Activity records for the systems that hold ePHI
Review activity, watch logins and respond, and see plainly what stays with you.
Requirements
| Clause | What it asks | ARRTECH |
|---|---|---|
| 164.308(a)(1)(ii)(D) | Information system activity review. | Ready HIPAA reports. → |
| 164.308(a)(5)(ii)(C) | Log-in monitoring. | Logins and failed logins. → |
| 164.308(a)(6)(ii) | Response and reporting. | Cases and playbook history. → |
| 164.310(d)(1) | Device and media controls. | Device control. → |
| 164.312(b) | Audit controls. | Signed, chained logs. → |
Review
Review system activity in one place
Ready reports and dashboards cover HIPAA. Any saved query becomes a report, on a schedule, by email or as PDF. Classification rules put every vendor’s events in common categories.
Logins
Watch log-in attempts
The ARRTECH DLP agent records logins and failed logins on each computer. The console audit log records logins, searches and configuration changes.
Incidents
Track every incident to its close
A case carries its type, severity, assignee, SLA, MITRE tactic and kill-chain phase, sub-cases and history, and downloads as a case report. ARRTECH SOAR opens incidents from SIEM alerts and keeps an execution history of playbook runs. The Operator node emails a person with up to five options and waits.
Devices
Control devices and media
ARRTECH DLP device control allows or blocks any device class or specific device by vendor, product or serial number, per user or computer, with a manager approval option.
Audit
Prove nobody changed your logs
ARRTECH SIEM hashes and signs every write and chains each signature file to the one before, so a changed or missing file breaks the chain. Any source exports with a standalone verification tool, so your assessor checks it without your SIEM.
Limits
Know what stays with you
No ARRTECH product produces the record for these requirements.
164.312(c)(2)
Integrity of ePHI. The SIEM’s signatures cover its log records only, not the ePHI itself.
164.308(a)(1)(ii)(A)
Risk analysis. That is your organization’s own work.
164.312(a)(2)(iv)
Encryption of ePHI. ARRTECH does not claim encryption at rest in its products.
164.308(b)
A business associate agreement. Confirm the terms with us before logs hold ePHI.
By rule
Naming a clause is not a claim of certification.
164.308(a)(1)(ii)(D)
Regularly review records of information system activity, such as audit logs and access reports. ARRTECH: ready reports and dashboards cover HIPAA.
164.308(a)(5)(ii)(C)
Procedures for monitoring log-in attempts and reporting discrepancies. ARRTECH: DLP records logins and failed logins on each computer.
164.308(a)(6)(ii)
Identify and respond to security incidents and document their outcomes. ARRTECH: SIEM cases and SOAR incidents with an execution history.
164.310(d)(1)
Govern the receipt and removal of hardware and electronic media. ARRTECH: device control by class, vendor, product or serial number.
164.312(b)
Mechanisms that record and examine activity in systems that contain ePHI. ARRTECH: collection from more than 500 source types, signed and chained.
Questions
Is there a HIPAA certification?
No. HHS does not endorse or recognize private certifications, and OCR does not certify products.
Does the SIEM come under the Security Rule?
Yes, if its logs hold ePHI.
Does DLP find health data?
ARRTECH does not claim a health data classifier.
Can our assessor check the logs without ARRTECH?
Yes. Any source exports with its signatures, the SIEM certificate and a standalone verification tool.
Sources
Guide
What is the HIPAA Security Rule?
The federal rule that sets administrative, physical and technical safeguards for electronic protected health information.
What are audit controls?
Mechanisms that record and examine activity in systems that contain ePHI, under 164.312(b).
Who enforces HIPAA?
The HHS Office for Civil Rights, for covered entities and business associates.
Next steps

Spot unusual behavior early. Learns what normal looks like for every user, computer and application from your SIEM, and flags what changes.

Get the evidence fast. Investigates each finding with read-only queries and hands a person the evidence. It never approves its own work.

Prove every log. Collects and signs logs from more than 500 source types and links related events, with a verification tool for every export.

Keep sensitive data in. Checks email, uploads, USB drives and AI prompts before sensitive data leaves the computer.

Respond with a person in charge. Runs incident response steps through your existing tools, with a person approving each decision.