Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Defense · ePHI Audit

Pick a person. See what they opened.

The question after an incident is never abstract. It is whether one named person opened one named record on one particular afternoon, and whether you can show it.

Included in Basic·Starting at $39/mo
Patient Protect — ePHI Audit
The Personnel ePHI Audit screen: a workforce member selected from a dropdown, and beneath it the ePHI they accessed row by row, each with a time, a patient, an action and a detail

HIPAA mapping

Where this fits in the Security Rule.

4 provisions this capability contributes to, each with the specific ePHI Audit behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.

§164.312(b)

Audit controls

Requires mechanisms that record and examine activity in systems containing ePHI. Access inside Patient Protect is recorded by workforce member, action and time, and the record is examinable from the interface rather than by requesting an export from someone.

§164.308(a)(1)(ii)(D)

Information system activity review

Requires procedures to regularly review records of system activity. Regularly is your practice's word to define, and the review is your practice's act. What this provides is a log that can actually be read by the person who has to do the reviewing.

§164.308(a)(3)(ii)(A)

Authorization and supervision

An addressable specification covering supervision of workforce members who work with ePHI. Supervision that produces no record is difficult to evidence, and per-person access history is the record it produces.

§164.316(b)(2)

Time limit

Requires six-year retention of the documentation this subpart requires — policies, procedures, actions, activities and designations. It is worth being precise: this is not a rule that raw access logs must be kept for six years, and any vendor telling you otherwise has read the provision quickly.

What it does

The question always arrives about one person and one record.

A patient calls and says they think someone at the practice looked at their chart. A workforce member leaves under a cloud. A laptop goes missing and you need to know what was reachable from it. In every one of those, the useful question is narrow and specific — did this person open this record, and when — and it is the question a practice with no log cannot answer at all.

The ePHI Audit answers it in the shape the question is asked. You choose a workforce member, and what comes back is the patient information they reached: the time it happened, whose record it was, what they did, and the detail of that action. Not a stream of system events to be filtered down, but a per-person history you can read.

The scope is worth stating plainly, because it is where most audit-log marketing goes wrong. This records activity inside Patient Protect. It does not see your electronic health record, your imaging system, or the workstation at the front desk — no product hosted elsewhere can watch software running on your premises. What it covers, it covers by name.

How it works

6 mechanisms keep ePHI Audit working.

01

Per-person, not per-system.

The screen starts by asking which staff member you mean, because that is how the question arrives. Most audit tooling starts from a firehose and asks you to filter your way down to a person, which works if you are a security analyst and does not if you are the office manager trying to answer a patient by Friday.

02

Patient context on the row.

Each entry names whose information was involved rather than only what screen was opened. “Viewed archive” tells you nothing on its own; “viewed archive, Love, Mazie, 5:40pm” is an answer. The pairing of person and patient is what makes the log usable in the conversation you are actually going to have.

03

Actions recorded as what happened.

Entries carry the action taken — viewing an archived record, managing a patient, adding personnel — with a result beside it. The vocabulary is the product's own rather than a generic create-read-update-delete, which means a reviewer can tell a routine action from an unusual one without a decoder ring.

04

Timestamps to the minute, in sequence.

Every row carries the date and the time. Access at 12:27am reads differently from access at 2:15pm, and a run of eleven views in nine minutes reads differently from eleven views across a week. Sequence is most of what an investigation is looking at.

05

Attribution that survives the shared workstation.

The log names a workforce member because access requires an individual account, and every person on the roster has one. This is the practical value of §164.312(a)(2)(i)'s unique user identification: without it a log records that “reception” opened a chart, which is not attribution and will not satisfy anyone asking.

06

Exportable when it stops being an internal matter.

The record can be taken out of the platform for an investigation, a regulator, or your counsel. What it cannot do is arrive pre-formatted for OCR, because there is no OCR log format — that claim is common and it is not true. What matters is that the underlying record exists and is legible, which is the part that cannot be created after the fact.

Who this is for

Built for the practices that need it most.

Practices that will get the phone call.

Every practice does eventually — a patient who suspects, a rumour about a colleague, a departure that ends badly. The practices that come out of it well are not the ones with better policies. They are the ones who could answer within a day.

Specialties where a look is the harm.

Behavioral health, substance use, reproductive health, HIV care. In these settings unauthorized viewing is itself the injury, not a precursor to one, and the ability to establish who opened a record is not administrative housekeeping.

Practices under a corrective action plan.

After an enforcement action, demonstrating that audit controls function is usually an explicit obligation. A log that exists and is readable is the evidence; a policy saying you intend to log is not.

What you get

5 outcomes you’ll feel in week one.

Starts from a person.

Choose a staff member and read their history.

Names the patient.

Whose record it was, not only which screen.

Timed to the minute.

Sequence is most of what an investigation reads.

Attributable by design.

Individual accounts mean the log names a person.

Exportable.

It leaves the platform when the matter does.

FAQ

What people ask first.

6 questions cover most first-time evaluations. See all FAQs →

Can I see everything one workforce member has done?
Yes — that is the shape the screen is built around. Select the person and their access history comes back with the time, the patient, the action and the detail on each row. It is the view you want during a periodic access review and the one you need when something has gone wrong.
Does this cover our EHR and our other systems?
No. It records activity inside Patient Protect. Nothing hosted outside your premises can observe software running on them, and a vendor claiming otherwise is describing an agent you would have had to install. Your EHR keeps its own log, and the two are separate records of separate systems.
Can the log be altered?
We are not going to make an absolute claim about our own running code on a marketing page. The strong words you will see used about audit logs elsewhere are assertions about an implementation you cannot inspect, offered by the party with the most to gain from them. Ask any vendor, us included, for the specific mechanism and for who outside the company has verified it — and treat a page that will not answer as having answered.
Does this satisfy a patient's request for an accounting of disclosures?
No, and the two are often confused. §164.528 gives an individual the right to an accounting of certain disclosures of their PHI, and the accounting it describes has its own required content and its own exclusions. An internal activity log is not that accounting merely by existing — it records which of your own workforce opened a record inside Patient Protect, which is a different question. Producing an accounting is work your practice does, and doing it properly is worth reading the provision for.
How long is the history kept?
Access history is retained as part of the platform record. It is worth separating this from the six-year rule people usually cite: §164.316(b)(2) requires six-year retention of the documentation the Security Rule asks for — your policies, your procedures, your designations and the actions you took — not of every log line a system generates.
Will a large practice's log become unusable?
Volume is the reason the view is scoped to one person rather than presented as one long stream. A practice generating thousands of events a month has an unreadable log if the only entry point is a global list, and the per-person starting point is what keeps it answerable at that size.

What it does not do.

  • Never 'immutable' or 'tamper-proof' — those need storage-layer evidence nobody has produced
  • Producing a log is not reviewing it; §164.308(a)(1)(ii)(D) asks the practice to review

One person, one record, one afternoon. Answerable.

The log cannot be created after you need it, which is the entire argument for having one before you do.