Most practices think about HIPAA security in terms of prevention. Firewalls, antivirus, passwords. All necessary and all incomplete, because the Security Rule also expects you to be able to see what happened.
The requirement is about records. HIPAA expects mechanisms that record and examine activity in systems containing electronic protected health information, and regular review of that activity. In plain terms: log what happens, and look at the logs.
Why this matters more than it sounds
When something goes wrong, the first question is always scope. Whose records were accessed, when, by whom, and did anything leave the building.
If you cannot answer that, the default assumption in a breach analysis is the worst case. A practice that can demonstrate exactly which twelve records were touched is in a completely different position from one that has to notify every patient because it cannot rule anything out.
That difference is the whole argument for logging. It is not about catching intruders in real time, which no small practice will do. It is about being able to bound the damage afterwards.
What a small practice actually needs
Logging turned on across your EHR, your email system, your file storage and your network devices. Most of it is already there and switched off, or on and never looked at.
Logs kept somewhere an attacker cannot delete them. Ransomware operators routinely clear local logs, which is precisely why they should not live only on the machine that generated them.
Retention long enough to be useful. Incidents are frequently discovered months after they began.
And someone actually reviewing them, at whatever cadence is realistic. Monthly and honest beats daily and imaginary.
The bit worth being careful about
If you send logs to an outside service, that service may then hold information that touches ePHI, which makes it a business associate and brings it inside your agreements and your risk analysis. That is manageable, but it needs to be a decision rather than an accident.
