Audit controls

Audit controls, tracked vendor by vendor

A composed audit-controls policy, plus a running check on whether each PHI vendor's log retention is configured for six years and whether a log review has actually been recorded this quarter.

The standard has two verbs, record and examine. Most clinics satisfy the first by accident, because their software logs by default, and never touch the second.

The policy is composed from your clinic’s facts

Your audit controls policy is generated from a maintained clause library against what you have recorded. It covers recording and examining activity in the systems that hold PHI, reliance on each system’s built-in logging where it exists, the shared-login problem that makes activity untraceable to a person, your own recorded review cadence, and retention tied to the reality that payer audits reach back years.

Clauses appear based on your recorded facts: paper records, shared workstations, field devices that sync late, AI tooling in the mix. What does not apply to you stays out of your policy.

What gets tracked after the policy exists

Seven requirements for this control, each holding or not:

  • The policy is active and reviewed within the last twelve months.
  • Every vendor recorded as touching PHI has a log retention configuration on file set to at least six years.
  • Every one of those vendors has a log review recorded within the last ninety days.
  • The platform’s own activity log retention is attested.
  • The policy is adopted, and its underlying facts have not drifted.

What this is, and what it is not

The system tracks whether your vendors’ log retention is configured correctly on paper and whether someone recorded that a review happened. It does not read your EHR’s audit log or any vendor’s log entries. A recorded review means a reviewer logged that they looked, with their summary and any anomaly count, not that the platform analyzed access itself.

That is still the difference between a clinic that reviews quarterly with a record of it and one that has never opened a log. The second clinic is the common case, and it is the one with nothing to show.

What an investigator gets

A dated, adopted policy. Per-vendor retention configuration on file. A dated series of recorded log reviews with reviewer and findings. Evidence that examining actually happens on a cadence, which is the half of this standard that clinics almost never satisfy.

The regulation: read the rule behind this control.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.