|
The Proofpoint Regulatory Compliance™ module makes it easy to ensure that your electronic communications—including email, webmail, web postings and FTP—do not improperly disclose sensitive data about employees, customers or patients. By blocking, quarantining or encrypting such content, it ensures that your organization follows best practices for data protection. It helps ensure compliance with many different types of email-related information privacy regulations, including HIPAA, GLBA, PCI compliance guidelines and SEC regulations. Predefined dictionaries and "smart identifiers" automatically scan for a wide variety of non-public information, including PHI (protected health information as defined by HIPAA), PFI (personal financial information as defined by GLBA) and international identification standards and let you take appropriate actions on noncompliant communications.
"There are thousands of PHI codes that we need to keep up-to-date, so I was impressed that I don't need to do dictionary maintenance - Proofpoint takes care of that. With our limited resources, our department does not have time to field a lot of rules. That's why it's so nice to have a solution like Proofpoint that works right out of the box and requires minimal ongoing maintenance." - Sharon Finney, Information Security Administrator, DeKalb Medical Center
Large enterprises, universities and government organizations are now subject to a growing number of privacy-related regulations that govern the handling of certain types of non-public information (NPI). These regulations extend to the content of email messages leaving the organization. Ensures Compliance with HIPAA, GLBA and Other RegulationsThe Proofpoint Regulatory Compliance™ module makes it easy to ensure that outbound messages comply with many different types of email-related regulations. Pre-defined dictionaries and "smart identifiers" automatically scan messages and attachments for a wide variety of non-public information including PHI (protected health information as defined by HIPAA) and PFI (personal financial information as defined by GLBA) and let you take appropriate actions on non-compliant communications. Rules can be easily created or modified via a point-and-click interface to support compliance with many other types of information privacy and data security regulations, such as state regulations (e.g., California AB 1950 and California SB 1386), Canada's PIPEDA, and various European privacy directives. Detect All Types of Privacy Data Inside EmailProofpoint Regulatory Compliance includes a wide variety of out-of-the-box features that help keep your organization compliant with today's information privacy rules. Proofpoint Regulatory Compliance monitors all outgoing email to detect NPI based on dictionaries as well as common NPI identifiers. Pre-defined and Custom DictionariesA variety of pre-defined dictionaries are included with Proofpoint Regulatory Compliance. These dictionaries define common protected health information code sets—such as standard disease, drug, treatment and diagnosis codes used by the healthcare industry—to simplify HIPAA compliance. Proofpoint also includes a variety of financial privacy dictionaries-such as SEC, insider trading and trade confirmation terms used in the financial services industry-to aid with compliance with GLBA, PCI and SEC compliance. New dictionaries can also be defined. These dictionaries can support both exact matches as well as regular expressions. The included HIPAA dictionaries can be expanded to include terms and codes specific to your medical environment, and new dictionaries can be added to support additional regulations such as NASD, PIPEDA, and others. Dictionary terms can be weighted to increase or decrease the matching strength of any term, or to allow exceptions. The Proofpoint Dynamic Update Service™ ensures that installed dictionaries are always up to date with the latest codes. NPI IdentifiersProofpoint Regulatory Compliance can also scan for common NPI identifiers such as US Social Security, Canadian Social Insurance, UK National Insurance, Japanese residence registration and driver's licence ID numbers, ABA routing numbers, and US and international credit card numbers. These "smart identifiers" are more sophisticated than simple regular expressions. The module looks for the correct number of digits, but also computes checksums to confirm that numerical strings that appear to be NPI are actually protected information. This technique greatly reduces the chance of false positives. Custom smart identifiers can easily be added to support customer-specific data types such as account numbers, patient numbers, medical record numbers, billing codes and local forms of ID. Like Proofpoint's built-in smart identifiers, custom-created identifiers can perform complex, algorithmic processing to ensure high detection accuracy while minimizing false positives. Flexible Privacy Rules and Policy DefinitionsA point and click interface makes defining and modifying even complex information privacy rules quick and easy. Rules can be configured to apply to individual occurrences of NPI or when a certain count of dictionary or NPI identifiers is reached. For example, a rule for tracking fraud or theft of credit card numbers can be setup to trigger only if more than three credit card numbers are detected in a message. Any number of information privacy rules can be defined to support specific compliance requirements. Multiple rules can be mapped into policies, for example a HIPAA policy, GLBA policy and AB 1950 policy. Policies can be further customized to apply only to lists of business partners or only to specified inbound or outbound message routes. Proofpoint’s policy and content scanning engines detect and “understand” text in any language, including multi-byte languages. Data loss prevention policies can match non-English keywords and dictionary terms written in international character sets including Japanese, Chinese and Cyrillic. Encryption SupportMany regulations specify that non-public data must be transmitted in a secure or encrypted format. Proofpoint Regulatory Compliance supports two types of encryption:
