Get Demo
↑

HIPAA Audit Log Requirements: What to Log and the 6-Year Documentation Rule

§164.312(b) audit controls — what to log, how 164.316(b)(2) 6-year documentation retention differs from operational SIEM retention.

Published: September 2026 Compliance · HIPAA 8–12 min read

§164.312(b) Audit Controls require covered entities and business associates to implement mechanisms that record and examine activity in systems containing ePHI. Buyers often ask for a “6-year HIPAA log retention law.” The 6-year clock in 45 CFR 164.316(b)(2) applies to Security Rule documentation (policies, procedures, and related docs) — not a separate statute that freezes every SIEM event for six years.

Related: HIPAA hub · HIPAA-compliant SIEM · ThreatHawk HIPAA logging.

Documentation retention — 45 CFR 164.316(b)(2): retain Security Rule documentation for 6 years from the date of creation or the date when it last was in effect, whichever is later. This covers policies, procedures, and related documentation — not a separate “6-year SIEM log retention” statute. Operational log retention is a risk-based practice supporting audit controls (164.312(b)).

§164.312 Technical Safeguards — Standards: Access Control (a), Audit Controls (b) Required, Integrity (c), Person/Entity Authentication (d) Required, Transmission Security (e). Implementation specifications under each standard are Required or Addressable as listed in the regulation.

What to Log (Practical Baseline)

Documentation vs Operational Logs

Artefact
Rule of thumb
Policies, procedures, risk analyses, BAAs, training records
Retain ≥ 6 years per 164.316(b)(2) (creation or last effective, whichever later)
Operational SIEM / system audit logs
Risk-based retention sufficient to examine activity under 164.312(b) and support investigations / OCR requests

Product Path

For a ThreatHawk-centric view of automated HIPAA audit logging, see How ThreatHawk SIEM Automates HIPAA Audit Logging and the solution page HIPAA-Compliant SIEM.

How CyberSilo Helps

Make Audit Controls Examinable

Collect the right ePHI events and keep the 6-year documentation set with the logs that prove reviews happened.

Frequently Asked Questions

Does HIPAA require 6 years of SIEM logs?

164.316(b)(2) requires retaining Security Rule documentation for 6 years. Operational log retention should be risk-based to support §164.312(b) audit controls — not confused with a separate 6-year log statute.

What does §164.312(b) require?

Hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.

Where should audit evidence live?

In systems that can produce searchable timelines (often a SIEM) plus documented review procedures and retention of Security Rule documentation.

HIPAA hub · OCR prep · §164.312 · ThreatHawk

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!