Healthcare Security – Requirements
Control Description | Support | AIE Rules/Alerts | Investigations | Reports |
---|---|---|---|---|
§164.310(a)(1): Facility Access Controls | Augment | HSS: Physical Access Usage Rule HSS: Door Access Success | HSS: Physical Security Auth Activity Inv | HSS: AIE Physical Security Auth Summary HSS: Physical Security Auth Activity Summary HSS: AIE Physical Security Auth Detail HSS: Physical Security Auth Activity Detail |
§164.310(b): Workstation Use | Augment | HSS: Workstation Device Driver Activity Rule | HSS: Workstation Device Driver Inv | HSS: Workstation Device Driver Summary |
§164.310(c): Workstation Security | Augment | HSS: Workstation Device Driver Activity Rule | HSS: Workstation Device Driver Inv | HSS: Workstation Device Driver Summary |
§164.310(d): Device and Media Controls | Augment | HSS: System Shutdown Rule | HSS: System Startup And Shutdown Inv HSS: System Critical And Error Conditions Inv HSS: Backup Activity Inv HSS: AIE Backup Failure Alert Inv HSS: ePHI and Backup System Failure/Error Inv | HSS: System Startup And Shutdown HSS: System Critical And Error Conditions HSS: Backup Activity Summary HSS: ePHI and Backup System Failure/Error Summary HSS: AIE Backup Failure Alert Summary HSS: System Startup And Shutdown Detail HSS: Backup Activity Detail HSS: ePHI and Backup System Failure/Error Detail |
§164.312(a)(1): Access Control | Augment | HSS: ePHI Abnormal Auth Rule HSS: Abnormal Auth Behavior Rule HSS: Disabled Admin Access Failure Rule HSS: Account Access Revoked Rule HSS: Default Act Access Failure Rule HSS: Recently Disabled Account with Access Failure Activity Rule HSS: Eligible Professional Act Access Failure Rule | HSS: Unapproved ePHI Account Access Inv HSS: Account Management Activity Inv HSS: Terminated Account Inv HSS: Default Account Inv HSS: New Account Inv HSS: Account Lockout Inv HSS: Disabled Accounts Inv HSS: Host Access Granted And Revoked Inv HSS: Logout Inv HSS: User Authentication Inv | HSS: Unapproved ePHI Account Access Summary HSS: Account Management Activity HSS: Terminated Account Summary HSS: Default Account Summary HSS: New Account Summary HSS: Account Lockout Summary HSS: Disabled Accounts HSS: Host Access Granted And Revoked HSS: Logout Summary HSS: Unapproved ePHI Account Access Detail HSS: Account Management Activity Detail HSS: Terminated Account Detail HSS: Host Access Granted And Revoked Detail |
§164.312(b): Audit Controls | Direct | HSS: Abnormal Amount of Data Transferred HSS: Abnormal Auth Behavior Rule HSS: Account Access Revoked Rule HSS: Data Loss Prevention Rule HSS: Default Act Access Failure Rule HSS: Disabled Admin Access Failure Rule HSS: Door Access Success HSS: Eligible Professional Act Access Failure Rule HSS: ePHI Abnormal Auth Rule HSS: FIM Abnormal Activity HSS: FIM Add Activity Rule HSS: FIM Delete Activity Rule HSS: FIM Group Change Activity Rule HSS: FIM Information Rule HSS: FIM Modify Activity Rule HSS: FIM Owner Change Activity Rule HSS: FIM Permission Activity Rule HSS: Ineligible Authentication Activity HSS: Misuse Rule HSS: Physical Access Usage Rule HSS: Primary Eligible Professional Utilization Statistics HSS: Recently Disabled Account with Access Failure Activity Rule HSS: Secondary Eligible Professional Utilization Statistics HSS: Suspicious Activity Rule HSS: System Shutdown Rule HSS: Terminated Account Activity Rule HSS: TST Environmental Error Alert HSS: Unapproved Account Access Rule HSS: Workstation Device Driver Activity Rule | HSS: Account Lockout Inv HSS: Account Management Activity Inv HSS: AIE Backup Failure Alert Inv HSS: AIE Rule Inv HSS: Applications Accessed By User Inv HSS: Attacks Detected Inv HSS: Audit Failure Inv HSS: Backup Activity Inv HSS: Business Associate UAM Inv HSS: Compromises Detected Inv HSS: Covered Entity Acct Access Failure