The HIPAA Security Rule requires healthcare organizations to “Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.” (Section 164.312). This rule poses a significant challenge for healthcare organizations, especially for those that rely on legacy systems. Unlike network devices and infrastructure systems, there is typically no application access logging mechanism in these systems. Developing such a mechanism, involves tremendous effort, since thousands of the organization’s programs need to be changed. In some cases there are mechanisms in place that track changes in the corporate databases, yet this method is insufficient, since it tracks only “update” actions performed in the database, but does not cover “read” or access actions.

