HIPAA §164.308(a)(1)(ii)(C) requires a sanction policy and its application: appropriate sanctions against workforce members who fail to comply with your security policies and procedures. This register is the evidence that you applied it — that the policy is real rather than a document.
Each entry records the workforce member, the date of the violation, a summary of what happened, the policy that was violated, the sanction applied and the date it was applied.
Sanction types are: verbal warning, written warning, retraining, suspension, termination, and other.
Neither date can be in the future. A violation or a sanction dated ahead of today would be a record of something that hasn't happened, and an auditor reading the register can't tell that apart from a typo.
A sanction policy with an empty register invites the obvious question at audit: has anyone ever breached a policy here, and if so what did you do? Recording the minor cases — a verbal warning, retraining after a phishing test — is what makes the answer credible.
Equally, this is a disciplinary record about named people. It is not a place for detail that belongs in an HR file.
Every entry writes an audit record, and that record deliberately captures the sanction type only — never the workforce member's name. The audit log has much wider visibility inside the product than this register does, so putting names there would spread the disciplinary record beyond the people meant to see it.
Export the register as CSV for an auditor, on Professional and above. It honours whatever filter is on screen.
Org admins only, including delegated admins. Contributors and auditors are refused the register and its export — this sits with incidents, breaches and individual-rights requests as a register that names people, rather than with the controls-and-titles registers an auditor is normally given.