Inv HSS: Covered Entity Acct Access Success Inv HSS: Covered Entity Acct Auth Failure Inv HSS: Covered Entity Acct Auth Success Inv HSS: Covered Entity Acct Disabled/Enabled Inv HSS: Default Account Inv HSS: Disabled Accounts Inv HSS: Eligible Professional Activity Inv HSS: ePHI and Backup System Failure/Error Inv HSS: ePHI Threat IP Activity Inv HSS: Failed Application Access Inv HSS: Failed File Access Inv HSS: Failed Host Access Inv HSS: File Integrity Monitor Inv HSS: Host Access Granted And Revoked Inv HSS: Host Change Inv HSS: Ineligible EHR Account Access Inv HSS: Logout Inv HSS: LogRhythm Data Loss Defender Log Inv HSS: Malware Detected Inv HSS: New Account Inv HSS: Object Access Inv HSS: Physical Security Auth Activity Inv HSS: Suspicious EHR System Activity Inv HSS: System Critical And Error Conditions Inv HSS: System Startup And Shutdown Inv HSS: Terminated Account Inv HSS: Top Applications Experiencing Errors Inv HSS: Top Hosts Experiencing Errors Inv HSS: TST Access Failure Inv HSS: TST Access Success Inv HSS: TST AIE Inv HSS: TST Authentication Failure Inv HSS: TST Authentication Success Inv HSS: TST Environment Error Inv HSS: TST Priv Acct Authentication Inv HSS: Unapproved ePHI Account Access Inv HSS: Use Of Non-Encrypted Protocols Inv HSS: User Authentication Inv HSS: User Misuse Inv HSS: User Object Access Inv HSS: Vulnerabilities Detected Inv HSS: Workstation Device Driver Inv | HSS: Account Lockout Summary HSS: Account Management Activity HSS: AIE Backup Failure Alert Summary HSS: AIE Physical Security Auth Summary HSS: AIE Rule Summary HSS: Alarm And Response Activity HSS: Applications Accessed By User HSS: Attacks Detected HSS: Audit Failure By Host HSS: Audit Failure By User HSS: Backup Activity Summary HSS: Business Associate UAM Summary HSS: Compromises Detected HSS: Covered Entity Acct Access Failure Summary HSS: Covered Entity Acct Access Success Summary HSS: Covered Entity Acct Auth Failure Summary HSS: Covered Entity Acct Auth Success Summary HSS: Covered Entity Acct Disabled/Enabled Summary HSS: Default Account Summary HSS: Disabled Accounts HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login HSS: ePHI and Backup System Failure/Error Summary HSS: ePHI Threat IP Activity Summary HSS: Failed Application Access HSS: Failed File Access HSS: Failed Host Access HSS: File Integrity Monitor Summary HSS: Host Access Granted And Revoked HSS: Host Change Summary HSS: Ineligible EHR Account Access Summary HSS: Logout Summary HSS: LogRhythm Data Loss Defender Log Summary HSS: Malware Detected HSS: New Account Summary HSS: Object Access Summary HSS: Physical Security Auth Activity Summary HSS: Security Event Summary HSS: Suspicious Activity By Host HSS: Suspicious Activity By User HSS: Suspicious EHR System Activity HSS: System Critical And Error Conditions HSS: System Startup And Shutdown HSS: Terminated Account Summary HSS: Top Applications Experiencing Errors HSS: Top Attackers HSS: Top Hosts Experiencing Errors HSS: Top Suspicious Users HSS: Top Targeted Applications HSS: Top Targeted Hosts HSS: TST Access Failure Summary HSS: TST Access Success Summary HSS: TST AIE Summary HSS: TST Authentication Failure Summary HSS: TST Authentication Success Summary HSS: TST Environment Error Summary HSS: TST Priv Acct Authentication Summary HSS: Unapproved ePHI Account Access Summary HSS: Use Of Non-Encrypted Protocols HSS: User Authentication Summary HSS: User Misuse Summary HSS: User Object Access Summary HSS: Vulnerabilities Detected HSS: Workstation Device Driver Summary HSS: Account Management Activity Detail HSS: AIE Physical Security Auth Detail HSS: Backup Activity Detail HSS: Business Associate UAM Detail HSS: Covered Entity Acct Access Failure Detail HSS: Covered Entity Acct Access Success Detail HSS: Covered Entity Acct Auth Failure Detail HSS: