decisionhealth Newsletters, Part B News - 2024 Issue 9 (September)
Take key lessons learned from latest high-dollar Security Rule settlement
Subscribe or sign in to view the full article.
Article Overview
This article covers a recent Office for Civil Rights settlement involving potential HIPAA Security Rule issues after a ransomware attack, and explains the general compliance areas organizations should review in response. It is aimed at health care compliance, privacy, security, and IT leaders who want an overview of the risk analysis, contingency planning, vendor oversight, and workforce training themes discussed in the article.
Why This Topic Matters
The piece highlights a high-dollar enforcement action and connects it to practical security governance topics that affect covered entities and business associates. It helps readers understand the kinds of organizational safeguards and preparedness measures that are being emphasized in current HIPAA security enforcement.
Article Sections
-
Compliance
Introduces the OCR settlement and summarizes the broad HIPAA Security Rule issues raised by the investigation. It also outlines general remediation themes and security priorities for covered entities and business associates.
-
Risk analysis and management
Discusses the broader topic of risk analysis, vulnerability management, and related security planning practices. It also touches on commonly used frameworks and general operational considerations for maintaining a security program.
-
Craft contingency planning
Reviews contingency planning as a security preparedness topic, including business continuity and recovery planning concepts. It also addresses general training and exercise practices used to support response readiness.
What You Will Learn
- The enforcement and compliance themes associated with a HIPAA Security Rule settlement
- Why risk analysis and ongoing risk management are emphasized in security programs
- How contingency planning fits into ransomware preparedness
- What broad categories of safeguards and workforce practices are discussed for protecting ePHI
Who Should Read This
- HIPAA compliance officers
- Privacy officers
- Health information managers
- Healthcare IT and security teams
- Covered entities
- HIPAA business associates
- Practice administrators
Subscribe or sign in to view the full article.



Quick, Current, Complete - www.findacode.com