HIPAA § 164.312(c)(2) - Mechanism to authenticate electronic protected health information

The HIPAA § 164.312(c)(2) requirement states, "Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner."

This requirement specifies monitoring files and directories containing healthcare data. The Wazuh FIM module meets this requirement by monitoring healthcare files and generating findings on modification or deletion. See the Wazuh FIM documentation for details on configuring file integrity monitoring.

Use cases: Detect file changes and deletion

The use cases in this section are performed on an Ubuntu 26.04 endpoint. Use a virtual machine or a dedicated lab environment for these use cases.

Detect file changes

In this use case, the Wazuh agent detects changes made to the patient_data.txt file in the /root/health_data directory. Perform the following steps on the Ubuntu endpoint:

  1. Create the health_data directory in the /root directory:

    # mkdir /root/health_data
    
  2. Create the file patient_data.txt in the /root/health_data directory:

    # touch /root/health_data/patient_data.txt
    
  3. Add the following configuration to the syscheck block of the Wazuh agent configuration file /var/ossec/etc/ossec.conf to monitor the /root/health_data directory for changes in real time:

    <directories realtime="yes">/root/health_data</directories>
    
  4. Restart the Wazuh agent to apply the changes:

    # systemctl restart wazuh-agent
    
  5. Write a line of test data to the file:

    # echo "User2 = medication3" > /root/health_data/patient_data.txt
    
  6. Navigate to Endpoint security > File Integrity Monitoring > Findings to see the file modification finding on the Wazuh dashboard.

    FIM file modification finding

    The finding includes differences in the file checksum, the modified file, the modification time, the mapped HIPAA requirement, and other information.

    FIM file modification finding details

Detect file deletion

In this use case, you configure the Wazuh agent to detect file deletion in a monitored directory. Perform the following steps on the Ubuntu endpoint to configure the FIM module to monitor the /root/health_records directory.

  1. Create the health_records directory in the /root directory if it is not present:

    # mkdir /root/health_records
    
  2. Create the file patient_data.txt in the /root/health_records directory:

    # touch /root/health_records/patient_data.txt
    
  3. Add the following configuration to the syscheck block of the agent configuration file /var/ossec/etc/ossec.conf to monitor the /root/health_records directory for changes in real time:

    <directories realtime="yes">/root/health_records</directories>
    
  4. Restart the Wazuh agent to apply the changes:

    # systemctl restart wazuh-agent
    
  5. Delete the patient_data.txt file from the monitored directory:

    # rm /root/health_records/patient_data.txt
    
  6. Navigate to Endpoint security > File Integrity Monitoring > Findings to see the file deletion finding on the Wazuh dashboard.

    FIM file deletion finding

    The finding also includes the file deleted, the endpoint where the file was deleted, and other details.

    FIM file deletion finding details