Covered Entity Acct Auth Success Detail HSS: Covered Entity Acct Disabled/Enabled Detail HSS: ePHI and Backup System Failure/Error Detail HSS: File Integrity Monitor Log Detail HSS: Host Access Granted And Revoked Detail HSS: Ineligible EHR Account Access Detail HSS: LogRhythm Data Loss Defender Log Detail HSS: Malware Detected Detail HSS: Physical Security Auth Activity Detail HSS: Security Event by Log Source Ent Detail HSS: System Startup And Shutdown Detail HSS: Terminated Account Detail HSS: TST Access Failure Detail HSS: TST Access Success Detail HSS: TST Authentication Failure Detail HSS: TST Authentication Success Detail HSS: TST Environment Error Detail HSS: TST Priv Acct Authentication Detail HSS: Unapproved ePHI Account Access Detail HSS: Usage Auditing Event Detail HSS: Use Of Non-Encrypted Protocol Detail HSS: Vulnerabilities Detected Detail |
§164.312(c)(1): Integrity | Augment | HSS: FIM Add Activity Rule HSS: FIM Delete Activity Rule HSS: FIM Group Change Activity Rule HSS: FIM Information Rule HSS: FIM Modify Activity Rule HSS: FIM Owner Change Activity Rule HSS: FIM Permission Activity Rule HSS: FIM Abnormal Activity | HSS: File Integrity Monitor Inv | HSS: File Integrity Monitor Summary HSS: File Integrity Monitor Log Detail |
§164.312(d): Person or Entity Authentication | Augment | HSS: Ineligible Authentication Activity | HSS: ePHI Threat IP Activity Inv HSS: User Authentication Inv | HSS: ePHI Threat IP Activity Summary |
§164.312(e)(1): Transmission Security | Augment | HSS: Abnormal Amount of Data Transferred HSS: ePHI Abnormal Auth Rule | HSS: ePHI Threat IP Activity Inv HSS: Use Of Non-Encrypted Protocols Inv HSS: LogRhythm Data Loss Defender Log Inv | HSS: Use Of Non-Encrypted Protocols HSS: ePHI Threat IP Activity Summary HSS: LogRhythm Data Loss Defender Log Summary HSS: Use Of Non-Encrypted Protocol Detail HSS: LogRhythm Data Loss Defender Log Detail |
§164.308(a)(1): Security Management Process | Augment | HSS: Suspicious Activity Rule HSS: Misuse Rule HSS: Unapproved Account Access Rule HSS: Terminated Account Activity Rule HSS: Data Loss Prevention Rule HSS: System Shutdown Rule | HSS: Failed File Access Inv HSS: User Object Access Inv HSS: Vulnerabilities Detected Inv HSS: Suspicious EHR System Activity Inv HSS: User Misuse Inv HSS: Compromises Detected Inv HSS: Malware Detected Inv HSS: Failed Application Access Inv HSS: Attacks Detected Inv HSS: Failed Host Access Inv HSS: Audit Failure Inv HSS: ePHI Threat IP Activity Inv HSS: Suspicious EHR System Activity Inv HSS: User Authentication Inv | HSS: Failed File Access HSS: User Object Access Summary HSS: Vulnerabilities Detected HSS: Top Applications Experiencing Errors HSS: Top Hosts Experiencing Errors HSS: Top Targeted Hosts HSS: Top Targeted Applications HSS: Security Event Summary HSS: Suspicious Activity By Host HSS: Suspicious Activity By User HSS: Top Suspicious Users HSS: User Misuse Summary HSS: Audit Failure By User HSS: User Authentication Summary HSS: Compromises Detected HSS: Malware Detected HSS: System Critical And Error Conditions HSS: Failed Application Access HSS: Attacks Detected HSS: Failed Host Access HSS: Top Attackers HSS: Audit Failure By Host HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login HSS: Suspicious EHR System Activity HSS: Ineligible EHR Account Access Summary HSS: Usage Auditing Event Detail HSS: Malware Detected Detail HSS: Usage Auditing Event Detail HSS: Security Event by Log Source Ent Detail HSS: Vulnerabilities Detected Detail HSS: Ineligible EHR Account Access Detail |
