| Administrative Safeguards |
| 164.308(a)(1) |
Security Management Process |
Risk Analysis |
R |
Understand your current risk profile
- Use Lumension® Scan to scan your entire network for known vulnerabilities and prioritize for remediation
- Use Lumension® Device Control to scan all your endpoints for devices being connected and data flows off network; decide to permit / deny
- Use Lumension® Application Control to scan your entire network for all apps currently in use; decide to permit / deny
|
| Risk Management |
R |
Manage risks on / to your network
|
| Sanction Policy |
R |
N/A |
| Information System Activity Review |
R |
Monitor system activity
|
| 164.308(a)(2) |
Assigned Security Responsibility |
|
|
N/A |
| 164.308(a)(3) |
Workforce Security |
Authorization and/or Supervision |
A |
Use Lumension® Device Control to control data flows off your network, no matter where / when users are logged on
- Control at user or group level
- Can be tied to MS Active Directory or Novell eDirectory
|
| Workforce Clearance Procedure |
A |
Use Lumension® Device Control to prevent unauthorized employees from downloading / transferring data off your network |
| Termination Procedure |
A |
Use Lumension® Device Control to prevent terminated employees from downloading / transferring data off your network |
| 164.308(a)(4) |
Information Access Management |
Isolating Healthcare Clearinghouse Functions |
R |
N/A |
| |
|
Access Authorization |
A |
Prevent unauthorized access
|
| |
|
Access Establishment and Modification |
A |
Monitor / Manage access
|
| 164.308(a)(5) |
Security Awareness and Training |
Security Reminders |
A |
Provide customizable messages to end users when attempting to contravene security policy
|
| Protection from Malicious Software |
A |
Protect your network from malware
|
| Log-in Monitoring |
A |
Look beyond network logins
|
| Password Management |
A |
Use Lumension® Device Control to enforce existing or new (strong) password usage
- Implement at user or group level
- Tied to existing MS Active Directory or Novell eDirectory
|
| 164.308(a)(6) |
Security Incident Procedures |
Response and Reporting |
R |
Prevent / Report on potentially harmful incidents
|
| 164.308(a)(7) |
Contingency Plan |
Data Backup Plan |
R |
Use Lumension® Device Control to force encryption of data being taken / stored offsite to prevent unauthorized usage |
| Disaster Recovery Plan |
R |
N/A |
| Emergency Mode Operation Plan |
R |
N/A |
| Testing and Revision Procedure |
A |
N/A |
| Applications and Data Criticality Analysis |
A |
N/A |
| 164.308(a)(8) |
Evaluation |
|
|
NA |
| 164.308(b)(1) |
Business Associate Contracts and Other Arrangements |
Written Contract or Other Arrangement |
R |
Use Lumension® Device Control to force encryption of data being sent to / used by third parties to prevent unauthorized usage |
| Physical Safeguards |
| 164.310(a)(1) |
Facility Access Controls |
Contingency Operations |
A |
N/A |
| Facility Security Plan |
A |
N/A |
| Access Control and Validation Procedures |
A |
Control access based on user / machine rights and other factors
|
| Maintenance Records |
A |
N/A |
| 164.310(b) |
Workstation Use |
|
|
Based on user / machine rights and other factors, ensure proper usage
|
| 164.310(c) |
Workstation Security |
|
|
Based on user / machine rights and other factors, restrict network / machine access
|
| 164.310(d)(1) |
Device and Media Controls |
Disposal |
R |
Use Lumension® Device Control to force encryption of data being saved onto removable devices / media to prevent unauthorized usage |
| Media Reuse |
R |
Use Lumension® Device Control to track and force encryption of data being saved onto removable devices / media to prevent unauthorized usage |
| Accountability |
A |
Use Lumension® Device Control to either track filename or create full copy of data being saved onto removable devices / media |
| Data Backup and Storage |
A |
Use Lumension® Device Control to create full copy of data being saved onto removable devices / media |
| Technical Safeguards |
| 164.312(a)(1) |
Access Control |
Unique User Identification |
R |
Use Lumension® Device Control to control access to removable devices / media and applications
- Based on user / machine rights and other factors
- Based on existing MS Active Directory or Novell eDirectory structures
|
| Emergency Access Procedure |
R |
N/A |
| Automatic Logoff |
A |
N/A |
| Encryption and Decryption |
A |
Use Lumension® Device Control to force encryption of data being saved onto removable devices / media to prevent unauthorized usage |
| 164.312(b) |
Audit Controls |
|
|
Monitor system activity
|
| 164.312(c)(1) |
Integrity |
Mechanism to Authenticate Electronic Protected Health Information |
A |
Use Lumension® Device Control to force encryption of data being saved onto removable devices / media to prevent unauthorized usage |
| 164.312(d) |
Person or Entity Authentication |
|
|
Use Lumension® Device Control to control access to removable devices / media and applications
- Based on user / machine rights and other factors
- By existing MS Active Directory or Novell eDirectory structures
|
| 164.312(e)(1) |
Transmission Security |
Integrity Controls |
A |
Use Lumension® Device Control to track and force encryption of data being saved onto removable devices / media to prevent unauthorized usage |
| |
|
Encryption |
A |
Use Lumension® Device Control to force encryption of data being saved onto removable devices / media to prevent unauthorized usage |
| Policies and Procedure and Documentation Requirements |
| 164.316(a) |
Policies and Procedures |
|
|
Enforce your policies and procedures
|
| 164.316(b)(1) |
Documentation |
Time Limit |
R |
N/A |
| Availability |
R |
N/A |
| Updates |
R |
N/A |