Key takeaways:
HIPAA requires you to keep security documentation – including records of required ‘actions, activities, or assessments’ – for at least six years under 45 CFR § 164.316(b)(2)(i). The Security Rule’s audit control standard (§ 164.312(b)) only requires that you record and examine system activity. It never sets a specific log-retention period.
In practice, most compliance experts treat audit trails and access logs that evidence those ‘actions, activities, or assessments’ as part of the six‑year documentation set, even though HHS has never issued a line‑by‑line interpretation for every log entry.
This guide explains how that six‑year figure is derived, when other laws push retention beyond six years, and how to treat conflicting guidance from HIPAA, CMS, and state record rules. It also walks through what a ‘compliant enough’ audit trail should contain, and how an additional governance layer for Microsoft 365 helps you meet those obligations without living in your SIEM.
Most teams quote six years for HIPAA audit log retention. This is because they read two parts of the Security Rule together: the audit controls standard, which sets no time limit, and the documentation standard, which sets six years. NIST guidance connects the two.
The Security Rule’s audit controls standard, 45 CFR § 164.312(b), only requires you to ‘implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.’
It doesn’t say how long you must keep those records, which is why the regulation itself never says ‘keep audit logs for X years’.
The time limit appears in a different section. Under 45 CFR § 164.316(b)(2)(i), covered entities and business associates must ‘retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.’
HHS explains in its own Security Series guidance that this six‑year period is the minimum retention period for Security Rule documentation.
NIST SP 800‑66 then connects the dots, stating that ‘documentation of actions and activities need to be retained for at least six years’, which most regulators and auditors interpret to include audit logs that evidence Security Rule-related actions.
OCR routinely points to NIST guidance as the practical blueprint for implementing HIPAA security requirements, even though NIST is not a regulation in itself.
That six‑year rule applies to Security Rule documentation such as policies and procedures, risk assessments, audit trails that show access to ePHI, training records, and business associate agreements.
It does not set a universal retention period for clinical medical records, as those are governed by state law. In some cases, they may be covered by payer or accreditation requirements, which often require 5-10+ years depending on jurisdiction and patient age.
A common myth is that ‘HIPAA requires seven‑year retention’. In reality, seven‑year figures usually come from state medical record statutes or from CMS rules for Medicare providers and do not change HIPAA’s six‑year minimum for Security Rule documentation.
Some states, including large ones like California and Pennsylvania, set their own record‑retention timelines, so organizations adopt the longer of HIPAA’s six‑year documentation rule and applicable state or payer rules.
HIPAA’s six‑year clock does not always start at creation and then run out. Under § 164.316(b)(2)(i), the timer runs for six years from the date a document was created or the date it was last in effect, whichever is later.
If you wrote an audit policy or deployed an audit configuration in 2018 and kept it in effect until 2024, you need to retain the supporting documentation until at least 2030.
“For audit logs and related evidence, that means you should never purge ‘old’ data solely based on its creation date without checking when the associated policy, system, or configuration was superseded. Many organizations align their log‑retention schedules to policy‑change dates and maintain a change register that shows when each control came into or went out of effect.”
– Danijel Čižek, Product Manager Team Lead at Syskit
The 2024 HIPAA Security Rule NPRM proposes, among other changes, to remove the ‘required’ vs. ‘addressable’ distinction from implementation specifications and tighten documentation expectations, which would indirectly increase scrutiny on audit logging practices.
OCR targeted May 2026 for the final rule, but it hasn’t been published yet, and the latest federal regulatory agenda now suggests 2027. The proposed changes don’t touch the six-year baseline, but they would reduce the room for casual interpretations once adopted.
In practice, plenty of healthcare organizations need to retain some audit logs longer than six years, even though HIPAA’s Security Rule sets six years as the baseline for Security documentation. State medical record laws, Medicare Advantage and Part D contracts, and litigation holds can all push audit log retention past HIPAA’s six-year baseline.
