Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Misconfiguration; no logging · 164.312(b) Audit Controls; 164.308(a)(1)(ii)(D) Review
Exploits: No or weak MFA; reused passwords · 164.312(d) Authentication; 164.308(a)(5) Training
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[cloud productivity & storage suite]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] records, protects, and reviews activity in the information systems, applications, and devices that create, receive, maintain, or transmit electronic protected health information (ePHI), so that inappropriate access or use can be detected, investigated, and acted upon. It satisfies the audit and activity-review requirements of the HIPAA Security Rule at 45 CFR §§ 164.312(b), 164.308(a)(5)(ii)(C), and 164.308(a)(1)(ii)(D).
This Policy applies to all workforce members (employees, contractors, interns, and volunteers), business associates, and any other party whose activity touches [Organization] systems, and to all system components (applications, endpoints, cloud services, and infrastructure) that store or process ePHI. It covers the audit records those components generate, the protection of those records, and the human review of access reports, log-in activity, and security alerts.
See where your organization stands on the controls this template cites.
Join Us[Organization] implements hardware, software, and procedural mechanisms that record activity in systems containing ePHI. Wherever the platform supports it, audit records capture who performed an action, what action (view, create, download, share, edit, delete, export, permission/configuration change), when (date and time), the target (file, record, or resource), and the source (user account, device, and where available the IP/network). At minimum, logging is enabled for:
[cloud productivity & storage suite]: successful and failed attempts to access, download, share, edit, or delete ePHI files and folders;Logging coverage is defined for the user, application, system/endpoint, and (where applicable) network levels. Where a level cannot be feasibly logged given [Organization]'s size and stack, the gap and the compensating control are documented in the risk analysis.
Audit records are protected so they can be relied on as evidence:
[Organization] monitors authentication activity for ePHI-relevant systems for indicators of misuse: for example, repeated failed sign-ins, access from unexpected locations or devices, sign-ins at atypical times, impossible-travel patterns, and use of disabled or terminated accounts. Workforce members must report any login discrepancy they notice (an account showing activity the owner did not perform, an unexpected MFA prompt, or a "last sign-in" that does not match their own use) promptly to the [Security Official]. Where the platform supports it, high-risk login events generate automated alerts to a monitored mailbox or alias. A login discrepancy that suggests compromise is treated as a suspected security incident and escalated under the Security Incident Response Policy.
[Organization] regularly reviews records of information system activity (audit logs, access reports, and security-incident tracking) to confirm that activity is appropriate and that the logging itself is functioning. The review program is risk-based and operates on a defined cadence:
[quarterly] by the [Security Official] or a designated reviewer, covering a defined scope (e.g., ePHI access activity, privileged-account use, sharing changes, failed-authentication trends) and confirming that the expected data is being captured and retained.Reviewers do not review their own activity. Where [Organization]'s size makes independent review infeasible (e.g., the [Security Official] is also the platform administrator), the following compensating controls apply: (i) dated, immutable or versioned review evidence (exports/snapshots plus a signed review note) stored in a restricted location; (ii) the platform's native audit logs as the authoritative system of record; (iii) alerting for high-risk events; and (iv) where feasible, a periodic (e.g., annual) external spot-check of one or more reviews for independence. This role consolidation and rationale are documented in the risk analysis.
Any review finding, alert, or reported discrepancy that indicates a confirmed or suspected compromise, unauthorized access to ePHI, data loss, or other security event is escalated without delay to the Security Incident Response Policy process. Routine findings (e.g., a misconfiguration or an access that needs tightening) are recorded and tracked to remediation. The full triage, investigation, containment, breach-assessment, and notification steps are defined in the Security Incident Response Policy and are not duplicated here.
In addition to routine review, an audit may be requested for a specific cause (for example, a complaint, a suspected violation, or an unusual access pattern). A for-cause request states the timeframe, scope, and nature of the audit and is approved by the [Security Official] before it proceeds. Detailed audit information is shared only with authorized parties on a minimum-necessary basis; if an audit reveals that a workforce member accessed ePHI inappropriately, the matter is referred for sanctions under the Workforce Security, Training & Sanctions Policy. Only de-identified results are shared with third parties, and counsel is consulted before any external communication.
Audit logs and the records of their review (review notes, findings, remediation, attestations) are retained for at least 6 years to meet HIPAA documentation requirements, stored with restricted access, and may be moved to lower-cost protected storage via lifecycle management as long as integrity and access controls are preserved.
[Security Official]: owns this Policy; defines audit scope, parameters, and cadence; performs or assigns log-in monitoring and activity review; approves for-cause audits; ensures escalation to the incident process.Audit Controls & Activity Review Procedures · Security Incident Response Policy · Access Control Policy · Workforce Security, Training & Sanctions Policy · Information System Activity Review evidence (review logs).
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.312(b) | Audit Controls | §1, §2, §7 |
| 164.308(a)(5)(ii)(C) | Log-in Monitoring | §3 |
| 164.308(a)(1)(ii)(D) | Information System Activity Review | §4, §5, §6 |
Reviewed at least annually by the [Security Official] and after any significant change to the ePHI environment. v1.0.