Enforced Policy Menus for FairWarning Managed Privacy Services, FairWarning Managed Privacy Services LITE, and FairWarning Drug Diversion Monitoring Services
Jump to:
- FairWarning Managed Privacy Services Enforced Policy Menu
- Managed Privacy Services LITE Enforced Policy Menu
- Drug Diversion Monitoring Services Enforced Policy Menu
FairWarning Managed Privacy Services Enforced Policy Menu
DATA COMPROMISE
Enforced Policy Definition Coworker Snooping Monitoring for user access to medical records of patients who work in the same user department. Household Snooping Monitoring for user access to medical records of patients who live at the same household address. Manager Snooping Monitoring for user access to medical records of a patient who is their manager. Guarantor Information Modification Monitoring for a user to modify the medical records of their own patient guarantor information. Break-the-Glass (BTG) Blank Override Reason Monitoring for users who perform the Break-the-Glass event and fail to provide an override reason. Patient of Interest/ VIP/ Temporary VIP Monitoring for user access to an identified patient of interest or VIP/ temporary VIP. Expired Patient of Interest Monitoring for user access to an expired (deceased) patient of interest based on an average User ID threshold. Self-Modification Monitoring for a user to modify their own medical records. Persons of Interest Captures access to high profile patients, including actors, singers, athletes, and politicians, who are listed in a public database. Requires the implementation of the POI table. Anomalous Workflow Detection Detects anomalies among a users daily workflow. Pediatric Departments accessing Adult Patients Monitoring for users who are accessing the medical records of adult patients (over 18 years old) and work in identified pediatric departments. Predominantly Female Departments accessing Male Patients Monitoring for users who are accessing the medical records of male patients (over 1 year old) and work in identified predominantly female departments. DATA EXFILTRATION
Enforced Policy Definition Deceased Demographic Access Monitoring for user access to Demographic Events of an expired (deceased) patient. High Access of Employees Monitoring for users who access a higher number of Customer employees than their peers. Peer group defined as users with the same User Department and Title. High View/ Print Demographics Monitoring for users who access or print a higher number of Demographic events than their peers. Peer group defined as users with the same User Department and Title. High Access of Demographics of Patients Under 12 Monitoring for users who access or print a higher number of Demographic events for patients under 12 than their peers. Peer group defined as users with the same User Department and Title. High Access of Demographics of Patients Over 65 MMonitoring for users who access or print a higher number of Demographic events for patients over 65 than their peers. Peer group defined as users with the same User Department and Title. Unusually High User Activity Monitoring for users who access a higher number of patient medical records than their peers. Peer group defined as users with the same User Department and Title. High View/ Print Insurance Information Monitoring for users who access or print a higher number of Insurance events than their peers. Peer group defined as users with the same User Department and Title. High View/ Print Specific Information (configurable) Monitoring for users who access or print a higher number of configured events than their peers. Peer group defined as users with the same User Department and Title. CYBERSECURITY THREATS
Enforced Policy Definition Access After Hours (Clinic or Department Specific) Monitoring for user access to patient medical records outside of approved business hours. Simultaneous Log-in Monitoring for user access performed on different work station IDs within five seconds of each other. Failed Log-In Attempts Monitoring for a user who fails to log-in; can be configured for failure after X amount of times. OTHER INFORMATION SECURITY THREATS
Enforced Policy Definition Monitoring on Leave Employees Monitoring for user access to patient medical records with a user status of on leave. Access After Termination Monitoring for user access to patient medical records after termination.
Managed Privacy Services LITE Enforced Policy Menu
DATA COMPROMISE
Enforced Policy Definition Coworker Snooping Monitoring for user access to medical records of patients who work in the same user department. Household Snooping Monitoring for user access to medical records of patients who live at the same household address. Manager Snooping Monitoring for user access to medical records of a patient who is their manager. Patient of Interest Monitoring for user access to an identified patient of interest or VIP/ temporary VIP. Self-Modification Monitoring for a user to modify their own medical records. Anomalous Workflow Detection Detects anomalies among a users daily workflow. DATA EXFILTRATION
Enforced Policy Definition High Access of Employees Monitoring for users who access a higher number of Customer employees than their peers. Peer group defined as users with the same User Department and Title. High View/ Print Demographics Monitoring for users who access or print a higher number of Demographic events than their peers. Peer group defined as users with the same User Department and Title. High Access of Demographics of Patients Under 12 Monitoring for users who access or print a higher number of Demographic events for patients under 12 than their peers. Peer group defined as users with the same User Department and Title. High Access of Demographics of Patients Over 65 MMonitoring for users who access or print a higher number of Demographic events for patients over 65 than their peers. Peer group defined as users with the same User Department and Title. High View/ Print Insurance Information Monitoring for users who access or print a higher number of Insurance events than their peers. Peer group defined as users with the same User Department and Title. CYBERSECURITY THREATS
Enforced Policy Definition Access After Hours (Clinic or Department Specific) Monitoring for user access to patient medical records outside of approved business hours. OTHER INFORMATION SECURITY THREATS
Enforced Policy Definition Access After Termination Monitoring for user access to patient medical records after termination.
Drug Diversion Monitoring Services Enforced Policy Menu
ANOMALOUS BEHAVIOR DETECTION
Enforced Policy Definition Unusual Access of Controlled Substances Monitoring for users who dispense a higher number of Controlled Substances than their peers. Peer group defined as users with the same User Department and Title. Unusual Waste Documentation Monitoring for users who waste a higher number of Controlled Substances than their peers. Peer group defined as users with the same User Department and Title. Abnormal Discrepancy Creation Monitoring for users who create a higher number of Controlled Substance Discrepancies than their peers. Peer group defined as users with the same User Department and Title. Unusual Behavior by Waste Witness Monitoring for users who act as a witness for waste of Controlled Substances significant more than their peers. Peer group defined as users with the same User Department and Title. Abnormal Override Activity Monitoring for users who dispense a higher number of Controlled Substances on Override than their peers. Peer group defined as users with the same User Department and Title. Abnormal Cancel Activity Monitoring for users who cancel a higher number of Controlled Substances transactions than their peers. Peer group defined as users with the same User Department and Title. Unusual Access of High-Risk Medications Monitoring for users who dispense a higher number of High-Risk Medications than their peers. Peer group defined as users with the same User Department and Title. Abnormal Access of Specific Patient Information Monitoring for users who access or print a higher number of configured events than their peers. Peer group defined as users with the same User Department and Title. Excessive Patient Additions Monitoring for users who manually add patients to the ADS significantly more than their peers. Peer group defined as users with the same User Department and Title. TARGETED DIVERSION MONITORING
Enforced Policy Definition Inventory Discrepancies Monitoring for Inventory Discrepancies of Controlled Substances accessed in the ADS. Excessive Waste Quantity Monitoring for users who waste the full quantity of the Controlled Substance that was dispensed. Deceased/Discharged Patient Access Monitoring for users who dispense Controlled Substances for deceased or discharged patients. High-Risk Department Monitoring Monitoring for users who access medications within a High-Risk Department, as configured by the customer. High-Risk Patient Population Monitoring Monitoring for users who access medications for High-Risk Patients, as configured by the customer. COMPROMISED SECURITY MONITORING
Enforced Policy Definition Access After Termination Monitoring for user access to the ADS after the user has been terminated. Access by Inactive/On Leave Employees Monitoring for user access to the ADS while the user is identified as Inactive or On Leave. Simultaneous Station Access Monitoring for user access performed on different ADS Device ID’s within 5 seconds of each other.