Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/Healthcare

Healthcare · HIPAA & HITECH

HIPAA does not ask you to keep logs.
It asks you to review them.

§164.308(a)(1)(ii)(D) requires procedures to regularly review records of system activity. It is a required implementation specification, not an addressable one. A log retention policy does not satisfy it, because a policy cannot review anything.

The gap

Three problems a binder does not solve

Nobody is reading the logs

Most covered entities and business associates below enterprise scale have log collection and no log review. The SIEM fires, the alerts accumulate, and the review procedure exists as a Word document with a revision date on it.

The breach clock starts before you notice

HITECH notification timelines run from discovery. An alert that sits untriaged for six days is six days of exposure you will have to account for in a 60-day notification window and, later, in an OCR inquiry.

You cannot prove the review happened

Even where review is genuinely occurring, the evidence is usually a person's recollection. What an investigator wants is a dated record showing what was looked at, what was concluded, and by whom.

The mechanism

The review happens. The proof comes with it.

Intruex reviews every alert your detection stack produces (every severity, every time) and writes a dated disposition with reasoning and a confidence value. The evidence of review is not a separate compliance artifact you have to assemble at audit time. It is the by-product of the review actually happening.

When an investigator asks what you did about the 3 a.m. access to the records system on the fourteenth, the answer is a record, not a recollection.

RequirementWhat Intruex performs
§164.308(a)(1)(ii)(D)
Information system activity review
Every alert triaged, dispositioned and dated, with written reasoning retained
§164.308(a)(6)
Security incident procedures
Escalation with a full investigation record and an approval-gated response path
§164.312(b)
Audit controls
Status history on every alert with actor, timestamp and note
§164.308(a)(8)
Evaluation
Control mapping and dashboards that show coverage rather than asserting it

Intruex is a security operations platform, not legal counsel. Mapping shows where our activity supports a control; your compliance program still owns the assessment.

If you have no SOC

We stand the detections up first

A behavioral health group, a regional practice network or a mid-size business associate frequently has an EHR, an endpoint agent and a Microsoft tenant, and nobody watching any of it.

So we build the detection layer first, as an engagement, and then run the platform on top of it. Vendors selling analyst hours saved have nothing to offer an organization with no analysts. We can start from zero.

Where PHI lives

Deployment matters more here than anywhere

Intruex receives alerts, not records. But alert metadata can carry identifiers, and your risk analysis has to account for where that metadata goes.

  • Intruex-hosted, under a business associate agreement
  • Inside your own cloud account, where the data never leaves your boundary
  • On-premises, where there is no outbound call to account for at all
Compare the tiers

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.