Skip to main content
These tabs hold your HIPAA evidence: who accessed protected health information, what incidents occurred, which vendors are covered by agreements, and where your policies live.

HIPAA Audit Trail

Immutable HIPAA audit trail recording every PHI access with actor, action, and IP address. Columns: Actor · Role · Action · Resource Type · Resource ID · Success · IP Address · Timestamp
This trail is immutable. Entries cannot be edited or deleted, by anyone, including administrators. That is what makes it usable as evidence.
Success matters as much as the successful accesses. A run of failed attempts against member records is a signal worth investigating.
The audit trail records metadata about access — who, what, when, from where. It does not record the clinical content viewed. Do not expect it to tell you what a user read, only what they opened.

Security Incidents

Security incident reports with HIPAA breach risk assessment and notification timelines. Columns: Title · Discovered · Status · ePHI Encrypted? · Risk Level · Within 60 Days?
Within 60 Days? tracks a hard regulatory deadline measured from Discovered, not from when the investigation concludes. Record the discovery date accurately and escalate immediately — the clock does not pause while you assess.

Business Associates

HIPAA Business Associate Agreements with lifecycle tracking and compliance audit dates. Columns: Company · Service · BAA Status · Signed · Expires · Sub-Agreements · Security Contact · Last Audit
Sub-Agreements is easy to overlook. A business associate who subcontracts your PHI needs agreements in place downstream too. Your obligation does not stop at the first vendor.
Vendors also appear in Vendors and purchasing with their BAA status. Same records, different view.

Compliance Documents

HIPAA compliance documents with 6-year retention, version control, and review scheduling. Columns: Title · Type · Version · Active · Approved · Next Review · Retention Expires
HIPAA documents carry a six-year retention requirement. Retention Expires tells you when a superseded document may be disposed of — not before.

Handling a suspected breach

1

Record the incident immediately

Set Discovered to the actual discovery date. This starts the 60-day clock.
2

Determine whether ePHI was encrypted

Encrypted data may not constitute a reportable breach.
3

Assess the risk level

Consider what data was involved and who could have accessed it.
4

Check the audit trail

The HIPAA audit trail shows what was accessed and by whom.
5

Notify within the window

Set Within 60 Days? once notification is complete.
This is not legal advice. Breach determination and notification obligations depend on circumstances. Involve your privacy officer and counsel.

Reviewing business associates

1

Filter on Expires

Agreements within 90 days of expiry need renewing.
2

Check Last Audit

A vendor not audited recently should be reviewed.
3

Confirm sub-agreements

Ask whether the vendor has added subcontractors since the agreement was signed.
4

Verify the security contact

An out-of-date contact is useless during an incident.

Troubleshooting

Member safeguards

Complaints, incidents, and member rights.

Security

Account security and login history.