Audit Controls on Hardware and Software, v1.0

Specifies that a health care related organization must implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.

Assessment Step

1
Record Activity on Systems (RecordActivityonSystems)
Does the covered entity or business associate implement hardware and/or software that record activity in information systems that contain or use electronic protected health information?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Record Activity on Systems
The covered entity or business associate must implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
Citations
HIPAA-Security-Rule
45 CFR Section 164.312(b)
HIPAA-Security-Rule
45 CFR Section 164.306