HIPAA audit controls
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
HIPAA wants a record of who touched ePHI. After a breach, that audit log is the difference between "we know what happened" and a guess.
What the safeguard requires
The audit controls standard requires mechanisms that record and examine activity in information systems containing or using ePHI. In plain terms: log who accessed PHI and what they did, and have a way to review it. It is a required (not addressable) implementation specification.
What to log
Capture access to ePHI systems and records — logins, record views where feasible, exports, administrative actions, and changes to access. The goal is a trail that can answer "who saw this patient's data, and when," which is exactly the question that arises after a suspected breach.
Review and protect
Logs nobody reviews satisfy the letter but not the intent. Establish a review process for anomalies, and protect the logs from alteration — an audit trail an insider can edit is not trustworthy. This mirrors the logging/monitoring controls in SOC 2 and ISO 27001.
Why it pays off at the worst time
The value of audit controls is realised during an incident: they let you scope what PHI was actually exposed, which drives your breach-notification obligations. Weak logging turns a contained incident into an unknowable one. SentinelPanda tracks the audit-control coverage and evidence.