When a security incident is discovered, one of the first questions is how long the attacker was inside and what they touched. Without logs, you cannot answer. With logs that nobody reviews, you may have the answer sitting unused for months. For small and mid-size healthcare organizations, the aim is not to collect every possible event. It is to capture the important ones and make sure someone is alerted when something looks wrong.
The HIPAA Security Rule requires audit controls, meaning mechanisms that record and examine activity in systems containing ePHI, and procedures to regularly review records of system activity such as audit logs and access reports. This article describes a practical approach.
Start with the systems that matter most and the events that tell the clearest story.
Successful and failed logins, especially repeated failures
Logins from unusual locations, countries or times
Use of multi-factor authentication, including denied prompts
Password resets and MFA changes
Creation of new accounts, and changes to groups and permissions
Use of administrator accounts
Changes to security settings, such as turning off protection or logging
Creation of forwarding rules to outside addresses, a common sign of mailbox compromise
Mass deletion or unusual sending volume
Sign-ins to mailboxes from new devices
Blocked connections and policy changes
New remote access connections
Unusual outbound traffic, such as a large transfer of data to an unfamiliar destination
Malware detections and protection being disabled
New software installs on servers
Large numbers of files being modified quickly, which can indicate ransomware
Who viewed which records and when
Access to records of residents who are not assigned to the user
Access to records of employees, family members or public figures, which is a common privacy concern
Exports and printing of large amounts of data
Logs left on individual machines can be wiped by an attacker or lost when a device fails. Send them to a central location, often a security information and event management tool or a managed monitoring service, and protect them from alteration. Restrict who can delete them.
Keep a consistent time source across systems, so that events from different devices line up correctly when you piece together a timeline.
HIPAA documentation retention requirements are generally six years, and while they apply to specific policies and records rather than every log, many organizations keep security logs for a meaningful period, such as several months online and longer in archive. Balance storage cost against investigative need, and ask your insurer and counsel whether any requirements apply. Many attacks are discovered long after they begin, so very short retention is risky.
Too many alerts lead to fatigue, and people stop looking. Focus on a short list of high-signal alerts.
Impossible travel: a login from one place and then another far away within minutes
Multiple failed logins followed by success
New administrator accounts created
Forwarding rules created to external addresses
Security tools turned off
Ransomware-like file activity
Sign-ins at times when the person is not scheduled
Decide who receives each alert, what they should do and how fast. After hours, a human must be reachable. An alert that goes to an unmonitored mailbox on a Friday night helps no one.
Daily or continuous: high-priority alerts handled by your IT provider or monitoring service
Weekly: a short review of exceptions, failed logins and new accounts
Monthly: access reports for the EHR, including a sample review of record access by a privacy officer
Quarterly: reviewing and tuning alert rules, and removing noise
Document that the reviews took place, who performed them and what was found.
Many small organizations do not have staff to watch alerts around the clock. A managed detection and response or monitoring service can do this, but ask what is monitored, how quickly they respond, what actions they can take and how they communicate with you.
UnityCare IT helps healthcare and senior-living organizations set up logging, tune alerts and review activity reports. If you are not sure what is being recorded today, we can help you find out and fill the gaps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172