What Are Audit Log Requirements for Patient Records? (164.312(b))

What Are Audit Log Requirements for Patient Records? (164.312(b))

Understand audit log requirements for patient records under HIPAA 164.312(b), including what to log, who is covered, and practical evidence of compliance.

LakeRidge Team
July 19, 2026
8 min read

Share:

Schedule Your Free Compliance Consultation

Feeling overwhelmed by compliance requirements? Not sure where to start? Get expert guidance tailored to your specific needs in just 15 minutes.

Personalized Compliance Roadmap
Expert Answers to Your Questions
No Obligation, 100% Free

CMMC Phase 2 begins November 10, 2026.

The audit log requirements for patient records under HIPAA require you to use hardware, software, or procedures that record and examine activity in systems that contain or use electronic protected health information (ePHI). In plain English, you need a reliable way to see who accessed patient data, what they did, when they did it, and whether the activity deserves investigation. HIPAA does not require one specific logging product, but it does require logs that are useful enough to review after a suspected mistake, misuse, or security incident.

What do audit log requirements for patient records require?

HIPAA’s Audit Controls standard appears at 45 C.F.R. § 164.312(b). The official requirement states: “Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.”

That sentence is short, but each part matters:

  • “Implement” means this cannot remain a policy promise or an item on a future IT to-do list. The logging and review process must actually be operating.
  • “Hardware, software, and/or procedural mechanisms” gives a small organization flexibility. Your electronic health record (EHR) audit trail, firewall logs, Microsoft 365 sign-in reports, and a written review procedure can work together. You do not need an enterprise security operations center to meet the standard.
  • “Record” means the system must preserve evidence of activity. Useful records commonly include successful and failed logins, patient-chart access, record changes, exports, printing, administrator actions, and remote-access events.
  • “Examine” means collecting logs is not enough. Someone must review them on a defined schedule and investigate suspicious activity, such as a terminated employee account logging in or one user opening an unusually high number of patient charts.
  • “Information systems that contain or use ePHI” includes more than the EHR. It can include scheduling platforms, billing systems, patient portals, file-storage services, email systems, backup platforms, mobile-device management tools, and remote access systems if they store, transmit, or process ePHI.

For an SMB recovering from a near miss, the key lesson is simple: if you had to reconstruct what happened, your logs should let you answer the basic questions without relying on employee memory. You should be able to determine which account was involved, which system was used, what patient information may have been touched, and what corrective action followed.

Who must meet HIPAA audit-control requirements, and when do they apply?

The requirement applies to HIPAA covered entities, including healthcare providers that transmit certain health information electronically, health plans, and healthcare clearinghouses. It also applies to business associates that create, receive, maintain, or transmit ePHI for a covered entity, such as managed IT providers, billing companies, cloud-hosted practice-management vendors, and transcription services.

Audit Controls are a required HIPAA Security Rule standard, not an optional best practice. The requirement is triggered whenever a system contains or uses ePHI. A small dental practice with five employees is not exempt because it uses a cloud EHR; a cloud-based system still needs usable audit trails, and the practice still needs to review activity under its control.

HIPAA allows flexibility in how you implement the control based on your size, technical environment, risk level, and resources. It does not allow you to decide that logging is unnecessary. A two-person clinic may use built-in audit reports and a monthly owner review, while a larger organization may centralize logs in a security information and event management platform. Both approaches can be reasonable if they reliably record relevant events and support timely review.

Start by listing every system that handles ePHI. Include systems employees use directly and systems that support them behind the scenes. Your risk analysis should help you decide which events matter most, particularly after a near miss involving a compromised password, misplaced device, incorrect recipient, or unauthorized chart access.

What does compliant audit logging look like in practice?

There is no single HIPAA-approved log format. An assessor will generally look for evidence that your organization has identified systems containing ePHI, enabled appropriate logging, protected logs from inappropriate alteration, and actually examined the results. The following examples show what that can look like in a small healthcare organization.

System and realistic setting What is recorded What an assessor could review
athenaOne or eClinicalWorks EHR audit trail enabled for all user roles User ID, patient chart viewed, date and time, chart updates, medication changes, printing, exporting, and failed access attempts A dated audit-trail report for a selected patient, plus a written procedure showing who reviews unusual access and how findings are documented
Microsoft 365 Business Premium with Microsoft Entra ID sign-in logs retained and Microsoft Purview audit enabled Successful and failed sign-ins, multifactor authentication events, mailbox access, file-sharing activity, and administrator changes Monthly sign-in review records, an alert or investigation ticket for unfamiliar locations, and proof that former employees’ accounts were disabled
Fortinet FortiGate firewall with VPN logging enabled and logs sent to FortiCloud Remote VPN logins, source IP addresses, failed login attempts, firewall rule changes, and administrator access A VPN access report, evidence of review after repeated failed logins, and documented approval for remote-access users
Veeam Backup & Replication protecting the EHR file server or encrypted backup repository Backup job results, restoration activity, retention changes, deletion attempts, and administrator actions Backup and restore reports, evidence of periodic restore testing, and a record showing that unusual deletion or configuration changes are investigated

In each example, the important point is not the brand name. It is that the organization can produce meaningful evidence. A useful patient-record audit log normally ties activity to an individual account rather than a shared login. It also uses reasonably accurate time settings, records enough detail to support an investigation, and is protected so a regular user cannot quietly erase or alter it.

For a small practice, “examine” may mean the office manager, privacy officer, owner, or outsourced IT provider reviews a short set of reports every month. The review should be more than checking a box. It should focus on events that could indicate misuse or compromise, including:

  • Repeated failed logins or logins from unexpected locations;
  • Access by inactive, terminated, or temporary staff accounts;
  • Bulk exports, mass printing, or unusually large downloads of patient information;
  • Access to charts outside an employee’s normal job duties;
  • Changes to user permissions, multifactor authentication settings, or audit-log settings; and
  • Unusual forwarding, sharing, or deletion activity in email and cloud storage.

Keep evidence of the review itself. A simple dated record can identify the reviewer, systems reviewed, date range, suspicious events found, actions taken, and whether the incident response process was activated. For example, an owner might document: Reviewed Entra sign-ins and EHR audit reports for June 1–30. Investigated three failed VPN attempts from an unfamiliar IP; account was disabled, password reset, and no successful access was found.

How much audit-log retention does HIPAA require?

HIPAA § 164.312(b) does not state a specific number of days or years that security logs must be retained. However, logs must be retained long enough to support your risk management, security monitoring, incident investigation, contractual obligations, and applicable state-law requirements. Deleting logs after a few days may leave you unable to determine the scope of an incident discovered weeks later.

Do not confuse log retention with HIPAA documentation retention. HIPAA generally requires documentation required by the Security Rule, such as policies, procedures, risk analyses, and compliance records, to be retained for six years under 45 C.F.R. § 164.316(b)(2). That rule does not automatically mean every raw system log must be kept for six years. Your written retention decision should explain what logs you retain, where they are stored, who can access them, and why the selected period is appropriate for your risks.

What should you do after a logging near miss?

A near miss is a reason to test whether your Audit Controls work, not merely a reason to turn on more settings. Preserve relevant logs before they expire, identify the affected systems and accounts, document what you can and cannot determine, and correct the gap. If you cannot tell whether a user opened, exported, emailed, or printed a patient record, that is a risk-analysis finding that should drive a specific remediation decision.

Your remediation may be modest but meaningful: eliminate shared EHR accounts, enable multifactor authentication, increase cloud audit retention, require monthly reviews, or have your managed service provider send a concise report to the practice owner. The best approach is the one your practice can sustain and demonstrate.

Frequently asked questions about HIPAA audit controls

Does HIPAA require audit logs for every patient record?

HIPAA requires mechanisms to record and examine activity in systems containing or using ePHI. In practice, your EHR should be able to show meaningful access and activity associated with patient records, especially viewing, changing, printing, exporting, and disclosing information.

How often should HIPAA audit logs be reviewed?

HIPAA does not prescribe one review frequency. Monthly review is a practical baseline for many small practices, while higher-risk events such as administrator changes, failed remote logins, or bulk exports should generate faster review or alerts.

Are EHR audit logs enough for HIPAA compliance?

No. EHR logs are important, but you should also consider systems such as email, cloud storage, remote access, backups, and identity-management tools when they contain or use ePHI.

Can my managed IT provider review HIPAA logs for us?

Yes, but the arrangement should be documented, the provider should have an appropriate business associate agreement when required, and your practice should receive evidence that reviews occurred and that suspicious events were escalated.

Next step: Make a one-page list of every system in your practice that handles ePHI, then confirm this week that each one can produce and preserve usable activity logs.

 

Quick & Simple

Discover Our Cybersecurity Compliance Solutions:

Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you

 CMMC Level 1 Compliance App

CMMC Level 1 Compliance

Become compliant, provide compliance services, or verify partner compliance with CMMC Level 1 Basic Safeguarding of Covered Contractor Information Systems requirements.
 NIST SP 800-171 & CMMC Level 2 Compliance App

NIST SP 800-171 & CMMC Level 2 Compliance

Become compliant, provide compliance services, or verify partner compliance with NIST SP 800-171 and CMMC Level 2 requirements.
 HIPAA Compliance App

HIPAA Compliance

Become compliant, provide compliance services, or verify partner compliance with HIPAA security rule requirements.
 ISO 27001 Compliance App

ISO 27001 Compliance

Become compliant, provide compliance services, or verify partner compliance with ISO 27001 requirements.
 FAR 52.204-21 Compliance App

FAR 52.204-21 Compliance

Become compliant, provide compliance services, or verify partner compliance with FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems requirements.
 ECC Compliance App

ECC Compliance

Become compliant, provide compliance services, or verify partner compliance with Essential Cybersecurity Controls (ECC – 2 : 2024) requirements.