90 likes | 196 Vues
This presentation by Bob Perlitz, President/CEO of Healthcare IS Consultants LLC, delves into the intricate challenges of HIPAA security compliance. It covers critical components including technical safeguards, administrative policies, and the importance of audit controls. Key standards such as contingency planning, risk analysis, and risk management are discussed extensively. Learn how to navigate the complexities of workforce security, access controls, and disaster recovery while ensuring the confidentiality and integrity of electronic protected health information.
E N D
HIPAA SecurityThe Biggest Challenge! Presented by: Bob Perlitz President/CEOHealthcare IS Consultants LLC
The “Pretenders” • 164.312 Technical Safeguards • (b) Standard: Audit Controls - Required • 164.308 Administrative Safeguards • (a) (7) (i) Standard: Contingency Plan • (A) Data Backup Plan - Required • (B) Disaster Recovery Plan – Required • (C) Emergency Mode Operations Plan - Required • (D) Testing & Revision Procedures – Addressable • (E) Applications & Data Criticality - Addressable
The “Contender”Access Controls • 164.308 Administrative Safeguards • (a) (3) Workforce Security – Addressable • 1 Specification • (a) (4) Information Access Management – Addressable • 2 Specifications • 164.310 Physical Safeguards • (a) Facility Access Controls – Addressable • 4 Specifications • 164.312 Technical Safeguards • (a) Access Control – 2 Required and2 Addressable • 4 Specifications
The “Undisputed Champ” Security Management Process • Risk Analysis - Required • Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity. • Risk Management - Required • Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a)