Managing and Maintaining Audit Records

In addition to system logs, Imprivata maintains a complete record of Imprivata activity in the Imprivata audit log.

In a G4 (fourth generation) Imprivata enterprise, the one or two G4 database appliances in the enterprise hold all audit data. Audit records are stored on and served from those database appliances. In a G4 enterprise, there is no longer a concept of an audit appliance. In a G3 (third generation) Imprivata enterprise, at least two G3 appliances served as audit appliances for the enterprise. Audit records were stored on and served from the audit appliances.

Audit records are uploaded from each Imprivata agent at every refresh interval that the agent is online.

The Imprivata audit log can hold millions of records. You can archive and delete audit logs as needed or schedule periodic deletions. Imprivata audit records are used to generate reports. Reports are described below.

NOTE: Imprivata retains audit information related to e-prescribing controlled substances for a minimum of two years per DEA regulations, or for longer depending on your state regulations.

To modify the amount of time for which Imprivata Enterprise Access Management MFA (formerly Confirm ID) audit records are retained, change the Preserve regulated audit records setting in the Record maintenance section of the Settings page.

In the Imprivata Admin Console, go to the gear icon > Settings. The Audit Records section includes:

  • The Manage audit records option, which allows you to view how many audit records you have (excluding regulated records related to the e-prescribing of controlled substances).

  • The Store SSO user names option. When selected, user names for SSO events are recorded in the audit logs.

  • The Record maintenance section, which allows you to archive and/or delete audit records and schedule audit log maintenance. See Maintaining Audit Records.

Audit Record Guidance

Maintaining large numbers of audit records can slow down certain operations. For example, upgrades, enterprise synchronizations, and backing up may be slowed. There are many factors that contribute to your experience, but in general:

  • Less than 5 million records — little or no slowdown
  • From 5-10 million records — possible slowdown
  • 10 million records or more — slowdown likely, consider removing audit records

This guidance assumes two database appliances in a G4 enterprise.