Logging Strategy for Healthcare: What to Capture, What to Ignore
Log everything and you cannot afford it. Log too little and the investigation fails. Choosing sources by the question they answer, and setting retention against dwell time.
GuardsArm Team
Security Experts
Logging decisions are usually made by licensing. A SIEM is priced per gigabyte, the budget sets a ceiling, and whatever fits gets ingested. That is a procurement process, not a strategy, and it reliably produces an estate where the noisy sources are collected and the decisive ones are not.
The better question is: which sources answer the questions we will actually ask during an incident?
Rank sources by the question they answer
| Source | Question it answers | Priority |
|---|---|---|
| Authentication (success and failure) | Who accessed what, from where | Essential |
| Process creation with command line | What ran on the endpoint | Essential |
| EHR audit trail | Who viewed or changed which record | Essential, and a HIPAA requirement |
| DNS queries with client IP | What did the host try to reach | Essential |
| Firewall and network flow | Where did traffic go between segments | High |
| Email gateway | How did it get in | High |
| Privileged access and elevation | Who became an administrator | High |
| Cloud control plane | Who changed the environment | High |
| Medical device network behaviour | Did a device deviate from its baseline | High, and usually missing |
| Web proxy | Browsing, downloads, exfiltration | Medium |
| Verbose application debug | Almost nothing | Low — and usually the biggest volume |
That last row is where budget disappears. Application debug logging is enormous and rarely answers a security question.
Retention has to exceed dwell time
The most common logging failure is not coverage but retention. An intrusion discovered on day 45 cannot be investigated with 30 days of data — you can see the current activity and not the initial access, which means you cannot establish scope, and cannot say with confidence what was reached.
A workable tiering:
- Hot, searchable, 90 days — authentication, process creation, DNS, EHR audit
- Warm, 6-12 months — network flow, firewall, email
- Cold archive, 1-7 years — everything required by retention policy, restorable within days rather than seconds
- EHR audit — per HIPAA documentation retention, which is longer than any of these
Cold storage is inexpensive. The mistake is discarding rather than demoting.
The clinical sources generic guidance misses
- EHR audit trail — not merely logins but record-level access. This is both the detection source for insider misuse and a regulatory requirement.
- Interface engine — message volumes and errors; a deviation is either a clinical incident or a data movement problem.
- Medical device network behaviour — devices cannot run agents, so their network activity is the only telemetry available. See IoMT security.
- Badge and physical access — correlating a badge-in with a logon from a different site is a high-confidence signal.
- Break-glass events — low volume, high value, must be retained and reviewed.
What to do about the noise
Rather than dropping a source entirely, reduce it intelligently:
- Filter at the collector, not at the SIEM, so you pay once
- Sample high-volume, low-value events rather than discarding the category
- Summarise — counts and aggregates for sources where individual events add nothing
- Route to cold directly for anything needed for compliance but not detection
The aim is that every retained source has a named reason: a detection it supports, an investigation question it answers, or a regulation that requires it. Anything that cannot be justified that way is a candidate for the collector filter.
For tuning what you do with these once ingested, see SIEM tuning.
GuardsArm designs logging and retention strategies for healthcare, including the clinical sources most deployments omit. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


