How to Perform a HIPAA Audit of OB Ultrasound Portal Proxy Access Controls

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Perform a HIPAA Audit of OB Ultrasound Portal Proxy Access Controls

Kevin Henry

HIPAA

June 30, 2026

9 minutes read
Share this article
How to Perform a HIPAA Audit of OB Ultrasound Portal Proxy Access Controls

Auditing proxy access in an OB ultrasound portal demands a focused review of how your system identifies users, limits what proxies can see and do, and records every action against the correct patient. This guide walks you step by step through the audit, ensuring ePHI access restrictions, audit trail integrity, and the minimum necessary standard are consistently enforced.

Use this as a practical playbook: confirm policies, test controls in the live workflow, and gather objective evidence. You will exit the audit with clear findings, prioritized risks, and actionable remediation items tied to HIPAA’s access control and auditing expectations.

HIPAA Access Control Requirements

Audit objectives and scope

Define the audit’s scope around the OB ultrasound portal and any integrated services that store or render images, reports, or messages. Include mobile apps, web portals, APIs, identity providers, and downstream storage used for ultrasound images and visit summaries.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Required safeguards to verify

  • Unique user identification for patients, proxies, and workforce users; no shared credentials.
  • Person or entity authentication and strong proofing for proxy identity verification.
  • Role- and attribute-based controls that enforce the minimum necessary standard.
  • Automatic logoff and session timeout policies appropriate to risk.
  • Audit controls capturing read, create, update, download, share, revoke, and admin actions.
  • Emergency access (“break-glass accounts”) with strict justification, time limits, and after-action review.

Evidence to collect

  • Access control and proxy policies, consent forms, and standard operating procedures.
  • Role matrices and permission catalogs for patients, proxies, clinicians, and administrators.
  • Configuration exports for MFA, session timeout policies, and access revocation procedures.
  • Sample audit logs demonstrating user ID, patient ID, event type, timestamp, and outcome.
  • Screenshots or recordings of end-to-end proxy enrollment, use, and revocation.
  • Training records, monitoring reports, and incident or break-glass review documentation.

Success criteria

  • Proxies can only access the specific patient’s OB content and actions authorized by the patient.
  • All proxy events are traceable to a unique identity and linked to the correct patient chart.
  • Audit trail integrity is tamper-evident, time-synchronized, retained, and regularly reviewed.
  • Emergency access is rare, justified, time-bounded, and followed by documented review.

Unique User Identification

What to verify

  • Every proxy is issued a distinct account; no shared family logins or staff “generic” accounts.
  • MFA is enforced for proxies and admins; identity proofing binds the proxy to a verified real person.
  • User IDs propagate consistently into logs, messages, imaging viewers, and API calls.
  • Identifiers tie each action to a single patient record to prevent cross-chart exposure.

Test procedures

  • Attempt to enroll two proxies with the same email or phone; confirm the system blocks duplicates.
  • Log in as a proxy, view an ultrasound image, then verify the audit event includes the proxy’s unique ID, patient MRN, object ID, timestamp, and outcome.
  • Disable MFA for a test proxy and confirm access is denied or escalates to step-up authentication.
  • Review session timeout policies by measuring idle timeouts on web and mobile sessions.

Common gaps

  • Shared household credentials masking who actually viewed images or results.
  • Proxy-to-patient linkage missing from downstream audit records, breaking traceability.
  • Inconsistent timeouts between web and mobile, creating avoidable exposure windows.

Proxy Access Controls

Onboarding and proxy identity verification

  • Collect explicit patient authorization for proxy access and verify the proxy’s identity via reliable documents or trusted identity proofing steps.
  • Record the relationship type (partner, intended parent, caregiver) and any limits set by the patient.
  • Provide clear terms of use that describe responsibilities, acceptable use, and revocation rights.

Authorization scope and ePHI access restrictions

  • Apply the minimum necessary standard to ultrasound images, reports, messages, and appointments.
  • Limit proxies to read-only access by default; require explicit authorization for messaging or downloads.
  • Use attribute-based rules (e.g., pregnancy episode dates) to confine what the proxy can see.
  • Hide sensitive elements if requested (e.g., fetal sex) and document the segmentation logic.

Access revocation procedures and lifecycle

  • Offer patient-controlled revocation in the portal and an assisted process via support staff.
  • Trigger automatic access review upon key events (relationship changes, postpartum, or age-of-majority transitions).
  • Ensure revocation propagates immediately to imaging viewers, APIs, and mobile tokens.
  • Log revocation with who requested it, who executed it, and effective timestamp.

Session timeout policies and device management

  • Set idle and absolute session timeout policies calibrated to risk; shorten on shared devices.
  • Invalidate tokens on logout and revocation; require re-authentication for high-risk actions.
  • Detect concurrent logins from unusual locations and block or force step-up authentication.

System Auditing of Proxy Access

Events that must be logged

  • Authentication: success/failure, MFA method, device, IP, geolocation approximation.
  • Authorization: access grants, changes to scope, and access revocation procedures.
  • Data actions: view, download, share, annotate, message send/receive, and image viewer launches.
  • Administrative actions: role changes, policy updates, break-glass activations.

