Security Logging and Alerts: What Small Providers Should Watch

When a security incident is discovered, one of the first questions is how long the attacker was inside and what they touched. Without logs, you cannot answer. With logs that nobody reviews, you may have the answer sitting unused for months. For small and mid-size healthcare organizations, the aim is not to collect every possible event. It is to capture the important ones and make sure someone is alerted when something looks wrong.

The HIPAA Security Rule requires audit controls, meaning mechanisms that record and examine activity in systems containing ePHI, and procedures to regularly review records of system activity such as audit logs and access reports. This article describes a practical approach.

What to log

Start with the systems that matter most and the events that tell the clearest story.

Sign-in activity

Successful and failed logins, especially repeated failures

Logins from unusual locations, countries or times

Use of multi-factor authentication, including denied prompts

Password resets and MFA changes

Privileged actions

Creation of new accounts, and changes to groups and permissions

Use of administrator accounts

Changes to security settings, such as turning off protection or logging

Email

Creation of forwarding rules to outside addresses, a common sign of mailbox compromise

Mass deletion or unusual sending volume

Sign-ins to mailboxes from new devices

Network and firewall

Blocked connections and policy changes

New remote access connections

Unusual outbound traffic, such as a large transfer of data to an unfamiliar destination

Endpoints and servers

Malware detections and protection being disabled

New software installs on servers

Large numbers of files being modified quickly, which can indicate ransomware

The EHR and applications holding PHI

Who viewed which records and when

Access to records of residents who are not assigned to the user

Access to records of employees, family members or public figures, which is a common privacy concern

Exports and printing of large amounts of data

Centralize and protect your logs

Logs left on individual machines can be wiped by an attacker or lost when a device fails. Send them to a central location, often a security information and event management tool or a managed monitoring service, and protect them from alteration. Restrict who can delete them.

Keep a consistent time source across systems, so that events from different devices line up correctly when you piece together a timeline.

Choose a retention period

HIPAA documentation retention requirements are generally six years, and while they apply to specific policies and records rather than every log, many organizations keep security logs for a meaningful period, such as several months online and longer in archive. Balance storage cost against investigative need, and ask your insurer and counsel whether any requirements apply. Many attacks are discovered long after they begin, so very short retention is risky.

Make alerts meaningful

Too many alerts lead to fatigue, and people stop looking. Focus on a short list of high-signal alerts.

Impossible travel: a login from one place and then another far away within minutes

Multiple failed logins followed by success

New administrator accounts created

Forwarding rules created to external addresses

Security tools turned off

Ransomware-like file activity

Sign-ins at times when the person is not scheduled

Decide who receives each alert, what they should do and how fast. After hours, a human must be reachable. An alert that goes to an unmonitored mailbox on a Friday night helps no one.

Review on a schedule

Daily or continuous: high-priority alerts handled by your IT provider or monitoring service

Weekly: a short review of exceptions, failed logins and new accounts

Monthly: access reports for the EHR, including a sample review of record access by a privacy officer

Quarterly: reviewing and tuning alert rules, and removing noise

Document that the reviews took place, who performed them and what was found.

Consider a managed service

Many small organizations do not have staff to watch alerts around the clock. A managed detection and response or monitoring service can do this, but ask what is monitored, how quickly they respond, what actions they can take and how they communicate with you.

UnityCare IT helps healthcare and senior-living organizations set up logging, tune alerts and review activity reports. If you are not sure what is being recorded today, we can help you find out and fill the gaps.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172