Audit controls and activity logs
Systems holding ePHI must record activity so you can review who accessed what. When choosing a tool, check that you — not only the vendor — can see sign-ins and access to records, and for how long.
Audit controls and activity logs at a glance
HIPAA audit controls are the mechanisms that record and let you examine activity in systems containing electronic protected health information. The Security Rule requires them under 45 CFR 164.312(b), together with a regular review of system activity such as audit logs and access reports. When choosing a tool, check that you as the customer can see sign-in and access logs, for long enough to investigate an incident.
| Rules | 45 CFR 164.312(b) and 164.308(a)(1)(ii)(D) |
|---|---|
| Status | Required |
| What to log | Sign-ins, access to and sharing of PHI, admin changes |
| Must also | Regularly review the logs |
| Check in tools | Customer-visible logs, retention period, export |
The audit controls standard (164.312(b)) requires “hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information”. It works together with a required administrative specification: regularly reviewing records of system activity such as audit logs, access reports and security incident tracking (164.308(a)(1)(ii)(D)).
Why logs matter in practice
Logs are what let you answer the questions that follow any incident: who opened this mailbox, when was this file shared, from which device did someone sign in. Without them, a suspected incident often has to be treated as a breach because you cannot show the information was not accessed.
What to check when choosing a tool
- Sign-in logs: successful and failed sign-ins, with time, user and location or IP.
- Access and sharing logs: who opened, sent, downloaded or shared PHI.
- Admin activity: changes to settings, users and permissions.
- Who can see them: logs available to you as the customer, not only on request from support.
- Retention: how long logs are kept on your plan — some tools keep only a few days on lower tiers.
- Export: whether you can export logs if you need to investigate or hand them to an expert.
Then decide, in your policies, who reviews the logs and how often.
Tools and services where this matters
- AI models and chat assistants →Tool
- Cloud storage and file sharing →Tool
- HIPAA compliance software →Tool
- HIPAA email services →Tool
- HIPAA hosting and cloud platforms →Tool
Guides
Related requirements
Frequently asked questions
How long should HIPAA audit logs be kept?
The audit controls standard does not set a retention period for logs themselves. HIPAA requires certain documentation to be kept for six years; decide log retention in your policies and check what each tool keeps on your plan.