• Magazine
    • Current Issue
    • Past Issues
    • Subscribe
    • Change Mailing Address
    • Surveys
    • Guidelines for Authors
    • Editorial Calendar and Deadlines
    • Dynamic Chiropractic
      • Newspaper
      • Subscription
    • The American Chiropractor
      • Magazine
  • Practice
    • Business Tips
    • Chiropractic Schools
    • Clinical & Technique
    • Ebooks
    • Ecourses
    • Sponsored Content
    • Infographics
    • Quizzes
    • Wellness & Nutrition
    • Podcast
  • Content Hubs
  • Products & Services
    • View Products & Services Directory
    • Browse Buyers Guide
    • Submit a Product
    • Vendor Login
  • Datebook
    • View Events
    • Post an Event
    • Become an Events Poster
  • Advertise
    • Advertising Information
    • Media Kit
    • Contact Us

Your Online Practice Partner

Chiropractic Economics
Your Online Practice Partner
Advertise Subscribe
  • Home
  • News
  • Webinars
  • Chiropractic Research
  • Students/New DCs

Audit trails, audit controls, and security within the chiropractic practice

Chiropractic Economics Staff August 11, 2014

494146877by Dava Stewart

In the last few years, there has been a great amount of discussion about electronic health records (EHR), patient privacy, security, and the rising number of times chiropractic practices are audited. With all of that in mind, the phrase “audit trails” may seem like something that would come from the Office of the Inspector General (OIG). But, in fact, audit trails have more to do with how software, EHR and other types of systems, are constructed.

Audit trails are simply logs that show who accessed an information system, when, and what operations were performed. This means that audit trails are a form of access management. The information within audit trails is not particularly useful alone — context is required. When multiple audit trails are used to trace and examine system activity, audit controls are being employed.1

Audit controls are useful for demonstrating that a practice is HIPAA compliant. Further, regular security audits of those controls are necessary. According to the American Health Information Association (AHIMA):

“The HIPAA security rule includes two provisions that require organizations to perform security audits:

Section 164.308(a)(1)(ii)(c), Information system activity review (required), which states organizations must “implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.”

Section 164.312(1)(b), Audit controls (required), which states organizations must “implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.”2

In addition, the 2009 Health Information Technology for Economic and Clinical Health (HITECH) part of the American Reinvestment and Recovery Act included provisions that require organizations that handle patient health information (PHI) to actively monitor for security breaches, making regular examination of audit trails and controls through security audits even more important.2

A compliance audit is likely to examine the existence of audit trails and controls, as well as the records related to monitoring for security breaches. Certified EHR systems have built in audit trails and controls, so a practice using a certified system has both audit trails and audit controls in place already. Third party organizations can be hired to conduct audits to make sure that PHI is secure. A practice that uses a certified EHR system and undergoes regular security audits is well-positioned should they be audited by the OIG.

Beyond compliance, audit trails, audit controls, and security audits can be employed to demonstrate meaningful use (MU) of EHR systems for practices that are working to receive stimulus dollars through the implementation and use of an EHR system. The stage one requirements for MU include that system actions be recorded and that an audit log can be created for a specific time period.2

As the entire healthcare system in the U.S. moves toward digitization, chiropractic offices must keep up. It is impossible to show a log of who opened a paper file. Evaluating, purchasing, and most importantly, fully implementing, a certified EHR system brings a practice much closer to full HIPAA compliance. Taking the extra step of hiring a third party to perform regular security audits provides an additional layer of protection in the case of a compliance audit by state or federal regulatory bodies.

References:

1Nunn, S. “Managing Audit Trails Journal of AHIMA 80, no.9 (September 2009): 44-45.

2AHIMA. “Security Audits of Electronic Health Information (Updated).” Journal of AHIMA 82, no.3 (March 2011): 46-50.

Filed Under: Practice Management Software, Resource Center

Current Issue

Issue 8 2026 Chiropractic Economics

Get Exclusive Content! Join our email list

Sign Up

Thank you for subscribing!

Follow Us

  • Facebook
  • X (Twitter)
  • Instagram
  • LinkedIn
  • YouTube logoYouTube logoYouTube

Compare Subscriptions

Dynamic Chiropractic

The American Chiropractor

8430 Enterprise Circle, Suite 200

Lakewood Ranch, FL 34202

Phone 800-671-9966

CONTACT US »

Privacy Policy | Terms of Service

Copyright © Chiropractic Economics, A Gallagher Company. All Rights Reserved.

SUBSCRIBE TO THE MAGAZINE

Get Chiropractic Economics magazine
delivered to your home or office. Just fill out our form to request your FREE subscription for 20 issues a year,
including two annual Buyers Guides.

SUBSCRIBE NOW »

Proud Sponsor of the Foundation for Chiropractic Progress
Issue 8 of Chiropractic Economics - The Final Issue - The Chiropractic Wellness Advantage