A security architect is designing a new cloud-native application for a healthcare provider. The application will process protected health information (PHI) and must comply with HIPAA. The architect must ensure that all data at rest and in transit is encrypted, and that access is logged and auditable. Which of the following controls BEST meets the requirement for auditing access to PHI?
HIPAA requires audit controls that record and examine activity in information systems containing or using electronic protected health information (ePHI). Application-level logging that captures user identity, timestamp, and the specific records accessed directly satisfies this. Storing logs securely ensures integrity and availability for audits. This is the most precise control for auditing access to PHI.
Why this answer
HIPAA's Security Rule requires audit controls that record and examine activity in systems containing ePHI. Application-level logging that captures user identity, timestamp, and the specific PHI accessed provides the necessary audit trail. Other controls like CloudTrail, AWS Config, or WAFs address different aspects of security but do not provide the granular access auditing required for PHI.
Exam trap
The trap here is assuming that infrastructure logging tools like CloudTrail or WAF logs are sufficient for HIPAA audit controls, when they lack the granularity to track access to specific PHI records.