Hardware, software, and procedural mechanisms to record and examine activity in systems containing ePHI.
Policies and procedures for detecting and responding to malicious activity and unauthorized access.
Policies for disposal, reuse, and accountability of media containing ePHI.
Technical policies for systems that maintain ePHI to allow access only to authorised persons.
Who opened which health record, from which address, at what second — and a per-user review that flags anyone reading more than their job needs.
Every access recorded against §164.312 and §164.308, scored by safeguard, and reviewable per user without leaving the product.