HIPAA Security Rule
HIPAA audit controls for Windows logs, with identifiers masked before they leave the host.
DPLens records and forwards activity from Windows systems that create, receive, maintain or transmit electronic protected health information (ePHI), protects it in transit, and can mask identifiers before delivery.
- §164.312(b) audit controls
- §164.312(c)(1) integrity
- §164.312(e)(1) transmission security
In short
DPLens supports HIPAA audit controls for Windows logs. The HIPAA Security Rule asks covered entities and business associates to implement mechanisms that record and examine activity in systems holding ePHI, to protect ePHI from improper alteration, and to guard it in transit. On Windows, DPLens collects the event logs and file changes that record that activity, sends them to your SIEM over TLS with certificate validation on by default, and can mask identifiers such as US social security numbers before they leave. Your risk analysis, activity reviews and policies remain yours.
This page relates DPLens features to the HIPAA Security Rule as currently codified. It is not legal advice. HHS has proposed changes to the Security Rule, so check the current text. Your privacy and security officers and counsel decide whether your safeguards are reasonable and appropriate. DPLens Ltd holds no certification, and using DPLens does not make you compliant.
The rule
What the Security Rule asks for
A paraphrase of the technical and administrative safeguards that concern logging.
§164.312(b)
Audit controls
Hardware, software or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
§164.312(c)(1)
Integrity
Policies and procedures to protect ePHI from improper alteration or destruction, with mechanisms to corroborate that it has not been altered as an addressable specification.
§164.312(e)(1)
Transmission security
Technical measures to guard against unauthorised access to ePHI sent over a network, with integrity controls and encryption as addressable specifications.
§164.308(a)(1)(ii)(D)
Information system activity review
Regularly review records of system activity, such as audit logs, access reports and security incident tracking reports.
Control map
HIPAA Security Rule mapping
| Requirement | How DPLens supports it | What you do |
|---|---|---|
| §164.312(b) Audit controls: record | Collects any Windows Event Log channel (Security, System, application and custom channels) and application log files from systems that hold ePHI; collection coverage shows sources producing nothing | Enable Windows auditing and application logging so the activity is recorded in the first place |
| §164.312(b) Audit controls: examine | Delivers to your SIEM, with normalisation to CIM or OCSF and aggregation of repeats to make review practical | Search, correlation, alerting and review in your SIEM |
| §164.312(c)(1) Integrity | Scheduled file integrity monitoring of files and folders (every 15 minutes, hourly or daily) reports changes as events; the agent's own audit trail is tamper-evident | Choose which files to watch, alert on changes and investigate them |
| §164.312(e)(1) Transmission security | TLS with certificate validation on by default; mutual TLS where the receiver requires it. Masking runs before anything is cached or sent. | Use TLS on every destination, and always for logs that may hold ePHI crossing untrusted networks |
| §164.308(a)(1)(ii)(D) Activity review | Reliable delivery: disk cache, failover, and every drop counted so gaps are visible | Review records regularly and document the reviews |
| Limiting ePHI in logs (supports your risk analysis) | Filter events you do not need; mask SSNs, email addresses, phone numbers and patterns such as medical record numbers; keyed hashing where you need to correlate | Decide what your logs may contain, and write the patterns for your own identifiers |
Masking
Reducing ePHI in your logs
Application logs from clinical and billing systems can carry patient identifiers. DPLens's built-in detectors find US social security numbers, email addresses, phone numbers, IP addresses and card numbers, and a pattern rule covers formats specific to you, such as medical record or account numbers. A match can be redacted, partly hidden, replaced with a marker or replaced with a keyed hash.
Masking, described on the log masking and PII redaction page, reduces how much ePHI reaches your SIEM. HIPAA's de-identification standard is a separate legal test, and keyed hashes stay linkable by anyone who holds the key, so protect the key and treat masked logs from ePHI systems as sensitive records unless your privacy officer has concluded otherwise.
For change detection on the systems themselves, see Windows file integrity monitoring; for how DPLens protects data at rest and in transit, see the Trust Centre.
How to do it
In the documentation
FAQ
Questions healthcare teams ask
Does DPLens Ltd receive any ePHI?
The software sends no event data to DPLens Ltd: there is no telemetry, licensing service or cloud control plane. Whether any agreement is needed for your wider relationship with us is for your counsel to decide.
How long should we keep audit logs?
That is a policy decision for you and your counsel. DPLens holds events only until they are delivered; you configure retention in your SIEM or archive.
Is encryption in transit required?
Under the current rule, encryption in transit is an addressable specification, so you assess whether it is reasonable and appropriate and document the decision. DPLens supports TLS with certificate validation on by default.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.