Audit Logs: An Important Tool for Protecting Your Practice and ePHI
When a security incident occurs, one of the first questions a medical practice needs to answer is: What happened?
Audit logs can help provide that answer. They create a record of activity on your computers, network, and software systems, including systems that contain or use electronic protected health information (ePHI).
What Can Audit Logs Tell You?
Depending on the system, audit logs may show:
- Who logged into a computer or system and when
- Which device or workstation was used
- What applications or systems were accessed
- Whether login attempts were successful or unsuccessful
- Whether someone accessed information they normally would not need
- Whether a patient's record was viewed or changed
- Whether unusual or suspicious activity occurred
- What happened before and after a security incident
The HIPAA Security Rule requires covered entities to implement and regularly review audit controls for information systems that contain or use ePHI.
Not All Audit Logs Are the Same
Your practice may have audit logs at several levels.
Network and computer logs can show activity involving workstations, servers, user accounts, applications, and the practice network. For example, they may show when an employee logged into a workstation, accessed Microsoft 365, opened the EHR, or logged out.
EHR and application logs provide more detail about activity within the specific application. An EHR audit log might show that a particular user opened and viewed a patient's chart, specifically viewed areas of their chart like medications or allergies, or made changes within a chart.
An EHR audit trail is valuable, but it does not necessarily provide a complete picture of activity across your entire network. Network and security logs can provide additional information about the device, account, login, and other activity surrounding an event.
Why Audit Logs Matter During a Security Incident
Suppose an employee's credentials may have been compromised. Without adequate logging, your practice may know that something happened but have difficulty determining exactly what occurred.
You may need to determine:
- When the unauthorized activity began
- Which account was involved
- What device was used
- Which systems were accessed
- Whether ePHI was accessed
- Which patient records may have been involved
- How the incident occurred
- What steps should be taken to prevent it from happening again
Audit logs can help reconstruct these events and provide important evidence for investigating a potential breach.
They can also assist with the required breach analysis, including determining what information may have been affected and what mitigation or corrective actions may be necessary.
Without adequate logs, an investigation can become more difficult, time-consuming, and expensive.
Don't Wait Until an Incident Happens
The best time to prepare for a HIPAA security incident is before one occurs.
Your practice should have an up-to-date risk analysis, appropriate security controls, written policies and procedures, and a process for reviewing and responding to security events.
HHS emphasizes that risk analysis should be an ongoing process and should be reviewed and updated as needed.
A prepared practice is better positioned to determine what happened, respond appropriately, document its actions, and reduce the risk of a similar incident occurring again.
How TLD Systems Can Help
TLD Systems can help medical practices establish and maintain their HIPAA compliance foundation, including:
- HIPAA risk analysis
- HIPAA security manuals and policies
- Risk mitigation plans
- Breach and incident-response procedures
- HIPAA compliance guidance
- Documentation and compliance support
- Assistance following a security incident
Don't wait until a security incident occurs to find out what your systems can—and cannot—tell you. Proper policies, documentation, security controls, and audit logs can make a significant difference when your practice needs to understand what happened and respond effectively.
TLD Systems is here to help your practice prepare before you need it.

Read Comments