A composed audit-controls policy, plus a running check on whether each PHI vendor's log retention is configured for six years and whether a log review has actually been recorded this quarter.
The standard has two verbs, record and examine. Most clinics satisfy the first by accident, because their software logs by default, and never touch the second.
Your audit controls policy is generated from a maintained clause library against what you have recorded. It covers recording and examining activity in the systems that hold PHI, reliance on each system’s built-in logging where it exists, the shared-login problem that makes activity untraceable to a person, your own recorded review cadence, and retention tied to the reality that payer audits reach back years.
Clauses appear based on your recorded facts: paper records, shared workstations, field devices that sync late, AI tooling in the mix. What does not apply to you stays out of your policy.
Seven requirements for this control, each holding or not:
The system tracks whether your vendors’ log retention is configured correctly on paper and whether someone recorded that a review happened. It does not read your EHR’s audit log or any vendor’s log entries. A recorded review means a reviewer logged that they looked, with their summary and any anomaly count, not that the platform analyzed access itself.
That is still the difference between a clinic that reviews quarterly with a record of it and one that has never opened a log. The second clinic is the common case, and it is the one with nothing to show.
A dated, adopted policy. Per-vendor retention configuration on file. A dated series of recorded log reviews with reviewer and findings. Evidence that examining actually happens on a cadence, which is the half of this standard that clinics almost never satisfy.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.