Free HIPAA procedures template · v1.0 · Applies to covered entities & business associates · Companion: Policy →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Misconfiguration; no logging · 164.312(b) Audit Controls; 164.308(a)(1)(ii)(D) Review
Exploits: No or weak MFA; reused passwords · 164.312(d) Authentication; 164.308(a)(5) Training
Template. These procedures operationalize the Audit Controls & Activity Review Policy. Replace
[bracketed]items with your specifics and adjust steps to match your tools and team size.
To provide repeatable, auditable steps for enabling and protecting audit logging, monitoring log-in activity, reviewing information system activity on a defined cadence, and handing confirmed or suspected events off to the incident process, implementing the Audit Controls & Activity Review Policy.
See where your organization stands on the controls this template cites.
Join Us[cloud productivity & storage suite] and the [identity provider / single sign-on] to surface authentication activity and to alert on high-risk login events (repeated failed sign-ins, new-device or new-location sign-ins, impossible-travel, use of disabled/terminated accounts); route alerts to a monitored mailbox or alias.[Security Official].[Security Official] evaluates the discrepancy; if it suggests compromise, hand it off to the incident process per §4. Record the discrepancy and its disposition either way.[quarterly]), the [Security Official] opens a review record in the [compliance tracking system] and assigns a reviewer who is not reviewing their own activity.[Security Official] approves the completed review (returning it for more detail if needed) and marks it done with any notes. Where the reviewer is also the administrator, attach a short attestation (date, scope covered, and a statement that findings and corrections were recorded) and, where feasible, obtain a periodic external spot-check for independence.[Security Official] classifies it as a suspected security incident.Logging-configuration records and risk-analysis notes · login-monitoring alert settings and discrepancy reports · [quarterly] activity-review records with findings, sign-offs, and attestations · alert-to-incident handoff references · retained audit logs. These are the artifacts an auditor will request to confirm the controls operate.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.312(b) | Audit Controls | §1, §5 |
| 164.308(a)(5)(ii)(C) | Log-in Monitoring | §2 |
| 164.308(a)(1)(ii)(D) | Information System Activity Review | §3, §4 |
Reviewed at least annually by the [Security Official]. v1.0.