ATG HIPAA Security Rule Alerts
Alert #8
Covered Entities Must Address Malicious Software
Malicious software means software, for example, a virus or worm or Trojan horse or spyware, designed to damage or disrupt a system.
Covered Entities Must Address Malicious Software
As part of the standard on Security Awareness and Training, Covered Entities must address procedures for guarding against, detecting, and reporting malicious software. The Malicious Software implementation specification is addressable, and must therefore be implemented if, after an assessment, the entity has determined that the specification is a reasonable and appropriate safeguard in its environment. If the entity decides that the addressable implementation specification is not reasonable and appropriate, it must document that determination and implement an equivalent alternative measure, presuming that the alternative is reasonable and appropriate, or if the standard can otherwise be met, the covered entity may choose to not implement the implementation specification or any equivalent alternative measure.
It is difficult to imagine any healthcare entity that for which it did not make sense to have solutions in place for:
- Anti-Virus protection
- Anti-Spyware protection
- Security patch management
- Data backup and recovery
ATG's LiveVault online and recovery backup solutions, can provide secure, continuous, automatic backup solutions that provide exact, readily retrievable copies of EPHI with 100% guaranteed recovery.
THE LAW
Office of the Secretary
45 CFR Parts 160, 162, and 164
Health Insurance Reform: Security Standards; Final Rule 4717
Subpart C-Security Standards for the Protection of Electronic Protected Health Information
¤ 164.308 Administrative safeguards.
(a) (5)(i) Standard: Security awareness and training. Implement a security awareness and training program for all members of its workforce (including management).
(ii) Implementation specifications.
Implement:
(A) Security reminders (Addressable). Periodic security updates.
(B) Protection from malicious software (Addressable). Procedures for guarding against, detecting, and reporting malicious software
Back to ATG HIPAA Security Alerts
Office of the Secretary
45 CFR Parts 160, 162, and 164
Health Insurance Reform: Security Standards; Final Rule 4717
Subpart C-Security Standards for the Protection of Electronic Protected Health Information
¤ 164.308 Administrative safeguards.
(a) (5)(i) Standard: Security awareness and training. Implement a security awareness and training program for all members of its workforce (including management).
(ii) Implementation specifications.
Implement:
(A) Security reminders (Addressable). Periodic security updates.
(B) Protection from malicious software (Addressable). Procedures for guarding against, detecting, and reporting malicious software