State medical record laws often exceed six years, especially for hospitals and pediatric care, and they act as a higher bar than the HIPAA ‘floor’. For example, Texas, Arkansas, and several other states require hospitals to retain adult medical records for 10 years. Meanwhile, North Carolina requires 11 years for adults and effectively until age 30 for minors, and Nevada requires five years for adults and prohibits destroying any record until the patient turns 23.
Audit logs live in the uncomfortable middle between ‘compliance documentation’ and ‘medical records’. When a state treats access history as part of the legal medical record, multi‑state organizations usually default to the longest applicable retention period across their footprint rather than run different log schedules per state.
There’s also a separate 10‑year retention rule from the Centers for Medicare & Medicaid Services. Medicare Advantage (Part C) and Part D contracts require MA organizations and their first tier, downstream, and related entities (FDRs) to retain records for 10 years.
This includes documentation needed to demonstrate compliance. The rule is independent of HIPAA, but if you are part of an MA or Part D delivery chain, it stretches your audit‑log retention expectation from six years to ten for those programs.
Two other forces extend retention even further – litigation holds and the ‘last in effect’ language in 45 CFR § 164.316(b)(2)(i).
If a policy or configuration created in 2015 stays in effect until 2024, you must keep the related documentation until 2030, regardless of the log creation dates. A litigation hold freezes deletion even longer, so audit logs that document disputed access events stay on ice until legal sign‑off, often well beyond any nominal six‑ or ten‑year schedule.
HIPAA-compliant audit logs focus less on a specific format and more on reliably answering ‘who did what, when, where, to which ePHI, and was it allowed’. The fields below give you a practical, defensible baseline.
|
Field |
Description |
Example |
|---|---|---|
|
User ID |
Unique identifier for the person |
jsmith@hospital.org |
|
Timestamp |
Date/time, UTC preferred |
2026-03-15T14:32:51Z |
|
Action |
What was done |
Viewed patient record |
|
Resource |
Specific data or record accessed |
Patient #12345 lab results |
|
Access origin |
Where the access came from |
IP: 10.0.4.22 |
|
Outcome |
Success or failure |
Failed: unauthorized |
HHS has never published a canonical field list for audit logs, and the Security Rule does not mandate a specific schema. It only requires that you ‘record and examine’ activity in systems containing ePHI. Practitioner consensus and NIST guidance drive the expectation that you can reliably tie each access back to a user, time, resource, and outcome with enough context to investigate.
For policy and design work, it helps to think in three event layers:
To avoid blind spots, distinguish three log types in your environment:
You need coverage across all three. Focusing only on the EHR’s user trail misses activity where ePHI lives in exports, reports, or collaboration tools. In a Microsoft 365‑centric organization, that means pulling in SharePoint Online, OneDrive, Teams, Exchange, and M365 group activity anywhere ePHI lands, then aligning those logs under one governance layer that can correlate users, resources, and actions down to file level.
Syskit Point builds on this foundation by turning raw, fragmented audit data into a coherent, actionable governance framework. Instead of manually correlating logs across services, it normalizes events into a unified view that ties users, actions, and content together with clear context.
This makes it significantly easier to investigate incidents, demonstrate HIPAA compliance, and detect risky behavior early. Granular reporting, automated alerts, and historical tracking reduce the time spent on audits while improving accuracy. Any potential problems can easily be found in a centralized Security & Compliance dashboard.
By enforcing consistency across Microsoft 365, Syskit Point keeps you ready to prove it – every permission, content, and configuration change across SharePoint, Teams, OneDrive, Exchange, and Groups, logged in one place.
To store HIPAA audit logs for six years, you need three things working together – tamper-evidence, strong encryption, and a storage architecture that stays affordable at scale.
HIPAA’s integrity standard (§164.312(c)(1)) requires you to protect ePHI from improper alteration or destruction, which applies directly to audit logs that document access. In practice, organizations usually mix two techniques:
“The ultimate goal is to prove that what you show an auditor or court is the same data that was written years ago, or that any deviations are detectable.”
