Instructor:
William Miaoulis
Product ID: 703347
Why Should You Attend:
Risk analysis and risk management plans are the foundation of a HIPAA compliance program and should be complete and provide the documentation that an examiner may ask for. Risk assessments are a key part of effective risk management and facilitate decision making at all three tiers in the risk management hierarchy including the organization level, network level, and information system level. Completing a risk analysis will guide an organization to make cost effective, risk based decisions and provide an enhanced security environment to protect data and reduce the risk of a reportable security breach.
This webinar will guide the user on the principles of risk analysis and risk management to prioritize risks. It will rely heavily on the NIST 800-30 which is mentioned in the preamble of the original rule and the OCR issued guidance on risk analysis (as revised and finalized on 09/18/2012.)
This session will:
Areas Covered in the Webinar:
Who Will Benefit:
This webinar will provide valuable assistance to all personnel in medical offices, practice groups, hospitals, academic medical centers, insurers, business associates (shredding, data storage, systems vendors, billing services, etc). The titles are:
William Miaoulis, CISA, CISM, is a senior healthcare information system (IS) professional with more than 20 years of healthcare Information Security experience. Mr. Miaoulis is the founder and primary consultant for HSP Associates. Prior to starting HSP Associates in January of 2013, Bill was the Chief Information Security Officer (CISO) and led the HIPAA security and privacy consulting efforts for Phoenix Health Systems for over 11 years and also was the HIPAA Consulting Manager for SAIC for 18 months. For seven years, he was the University of Alabama Birmingham (UAB) Medical Center’s Information Security Officer, where he instituted the first security and privacy programs at UAB starting in October 1992.
Mr. Miaoulis contributes to the industry by frequently speaking at conferences on security matters, including recent sessions on Risk Analysis/Risk Management, Creating and Implementing Effective Security Policies, Understanding the HIPAA Security Rule, and Creating Effective Security Incident Response Procedures. He has been interviewed and quoted by numerous publications including: SC Magazine, Health Data Management, Briefings on Healthcare Security, Computerworld; and Health Information Compliance Insider. He has worked with AHIMA to produce the book “Preparing for a HIPAA Security Compliance Assessment” and also has worked on updating the AHIMA Security Practice Briefs.
Topic Background:
The HIPAA security rule requires the risk analysis be completed to determine security risks to the confidentiality, integrity and availability of protected health information. It also requires implementing measures “to sufficiently reduce those risks and vulnerabilities to a reasonable and appropriate level.”
Organizations have been fined or agreed to pay millions of dollars and agree to compliance action plans when the OCR auditors have found them to be HIPAA non-compliant. In addition, the lack of sufficient controls has led to many organizations having to report breaches to HHS, the patient and the media. The EMR Meaningful Use Post-Pay audits will request an entities risk analysis(s) and supporting implementation plans and completion dates such as:
“Protect Electronic Health Information: Provide proof that a security risk analysis of the Certified EHR Technology was performed prior to the end of the reporting period (i.e. report which documents the procedures performed during the analysis and the results of the analysis). If deficiencies are identified in this analysis, please supply the implementation plan; this plan should include the completion dates.”
It is not the vendor’s responsibility to conduct an application risk analysis; it is the covered entities responsibility. The Meaningful Use guidance has also shown that your risk analysis cannot be limited to just the Certified Electronic Medical Record.
Our refund policy is governed by individual products and services refund policy mentioned against each of offerings. However in absence of specific refund policy of an offering below refund policy will be effective.
Registrants may cancel up to two working days prior to the course start date and will receive a letter of credit to be used towards a future course up to one year from date of issuance. ComplianceOnline would process/provide refund if the Live Webinar has been cancelled. The attendee could choose between the recorded version of the webinar or refund for any cancelled webinar. Refunds will not be given to participants who do not show up for the webinar. On-Demand Recordings can be requested in exchange. Webinar may be cancelled due to lack of enrolment or unavoidable factors. Registrants will be notified 24hours in advance if a cancellation occurs. Substitutions can happen any time. On-Demand Recording purchases will not be refunded as it is available for immediate streaming. However if you are not able to view the webinar or you have any concern about the content of the webinar please contact us at below email or by call mentioning your feedback for resolution of the matter. We respect feedback/opinions of our customers which enables us to improve our products and services. To contact us please email [email protected] call +1-888-717-2436 (Toll Free).
+1-888-717-2436
6201 America Center Drive Suite 240, San Jose, CA 95002, USA
Copyright © 2023 ComplianceOnline.com Our Policies: Terms of use | Privacy
PAYMENT METHOD: 100% Secure Transaction