§164.312(b)
Audit Controls
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Implement mechanisms that record and examine activity in information systems containing or using ePHI.
Points of focus
- Log access and administrative activity affecting ePHI
- Protect audit records from unauthorized alteration
- Review activity at a frequency informed by risk
Implementation notes
Capture reads, exports, impersonation, permission changes, and privileged data operations with tenant and actor context; centralize tamper-resistant logs and alert on unusual ePHI access patterns. Operationalize log access and administrative activity affecting ephi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain application and cloud audit-log configurations with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that database administrator activity bypasses application logging and is invisible Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample application and cloud audit-log configurations with dates and named reviewers. Be ready to walk through how you detect and correct: database administrator activity bypasses application logging and is invisible
Evidence auditors typically request:
- Application and cloud audit-log configurations
- Sample ePHI access trail tied to unique identities
- Alert reviews and investigation tickets
Common gaps
- Database administrator activity bypasses application logging and is invisible
- Logs exist but retention is shorter than the investigation and customer-notification process needs
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.312(b) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.312(b)