BC Advantage - 2019 Issue 2
Recent HHS Guidance Underscores the Importance of HIPAA Compliance
Subscribe or sign in to view the full article.
Article Overview
This article explains how recent HHS cybersecurity guidance fits into HIPAA, HITECH, and related federal security expectations for healthcare organizations. It is aimed at healthcare compliance, privacy, security, and operations professionals who need a broad understanding of the guidance, the risk-management framework it supports, and the organizational practices discussed in the article.
Why This Topic Matters
The article helps readers understand why cybersecurity guidance from HHS and related organizations matters for protecting patient information, supporting compliance efforts, and reducing breach risk and associated costs.
Article Sections
-
The December 2018 HHS Health Industry Cybersecurity Practices Publication
Introduces the HHS cybersecurity publication, its purpose, and its role in supporting healthcare cybersecurity awareness and guidance. Summarizes the publication’s overall scope and its relationship to industry-led best practices.
-
Practical Applications of the Guidance
Discusses how the guidance may be applied within healthcare organizations through broader risk-management approaches. Also covers related cybersecurity framework concepts and the organizational areas emphasized in the article.
-
Designated Security Officer
Describes the organizational responsibility for security leadership and the role discussed in the article within a compliance program.
-
Security Policy Framework
Covers policy, procedure, and documentation topics associated with managing security risk and supporting organizational safeguards.
-
Annual Risk Analyses
Addresses ongoing risk analysis activities and the article’s discussion of assessing threats, vulnerabilities, and organizational exposure.
-
Technical Safeguards
Reviews technical safeguard concepts discussed in the article, including layered security, monitoring, and protection of sensitive information and systems.
-
Security Awareness and Training Program
Summarizes the training-related aspects of the guidance, including workforce awareness and role-based education.
-
Conclusion
Closes with the article’s high-level message about the value of using cybersecurity guidance to support compliance and risk reduction.
What You Will Learn
- How HHS cybersecurity guidance relates to HIPAA compliance efforts
- What broad categories of cybersecurity practices are discussed for healthcare organizations
- How risk management frameworks are presented in the context of healthcare security
- Which organizational safeguards and training areas are emphasized
- Why the guidance is relevant to privacy, security, and compliance teams
Who Should Read This
- Healthcare compliance professionals
- Privacy officers
- Security officers
- Healthcare administrators
- Business associates and subcontractors
- IT and cybersecurity teams in healthcare
- Legal and risk management professionals
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com