§164.308(a)(3): Workforce Security | Augment | HSS: ePHI Abnormal Auth Rule HSS: Abnormal Auth Behavior Rule HSS: Disabled Admin Access Failure Rule HSS: Account Access Revoked Rule HSS: Default Act Access Failure Rule HSS: Recently Disabled Account with Access Failure Activity Rule HSS: Eligible Professional Act Access Failure Rule | HSS: Failed File Access Inv HSS: User Object Access Inv HSS: Vulnerabilities Detected Inv HSS: Suspicious EHR System Activity Inv HSS: User Misuse Inv HSS: Compromises Detected Inv HSS: Malware Detected Inv HSS: Failed Application Access Inv HSS: Attacks Detected Inv HSS: Failed Host Access Inv HSS: Audit Failure Inv HSS: ePHI Threat IP Activity Inv HSS: Suspicious EHR System Activity Inv HSS: Terminated Account Inv HSS: Ineligible EHR Account Access Inv | HSS: Unapproved ePHI Account Access Summary HSS: Account Management Activity HSS: Terminated Account Summary HSS: Applications Accessed By User HSS: Audit Failure By User HSS: User Authentication Summary HSS: Ineligible EHR Account Access Summary HSS: Ineligible EHR Account Access Detail HSS: Unapproved ePHI Account Access Detail HSS: Terminated Account Detail HSS: Usage Auditing Event Detail |
§164.308(a)(4): Information Access Management | Augment | HSS: Abnormal Amount of Data Transferred HSS: Data Loss Prevention Rule HSS: ePHI Abnormal Auth Rule | HSS: ePHI Threat IP Activity Inv HSS: Use Of Non-Encrypted Protocols Inv HSS: LogRhythm Data Loss Defender Log Inv | HSS: Use Of Non-Encrypted Protocols HSS: ePHI Threat IP Activity Summary HSS: LogRhythm Data Loss Defender Log Summary HSS: LogRhythm Data Loss Defender Log Detail HSS: Use Of Non-Encrypted Protocol Detail |
§164.308(a)(6): Security Incident Procedures | Augment | HSS: Data Loss Prevention Rule HSS: Suspicious Activity Rule HSS: Misuse Rule HSS: FIM Add Activity Rule HSS: FIM Delete Activity Rule HSS: FIM Group Change Activity Rule HSS: FIM Information Rule HSS: FIM Modify Activity Rule HSS: FIM Owner Change Activity Rule HSS: FIM Permission Activity Rule HSS: FIM Abnormal Activity | HSS: LogRhythm Data Loss Defender Log Inv HSS: Suspicious EHR System Activity Inv HSS: User Misuse Inv HSS: Compromises Detected Inv HSS: Malware Detected Inv | HSS: LogRhythm Data Loss Defender Log Summary HSS: Suspicious Activity By Host HSS: Suspicious Activity By User HSS: Compromises Detected HSS: Malware Detected HSS: User Misuse Summary HSS: LogRhythm Data Loss Defender Log Detail HSS: Malware Detected Detail |
§164.308(a)(7): Contingency Plan | Augment | HSS: System Shutdown Rule | HSS: System Startup And Shutdown Inv HSS: System Critical And Error Conditions Inv HSS: Backup Activity Inv HSS: AIE Backup Failure Alert Inv HSS: ePHI and Backup System Failure/Error Inv | HSS: System Startup And Shutdown HSS: System Critical And Error Conditions HSS: Backup Activity Summary HSS: ePHI and Backup System Failure/Error Summary HSS: AIE Backup Failure Alert Summary HSS: System Startup And Shutdown Detail HSS: Backup Activity Detail HSS: ePHI and Backup System Failure/Error Detail |
§164.308(a)(8): Evaluation | Augment | N/A | HSS: AIE Rule Inv | HSS: AIE Rule Summary HSS: Top Applications Experiencing Errors HSS: Top Hosts Experiencing Errors HSS: Top Attackers HSS: Top Suspicious Users HSS: Top Targeted Applications HSS: Top Targeted Hosts HSS: Unapproved ePHI Account Access Detail HSS: Usage Auditing Event Detail HSS: Malware Detected Detail HSS: Usage Auditing Event Detail HSS: Security Event by Log Source Ent Detail HSS: Vulnerabilities Detected Detail HSS: Ineligible EHR Account Access Detail HSS: Account Management Activity Detail |
§164.314(b)(1): Requirements for Group Health Plans | Augment | N/A | N/A | HSS: Top Attackers HSS: Top Applications Experiencing Errors HSS: Top Hosts Experiencing Errors HSS: Top Suspicious Users HSS: Top Targeted Applications HSS: Top Targeted Hosts |
§164.316(b)(1): Documentation | Augment | N/A | HSS: Backup Activity Inv HSS: AIE Backup Failure Alert Inv HSS: ePHI and Backup System Failure/Error Inv | HSS: Backup Activity Summary HSS: ePHI and Backup System Failure/Error Summary HSS: AIE Backup Failure Alert Summary HSS: Backup Activity Detail HSS: ePHI and Backup System Failure/Error Detail |
