Every open security incident has an owner, every closed one carries a resolution, closure decision, and mitigation record.
The definition is broader than most clinics assume. Attempted access counts. The phishing email an RBT reported and clicked nothing on is a security incident, and it belongs in the record.
Your incident response policy covers what counts as an incident, how staff report one, response and mitigation, when an incident may also be a breach, vendor-reported incidents, and documentation with retention.
Seven requirements:
Those two middle requirements are the lifecycle check. An incident with no owner drifts. An incident closed with no closure decision leaves you unable to say what you concluded or why, which is the position the burden of proof makes expensive.
The system tracks the lifecycle of incidents you record. It cannot know about an incident nobody logged, and it does not judge whether your response was adequate. A closure decision is what someone concluded, not a determination the system reviewed.
Which points at the real prerequisite: the reporting path has to work, and staff have to use it. The system makes the record complete once an incident is in it.
An incident log where open items have owners and closed items have documented conclusions. Dates on both. Under a rule where an empty log reads as a clinic that never looked, a log that shows the looking.
The regulation: read the rule behind this control.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.