Trend Micro Healthcare Solutions
Regulatory Compliance and Trend Micro Enterprise Security

Healthcare organizations are under growing pressure to improve efficiency and cut costs, while at the same time, new and existing regulations require increased security for Protected Health Information (PHI).
The good news: you can address all of these problems with Trend Micro Enterprise Security. We offer you unique and cost effective solutions that allow you to:
- Confidently implement EMR/EHR modernizationng
- Comply with HIPAA , HITECH and PCI regulationsng
- Maximize PHI data protectionng
- Enable secure virtualization and cloud computing
HITECH Act and HIPAA Compliance:
The chart below maps HITECH Act and HIPAA compliance requirements to Trend Micro solutions across complex distributed networks, including virtual and cloud-based servers. We can also help you achieve compliance with PCI DSS.
| US Healthcare Regulation or Challenge | |||||
|---|---|---|---|---|---|
| Trend Micro Enterprise Solutions | |||||
| Endpoint Security | Web Security | Messaging Security | Data Protection | Trend Micro Services | |
| HITECH Act | |||||
| Breach notification for unsecured ePHI | |||||
| Encryption (“safe harbor” from breach notification) | |||||
| Extend HIPAA requirements to business associates | |||||
| HIPAA (Health Insurance Portability and Accountability Act) | |||||
| Protection of ePHI confidentiality, availability, and integrity | |||||
| Minimize data collection and use | |||||
| Transmission security | |||||
| Integrity | |||||
| Access control and authentication | |||||
| Device and media controls | |||||
| Security awareness and rraining and security incident procedures | |||||
| Security management process | |||||
| Retrieve exact copies of ePHI | |||||
| Protection from malicious software | |||||
| PCI DSS (Payment Card Industry Data Security Standard) | |||||
| Protection from malicious software | |||||
Server Security for Healthcare:
Healthcare organizations are facing increasing scrutiny from regulators, practitioners, and patients to ensure the integrity, security, and confidentiality of healthcare information. Financially motivated attackers develop new threats daily with the intent to steal and sell valuable data—including identities and computing resources.
Cybercriminals are able to bypass most perimeter security systems. They now target software vulnerabilities in critical e-Health solutions, including web-based EHR/EMR applications, as well as underlying enterprise servers and operating systems.
Trend Micro™ Deep Security for Healthcare
Trend Micro™ Deep Security delivers powerful server and application protection that allows physical and virtualized systems to become self-defending. It provides comprehensive server security that is integral to datacenter modernization initiatives, including virtualization and cloud computing. Deep Security deployed on physical servers and virtualized environments, provides comprehensive, unified protection, including:
- Intrusion detection and prevention (IDS/IPS)
- Web application protection
- Application control
- Firewall
- Integrity monitoring
- Log inspection
Trend Micro™ Deep Security Manager is a powerful, centralized, management system that allows administrators to apply security profiles to servers, and track threats and preventive actions taken in response to them. Detailed reports document attempted attacks, and provide an auditable history of security configurations and changes to gain visibility into activity and meet compliance requirements.
Trend Micro™ Deep Security Virtual Appliance transparently enforces security policies on VMware vSphere virtual machines for IDS/IPS, web application protection, application control, and firewall protection—coordinating with Deep Security Agent, if desired, for integrity monitoring and log inspection.
Trend Micro™ Deep Security Agent is a small software component that is deployed on the server or virtual machine being protected and enforces the security policy for that machine. The Agent defends the server by monitoring incoming and outgoing traffic for protocol deviations, content that signals an attack, or policy violations. When necessary, the Agent intervenes and neutralizes the threat by blocking the malicious traffic.
Trend Micro™ Security Center provides information on the latest vulnerabilities and security updates that shield these vulnerabilities and reduce risk. Security updates are delivered quickly (typically within two hours of Microsoft security advisories) and can be distributed to customers’ Deep Security Managers, automatically or on-demand, for deployment to thousands of servers within minutes.
Key Features and Benefits
- Provides targeted, software-based protection for the widest range of platforms used to run mission-critical applications and store sensitive data, including Windows, Solaris, Linux, HP-US, and AIX running on traditional hardware or VMware, Microsoft or Citrix virtualization platforms.
- Shields software vulnerabilities, which are commonly found in operating systems, enterprise and e-Health applications. This allows patches to be deployed on a more efficient, scheduled basis, with minimal impact on host or IT resources.
- Detects and prevents attacks that target medical, patient or personal data, and alerts staff the moment an attack has been attempted.
- Enables centralized, web-based management, allowing administrators to create and manage security policies, and track threats and preventive actions from a familiar, explorer-style UI.
- Proactively recommends the appropriate protection for servers and virtual machines, to ensure correct protection is in place, with minimal effort.
- Ensures standard security configurations are consistently and automatically applied to all appropriate systems, thus reducing the risk of an attack.
- Provides detailed log information on who attacked, when they attacked, and what they attempted to exploit. Administrators can be automatically notified when an incident has occurred.
- Works with security information and event management (SIEM) systems and includes a web-services interface for advanced automation
- Integrates with VMware vCenter, Microsoft Active Directory and other enterprise directories to allow organizational and operational information to be quickly imported into Deep Security Manager.
- Delivers a wide selection of detailed reports that document attempted attacks, and provide an auditable history of security configurations and changes. These reports can be generated and issued on a scheduled or ad-hoc basis.
- Automatically delivers regular security updates that protect newly discovered vulnerabilities from exploit.
