HIPAA Covered entities, including hospitals and physicians who are implementing electronic records with hopes of attaining Meaningful Use and qualifying for federal incentives, are performing a computer security risk analysis, or risk assessment. Conducting regular risk assessments has been a requirement of HIPAA since 2005. However, many organizations have been weak in their compliance. Organizations [...]
The Obama Administration continues to accelerate its enforcement of the HIPAA Privacy and Security rules. This month saw two additional $1M+ fines. On February 4, 2011, the Department of Health and Human Services (HHS) issued its first-ever Civil Monetary Penalties. The fines were levied against a Washington DC area clinic/health plan, Cignet Health, which received [...]
Risk Assessment: Quantifying Risk and Impact