164.312(c)(2) Mechanism to Authenticate ePHI (Addressable)
Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner. NIST recommends hash-based or signed integrity verification.
3
artefacts
3
held by a system
0
at each review
easy
to go live
SIEM / log platform
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Hash or signature verification configuration · Cloud console / configuration management
- FIM alert investigation records · SIEM / log platform
- Audit trail of integrity events · SIEM / log platform
periodic reviewEvidence produced at each review
none for this control
governing documentDocuments that govern the control
none for this control
First move
Automate the pull from your SIEM / log platform. Retention and alert rules exported from the SIEM; review evidence is the closed-alert record with reviewer and time.
Common gaps auditors find
- No verification process defined
- Alerts triggered but unactioned
- Critical data sets excluded
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheet164.312(c)(1) Integrity (Standard) · 164.312(d) Person or Entity Authentication (Standard)