Field-level expectations for audit trail integrity

  • Immutable event ID, event type, timestamp (with synchronized time source), and outcome.
  • Unique user ID, proxy/patient linkage, role at the time of action, and session ID.
  • Object identifiers (study UID, image ID, report ID), action channel (web/mobile/API), and IP/device fingerprint.
  • Cryptographic hashing or append-only storage to make tampering detectable.

Sample test cases

  • Proxy views a prenatal ultrasound series; confirm separate events per image or viewer session with correct patient linkage.
  • Proxy downloads a report; verify a distinct “download” event and that read vs. download are not conflated.
  • Revoke proxy access, then attempt re-entry; ensure a “denied” event is recorded with reason “revoked.”
  • Modify proxy permissions; confirm before/after permissions are captured with the admin’s identity.
  • Correlate portal events with backend storage logs to prove end-to-end traceability.

Audit Logging and Monitoring

Retention and protection

  • Retain logs according to policy and legal requirements; store in write-once or append-only locations.
  • Encrypt logs at rest and in transit; restrict access by role and purpose.
  • Synchronize clocks across systems to preserve event order and audit trail integrity.

Operational monitoring

  • Feed logs to a SIEM and alert on anomalies: mass downloads, off-hours spikes, repeated denials, or unusual geolocation changes.
  • Flag any use of break-glass accounts for immediate review and patient notification as policy dictates.
  • Run daily sampling of proxy sessions to confirm proper linkage to the intended patient chart.

Metrics and reporting

  • Number of active proxies per patient and per episode of care; percentage with MFA enabled.
  • Time to fulfill access revocation procedures and to remove orphaned tokens.
  • Counts of denied events, downloads, and message sends by role and timeframe.
  • Volume and outcomes of identity proofing attempts for proxy identity verification.

Role-Based Access Control

Define roles and permissions

  • Patient: full access to own records; can grant or revoke proxy access.
  • Proxy (default): read-only access to a defined episode, limited messaging if authorized.
  • Clinician/sonographer: access limited to assigned patients and duties.
  • Administrator: configuration only; no patient data unless explicitly required.
  • Break-glass accounts: emergency-only with automatic expiration and mandatory justification.

Minimum necessary standard in practice

  • Start with least privilege; expand only with explicit, time-bound justification.
  • Segment high-sensitivity data and require extra consent or step-up authentication to view.
  • Use deny-by-default rules for actions like downloads, sharing, or message attachments.

Periodic access reviews

  • Quarterly recertification for all proxies and admins; remove dormant or unnecessary access.
  • Report on role drift, permission creep, and exceptions granted outside standard workflows.
  • Test role boundaries by attempting actions outside the assigned scope and confirming denial.

Emergency Access Procedures

Break-glass accounts and controls

  • Define when emergency access is permissible (immediate safety risk, life-threatening scenarios).
  • Require entry of a clinical justification and case number before access is granted.
  • Limit the scope and time; auto-expire access and force re-authentication frequently.
  • Generate real-time alerts to compliance and audit the session in near real time.

Testing emergency workflows

  • Conduct tabletop and live simulations in the OB setting (e.g., emergent fetal distress).
  • Verify that emergency access never creates persistent or proxy-like privileges afterward.
  • Ensure all actions are logged distinctly as emergency events for focused review.

After-action review and remediation

  • Within a defined window, review the break-glass session, confirm necessity, and document outcomes.
  • Identify any data accessed beyond the minimum necessary standard and address control gaps.
  • Incorporate lessons learned into training, configuration changes, and monitoring rules.

Conclusion

By validating unique identification, tightening proxy access controls, capturing high-fidelity audit events, monitoring continuously, enforcing role-based least privilege, and governing break-glass accounts, you create a defensible posture. Your OB ultrasound portal will reliably honor ePHI access restrictions, protect audit trail integrity, and operationalize HIPAA’s access control principles without slowing clinical care.

FAQs

What are the key requirements for proxy access under HIPAA?

You must uniquely identify the proxy, authenticate them strongly, document patient authorization, and restrict the proxy’s permissions to the minimum necessary standard. All proxy actions must be logged with user and patient linkage, subject to session timeout policies, and revocable on demand. If emergency access is ever used, break-glass accounts must be time-bound, justified, and reviewed promptly.

How should proxy access be audited in OB ultrasound portals?

Scope the audit around enrollment, use, and revocation. Collect policies and role matrices; test identity proofing; review ePHI access restrictions in the imaging viewer; and examine logs for view, download, and message events. Verify audit trail integrity with synchronized timestamps, immutable storage, and end-to-end correlation from the portal to backend imaging systems.

What procedures ensure compliance with HIPAA access control rules?

Establish clear proxy onboarding and consent steps, enforce MFA, implement role-based access with least privilege, and configure session timeout policies. Operate a monitoring program with SIEM alerts, periodic access reviews, documented access revocation procedures, and a formal break-glass process that includes immediate notification and after-action review.

How is user identity verified for proxy access?

Use multi-layered proxy identity verification: capture government-issued ID or equivalent evidence, match demographic details, require multifactor authentication, and bind the verified identity to the patient-designated relationship. Log every enrollment step, store consent records, and deny access until verification is complete or risk-based proofing is satisfied.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles