Skip to main content
Security Safeguards

Audit Logging

Recording who accessed PHI and when, as required by the HIPAA Security Rule.

Audit logging (audit controls) is the recording of who accessed protected health information and when, so activity can be reviewed and incidents investigated. It is a firm technical-safeguard requirement under the HIPAA Security Rule (45 CFR §164.312(b)), not an optional feature.

Managed HIPAA hosting records this activity automatically and monitors for unusual access. See key security measures for HIPAA-compliant hosting. For the serverless case, where debug logs and audit logs must be kept apart, see is AWS Lambda HIPAA compliant. Web frameworks rarely ship an audit trail. Our Laravel HIPAA compliant guide shows how a Laravel app adds one.

Stay current on HIPAA hosting

Practical guidance on compliance, hosting and the rules that actually apply to your practice.

Email me occasional updates about HIPAA hosting and compliance. No more than a few times a month, and you can unsubscribe at any time.