An article from the Journal of the American Medical Informatics Association states, “Electronic health record audit logs capture a time-sequenced record of clinician activities while using the system.” An audit log is a broad term that refers to a time-stamped record of activity that occurs within an electronic system. An audit log can typically show the account that accessed a patient's record, the action taken, and the precise time of access. The creation of an audit log program should also account for email. The 2026 Paubox Healthcare Email Security Report reviewed 170 healthcare breaches related to email in 2025. HIPAA compliant email allows organizations to send log alerts to the appropriate team members, assign the investigation, and document decisions without exposing protected health information to an unauthorized channel.
Audit logs support two distinct HIPAA duties
The Health and Human Services (HHS) summary of the HIPAA Security Rule says, “A regulated entity must implement hardware, software, and/or procedural mechanisms to record and examine activity in information systems that contain or use ePHI.” Electronic protected health information (ePHI) is PHI that is created, received, maintained, or transmitted electronically. Audit logs apply to any system that contains or uses ePHI. With HIPAA compliant email, compliance teams can confidently send out reviewed instructions and exception reports to the right people.
Beyond just logging system activity, reviewing those records constitutes the second crucial duty. According to a report to Congress from the HHS department, “Regular review of records of information system activity, such as audit logs, access reports, and security incident tracking reports, is required by the Security Rule.” During the HIPAA Audit Program, the Office for Civil Rights (OCR) discovered healthcare organizations that failed to review any system activity, only reviewed audit logs after an incident, or reviewed them occasionally and by chance.
What an effective audit trail should show
Researchers from the Journal of Biomedical Informatics noted, “Modern EHR systems already generate access logs to enable the construction of audit trails regarding what information care providers observe and what actions they take.” Ideally, a meaningful event log should include the user’s identity, affected patient or system object, action taken, timestamp, source application, and action result. We recommend this because every organization faces distinct risks and has a different system environment, not because HIPAA specifically demands it.
Ensuring individual accountability for each user relies on unique login credentials. The OCR HIPAA Audit Protocol highlights this HIPAA clause for unique user identification, “Assign a unique name and/or number for identifying and tracking user identity.” When someone shares their credentials with a colleague, it becomes difficult to know exactly who in the workforce was responsible for an action. Service accounts and shared mailbox accounts should have approved account owners, restricted permissions, and even more documentation linking the activity back to a single person.
Rarely does a single system hold all the details of an incident. According to the NIST Guide to Computer Security Log Management, “Event correlation is finding relationships between two or more log entries.” Reviewing an employee’s EHR logins along with their identity provider sign-ins could uncover the exact workstations they used to sign into email. Combining access alerts with email audit logs, administrator changes, endpoint alerts, cloud alerts, and even network traffic can show whether a suspicious login was used to access patient records, forward mailboxes, or change permissions.
Using audit logs for access monitoring
The HHS report further states that regular review allows an organization to know what normal activity looks like so they can spot activities that may indicate a security incident is happening or has already occurred. For example, a baseline could include job title, department, work hours, relationship to patients, and normal volume of records accessed. Although these examples from after-hours access or large data dumps may warrant investigation, they do not automatically mean an employee was malicious because healthcare workflows can be very different.
Another AMIA research paper on auditing said, “These rule-based systems define behavior deemed to be high-risk a priori (e.g., family member, co-worker access).” Other types of alerts can be triggered by accessing high-profile patients, too many failed login attempts, an inactive user accessing records, exporting large amounts of information, or viewing records that are not part of an employee’s department. Teams should categorize the severity level of each alert and have a defined response plan instead of reporting every alert as a violation.
Automated monitoring tools can assist with sorting through large amounts of recorded data. One peer-reviewed JAMIA study concluded, “The results suggest that statistical and machine-learning methods can play an important role in helping privacy officers detect suspicious accesses to EHRs.” In a separate dataset containing 58 real inappropriate accesses, their logistic-regression model and support vector-machine model had sensitivities of .76 and .79, whereas the baseline method caught none. The researchers did warn that every organization’s workflow is different and may not generalize to every healthcare organization. HIPAA compliant email allows monitored activity to be sorted by automation, with the final review assigned to a person.
Audit logs do have limits to how much they can measure. Researchers in a JAMIA systematic review wrote, “Nineteen studies validated results (22%), but only 9 (11%) through direct observation, demonstrating varying levels of measure accuracy.” Did the user who accessed a patient’s record actually read it? How long did they view the screen? Was it an automatic lookup triggered by another application? Investigators should make reviewers aware of the inherent imperfections in log files when discussing potential violations.
Using audit logs during security investigations
In an article about mailbox compromise, Paubox says, “Technical evidence about the intrusion may already be disappearing as an email is deleted and access logs overwrite older sign-in records.” Security teams should document where they found certain evidence and take steps to preserve the evidence before normal deletion occurs. It’s important to limit access to the investigation team and not anyone else who may want to view the evidence. If an email mailbox was involved in a suspected security incident, it may be best to copy any communication to an unaffected HIPAA compliant email account.
After evidence is collected, security teams should build a timeline of events, including when the incident was first known to occur, what happened next, how it was contained, and when the unauthorized user stopped accessing PHI. Ensuring every server clock is synchronized with a common time source, per NIST's guidance, is a key step in constructing an accurate timeline. Reviewing employee sign-ins along with patient record activity, email activity, permission changes, file downloads, and session logouts can show investigators exactly what occurred.
Audit logs are also used when assessing and responding to a HIPAA breach. According to 45 CFR § 164.402, as soon as there is an unauthorized acquisition, access, use, or disclosure of PHI, a breach is presumed to occur unless the healthcare organization can prove there is a low risk that PHI was actually compromised. A risk assessment considers what was breached, who was involved, whether PHI was actually accessed, and how the organization responded. Logs can provide evidence for these questions, but they do not replace the need for a documented legal and privacy analysis.
Building a practical audit-log program
The NIST tells us log management is "the process for generating, transmitting, storing, analyzing, and disposing of log data.” Healthcare organizations can relate this log lifecycle to five practical steps.
- Identify every system that contains or uses PHI and find out who’s responsible for their logs.
- Configure all relevant events to capture, ensure identities are individual, agree on timestamps, and set up alerts based on risk.
- Protect logs from hackers and insiders who will alter, delete, view, or restart log records before they are archived.
- Schedule when logs should be reviewed, by whom, when escalated, and where to document the results.
- Test your incident response plan by pretending someone inappropriately accessed ePHI, their account was compromised, or a third party spilled billions of records.
FAQs
Does HIPAA require healthcare organizations to retain every raw audit log for six years?
HIPAA does not specifically require every raw system log to be retained for six years. HIPAA requires certain Security Rule documentation to be kept for at least six years, so healthcare organizations should have a written schedule that also takes into consideration investigation, contracts, state laws, and litigation holds.
Can an audit log include ePHI?
Yes, if a log has patient names, record numbers, descriptions of the event, or anything else that can identify a person’s health information, payment information, or care they received, then the log is considered ePHI.
Does a patient have the right to know who opened their medical record?
Patients do not have the automatic right to know who in the workforce accessed their medical record for treatment, payment, or healthcare operations.