PCI Compliance:
Addressing Today’s Top PCI Concerns
Achieving and maintaining PCI compliance and true security requires constant evaluation of the potential impact of evolving threats, employee behavior, and new business and technology initiatives. Trend Micro offers you unique and cost-effective solutions to address today’s top PCI challenges.
| Challenges | ||
|---|---|---|
| Business or Technology Driver | PCI Challenge | Trend Micro Solution |
| Virtualization | Virtualization allows for cost efficient and flexible datacenters and paves a path toward integrated cloud computing. But the complexity and fluidity of virtual environments pose special challenges, rendering traditional network security implementations for IPS, firewalls, and antivirus ineffective in preventing attacks on virtual servers that process or host cardholder data. | Trend Micro™ Deep Security provides advanced software-based security that protects physical, virtual and cloud-based servers with integrated IPS, firewall, configuration validation and more. Trend Micro™ Core Protection for Virtual Machines is designed specifically to meet the unique needs of the virtual environment with automated protection against malware. |
| Effective Data Protection | Traditional data loss prevention and data encryption solutions are complex and cumbersome to manage and use. | Trend Micro Data Protection solutions protect and encrypt PAN data wherever it resides and enable secure collaboration without end-user actions or usability limitations. |
| Worker Mobility | Mobile laptops and PDAs are at risk for inbound attacks and cardholder data loss, but network security solutions are ineffective in these cases. | Trend Micro OfficeScan™ endpoint protection and web reputation technology keep your employee devices protected from malware both on and off the corporate network. |
| IT Risk Management | Despite robust security measures, targeted and zero-day threats can penetrate even the most security-conscious organizations and threaten cardholder data security. | Trend Micro Vulnerability Management Services provides a SaaS-based suite of services which automate vulnerability, security, and compliance management across both internal and externally facing IT assets.
Trend Micro™ Threat Management Services provides network threat discovery and remediation services that detect and remove these evasive threats and continuously ensure your security posture. Deep Security delivers protection from zero-day threats and enables virtual patching to establish immediate protection for ‘un-patched’ or ‘un-patchable’ systems. |
| Controlling Cost and Complexity | According to Information Week, management complexity is the number one issue in security. With distributed environments, multiple point products and constant security signature updates, the cost and complexity of PCI compliance and secure operations is skyrocketing. | Trend Micro Enterprise Security and Smart Protection Network™ change the game by greatly simplifying security management and reducing resource requirements. We offer the breadth of solutions—including Software As A Service (SaaS) and virtualized appliances—that will allow you to reduce vendors, consolidate security and systems management, and cost effectively secure corporate and branch/POS (Point of Sale) environments. |
| Setting Your Budget Priorities | Rapidly achieving complete PCI compliance is difficult and costly. The PCI Council has issued a 6-step “prioritized approach” whitepaper which offers guidance on a risk-based prioritized compliance roadmap. | Trend Micro OfficeScan, Deep Security, and Messaging Security products each address many of the top-tier priorities cited by the PCI Council. |
Match the solution to the healthcare requirement:
Trend Micro offers proven solutions that address healthcare regulatory requirements. Beyond addressing regulations, these solutions enable you to truly safeguard your business infrastructure against the compromise of cardholder data.
The following table summarizes both the direct mappings with industry regulations and best practices recommended for protecting private healthcare data and your IT infrastructure.
| Challenges | |
|---|---|
| Healthcare IT Requirement | Direct Mapping |
| HITECH Act of 2009, § 13402, § 13407, Interim Regulations – Breach Notification for Unsecured Protected Health Information |
|
| HITECH Act of 2009, Interim Regulations – “Safe Harbor” through encryption and HIPAA § 164.312 (a)(2)(iv) – Encryption and decryption |
|
| HITECH Act of 2009/HIPAA § 164.308(b)(1) – Extend HIPAA requirements to business associates and HIPAA Security Rule § 164.308(b)(1), § 164.34(a)(1) – Business Associate Contracts or Other Arrangements | All Trend Micro solutions can be implemented by business associates, but if covered entity wants to enforce, they can use Trend Micro Email Encryption for ‘in the cloud’ key and encryption service hosting, all with zero client for the sending/receiving parties. |
| HIPAA § 164.306(a)(1) - Protect ePHI: facilities must protect the confidentiality, availability and integrity of all ePHI created, received, maintained, and transmitted | All Trend Micro solutions, implemented using the recommended risk assessment and best practices as highlighted by the NIST publications and the HSS interim rules |
| HIPAA § 164.514(d) Collect and use the minimum data necessary |
|
| HIPAA Security Rule § 164.312(e)(1) – Transmission Security |
|
| HIPAA Security Rule § 164.312(c)(1) – Integrity |
|
| HIPAA Security Rule § 164.312(a)(1) – Audit Controls |
|
| HIPAA Security Rule § 164.312(a)(1) – Access Control and § 164.312(d) – Person or Entity Authentication | All products offer the creation of unique user ID, etc. |
| HIPAA Security Rule § 164.310(d)(1) – Device and Media Controls |
|
| HIPAA Security Rule § 164.308(a)(5) – Security Awareness and Training and Rule § 164.308(a)(6) Security Incident Procedures |
|
| HIPAA Security Rule § 164.308(a)(1) – Security Management Process |
|
| HIPAA Security Rule § 164.308(a)(7)(ii)(A) – Data Backup Plan |
|
| HIPAA Security Rule § 164.308(a)(5)(ii)(B) – Protection from malicious software (NIST 800-53, AT-2, SI-3, SI-4, SI-9) |
|