– Danijel Čižek, Product Manager Team Lead at Syskit
Audit logs often contain ePHI or at least sensitive identifiers, so they must meet your standard encryption controls. A common baseline is AES‑256 for data at rest and TLS 1.2 or higher for data in transit between collectors, storage, and analytics tools. That keeps long‑term archives defensible from both integrity and confidentiality angles.
To keep six‑year retention financially sane, most teams tier their log storage:
A classic failure mode is leaving default retention values untouched. For example, Microsoft 365’s default unified audit log retention is 180 days. Organizations that never adjust those settings fall short of their own six‑year policy from day one. Long‑term retention usually requires E5 plus a paid 10-year add-on.
A governance layer for Microsoft 365, such as Syskit Point, helps by centralizing and normalizing audit data across SharePoint, Teams, OneDrive, Exchange, and M365 Groups, with scheduled, exportable reports you can keep alongside your long‑term archive.
Enterprise customers can host Syskit Point in their own Azure tenant and pair its unlimited audit log retention with their preferred immutable storage and hashing strategy.
HIPAA expects you to review audit logs, so don’t just keep them in a vault for six years. Under 45 CFR §164.308(a)(1)(ii)(D), covered entities and business associates must perform Information System Activity Reviews, which includes log-in records, audit logs, access reports, and security incident tracking.
This is an ongoing operational obligation. Regulators look for structured processes that show someone is actively watching for suspicious behavior rather than relying on storage alone.
When OCR investigates, it typically asks for proof of reviews – who reviewed which logs, on what dates, what anomalies they found, and what corrective actions they took. A checklist or SIEM dashboard is not enough by itself. You need a trail of review records that show real humans (or defined roles) are examining alerts and following up.
A workable approach combines:
Documenting the review is as important as performing it. Capture who reviewed, which dashboards or reports they used, what they concluded, and any tickets or remediation work that followed.
For Microsoft 365 environments, a governance layer like Syskit Point helps by surfacing permission changes, external sharing, and risky access patterns across SharePoint, Teams, OneDrive, Exchange, and M365 workspaces. The Permissions Matrix shows precisely who has access to what across your organization.
Built-in security and compliance checks cover users, files, permissions, and sensitivity labels, supporting HIPAA, ISO, and GDPR requirements.
Instead of manual PowerShell exports, reviewers work from consistent reports and dashboards and can tie review notes or follow‑up actions directly to the events they see, which makes it much easier to produce evidence during an audit.
Pharmaceutical manufacturer Coripharma uses Syskit Point's central access overview to supply auditors with access evidence immediately – saving its IT team the equivalent of half a person's annual workload along the way.
A defensible HIPAA audit log retention policy fits on one page if you anchor it to a few clear decisions.
As we’ve seen, for organizations running Microsoft 365, the auditing and retention capabilities discussed throughout this article can be supported from a single governance layer. Syskit Point centralizes M365 activity and helps you implement the policy you just designed.
Yes. Under HIPAA and HITECH, business associates must implement the Security Rule safeguards and retain required documentation. This includes audit logs that evidence Security Rule ‘actions, activities, or assessments’, for at least six years from creation or last effective date, or longer where a documented risk analysis justifies it.
In practice, most BA agreements either mirror or exceed the covered entity’s own retention schedule, so a cloud provider or MSSP hosting ePHI cannot adopt a shorter period without explicit agreement and written justification.
Once the applicable retention period (HIPAA, state law, CMS, contract, and any litigation holds) has passed, audit logs must be disposed of in a way that protects the confidentiality and integrity of any ePHI they contain. HHS‑aligned guidance recognizes three broad destruction approaches.
You should document the destruction process, including date, media, method, and approvals, and ensure any legal hold or investigation has been formally released before deletion proceeds.