Back to Blog
Security Operations
9 min read

Logging Strategy for Healthcare: What to Capture, What to Ignore

Log everything and you cannot afford it. Log too little and the investigation fails. Choosing sources by the question they answer, and setting retention against dwell time.

GuardsArm Team

Security Experts

December 12, 2025

Logging strategy

Logging decisions are usually made by licensing. A SIEM is priced per gigabyte, the budget sets a ceiling, and whatever fits gets ingested. That is a procurement process, not a strategy, and it reliably produces an estate where the noisy sources are collected and the decisive ones are not.

The better question is: which sources answer the questions we will actually ask during an incident?

Volume != value
The highest-volume sources are rarely the most useful in an investigation
Retention beats breadth
Fewer sources kept longer usually beats more sources kept briefly
Clinical sources
EHR audit and device telemetry are omitted from generic guidance entirely

Rank sources by the question they answer

SourceQuestion it answersPriority
Authentication (success and failure)Who accessed what, from whereEssential
Process creation with command lineWhat ran on the endpointEssential
EHR audit trailWho viewed or changed which recordEssential, and a HIPAA requirement
DNS queries with client IPWhat did the host try to reachEssential
Firewall and network flowWhere did traffic go between segmentsHigh
Email gatewayHow did it get inHigh
Privileged access and elevationWho became an administratorHigh
Cloud control planeWho changed the environmentHigh
Medical device network behaviourDid a device deviate from its baselineHigh, and usually missing
Web proxyBrowsing, downloads, exfiltrationMedium
Verbose application debugAlmost nothingLow — and usually the biggest volume

That last row is where budget disappears. Application debug logging is enormous and rarely answers a security question.


Retention has to exceed dwell time

The most common logging failure is not coverage but retention. An intrusion discovered on day 45 cannot be investigated with 30 days of data — you can see the current activity and not the initial access, which means you cannot establish scope, and cannot say with confidence what was reached.

Why retention must exceed dwell timeAn investigation starting at discovery must reach back to initial access; retention shorter than dwell time makes scoping impossible.Initial accessday 0DwellweeksDiscoveryday 45Investigateneeds day 0 data
30-day retention against a 45-day dwell means the beginning of the incident is simply gone.

A workable tiering:

  • Hot, searchable, 90 days — authentication, process creation, DNS, EHR audit
  • Warm, 6-12 months — network flow, firewall, email
  • Cold archive, 1-7 years — everything required by retention policy, restorable within days rather than seconds
  • EHR audit — per HIPAA documentation retention, which is longer than any of these

Cold storage is inexpensive. The mistake is discarding rather than demoting.

Cheaper to keep than to wish you had
Archive storage costs a small fraction of hot SIEM ingest. Moving older data to cold rather than deleting it preserves the ability to answer the scope question, which is the one that determines your breach notification obligation.

The clinical sources generic guidance misses

  • EHR audit trail — not merely logins but record-level access. This is both the detection source for insider misuse and a regulatory requirement.
  • Interface engine — message volumes and errors; a deviation is either a clinical incident or a data movement problem.
  • Medical device network behaviour — devices cannot run agents, so their network activity is the only telemetry available. See IoMT security.
  • Badge and physical access — correlating a badge-in with a logon from a different site is a high-confidence signal.
  • Break-glass events — low volume, high value, must be retained and reviewed.

What to do about the noise

Rather than dropping a source entirely, reduce it intelligently:

  • Filter at the collector, not at the SIEM, so you pay once
  • Sample high-volume, low-value events rather than discarding the category
  • Summarise — counts and aggregates for sources where individual events add nothing
  • Route to cold directly for anything needed for compliance but not detection

The aim is that every retained source has a named reason: a detection it supports, an investigation question it answers, or a regulation that requires it. Anything that cannot be justified that way is a candidate for the collector filter.

For tuning what you do with these once ingested, see SIEM tuning.

GuardsArm designs logging and retention strategies for healthcare, including the clinical sources most deployments omit. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.