Skip to main content
Health-tech applications handling Protected Health Information (PHI) must maintain detailed access logs under HIPAA. Immutable provides the tamper-evident audit trail, IP geolocation tracking, alert rules for suspicious access, and long-term retention that HIPAA compliance demands.

Multi-Clinic Setup with Tenant Isolation

Use tenant_id to isolate events by clinic or healthcare organization. Each clinic’s staff only sees their own audit trail.

Tracking PHI Access Events

Patient Record Viewed

Never store actual PHI (patient names, SSNs, diagnoses) in audit log metadata. Use opaque identifiers like MRN numbers and record IDs. The audit log tracks who accessed what, not the PHI content itself.

Prescription Created

Lab Results Accessed and Record Exported

IP Geolocation Tracking

Immutable automatically enriches every event with IP geolocation data. This is critical for healthcare compliance — you can detect when PHI is accessed from unexpected locations. Every event response includes:
Use this data to investigate access patterns and feed into alert rules.

Alert Rules for Suspicious Access

Off-Hours Access Alert

Detect when patient records are accessed outside of clinic hours:

New Country Login Alert

Detect when a staff member accesses the system from an unfamiliar country:
HIPAA requires that you investigate and document all suspicious access incidents. Configure alert rules to notify your compliance officer immediately when off-hours or foreign-location access is detected.

Retention Settings for HIPAA

HIPAA requires covered entities to retain audit logs for a minimum of 6 years. Immutable’s Enterprise plan provides unlimited retention.
For HIPAA compliance, you need the Enterprise plan with unlimited retention configured to at least 7 years (the most conservative interpretation of HIPAA’s 6-year requirement). Contact support to configure your retention policy.

Querying Access History for Audits

When a HIPAA audit or breach investigation requires you to produce all access records for a specific patient:

What’s Next

Geolocation

Learn how IP geolocation enrichment works.

Alert Rules

Configure alerts for off-hours and new country access.

Retention

Configure retention policies for long-term compliance.

Suspicious Login Detection

Full guide to detecting suspicious access patterns.