
The Short Answer
HIPAA's Security Rule requires covered entities to keep their security documentation for six years from the date it was created or last in effect, whichever is later (45 CFR 164.316(b)(2)). That documentation includes written policies and procedures, and written records of the security activities the rule requires. Two of those activities matter most here: regularly reviewing system activity, and documenting security incidents and how they were resolved.
The rule does not name a specific retention period for raw audit log data. That distinction matters, and it is where many practices, and many IT providers, get the requirement wrong in both directions. Some assume that because they have logging, they are covered. Others assume that six years of stored logs is the whole requirement.
In practice, audit-log retention for a medical practice has three layers:
Records that logs were reviewed. Required, and retained for six years.
Records of security incidents and their outcomes. Required, and retained for six years.
The raw log data itself. Not assigned a retention period by the rule, but it is the only evidence that can answer what happened to patient data during a breach investigation. Six years is the defensible standard.
This post explains each layer, why the third one matters more than the regulation's wording suggests, and what to ask your IT provider.
A note on timing: this post reflects the HIPAA Security Rule currently in effect. HHS has proposed significant amendments to the rule, but as of this writing they have not been finalized.
Layer 1: Proof That Someone Actually Looked
HIPAA's Security Rule requires practices to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports (45 CFR 164.308(a)(1)(ii)(D)). This is a required implementation specification, not an optional one.
Here is the part most practices miss: having logs does not prove anyone reviewed them. Six years of stored log data shows the practice kept the data. It says nothing about whether anyone examined it. If OCR asks how the practice meets the review requirement, "our system records everything" is not an answer.
What satisfies the requirement is a record of the review itself. For practices with a managed security operations center (SOC) monitoring their systems, that record typically takes the form of a periodic report. It shows what was monitored during the period, how much activity was analyzed, what was flagged, what was investigated, and what the outcome was.
The months when nothing happened matter as much as the months when something did. A report that says "activity reviewed, no threats identified" is evidence that the requirement was met. Silence is not.
Layer 2: Documenting What Happened and How It Was Resolved
The Security Rule also requires practices to identify and respond to security incidents, mitigate their harmful effects where practicable, and document incidents and their outcomes (45 CFR 164.308(a)(6)(ii)).
An incident record should show when the event was detected, what systems were involved, what was done in response, and how it was resolved. An incident that was flagged but never documented as closed is a weaker position than most practices realize. It shows the practice knew about a problem, but it does not show the practice dealt with it.
Both the review records and the incident records are documentation under 164.316(b)(2), which means both are retained for six years.
Layer 3: The Raw Logs, and Why They Matter Most When Something Goes Wrong
This is the layer the regulation is least explicit about, and the one that matters most in a breach.
Under HIPAA's Breach Notification Rule, an unauthorized access to patient information is presumed to be a reportable breach unless the practice can demonstrate a low probability that the information was compromised (45 CFR 164.402). The burden of proving that falls on the practice (45 CFR 164.414(b)).
Making that showing means answering specific questions. What did the intruder access? Which patient records were involved? Was data viewed, copied, or taken? Those answers live in the raw logs: EHR access records, sign-in records, and endpoint and cloud activity. Review reports and incident records summarize what was detected. They cannot reconstruct activity that was never flagged.
That is the scenario that matters most. Breaches are frequently discovered months after the initial intrusion, precisely because the attacker was not detected. When that happens, the monthly review reports will accurately show that nothing was found at the time. The investigation then has to work backward through the raw data. If that data is gone, the practice cannot prove the scope of the incident was limited. Its default becomes notifying every patient whose information could have been exposed.
Six years is also the window in which HHS can bring a civil money penalty action for a HIPAA violation (42 U.S.C. 1320a-7a(c)(1)). A practice that keeps its raw logs for that period can reconstruct its security posture throughout the entire window in which it could be held accountable.
For these reasons, six-year retention of raw log data is the prevailing interpretation of HIPAA's documentation requirements, and the safest one. It is also a real cost that scales with the size of the practice's environment. That makes it a decision the practice should make deliberately and document, not one that should be assumed or overlooked.
How This Differs from Day-to-Day Security Monitoring
A well-managed practice will have security monitoring running continuously, collecting and analyzing activity from workstations, servers, and cloud services. Many monitoring platforms keep a rolling window of data, often around one year, to support active threat detection and investigation of recent events.
That operational window is valuable, but it is not the same thing as six-year compliance retention. When your IT provider tells you "we have monitoring," the right follow-up questions are how long the underlying data is kept, and whether it covers every system that touches patient information. Some platforms offer extended retention tiers; others require exporting logs to a separate protected archive. Either approach can work. What matters is that the data exists for the full period, is protected from tampering or deletion, can actually be searched when needed, and is documented in your HIPAA program.
What a Complete Approach Looks Like
At minimum, a practice's audit-log program should:
Capture activity from the EHR, identity and sign-in systems, endpoints, Microsoft 365, and any other platform that processes patient information.
Produce a regular, dated record showing that activity was reviewed, including in periods when nothing was found.
Document every security incident from detection through resolution.
