Laserfiche WebLink
Workforce Members <br />Security Reminders <br />(addressable) <br />Protection from Malicious <br />Software <br />(addressable) <br />Log -in Monitoring <br />(addressable) <br />Password Management <br />(addressable) <br />References: <br />45 C.F.R. § 164.308(a)(5)(i). <br />Definition of "security incident" <br />City of Ramsey HIPAA Security Policy <br />Security and Awareness Training <br />[Administrative Safeguard] <br />Standard <br />The Health Plan shall implement a security awareness and training program for all new and existing <br />members of its workforce (including management). In addition, periodic re- training should be conducted <br />when operational, environmental, or other key factors change and such change impacts the security of <br />ePHI. <br />Interpretation and Implementation Specifications <br />1. An employee /workforce member, for the purposes of <br />this policy, means any employee, trainee, volunteer, , or <br />any other person(s) whose conduct, in the performance <br />of work for the Health Plan, is under the direct <br />control /supervision of the Health Plan, regardless of <br />payment source. <br />2. The Health Plan shall conduct periodic security updates. <br />3. The Health Plan shall establish procedures for guarding <br />against, detecting, and reporting malicious software. <br />4. The Health Plan shall establish procedures for <br />monitoring log -in attempts and reporting discrepancies. <br />5. The Health Plan shall establish procedures for creating, <br />changing, and safeguarding passwords. <br />Security Incident Procedures <br />[Administrative Safeguard] <br />Standard <br />The Health Plan shall implement policies and procedures to address "security incidents," including how to <br />identify security incidents and require reporting of such a security incident to the appropriate person(s). <br />Interpretation and Implementation Specifications <br />1. The attempted or successful unauthorized access, use, <br />disclosure, modification, or destruction of information or <br />interference with system operations in an inform ation <br />system. <br />Response and Reporting 2. The Health Plan shall identify and respond to suspected <br />(addressable) or known security incidents; mitigate to the extent <br />