Audit Controls Procedures, v1.0

Specifies that a health care related organization must implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.

Assessment Step

1
Examine Activity on Systems (ExamineActivityonSystems)
Does the covered entity or business associate implement procedural mechanisms that examine activity in information systems that contain or use electronic protected health information?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Examine Activity on Systems
The covered entity or business associate must implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
Citations
HIPAA-Security-Rule
45 CFR Section 164.312(b)
HIPAA-Security-Rule
45 CFR Section 164.306