Retain review records and incident records for six years.
Retain raw log data for six years, or document the practice's decision not to in its risk analysis.
Describe all of the above in the practice's written Security Rule policies.
Onsite Technical Services implements, operates, monitors, and documents the technical safeguards that support a practice's HIPAA program. The practice remains responsible for its overall compliance program.
For HIPAA clients, OTS retains the monthly monitoring review records and security incident records for six years as part of the managed program. Six-year retention of the raw log data is offered as a separate line item, sized to the practice's devices and users, because that obligation belongs to the practice and its cost scales with the environment. Practices that choose not to retain raw logs for the full period document that decision as an accepted risk in their risk analysis. Either way, the practice's documentation states exactly what is retained and for how long.
Questions Every Practice Administrator Should Ask Their IT Provider
Which systems are generating audit logs? Your EHR vendor may keep its own audit trail. That does not mean your sign-in activity, Microsoft 365 activity, and endpoint events are also being captured.
How do you prove the logs were actually reviewed? Ask to see the record of review, and ask what it looks like for a month when nothing was found. If the answer is "we'd have told you if something came up," there is no review record.
How are incidents documented and closed? Every flagged incident should have a record showing what was done and when it was resolved.
How long is the raw log data kept, and where? Get a specific number. "We have logging" is not the same as "we retain six years of searchable, tamper-protected data."
How is the retained data protected? Logs that a ransomware attack or a departing employee could delete are not a reliable record.
If we discovered a breach that started more than a year ago, what could we reconstruct? This question tests whether your provider understands the difference between operational monitoring and long-term retention.
Is all of this written into our HIPAA program? Your Security Rule policies should describe how activity is reviewed, how incidents are documented, and how long each type of record is kept.
How This Connects to the Rest of Your HIPAA Program
Audit-log retention is one piece of the technical safeguards HIPAA requires. Access controls, encryption, automatic logoff, and integrity controls all generate their own records and feed the same audit trail. Think of it like a security camera system. Live monitoring catches problems as they happen, a log of who reviewed the footage proves someone was watching, and the stored footage is what lets you reconstruct an event long after the fact. A practice needs all three.
For Phoenix-area medical practices working with Onsite Technical Services under a managed IT engagement, Business Technology Reviews (BTRs) are included as part of the standard recurring program, not billed separately. Those reviews are an opportunity to confirm that monitoring coverage, review records, incident documentation, and retention settings still match what your HIPAA program requires as systems and staff change.
The planning benchmark for properly managed medical practice IT in the Phoenix area, including the technical safeguards layer, is approximately $200 to $250 per user per month. This is planning guidance, not a quote. The right figure for your practice depends on your size, systems, and scope.
Summary: The Three Layers at a Glance
| Layer | What it is | Why it matters | Retention |
|---|---|---|---|
| Review records | Periodic reports showing activity was monitored and reviewed | Proves the required activity review actually happened | Six years (required documentation) |
| Incident records | Documentation of each incident from detection to resolution | Proves incidents were handled, not just noticed | Six years (required documentation) |
| Raw log data | The underlying activity records from all ePHI systems | Only evidence that can reconstruct a breach, including undetected ones | Six years recommended; any shorter period documented as an accepted risk |
Frequently Asked Questions
Does HIPAA specifically require six years of audit-log retention?
Not in so many words. HIPAA requires six-year retention of security documentation, including records of required activities such as system activity review and incident handling (45 CFR 164.316(b)(2)). The rule does not assign a separate retention period to raw log data. Keeping raw logs for six years is the prevailing interpretation because they are the evidence behind those required activities. They are also the only way to meet the practice's burden of proof in a breach investigation.
If we keep six years of logs, are we covered?
Not by itself. Stored logs show you kept data; they do not show anyone reviewed it. HIPAA requires regular review of system activity, so you also need a dated record of each review, plus documentation of any incidents and how they were resolved.
Is my EHR's built-in audit trail enough?
It is an important piece, but it rarely covers everything. Sign-in activity across your network and Microsoft 365, endpoint security events, and configuration changes can all be relevant to an investigation. A complete approach captures activity from every system that touches patient information.
What happens if we can't produce logs during a breach investigation?
Because a breach is presumed reportable unless the practice can show a low probability of compromise, missing logs usually mean the practice cannot make that showing. The practical result is often notifying every patient whose information could have been exposed. The gap in documentation can also count against the practice in an OCR review.
How does log retention differ from our backups?
Backups let you restore systems and data after an incident. Log retention lets you reconstruct what happened to patient data. A restored backup does not bring back the activity history from before the incident unless that history was being retained separately. Both are required, and they serve different purposes.
Does Arizona law change any of this?
Arizona has its own retention rule for patient medical records (A.R.S. 12-2297). Adult records must be kept at least six years after the patient's last date of service. A minor's records must be kept until the later of three years after the patient turns 18 or six years after the last date of service. Source data such as lab results and diagnostic images must be kept six years from the date collected. These rules cover the clinical record itself, not security logs. Your practice needs to meet both the state and HIPAA requirements, and they should not be confused with each other.