§13201(a): Pilot Testing of Standards and Implementation Specifications | Augment | HSS: TST Environmental Error Alert | HSS: TST Access Failure Inv HSS: TST Access Success Inv HSS: TST Authentication Failure Inv HSS: TST Authentication Success Inv HSS: TST Environment Error Inv HSS: TST Priv Acct Authentication Inv HSS: TST AIE Inv | HSS: TST Access Failure Summary HSS: TST Access Success Summary HSS: TST Authentication Failure Summary HSS: TST Authentication Success Summary HSS: TST Environment Error Summary HSS: TST Priv Acct Authentication Summary HSS: TST AIE Summary HSS: TST Access Failure Detail HSS: TST Access Success Detail HSS: TST Authentication Failure Detail HSS: TST Authentication Success Detail HSS: TST Environment Error Detail HSS: TST Priv Acct Authentication Detail |
§13201(b): Voluntary Testing Program | Augment | HSS: TST Environmental Error Alert | HSS: TST Access Failure Inv HSS: TST Access Success Inv HSS: TST Authentication Failure Inv HSS: TST Authentication Success Inv HSS: TST Environment Error Inv HSS: TST Priv Acct Authentication Inv HSS: TST AIE Inv | HSS: TST Access Failure Summary HSS: TST Access Success Summary HSS: TST Authentication Failure Summary HSS: TST Authentication Success Summary HSS: TST Environment Error Summary HSS: TST Priv Acct Authentication Summary HSS: TST AIE Summary HSS: TST Access Failure Detail HSS: TST Access Success Detail HSS: TST Authentication Failure Detail HSS: TST Authentication Success Detail HSS: TST Environment Error Detail HSS: TST Priv Acct Authentication Detail |
§13402(b): Notification of Covered Entity by Business Associate | Augment | N/A | HSS: Covered Entity Acct Auth Failure Inv HSS: Covered Entity Acct Auth Success Inv HSS: Covered Entity Acct Access Failure Inv HSS: Covered Entity Acct Access Success Inv HSS: Covered Entity Acct Disabled/Enabled Inv HSS: Business Associate UAM Inv | HSS: Covered Entity Acct Auth Failure Summary HSS: Covered Entity Acct Auth Success Summary HSS: Covered Entity Acct Access Failure Summary HSS: Covered Entity Acct Access Success Summary HSS: Covered Entity Acct Disabled/Enabled Summary HSS: Business Associate UAM Summary HSS: Covered Entity Acct Auth Failure Detail HSS: Covered Entity Acct Auth Success Detail HSS: Covered Entity Acct Access Failure Detail HSS: Covered Entity Acct Access Success Detail HSS: Covered Entity Acct Disabled/Enabled Detail HSS: Business Associate UAM Detail |
§13402(c): Breaches Treated as Discovered | Augment | Case Management |
|
|
§13402(d): Timeliness of Notification | Direct | Case Management | ||
§13405(b): Disclosures Required to be Limited to the Limited Data Set or the Minimum Necessary. | Augment | N/A | HSS: Covered Entity Acct Auth Failure Inv HSS: Covered Entity Acct Auth Success Inv HSS: Covered Entity Acct Access Failure Inv HSS: Covered Entity Acct Access Success Inv HSS: Covered Entity Acct Disabled/Enabled Inv HSS: Business Associate UAM Inv | HSS: Covered Entity Acct Auth Failure Summary HSS: Covered Entity Acct Auth Success Summary HSS: Covered Entity Acct Access Failure Summary HSS: Covered Entity Acct Access Success Summary HSS: Covered Entity Acct Disabled/Enabled Summary HSS: Business Associate UAM Summary HSS: Covered Entity Acct Auth Failure Detail HSS: Covered Entity Acct Auth Success Detail HSS: Covered Entity Acct Access Failure Detail HSS: Covered Entity Acct Access Success Detail HSS: Covered Entity Acct Disabled/Enabled Detail HSS: Business Associate UAM Detail |
