decisionhealth Newsletters, Part B News - 2024 Issue 9 (September)
Part II: Heed lessons from high-dollar Security Rule settlement
Subscribe or sign in to view the full article.
Article Overview
This article discusses operational guidance for organizations looking to strengthen HIPAA Security Rule compliance after a high-dollar settlement. It focuses on broad areas such as policy review, monitoring regulatory changes, vendor and contractor oversight, breach notification planning, incident response controls, and ongoing workforce training. The piece is aimed at compliance, privacy, security, and healthcare IT stakeholders evaluating their own policies and third-party relationships.
Why This Topic Matters
It helps organizations understand the kinds of governance, documentation, monitoring, and training practices that can affect security compliance and third-party risk management in healthcare settings.
Article Sections
-
Policy and procedure updates
Discusses maintaining and periodically reviewing organizational policies and procedures in response to changing regulations and threats. It also addresses compliance coordination, communication, and use of technology to support policy management.
-
Vendor and contractor relationships
Covers due diligence for outside relationships, including oversight practices, contractual planning, and ongoing monitoring of vendor compliance. The section also addresses how organizations may evaluate third-party security posture and related controls.
-
Incident response and audit controls
Reviews broad incident response planning, logging, audit practices, and access control considerations. It also touches on security monitoring tools and organizational safeguards for protected health information.
-
Training never ends
Focuses on employee training and continuing education as part of an ongoing compliance program. It mentions interactive training formats used to reinforce awareness and adherence.
What You Will Learn
- How organizations can structure a proactive compliance maintenance process
- What areas are commonly addressed in vendor oversight and contractual security management
- Which broad components are involved in incident response and audit readiness
- How ongoing workforce training supports privacy and security compliance efforts
Who Should Read This
- Healthcare compliance professionals
- Privacy and security officers
- Healthcare IT leaders
- Practice managers
- Risk management teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com