Introduction As the world is more connected to digital life, state and federal agencies are issuing a growing number of standards and mandates focused on data privacy and protection. Across the U.S., many states—for example, California, Nevada, and Maine—have already...
Risky Business: How to Conduct a NIST-based Risk Analysis to Comply with the HIPAA Security Rule
In addition to being a HIPAA Security Rule requirement, conducting regular risk analyses is a fundamental business practice, yet many healthcare organizations struggle with the basics, from understanding Introduction Despite many warnings from the Office for Civil...
Build A Culture of Compliance Through Principle-Based Policy Governance
Introduction Organizations of all sizes struggle with embedding policies and procedures successfully into their day-to-day operations. That’s because for many, these policies fill binders and shared drives, overwhelming employees with pages and pages of instruction...
Entities Dealing With Email Breach, IT Systems/Phone Outage
Latest Incidents Foreshadow Challenges Heading Into New Year
Report Dissects Conti Ransomware Attack on Ireland’s HSE
Outlines Key Shortcomings That Country’s National Health System Must Address
Keys to an Effective HIPAA Data Breach Response
Wes Morris, Managing Principal Consultant, Clearwater, speaks with Andrea Lee Linna, Partner, McGuireWoods, about the key steps that can make the difference between an organization's effective response to a HIPAA data breach and one that sets it down a troublesome...
How to stop ransomware? It starts with an enterprise risk management program
“It’s not about ultimate security. It’s about doing what’s right for the organization, and it should be business-driven,” said one expert at the HIMSS Healthcare Cybersecurity Forum.
Convincing healthcare boards of cybersecurity needs
Clearwater Compliance vice president for consulting services Cathie Brown stresses the need for cybersecurity collaboration between the board and IT pros.
Technical Testing and the HIPAA Security Rule: What’s Needed to Safeguard Your Organization
This presentation is a recording of a web event given on 11/23/2021 by Clearwater Consultant, Chris Dowhan, OSCP, GREM, GWAPT Overview As defined in 45 CFR §164.308(a)(8), technical evaluations are a part of the HIPAA Security Rule, but with no testing methodology or...
Ohio Hospital Still Struggling One Week After Cyberattack
How Can Other Healthcare Entities Better Prepare for Disruptive Attacks?