In August 2009, the Federal Trade Commission (FTC) issued the Health Breach Notification Rule (Breach Rule), which requires vendors of personal health records and related entities to provide notice to consumers following a breach. After over a decade without any...
Clearwater Rated Healthcare’s Top Security Advisor and Compliance and Risk Management Solution
Ranking in Black Book’s Survey of Nearly 3,000 Security and IT Professionals Affirms Breadth and Strength of Company’s Expertise and Capabilities
HIPAA Security Rule Compliance: A Discussion with Former OCR Director Roger Severino
In statements throughout his tenure as Director of HHS' Office for Civil Rights from 2017-2021, Roger Severino was repeatedly critical of organizations for not performing a risk analysis or taking action to mitigate identified risks, as required by the HIPAA Security...
Tech Vendor Email Breach Affects Dozens of Health Entities
Incident Is Latest Reminder of Business Associate Security Risks
Technical Testing and the HIPAA Security Rule: What’s Needed to Protect Your Healthcare Organization
Introduction The HIPAA Security Rule, is a set of national standards designed to help organizations protect PHI that’s created, received, used, or maintained by a healthcare covered entity, with compliance expectations that extend to business associates as well....
How Physician Groups Can Overcome Common Cybersecurity and HIPAA Compliance Challenges
Introduction Across the healthcare industry, large physician groups are becoming increasingly common, as investors bring disparate physician practices together to keep up with healthcare challenges and ever-more complex treatment and service delivery needs. Today,...
Building Frameworks to Manage Healthcare Data Within the Changing U.S. Privacy Landscape
Introduction As the world is more connected to digital life, state and federal agencies are issuing a growing number of standards and mandates focused on data privacy and protection. Across the U.S., many states—for example, California, Nevada, and Maine—have already...
Risky Business: How to Conduct a NIST-based Risk Analysis to Comply with the HIPAA Security Rule
In addition to being a HIPAA Security Rule requirement, conducting regular risk analyses is a fundamental business practice, yet many healthcare organizations struggle with the basics, from understanding Introduction Despite many warnings from the Office for Civil...
Build A Culture of Compliance Through Principle-Based Policy Governance
Introduction Organizations of all sizes struggle with embedding policies and procedures successfully into their day-to-day operations. That’s because for many, these policies fill binders and shared drives, overwhelming employees with pages and pages of instruction...
Entities Dealing With Email Breach, IT Systems/Phone Outage
Latest Incidents Foreshadow Challenges Heading Into New Year