The HIPAA Security Rule defines malicious software is defined as "software, for example, a virus, designed to damage or disrupt a system." To answer your specific question, yes, I think spyware and adware definitely falls in this category. No one but the marketing companies and other malicious outsiders benefit from spyware and adware. In fact, many organizations are harmed, and the security and privacy of PHI and other confidential information are breached every day from this stuff. Therefore, you should address and handle this malware just like any virus, worm or Trojan horse. There are some great shareware and commercial products out there to help fill this void that typical antivirus software doesn't cover.
For more info on this topic, please visit these SearchSecurity.com resources:
Dig deeper on HIPAA
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.