Lyniate Team

Audit Logging: A Requirement for Interface Engines

March 11, 2015

Audit logging has long been a required functionality for EHRs. As clinicians have broad access to patient medical records stored in the EHR, it is critical for providers to have privacy and security tools in place that can monitor the unnecessary perusing of patient records.

Recently it was reported that an employee of University Hospitals improperly accessed medical and personal information of 692 patients over a three-year period. Thus, the need for improved audit logging controls continues.

Backend applications historically have gotten a get-out-of-jail free card with regards to audit logging. The perception is that the software is kept secure to data room servers, where access is limited to IT personnel only. These IT personnel are trusted individuals who have administrative rights to roam among sensitive data regardless. However, modern integration engines provide features and functionality which break outside the secured IT datacenter.

Integration engines now extend into departments, allowing technicians to view, monitor, and debug message flow themselves. This empowers departments with the necessary tools to get data flowing again during interruptions, without being so dependent on the interface team. But, this now exposes message PHI outside the security of the IT professionals who traditionally manage and debug the interfaces. This departmental access makes it critical that an integration engine incorporates the same audit logging capabilities as an EHR into the product.

Tracking of any PHI exposure is critical. Meaningful Use sets the standard for the functionality that must be included in an Audit Logging solution. Key audit logging requirements include:

>The ability to log events such as:

  • Additions
  • Deletions
  • Changes
  • Queries
  • Printing
  • Copying

>The ability to log pertinent data such as:

  • Date and time of event
  • Patient identification
  • User identification
  • Type of action (from the list above)
  • Identification of data (such as labs, demographic, etc.)

>Having audit logging on by default

>Administrator maintains privileges to turn off

>Tamper resistant data storage

>Ability to generate reports

Corepoint Integration Engine has modeled its audit logging requirements after the Meaningful Use definitions, and has passed the criteria for the 2014 Edition for EHR technologies. Visit our Take a Tour page to learn more about the latest features available in Corepoint Integration Engine that are helping customers of all sizes exchange data, scale smarter, and improve patient care.

Related Blogs

How State HIEs Are Advancing Interoperability

Abigael Grippe

How State HIEs Are Advancing Interoperability

Read more

Abigael Grippe

TEFCA: Everything Healthcare Organizations Need to Know

Read more
Lyniate_Rapid_illustration_api_gateway_manager (1)

Lyniate Team

Lyniate introduces Rapid, a healthcare API gateway

Rapid is a healthcare API gateway and manager designed to help health teams create and safeguard APIs, including Fast Healthcare Interoperability Resources (FHIR)-based APIs like those required by the CMS Interoperability and Patient Access Rule.

Read more