Conference on HIPAA Security Risk Analysis Software – Not all Tools are Created Equal

Expiré
Dates : 10 décembre 2015 » 10 décembre 2015

Lieu : Fremont, Californie
États-Unis

Book your hotel


Organisateur :

Domaine : Santé et Médecine; HIPAA Security Risk Analysis Software – Not all To
Mathématiques et Statistiques; Sciences de l'ingénieur; Informatique; Economie; Santé et Médecine;
Mots-clé:: Analysis, Information Security, Technology, Data Security, Security and Privacy, Information Technology, Internet, Business, Health
Description :

Overview: Under the Health Insurance Portability and Accountability Act (HIPAA) Security Rule all electronic protected health information (e-PHI) created, received, maintained, or transmitted by a "covered entity" and "business associate" is subject to the Security Rule. If we assume that information technology powers modern health care, then it stores or disseminates most everything an entity might know about a patient. Thus, e- PHI security and privacy is fundamental and paramount.

The Security Rule requires entities to evaluate risks and vulnerabilities in their technology environments and to implement reasonable and appropriate security measures to protect e-PHI. The Office for Civil Rights (OCR), the security watchdog for the Department of Health and Human Services (DHHS), in particular, is responsible for issuing annual guidance on the provisions in the HIPAA Security Rule.1 The OCR is also the body responsible for ensuring that covered entities are complying with the intent of the Security Rule. From a compliance perspective then, it may seem especially wise to take heed to what the OCR is saying.

In its first guidance released on July 14, 2010,2 the OCR states "A risk analysis is foundational, and must be understood in detail before OCR can issue meaningful guidance that specifically addresses safeguards and technologies that will best protect electronic health information."

In short, an information technology risk analysis is the fundamental security cornerstone the DHHS expects covered entities to meet. As the OCR ratchets up its compliance activities, as it has promised to do after the passage of the Health Information Technology for Economic and Clinical Health (HITECH) Act, covered entities who have not conducted an adequate. 

A risk analysis using a risk-based approach is the very foundation from which to build your information security compliance program. Without this baseline, your organization is swimming aimlessly.

The OCR goes on to stress in its Guidance on Risk Analysis: We note that some of the content contained in this guidance is based on recommendations of the National Institute of Standards and Technology (NIST). NIST, a federal agency, publishes freely available material in the public domain, including guidelines. Although only federal agencies are required to follow guidelines set by NIST, the guidelines represent the industry standard for good business practices with respect to standards for securing e-PHI. Therefore, non-federal organizations may find their content valuable when developing and performing compliance activities. So in short, OCR "suggests" that a covered entity might use the NIST risk-based approach for doing a risk analysis. Our view is that when CMS "suggests" something, it very much is like God telling you to do so. "Suggestion" is merely loosely worded as an imperative. Of course, other good risk frameworks exist, such as Control Objectives for Information Technology (COBIT) developed by the Information Systems for Auditing and Control Association (ISACA), or Octave developed by the CERT institute at the Carnegie-Mellon University. These frameworks may be used, but why bother? The NIST guidance, as provided in its Special Publication 800-30 and 800-30 rev1, is excellent, thorough, and easily tailored for small, medium, and large covered entities. In short, any solution must encompass the 78 HIPAA Security Audit Protocols, as issued by the OCR, combined with the NIST SP800-30 rev1 methodlolgy. I believe only the software solutions that can simplify the rules, automate the risk analysis process and documentation which have passed numerous audits are worth considering. 

Why should you attend: HIPAA doesn't require any specific certification to HIPAA Security Risk Analysis software or professional services. When is the investment needed for third-party professional services versus self-assessing? How do you know the software or firm hired is qualified to give your organization assurances for compliance and security? How can a tool scale up or down for smaller organizations and larger organizations with complex Parent-Child relationships (i.e. regional, county or national offices). Group Health Plans, Hospitals, Clinics and Business Associates all have unique needs so selecting software tools that covers all the requirements while automating as much of the documentation and processes as possible is paramount. Attend this session to ensure the choices you make are guaranteed success for your organization's investment. 

