HIPAA Security Rule

HIPAA audit controls for Windows logs, with identifiers masked before they leave the host.

DPLens records and forwards activity from Windows systems that create, receive, maintain or transmit electronic protected health information (ePHI), protects it in transit, and can mask identifiers before delivery.

  • §164.312(b) audit controls
  • §164.312(c)(1) integrity
  • §164.312(e)(1) transmission security

In short

DPLens supports HIPAA audit controls for Windows logs. The HIPAA Security Rule asks covered entities and business associates to implement mechanisms that record and examine activity in systems holding ePHI, to protect ePHI from improper alteration, and to guard it in transit. On Windows, DPLens collects the event logs and file changes that record that activity, sends them to your SIEM over TLS with certificate validation on by default, and can mask identifiers such as US social security numbers before they leave. Your risk analysis, activity reviews and policies remain yours.

Not legal or audit advice.

This page relates DPLens features to the HIPAA Security Rule as currently codified. It is not legal advice. HHS has proposed changes to the Security Rule, so check the current text. Your privacy and security officers and counsel decide whether your safeguards are reasonable and appropriate. DPLens Ltd holds no certification, and using DPLens does not make you compliant.

Last reviewed 1 October 2026.

The rule

What the Security Rule asks for

A paraphrase of the technical and administrative safeguards that concern logging.

§164.312(b)

Audit controls

Hardware, software or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.

§164.312(c)(1)

Integrity

Policies and procedures to protect ePHI from improper alteration or destruction, with mechanisms to corroborate that it has not been altered as an addressable specification.

§164.312(e)(1)

Transmission security

Technical measures to guard against unauthorised access to ePHI sent over a network, with integrity controls and encryption as addressable specifications.

§164.308(a)(1)(ii)(D)

Information system activity review

Regularly review records of system activity, such as audit logs, access reports and security incident tracking reports.

Control map

HIPAA Security Rule mapping

HIPAA Security Rule sections mapped to DPLens capabilities and what you do
RequirementHow DPLens supports itWhat you do
§164.312(b) Audit controls: recordCollects any Windows Event Log channel (Security, System, application and custom channels) and application log files from systems that hold ePHI; collection coverage shows sources producing nothingEnable Windows auditing and application logging so the activity is recorded in the first place
§164.312(b) Audit controls: examineDelivers to your SIEM, with normalisation to CIM or OCSF and aggregation of repeats to make review practicalSearch, correlation, alerting and review in your SIEM
§164.312(c)(1) IntegrityScheduled file integrity monitoring of files and folders (every 15 minutes, hourly or daily) reports changes as events; the agent's own audit trail is tamper-evidentChoose which files to watch, alert on changes and investigate them
§164.312(e)(1) Transmission securityTLS with certificate validation on by default; mutual TLS where the receiver requires it. Masking runs before anything is cached or sent.Use TLS on every destination, and always for logs that may hold ePHI crossing untrusted networks
§164.308(a)(1)(ii)(D) Activity reviewReliable delivery: disk cache, failover, and every drop counted so gaps are visibleReview records regularly and document the reviews
Limiting ePHI in logs (supports your risk analysis)Filter events you do not need; mask SSNs, email addresses, phone numbers and patterns such as medical record numbers; keyed hashing where you need to correlateDecide what your logs may contain, and write the patterns for your own identifiers

Masking

Reducing ePHI in your logs

Application logs from clinical and billing systems can carry patient identifiers. DPLens's built-in detectors find US social security numbers, email addresses, phone numbers, IP addresses and card numbers, and a pattern rule covers formats specific to you, such as medical record or account numbers. A match can be redacted, partly hidden, replaced with a marker or replaced with a keyed hash.

Masking, described on the log masking and PII redaction page, reduces how much ePHI reaches your SIEM. HIPAA's de-identification standard is a separate legal test, and keyed hashes stay linkable by anyone who holds the key, so protect the key and treat masked logs from ePHI systems as sensitive records unless your privacy officer has concluded otherwise.

For change detection on the systems themselves, see Windows file integrity monitoring; for how DPLens protects data at rest and in transit, see the Trust Centre.

FAQ

Questions healthcare teams ask

Does DPLens Ltd receive any ePHI?

The software sends no event data to DPLens Ltd: there is no telemetry, licensing service or cloud control plane. Whether any agreement is needed for your wider relationship with us is for your counsel to decide.

How long should we keep audit logs?

That is a policy decision for you and your counsel. DPLens holds events only until they are delivered; you configure retention in your SIEM or archive.

Is encryption in transit required?

Under the current rule, encryption in transit is an addressable specification, so you assess whether it is reasonable and appropriate and document the decision. DPLens supports TLS with certificate validation on by default.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.