Search code examples
databaseloggingcontent-management-systembackendhipaa

Website back end users activity log and HIPAA compliance


Can someone inform me as to what is the required length of time I should keep website user activity logs in a DB to meet HIPAA compliance?

Thanks


Solution

  • Disclaimer: I am not a lawyer and I second Josh Berke's comment.

    Six months is generally what I've heard discussed as a minimum, but when it comes to HIPAA compliance there is no such thing as being too safe. If there's no technical limitation, retain audit trails for as long as you can.