A Multi-Tiered Approach to Risk Monitoring Strategy

A Multi-Tiered Approach to Risk Monitoring Strategy

The HIPAA Security Rule, as well as NIST and other standards, stipulate that a risk analysis and risk management process should be ongoing, and not a once and done process. The Office for Civil Rights “Guidance on Risk Analysis Requirements Under the HIPAA Security...
A Thoughtful Approach to Managing Cyber Risk

A Thoughtful Approach to Managing Cyber Risk

As my colleague Alex Masten did an excellent job of describing in another recent Clearwater blog, the HIPAA Security Rule maintains that a risk analysis must be performed as new systems and technologies are implemented, or there are any material environmental changes....