Audit controls: who opened this child's record, and when
45 CFR 164.312(b) requires systems that record and examine activity, not just one that records it. A log nobody reads has only done half of what the rule asks.
Last verified: 2026-09-08
Ask a clinic if they have audit controls, and the honest answer is usually “the software logs things somewhere.” That may be true. It is also not the same as having audit controls.
What the rule actually requires
Audit controls is a Required standard: implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI (45 CFR 164.312(b)).
There are no implementation specifications under this standard. The rule leaves the mechanism to you, under the general flexibility written into 164.306(b), which lets a covered entity choose reasonable and appropriate measures for its own circumstances.
Notice the two verbs in the standard itself: record and examine. A system that writes logs nobody ever reads has done half of what the sentence says. The examining half is not optional flavor text, it is its own required administrative specification: information system activity review, at 45 CFR 164.308(a)(1)(ii)(D). Audit controls and activity review are two halves of one answer, not two separate obligations you can satisfy independently.
What the rule does not say
What audit controls does not require is just as important as what it does. There is no mandated log format, no specific retention period written into this standard, and no required software category. That silence is deliberate, the same 164.306(b) flexibility that runs through the whole Security Rule.
“A system that writes logs nobody ever reads has done half of what the sentence says.”
One correction worth making explicitly, because it gets repeated often and confuses the actual obligation: the Security Rule does not impose a six-year retention period on audit logs. The six-year rule, at 45 CFR 164.316(b)(2)(i), applies to the documentation the rule requires you to maintain, policies, procedures, risk analyses, and the like. Conflating the two leads clinics to either over-retain raw log data indefinitely or, worse, assume logs don’t need to be kept at all because “the six-year rule doesn’t apply to us.” Both are wrong for different reasons.
What a real answer looks like, next to what most clinics have
| What the rule requires | What most clinics actually have | |
|---|---|---|
| Recording | Activity is logged: who accessed what, when | Logging exists somewhere in the software, unconfigured or default |
| Examining | Logs are actually reviewed on a defined cadence | Nobody has ever opened the log |
| Attribution | Access ties to one identity | Shared logins make “who” unanswerable |
| The test | Can you say who opened this child’s record, and when | “I’d have to ask the vendor” or “I’m not sure that’s tracked” |
The gap here is not usually a missing feature. Most EHRs and practice management systems log activity by default. The gap is that nobody set up a way to examine it, and nobody can answer the actual question an investigator asks.
Why this depends on access control working
Audit controls only produces useful answers if unique user identification, the Required specification under access control (164.312(a)(2)(i)), is actually in place. A log that says “the front desk account opened forty records” tells you nothing, because the front desk account is four different people. Audit controls and unique logins are, in practice, one system, not two.
The short version
- Audit controls (164.312(b)) require mechanisms that record AND examine system activity. A log nobody reads has done half the job.
- The examining half is a separate required administrative specification: information system activity review, at 164.308(a)(1)(ii)(D).
- The Security Rule does not itself impose a six-year retention period on audit logs. That six-year rule, at 164.316(b)(2)(i), applies to required documentation, a distinction worth getting right.
- There are no implementation specifications under audit controls. The rule leaves the mechanism to you, under the general flexibility of 164.306(b).
- The test in an ABA clinic is simple: can you say who opened this child's record, and when? If not, you have storage, not audit controls.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Technical safeguards, including audit controls45 CFR 164.312(b)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- Administrative safeguards, including information system activity review45 CFR 164.308(a)(1)(ii)(D)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Documentation, including the six-year retention requirement45 CFR 164.316(b)(2)(i)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316
A real answer to who opened this record.
WiseUpHIPAA keeps a live, reviewable record of who accessed what and when, tied to a unique identity, not a shared login. Not a log sitting unread. A record someone can actually be shown.