§13405(c): Accounting of Certain Protected Health Information Disclosures Required if Covered Entity Uses Electronic Health Record. | Augment | HSS: ePHI Abnormal Auth Rule HSS: Abnormal Auth Behavior Rule HSS: Disabled Admin Access Failure Rule HSS: Account Access Revoked Rule HSS: Default Act Access Failure Rule HSS: Recently Disabled Account with Access Failure Activity Rule HSS: Eligible Professional Act Access Failure Rule | HSS: Failed File Access Inv HSS: User Object Access Inv HSS: Vulnerabilities Detected Inv HSS: Suspicious EHR System Activity Inv HSS: User Misuse Inv HSS: Compromises Detected Inv HSS: Malware Detected Inv HSS: Failed Application Access Inv HSS: Attacks Detected Inv HSS: Failed Host Access Inv HSS: Audit Failure Inv HSS: ePHI Threat IP Activity Inv HSS: Suspicious EHR System Activity Inv HSS: User Authentication Inv | HSS: Failed File Access HSS: User Object Access Summary HSS: Vulnerabilities Detected HSS: Top Applications Experiencing Errors HSS: Top Hosts Experiencing Errors HSS: Top Targeted Hosts HSS: Top Targeted Applications HSS: Security Event Summary HSS: Suspicious Activity By Host HSS: Suspicious Activity By User HSS: Top Suspicious Users HSS: User Misuse Summary HSS: Audit Failure By User HSS: User Authentication Summary HSS: Compromises Detected HSS: Malware Detected HSS: System Critical And Error Conditions HSS: Failed Application Access HSS: Attacks Detected HSS: Failed Host Access HSS: Top Attackers HSS: Audit Failure By Host HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login HSS: Suspicious EHR System Activity HSS: Ineligible EHR Account Access Summary HSS: Usage Auditing Event Detail HSS: Malware Detected Detail HSS: Usage Auditing Event Detail HSS: Security Event by Log Source Ent Detail HSS: Vulnerabilities Detected Detail HSS: Ineligible EHR Account Access Detail |
§13411: Audits. | Augment | N/A | HSS: AIE Rule Inv HSS: Top Hosts Experiencing Errors Inv HSS: Top Applications Experiencing Errors Inv HSS: Covered Entity Acct Auth Failure Inv HSS: Covered Entity Acct Auth Success Inv HSS: Covered Entity Acct Access Failure Inv HSS: Covered Entity Acct Access Success Inv HSS: Covered Entity Acct Disabled/Enabled Inv HSS: Business Associate UAM Inv | HSS: AIE Rule Summary HSS: Top Applications Experiencing Errors HSS: Top Hosts Experiencing Errors HSS: Top Attackers HSS: Top Suspicious Users HSS: Top Targeted Applications HSS: Top Targeted Hosts HSS: Covered Entity Acct Auth Failure Summary HSS: Covered Entity Acct Auth Success Summary HSS: Covered Entity Acct Access Failure Summary HSS: Covered Entity Acct Access Success Summary HSS: Covered Entity Acct Disabled/Enabled Summary HSS: Business Associate UAM Summary HSS: Unapproved ePHI Account Access Detail HSS: Usage Auditing Event Detail HSS: Malware Detected Detail HSS: Usage Auditing Event Detail HSS: Security Event by Log Source Ent Detail HSS: Vulnerabilities Detected Detail HSS: Ineligible EHR Account Access Detail HSS: Account Management Activity Detail HSS: Covered Entity Acct Auth Failure Detail HSS: Covered Entity Acct Auth Success Detail HSS: Covered Entity Acct Access Failure Detail HSS: Covered Entity Acct Access Success Detail HSS: Covered Entity Acct Disabled/Enabled Detail HSS: Business Associate UAM Detail |
§495.6(d)(1): Use computerized provider order entry (CPOE) for medication orders directly entered by any licensed healthcare professional who can enter orders into the medical record per state, local and professional guidelines. | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary-Event HSS: Eligible Professional Activity Summary-Login |
§495.6(d)(2): Implement drug-drug and drug-allergy interaction checks | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary-Event HSS: Eligible Professional Activity Summary-Login |
§495.6(d)(4): Generate and transmit permissible prescriptions electronically (eRx) | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary-Event HSS: Eligible Professional Activity Summary-Login |
