The Clause Everyone Has and Almost Nobody Meets

Every covered entity in the country has the same requirement sitting in its HIPAA obligations, and almost every small practice quietly fails it.

45 CFR §164.308(a)(1)(ii)(D) — “Information System Activity Review” — requires you to “implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.” It is not addressable. It is a required implementation specification of the Security Management Process, the very first standard in the Security Rule’s administrative safeguards. Its companion, §164.312(b), requires the technical half: mechanisms that record and examine activity in information systems containing electronic PHI.

Notice the verbs. Not generate logs. Not retain logs. Review them, regularly, as an implemented procedure.

Now ask the honest question for a practice of your size: who, by name, reviewed your EHR access logs last week? What did they find? Where is that written down?

If those questions produce silence, you are not unusual. You are typical — and the requirement has been in force since the Security Rule’s compliance date in 2005.

Why This Matters More in Behavioral Health

All PHI is sensitive. Behavioral health records are in a different category, and everyone who works in the field knows it intuitively even if the compliance documents flatten the distinction.

A therapy note is not a cholesterol panel. It can contain a patient’s diagnoses, their marriage, their children, their substance use, their employer, their trauma history, and their darkest disclosures — recorded in a clinician’s own words, in a document the patient will never read. Patients come to behavioral health providers on an explicit promise of confidentiality; a substantial number would not come at all without it, and the willingness to disclose is not incidental to the treatment. It is the treatment.

A breach of those records does not create only regulatory exposure. It breaks the clinical foundation of the practice. And recent years have furnished brutal examples of exactly what happens when this data reaches criminals: breached therapy records used not to commit financial fraud but to extort patients directly — contacting people individually and threatening to publish their sessions. That is a category of harm with no analogue in a dermatology practice.

That sensitivity cuts two ways under the Security Rule. First, the risk to individuals is higher, and the Rule’s flexibility standard asks what safeguards are “reasonable and appropriate” given the risks to ePHI — which means the bar for a practice holding psychotherapy content is effectively higher than for one holding scheduling data, not lower because the practice is small.

Second, the insider dimension is sharper. Behavioral health practices are often embedded in communities: patients are neighbors, colleagues, the children of staff members’ friends. The temptation to look is real, and inappropriate access by authorized users is among the most common categories of PHI violation. No firewall addresses it. No encryption addresses it. Activity review is the control that finds it — which is precisely why the Rule makes it required rather than addressable.

What OCR Finds When It Investigates a Small Practice

  • No current risk analysis — §164.308(a)(1)(ii)(A), the single most frequently cited failure in enforcement actions.
  • No information system activity review — audit logs that existed but were never examined by anyone.
  • No documented security incident procedures — §164.308(a)(6), or procedures that were written and never operated.
  • Access that was never right-sized — staff with permissions well beyond their role, invisible because nobody reviewed who was looking at what.
  • The logs’ only function: establishing, in the investigator’s timeline, exactly how long the intrusion went unnoticed.

When the Office for Civil Rights investigates a breach — and a breach affecting 500 or more individuals brings notification to affected individuals and HHS within 60 days, media notice, public listing on the HHS breach portal, and near-certain investigation — that cluster of findings is what recurs. The pattern is consistent enough to plan around: enforcement rarely turns on exotic technical failures. It turns on the basics that were documented as policy and never performed as practice.

The Small-Practice Reality

None of this failure comes from indifference. It comes from structure.

A behavioral health practice with three to fifteen clinicians typically has no IT staff at all. An outside vendor manages the EHR, the workstations, maybe the email tenant. That vendor keeps systems running; nobody has hired anyone to keep them watched, and the difference between those two jobs is invisible until an incident makes it obvious. The practice manager who nominally owns compliance already carries scheduling, billing, credentialing, insurance verification, and the phone.

Meanwhile the practice’s actual attack surface looks like everyone else’s, because it is built from the same components:

The events that precede a PHI breach are entirely ordinary in appearance: a login from an unfamiliar location, a mailbox forwarding rule created at midnight, malware on the front-desk machine, credentials being tested against your accounts overnight, a clinician account accessing forty charts in an hour on a day they saw six patients. All of it lands in logs nobody reads.

Hiring even one security analyst is unthinkable at this scale, and genuine around-the-clock coverage would take several. This is the gap between what the Security Rule requires and what a small practice can staff — and it has stood, essentially unaddressed, since the Rule took effect.

Do Not Wait for the Rule to Change

There is a common assumption worth correcting directly. HHS published a proposed overhaul of the Security Rule in January 2025 that would substantially tighten monitoring, audit, and incident response expectations — and many practices have treated it as a future problem to plan against.

That proposal is not final. It drew thousands of comments and organized opposition from major provider organizations, and HHS has moved it to its long-term regulatory agenda with final action currently anticipated in 2027, which is a date that has already slipped once and could slip again.

The practical implication is the opposite of relief. The obligation that binds you today is not the proposed rule. It is §164.308(a)(1)(ii)(D), which has been required for twenty years, and which OCR enforces now. Waiting for the update means waiting to comply with something you were already required to do — and the enforcement risk in the meantime is entirely unchanged.

What “Regularly Review” Actually Looks Like

The Rule does not prescribe a frequency, which is where most practices get lost. It requires procedures appropriate to your risk — and the honest translation for a practice holding psychotherapy notes and running cloud email is that a quarterly skim of a log file is not proportionate to the risk profile.

The activity that matters falls into recognizable categories:

Every one of these produces a log entry in systems most practices already run. The requirement is not to buy more sensing. It is to have someone examine what the sensing already produces — and to write down that it happened.

What Intruex Does About It

Intruex is an AI security operations platform: a coordinated team of specialist AI analysts that connects to the systems you already run — leading endpoint and cloud platforms, or nearly any log source via a standards-based interface — and investigates every security alert your environment produces, continuously.

Mapped to your obligations:

What to Do This Month

Confidentiality Is the Product

Behavioral health practices sell exactly one thing before any clinical modality: a safe place to say true things. Everything else in the practice — the training, the modality, the therapeutic alliance — is downstream of a patient’s belief that what they say in that room stays in that room.

The Security Rule’s log-review requirement, read generously, is just that promise translated into operations: someone is making sure no one else is listening.

For twenty years, small practices could not afford to keep that part of the promise properly. The requirement was real, the intent was there, and the staffing model to satisfy it simply did not exist below a certain size. That is what has changed. It is a subscription now, not a security department.

The Core Question

If a staff member opened the chart of a neighbor they are not treating — or a clinician’s credentials were used from an unfamiliar country at 3 a.m. to read forty therapy notes — how would your practice find out, and how long would it take? If the honest answer is “the patient would have to tell us,” then §164.308(a)(1)(ii)(D) is documented in your policies and absent from your operations, which is exactly the finding OCR writes.

Sources: 45 CFR §164.308(a)(1)(ii)(D) (Information System Activity Review, a required implementation specification), §164.312(b) (Audit Controls), and §164.308(a)(6) (Security Incident Procedures). HIPAA Breach Notification Rule, 45 CFR §§164.400-414 (60-day notification and the 500-individual threshold). HHS proposed Security Rule modifications published January 6, 2025; as of publication the rulemaking remains non-final and has been moved to the agency’s long-term agenda with final action currently anticipated in 2027. This article is informational and is not legal or compliance advice.