Security Awareness Program Training Policy
Overview
iEHR is responsible for ensuring the confidentiality, integrity, and availability of all Protected Health Information (PHI) stored on its systems. iEHR has an obligation to provide appropriate protection against threats, which could adversely affect the security of the system or its data entrusted on the system. Implementation of this policy will limit the exposure and possible effects of common threats to the systems.
Scope
The security awareness program is designed to educate all users on the security policy for iEHR.
Definitions
- Email: The electronic transmission of information through a mail protocol such as SMTP, POP, or IMAP.
- User: any employee or other person authorized by iEHR to read, enter or update information created or transmitted via the electronic mail system.
Policy
- The Security Officer will be responsible for implementing and ensuring this policy is followed by all employees.
- The Security Officer may create a Security Awareness Training Team to help implement the training.
- The security awareness training for workforce members should focus on:
- Employee responsibility for computer security
- Impact of unauthorized access
- Address the quickly and ever-changing data security threat environment
- Educating users on the creation of good passwords
- How to properly maintaining workstations
- Avoiding malicious software
- Informing users of email and Internet access policies, including:
- Tools used to monitor usage
- How to identify social engineering tactics
- Social media usage
- Physical security
- Reporting procedures
- Emergency procedures
- The security awareness training for system administrators should include:
- Training on how to configure systems securely
- Education on user account management policies
- Secure remote access for support of systems
- New employees will be required to take this training within the first month of employment.
- Training will be conducted annually, during a time specified by the Security Officer/ Security Awareness Training Team.
- The Security Officer/ Security Awareness Training Team may implement monthly security training updates.
- All users are required to read these updates and implement any changes.
Violations
Any individual, found to have violated this policy, may be subject to disciplinary action up to and including termination of employment. Violations shall be noted in the iEHR issue tracking system and support teams shall be dispatched to remediate the issue.