§495.6(d)(11): Implement one clinical decision support rule relevant to specialty or high clinical priority along with the ability to track compliance with that rule | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary-Event HSS: Eligible Professional Activity Summary-Login |
§495.6(d)(12): Provide patients with an electronic copy of their health information (including diagnostics test results, problem list, medication lists, medication allergies) upon request | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary-Event HSS: Eligible Professional Activity Summary-Login |
§495.6(d)(14): Capability to exchange key clinical information (for example, problem list, medication list, medication allergies, and diagnostic test results), among providers of care and patient authorized entities electronically | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary-Event HSS: Eligible Professional Activity Summary-Login |
§495.6(d)(15): Protect electronic health information created or maintained by the certified EHR technology through the implementation of appropriate technical capabilities | Augment | HSS: ePHI Abnormal Auth Rule HSS: Abnormal Auth Behavior Rule HSS: Disabled Admin Access Failure Rule HSS: Account Access Revoked Rule HSS: Default Act Access Failure Rule HSS: Recently Disabled Account with Access Failure Activity Rule HSS: Eligible Professional Act Access Failure Rule | HSS: Failed File Access Inv HSS: User Object Access Inv HSS: Vulnerabilities Detected Inv HSS: Suspicious EHR System Activity Inv HSS: User Misuse Inv HSS: Compromises Detected Inv HSS: Malware Detected Inv HSS: Failed Application Access Inv HSS: Attacks Detected Inv HSS: Failed Host Access Inv HSS: Audit Failure Inv HSS: ePHI Threat IP Activity Inv HSS: Suspicious EHR System Activity Inv HSS: User Authentication Inv | HSS: Failed File Access HSS: User Object Access Summary HSS: Vulnerabilities Detected HSS: Top Applications Experiencing Errors HSS: Top Hosts Experiencing Errors HSS: Top Targeted Hosts HSS: Top Targeted Applications HSS: Security Event Summary HSS: Suspicious Activity By Host HSS: Suspicious Activity By User HSS: Top Suspicious Users HSS: User Misuse Summary HSS: Audit Failure By User HSS: User Authentication Summary HSS: Compromises Detected HSS: Malware Detected HSS: System Critical And Error Conditions HSS: Failed Application Access HSS: Attacks Detected HSS: Failed Host Access HSS: Top Attackers HSS: Audit Failure By Host HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login HSS: Suspicious EHR System Activity HSS: Ineligible EHR Account Access Summary HSS: Usage Auditing Event Detail HSS: Malware Detected Detail HSS: Usage Auditing Event Detail HSS: Security Event by Log Source Ent Detail HSS: Vulnerabilities Detected Detail HSS: Ineligible EHR Account Access Detail |
§495.6(e)(9): Capability to submit electronic data to immunization registries or immunization information systems and actual submission in accordance with applicable law and practice | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login |
§495.6(e)(10): Capability to submit electronic syndromic surveillance data to public health agencies and actual submission in accordance with applicable law and practice | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login |
§495.6(e)(1): Implement drug formulary checks | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login |
§495.6(e)(5): Provide patients with timely electronic access to their health information (including lab results, problem list, medication lists, and allergies) within four business days of the information being available to the EP | Augment | HSS: Primary Eligible Professional Utilization Statistics HSS: Secondary Eligible Professional Utilization Statistics | HSS: Eligible Professional Activity Inv | HSS: Eligible Professional Activity Summary- Event HSS: Eligible Professional Activity Summary- Login |