SESK: Stuff Everyone Should Know · sesk.info/hipaa-phishing-malicious-software
Which HIPAA security awareness topic covers phishing emails?
Awareness procedures for guarding against malicious software are addressable.
- Procedures for guarding against, detecting, and reporting malicious software ✔
- Audit logs
- Facility key control
Why: The Security Rule includes addressable procedures for guarding against, detecting, and reporting malicious software. Phishing emails are a common delivery method for malware.
Huh, didn't know that: Training should teach staff not to click suspicious links or attachments.
Why did the phishing email get caught? It didn't pass the staff's suspicious-link test.
Like this card?
References
Answer: Procedures for guarding against, detecting, and reporting malicious software. The Security Rule includes addressable procedures for guarding against, detecting, and reporting malicious software. Phishing emails are a common delivery method for malware.
- 45 CFR 164.308(a)(5)(ii)(B) www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
Protection from malicious software (Addressable). Procedures for guarding against, detecting, and reporting malicious software.
Checked 2026-10-10.
Think this answer is wrong? Tap "Challenge this answer" on the card in the game and tell us why.
More stuff everyone should know
That's stuff everyone should know.