HIPAA Audit Trail
Immutable HIPAA audit trail recording every PHI access with actor, action, and IP address. Columns: Actor · Role · Action · Resource Type · Resource ID · Success · IP Address · TimestampThis trail is immutable. Entries cannot be edited or deleted, by anyone, including administrators.
That is what makes it usable as evidence.
Security Incidents
Security incident reports with HIPAA breach risk assessment and notification timelines. Columns: Title · Discovered · Status · ePHI Encrypted? · Risk Level · Within 60 Days?Business Associates
HIPAA Business Associate Agreements with lifecycle tracking and compliance audit dates. Columns: Company · Service · BAA Status · Signed · Expires · Sub-Agreements · Security Contact · Last Audit
Vendors also appear in Vendors and purchasing with their BAA
status. Same records, different view.
Compliance Documents
HIPAA compliance documents with 6-year retention, version control, and review scheduling. Columns: Title · Type · Version · Active · Approved · Next Review · Retention ExpiresHandling a suspected breach
1
Record the incident immediately
Set Discovered to the actual discovery date. This starts the 60-day clock.
2
Determine whether ePHI was encrypted
Encrypted data may not constitute a reportable breach.
3
Assess the risk level
Consider what data was involved and who could have accessed it.
4
Check the audit trail
The HIPAA audit trail shows what was accessed and by whom.
5
Notify within the window
Set Within 60 Days? once notification is complete.
Reviewing business associates
1
Filter on Expires
Agreements within 90 days of expiry need renewing.
2
Check Last Audit
A vendor not audited recently should be reviewed.
3
Confirm sub-agreements
Ask whether the vendor has added subcontractors since the agreement was signed.
4
Verify the security contact
An out-of-date contact is useless during an incident.
Troubleshooting
Related
Member safeguards
Complaints, incidents, and member rights.
Security
Account security and login history.

