Investigation Logs: What to Keep and for How Long

After a security incident, one of the first questions is simple: what happened, and when? The answer lives in logs. Unfortunately, many small and mid-size organizations discover during a breach that the logs they need were never turned on, were overwritten after a week or were stored on the very system the attacker controlled.

Deciding in advance which logs to keep, and for how long, costs little and pays off heavily when you need to scope a breach, answer your insurer or determine whether protected health information was accessed.

Why logs matter for healthcare

Under the HIPAA Breach Notification Rule, a covered entity that discovers a breach of unsecured protected health information must assess the risk and notify affected individuals, HHS and sometimes the media. You cannot make that assessment well without evidence of what was accessed. The HIPAA Security Rule also requires audit controls and regular review of system activity, and it expects documentation to be kept for six years.

Good logs let you answer practical questions:

How did the attacker get in?

Which accounts and systems were touched?

Was data copied out of the environment?

Is the intruder still there?

The logs that matter most

You do not need to keep everything. Prioritize sources that show identity, access and movement.

Identity and email

Sign-in logs from your directory and cloud identity platform, including successes, failures, locations and multi-factor results

Administrative activity logs showing changes to users, roles, mail rules and settings

Email audit logs, which can reveal forwarding rules and suspicious mailbox access

Network and perimeter

Firewall logs showing allowed and blocked connections

VPN and remote access logs recording who connected and from where

DNS and web filtering logs, if available, to spot connections to malicious sites

Endpoints and servers

Endpoint security alerts and telemetry from antivirus or endpoint detection tools

Windows security event logs from servers and domain controllers

PowerShell and command-line logging, where it can be enabled, since attackers often use built-in tools

Applications holding patient data

EHR access and audit logs, showing who viewed or changed resident records

File server and cloud storage access logs

Database logs for systems you host yourself

Backups and security tools

Backup job logs, including deletion events

Alerts and actions from your security monitoring platform

Retention targets

Retention depends on your regulatory obligations, contracts and insurance, so confirm with counsel. As a practical starting point, many organizations aim for:

90 days of immediately searchable logs for quick investigation and daily monitoring.

12 months of retained logs, possibly in cheaper archive storage, because intruders often remain undetected for long periods.

Longer retention for specific records, such as access audit logs for patient data and security policy documentation, aligned with your own HIPAA documentation retention policy and legal advice.

Cloud platforms often default to short retention unless you configure or license for more, so check the settings rather than assuming.

Protect the logs

Logs are valuable to attackers who want to hide their tracks. Protect them:

Send copies to a central, separate location, so deleting a log on a compromised server does not erase the evidence.

Restrict who can modify or delete logs, using separate administrative accounts.

Synchronize clocks across systems, since mismatched time stamps make timelines unreliable.

Back up archived logs and test that you can retrieve them.

Remember that logs may contain sensitive information, and apply appropriate access controls.

Assign ownership and review

A log nobody reads is only useful after the fact, which is still useful, but reviewing regularly catches problems earlier. Decide who reviews alerts, how often and what triggers escalation. Document your logging and retention standard in your security policies, and include it in your annual security risk analysis.

A quick action list

Inventory your systems and note which logs each produces.

Turn on logging where it is off.

Centralize logs in a protected location.

Set retention targets and verify them.

Test your ability to answer one real question, such as "show every sign-in for this account last month."

UnityCare IT helps healthcare organizations configure logging, centralize it and set retention that supports investigations, insurance requirements and HIPAA documentation.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172