Direct Inward Dialing: +1 408 916 9892
Segment: Health Care / Insurance Industry
HIPAA is the acronym for Health Insurance Portability and Accountability Act of 1996. It is a federal law that has been amended to the Internal Revenue Code of 1996. It was designed to improve portability and continuity of health insurance coverage in group and individual markets.
Title–I HIPAA Compliance - HIPAA protects health insurance coverage for workers and their families when they change or lose jobs.
Title-II HIPAA Compliance - The Administrative Simplification (AS) provisions requires the establishment of national standards for electronic health care transactions and national identifiers for providers, health insurance plans, and employers. AS provisions also address the security and privacy of health data. The standards are meant to improve the efficiency and effectiveness of the nation's health care system by encouraging the widespread use of electronic data interchange in the US health care system.
HIPAA / HITECH Omnibus Final Rule came into effect in late March 2013, with a 180-day safe compliance period that recently ended on September 23, 2013. The rule greatly enhances a patient’s privacy protections, provides individuals new rights to their health information, and strengthens the government’s ability to enforce the law. The HIPAA privacy and security rules have focused on health care providers, health plans and other entities that process health insurance claims. The changes announced today expand many of the requirements to business associates of these entities that receive protected health information, such as contractors and subcontractors.
In Short:
Note: Click the section numbers in the following table to view the various ADAudit Plus audit reports that will help satisfy a particular clause.
Section Number | Description | Reports |
164.308 (a) (3) (ii) (a) | Implement procedures for the authorization and / or supervision of workforce members who work with electronic protected health information or in location where it might be accessed. |
|
164.308 (a) (1) (ii) (d) / 164.312 (b) |
Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports. Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information. |
System Activity:
|
164.308 (a) (4) / 164.308 (a) (1) | Implement policies and procedures to prevent, detect, contain, and correct security violations. (Unauthorized changes). | Object Changes in AD & GPO / File Servers |
164.308 (a) (5) (ii) (c) | Procedures for monitoring log-in attempts and reporting discrepancies. |
|
164.308 (a) (4) (c) | Implement policies and procedures that, based upon the entity's access authorization policies, establish, document, review, and modify a user's right of access to a workstation, transaction, program, or process. |
|
A broader look at various audit reports in ADAudit Plus, which satisfy the requirements under a particular category. The reports ensure thorough monitoring and reporting / alerting, besides custom reporting and profile-based reporting.
Logon Failures | Logon Failures based on users | Failures due to Bad Password | Failures due to Bad User Name | Logon Activity based on DC | Logon Activity based on IP Address | Domain Controller Logon Activity | Member Server Logon Activity | Workstation Logon Activity | User Logon Activity | Recent User Logon Activity | Last Logon on Workstations | User's Last Logon | Users logged into multiple computers
Currently Logged On Users | Logon Duration | Local Logon Failures | Logon History | Terminal Services Activity | Users Logon Duration on Computers | Interactive Logon Failure | Terminated Users Session | RADIUS Logon Failures (NPS) | RADIUS Logon History (NPS)
All File or Folder Changes | Files Created | Files Modified | Files Deleted | Successful File Read Access | Failed attempt to Read File | Failed attempt to Write File | Failed attempt to Delete File | Folder Permission Changes | Folder Audit Setting Changes (SACL) | Files Moved (or) Renamed | Changes based on Users | Changes based on Servers | Files Copy-N-Pasted
All AD Changes | All AD Changes By User | All AD Changes on DCs | User Management | Group Management | Computer Management | OU Management | GPO Management | Administrative User Actions
Currently Logged On Users | Logon Duration | Local Logon Failures | Logon History | Terminal Services Activity | Users Logon Duration on Computers | Interactive Logon Failure | Terminated Users Session | RADIUS Logon Failures (NPS) | RADIUS Logon History (NPS)
User Permission Changes | Domain Level Permission Changes | Group Policy Settings Changes | Computer Configuration Changes | User Configuration Changes | Password Policy Changes | Account Lockout Policy Changes | Security Settings Changes | Administrative Template Changes | User Rights Assignment Changes | Windows Settings Changes | Group Policy Permission Changes | Group Policy Preferences Changes | Group Policy Settings History | Extended Attribute Changes | Domain Object Changes: Domain Policy Changes | Changes to Domain DNS Object | Domain Level Permission Changes
Summary Report | Process Tracking | Policy Changes | System Events | Object Management | Scheduled Task
Recent User Logon Activity | Logon Failures | Terminal Services Activity | Logon Duration | Domain Policy Changes | Logon History | User Management | Group Management | Computer Management | OU Management | GPO Management | Administrative User Actions | All File or Folder Changes
Recent User Logon Activity | Logon Failures | Terminal Services Activity | Logon History | Administrative User Actions | All File or Folder Changes | RADIUS Logon History (NPS) | Successful File Read Access | Folder Permission Changes | Folder Audit Setting Changes
Folder Audit Setting Changes | Folder Permission Changes | Successful File Read Access | All File or Folder Changes | GPO Management | User Management | Group Management | Domain Policy Changes | Logon Duration | Local Logon Failures | Terminal Services Activity
Terminal Services Activity | Local Logon Failures | Logon History | Group Management | User Management | Administrative User Actions | Computer Management | OU Management | All File or Folder Changes | Failed attempt to Write File | Failed attempt to Delete File