
  • Access and sharing logs: who opened, sent, downloaded or shared PHI.
  • Admin activity: changes to settings, users and permissions.
  • Who can see them: logs available to you as the customer, not only on request from support.
  • Retention: how long logs are kept on your plan — some tools keep only a few days on lower tiers.
  • Export: whether you can export logs if you need to investigate or hand them to an expert.

Then decide, in your policies, who reviews the logs and how often.

Tools and services where this matters

Guides

Frequently asked questions

How long should HIPAA audit logs be kept?

The audit controls standard does not set a retention period for logs themselves. HIPAA requires certain documentation to be kept for six years; decide log retention in your policies and check what each tool keeps on your plan.