ReportingProofpoint Regulatory Compliance helps your organization monitor or track compliance progress with graphical reports that show the number of regulatory breaches over a given timeframe as well as the top offenders of these policies. Reports can be emailed on a scheduled basis or published to an intranet site. In most enterprises, content security policies are managed by a variety of business users who own responsibility for compliance or data protection. Proofpoint Compliance Incident Manager™ reports make it easy for these managers to review content security violations and take appropriate actions on non-compliant messages. Managers are immediately notified of policy violations and associated severity levels, so business users can easily and effectively review non-compliant messages and release, reroute, approve or otherwise dispose of such messages using Proofpoint's graphical user interface. As a first step to understanding their regulatory risk exposure in email, organizations can deploy Proofpoint Regulatory Compliance in an audit mode, which monitors all regulatory breaches without altering messages in any way. Reports can then be used to quantify your organization's level of risk. Smart IdentifiersProofpoint's smart identifier technology offers higher accuracy than simple regular expressions, looking not just for a certain pattern of characters, but also computing checksums, incorporating dictionary lookups or performing other tests to confirm that alphanumeric strings that appear to be violations are truly protected information. A plug-in architecture allows customers to add their own customized "smart identifiers" to Proofpoint Regulatory Compliance as needed. Custom smart identifiers can be created for detecting customer- or location-specific data types such as account numbers, patient numbers, medical record numbers, billing codes, local forms of ID, etc. Like Proofpoint's built-in smart identifiers, custom-created identifiers can perform complex, algorithmic processing to ensure high detection accuracy while minimizing false positives. Quick Inspection Violation AnalysisIn most enterprises, content security policies are managed by a variety of business users—such as compliance, security, risk management, HR and other line-of-business managers—who own responsibility for compliance and privacy protection. The Proofpoint Regulatory Compliance™ module's "quick inspection" violation view makes it easy for these users to more rapidly identify and take action on messages and attachments that are flagged as privacy breaches or policy violations. Attachment Scanning and Support for Custom or Proprietary Document TypesBuilt-in attachment scanning capabilities allow you to apply your Regulatory Compliance policies to the contents of message attachments. Policies can be enforced on content in more than 400 types of document attachments. In addition to the hundreds of built-in document types that Proofpoint's outbound email security modules natively understand, administrators can use Proofpoint's File Type Profiler to easily extend support to new, custom or proprietary file types (e.g., proprietary CAD/CAM formats). Flexible Message ActionsMessages that are identified as containing NPI can be handled using any of Proofpoint's standard message dispositions, including:
Compliant SecurityMany privacy and data security regulations not only specify rules for handling non-public information, but also define security requirements for systems that process this information. Proofpoint provides the security and access control features required to meet these regulations.
Proofpoint Regulatory Compliance is the industry's most advanced and easy-to-use solution for protecting data privacy in email and other message streams, offering:
Smart Identifiers and Dictionaries Included with Proofpoint Regulatory ComplianceProofpoint Regulatory Compliance Includes the essential building blocks to meet a wide variety of privacy regulations right out of the box: Healthcare code setsThe module includes a large assortment of dictionaries preloaded with code sets for PHI detection, required for compliance with HIPAA and other healthcare regulations.
Financial & privacy smart identifiersIncludes "smart identifiers" for personal identity and PFI detection, such as:
Customized smart identifiersA plug-in architecture allows you to add your own custom "smart identifiers" for customer- or location-specific data types such as:
DeKalb Medical CenterThis Atlanta, GA hospital system uses Proofpoint Regulatory Compliance to ensure the security of protected health information while blocking hundreds of thousands of spam emails each month. Integration with PGP encryption ensures that sensitive information is automatically encrypted before transmission. Outback SteakhouseRestaurant chain Outback Steakhouse grills spam and viruses with the Proofpoint Messaging Security Gateway anti-spam appliance. Outback also protects sensitive customer information in outbound email using Proofpoint's Regulatory Compliance and Secure Messaging modules. Meadville Medical CenterThis 1300 employee hospital uses Proofpoint Regulatory Compliance and Secure Messaging modules to ensure the security of protected health information - and HIPAA compliance - by automatically encrypting email that contains sensitive PHI before transmission. MedCentral Health SystemThis Ohio-based hospital system keeps 3000 inboxes secure against spam and HIPAA compliance violations using the Proofpoint messaging security appliance. Pella Regional Health CenterThis Iowa health clinic group uses Proofpoint Regulatory Compliance to ensure the security of patient health information. Content-aware encryption ensures that sensitive information in email is transmitted in compliance with HIPAA regulations. Placer County Office of EducationCalifornia's fastest-growing school districts keep student information secure-while blocking spam and viruses-using Proofpoint's inbound & outbound email security modules. South Nassau Communities HospitalThis Long Island acute care facility uses Proofpoint to ensure that outbound email complies with HIPAA regulations that protect the confidentiality of patient personal health information. Proofpoint Regulatory Compliance automatically enforces compliance while anti-spam and anti-virus features keep 2200 inboxes clean. |
![]() WebinarsRelated ModulesWhite Papers![]() |