Areas Covered in the Session:

  • Introduction to Speaker
  • Industry events and trends
  • How to do a HIPAA Security Risk Analysis
  • How free and commercial tools handle this
  • Pros and Cons with each type of solution offering


Who Will Benefit:

  • HIPAA Privacy and Security Officers
  • Business Associates & Subcontractors
  • Healthcare Business Insurers
  • Health Information Management Professionals
  • Healthcare In-house Legal Counsel
  • Healthcare Risk Managers
  • EHR & PHR Vendors
  • State and Federal Government Policymakers
  • Healthcare Attorneys
  • Healthcare Consultants
  • Medical Records/Health Information Managers (HIM)
  • Clinic Owners & Operations Managers

 

Speaker :

 

Steven Marco , President of Modern Compliance Solutions, has a passion for IS Security and over 18 years as a leader in executing various regulatory compliance mandates and Health IT. A CISA since 1999, he helped pioneer Internet Security Services and manage risk for numerous Fortune 500 companies while at Deloitte & Touche. At Resources Global Professionals, he led IT through their Sarbanes Oxley 404 audit and successful IPO in 2002. He currently drives risk management services through data security and regulatory compliance consulting, while developing industry-leading compliance automation software called HIPAA One. Steve holds a Bachelor’s Degree from Ryerson University in Computer Information Systems Management and Corporate Law.

 

Price : $139.00 

 

 

Contact Info:

 

 

MentorHealth

Phone No: 1-800-385-1607

FaX: 302-288-6884 

support@mentorhealth.com

Event Link: http://bit.ly/1P23QCA

http://www.mentorhealth.com/


Conference on HIPAA Security Risk Analysis Software – Not all Tools are Created Equal se tiendra en Fremont,CA,USA, États-Unis entre le 10 décembre 2015 et 10 décembre 2015.Il couvre des domaines spécifiques de Santé et Médecine comme HIPAA Security Risk Analysis Software – Not all To. Visitez le site web de la conférence pour des informations plus détaillées ou contactez l'organisateur pour des questions spécifiques.
Ajouter au calendrier 2015-12-10 2015-12-10 Europe/London Conference on HIPAA Security Risk Analysis Software – Not all Tools are Created Equal https://www.sciencedz.net/fr/conference/16040-conference-on-hipaa-security-risk-analysis-software-ndash-not-all-tools-are-created-equal Fremont,CA,USA - États-Unis

Trouver d'autres conférences connexes

Vous cherchez d'autres conférences scientifiques auxquelles participer ? Explorez un large éventail d'événements à venir dans divers domaines et lieux. Que vous recherchiez des sujets spécialisés, des lieux spécifiques ou des dates, nous avons un large éventail de conférences à vous proposer.
Conférences en Santé et Médecine en États-Unis 2015 : Découvrez les dernières tendances et recherches en Santé et Médecine en participant à des conférences en États-Unis en 2015. Créez des réseaux avec des professionnels, des chercheurs et des leaders de l'industrie pour rester à la pointe des avancées technologiques.
Conférences et séminaires en Californie
Conférences et séminaires en États-Unis
Conférences et séminaires en États-Unis en 2015
Conférences et séminaires en Santé et Médecine
Conférences et séminaires en Santé et Médecine en 2015
Conférences et séminaires en Santé et Médecine en États-Unis
Conférences et séminaires en Santé et Médecine en États-Unis en 2015
Tous les événements
Evénements par pays

Avertissement: Nous visons à fournir des informations exactes et fiables sur les événements à venir, mais nous ne pouvons pas accepter la responsabilité pour le texte des annonces ou de la bonne foi des organisateurs de l'événement.S'il vous plaît, n'hésitez pas à nous contacter si vous remarquez des informations incorrectes ou trompeuses et nous tenterons d'y remédier.Nous ne sommes impliqués dans l'organisation d'aucun des événements répertoriés et nous ne gérons pas les paiements d'inscription au nom des organisateurs.