Practice - Creating an Audit Policy for HIPAA

In this example, you will use the predefined HIPAA Glossary entries that are provided with ZixGateway to pre-test the effects of applying two encryption policies. The first policy records the messages that contain HIPAA information in the body or attachments. The second policy records the messages that contain HIPAA information in the subject.

To create an audit policy:

  1. On the Status tab, select a cluster.
  2. On the Manage Policies tab, select the Content tab.
  3. Create an audit log for messages that contain HIPAA information in the body or attachments.

  4. Enter “HIPAA-Body_Atachments” in the Label field.
  5. Select the arrow next to the From field and enter “*@marketing.zixcustomer.com”, then click Add Pattern.
  6. Select the arrow next to the To field and select Enable All Patterns.
  7. Click .
  8. The Glossary and Bindings dialog displays.

  9. In the HIPAA Violation (standard) row, select Body and Attachments.
  10. Click OK.
  11. You are returned to the Content tab.

  12. In the Send Options row, select Send, Encrypt & Send, and Send Unencrypted.
  13. For Output Type select Audit (not matched).
  14. Click Apply.
  15. Create a log for those messages that contain HIPAA information in the subject.

  16. Enter “HIPAA-Subject” in the Label field.
  17. Select the arrow next to the From field and enter “*@marketing.zixcustomer.com”, then click Add Pattern.
  18. Select the arrow next to the To field and select Enable All Patterns.
  19. Click  
  20. The Glossary and Bindings dialog displays.

  21. Select Subject the HIPAA Violation (standard) row.
  22. Click OK.
  23. You are returned to the Configure a Content Policy form.

  24. In the Send Options row, select Send, Encrypt & Send and Send Unencrypted.
  25. For Output Type select Log (matched).
  26. Click Apply.

You have created Audit-Log policies that you can use for testing to see if the application of two HIPAA Encryption Policies will achieve the desired results.

View the audit results on the Content Log Server that you specified when you configured your ZixGateway appliance. See Viewing Audit-Log Results.

Main Topic