HIPAA and information security risk: Implementing an enterprise-wide risk management strategy

被引:1
|
作者
Alberts, C [1 ]
Dorofee, A [1 ]
机构
[1] Carnegie Mellon Univ, Inst Software Engn, Pittsburgh, PA 15213 USA
关键词
HIPAA; information security risk; information security readiness; OCTAVE; practice; asset; threat; vulnerability;
D O I
10.1117/12.435462
中图分类号
R318 [生物医学工程];
学科分类号
0831 ;
摘要
The Health Insurance Portability and Accountability Act (IAA) of 1996 effectively establishes a standard of due care for healthcare information security. One of the challenges of implementing policies, procedures, and practices consistent with HIPAA requirements in the Department of Defense Military Health System (MHS) is the need for a method that can tailor the requirements to a variety of organizational contexts. This paper will describe a self-directed information security risk evaluation that will enable military healthcare providers to assess their risks and to develop mitigation strategies consistent with HIPAA guidelines. The self-directed risk assessment can be tailored for the ranges of operating environments found in the MHS. It will focus on both organizational and technological improvements using the HIPAA regulations as a benchmark for information security readiness. The evaluation will utilize a interdisciplinary team in an organization to oversee the process and apply recommendations generated by the team. In addition, staff from multiple organizational levels in the organization will contribute their unique knowledge of the enterprise's operations. This information combined with technology-based vulnerabilities yields the organization's risks. This paper will also describe the results of early field tests of the evaluation and provide a summary of lessons learned.
引用
下载
收藏
页码:97 / 108
页数:12
相关论文
共 50 条
  • [31] Implementing a risk management approach for optimizing information security systems
    Petrescu, Marius
    Stegaroiu, Ion
    Braboveanu, Mioara
    Petrescu, Anca-Gabriela
    Sirbu, Nicoleta
    BUSINESS TRANSFORMATION THROUGH INNOVATION AND KNOWLEDGE MANAGEMENT: AN ACADEMIC PERSPECTIVE, VOLS 1-2, 2010, : 304 - 309
  • [32] The Power of Enterprise PMOs and Enterprise-Wide Project Management
    Frame, Davidson
    PROJECT MANAGEMENT JOURNAL, 2015, 46 (05) : E4 - E4
  • [33] A methodology for enterprise-wide risk assessment in small banks and credit union
    Duncan, Philippa
    JOURNAL OF MONEY LAUNDERING CONTROL, 2021, 24 (02): : 372 - 393
  • [34] IT Security Live 2013 - Control of enterprise-wide IT infrastructures
    IT-Security Live 2013 - Beherrschung von unternehmensübergreifenden IT-Infrastrukturen
    Schimpf, G., 1600, Springer Verlag (36):
  • [35] An Enterprise-Wide Knowledge Management Approach to Project Management
    Oun, Tariq A.
    Blackburn, Timothy D.
    Olson, Bill A.
    Blessner, Paul
    ENGINEERING MANAGEMENT JOURNAL, 2016, 28 (03) : 179 - 192
  • [36] An enterprise-wide knowledge management system infrastructure
    Lee, SM
    Hong, SG
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2002, 102 (1-2) : 17 - 25
  • [37] Enterprise-wide integrated infrastructure asset management
    1600, Public Works Journal Corp, Ridgewood, NJ, USA (126):
  • [38] An enterprise-wide knowledge management system infrastructure
    Lee, Sang M.
    Hong, Soongoo
    Industrial Management and Data Systems, 2002, 102 (1-2): : 17 - 25
  • [39] Enterprise-wide information logistics: Conceptual foundations, technology enablers, and management challenges
    Winter, Robert
    PROCEEDINGS OF THE ITI 2008 30TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES, 2008, : 41 - 49
  • [40] 1 Enterprise-wide Requirements & Decision Management
    DeGregorio, Gary
    INCOSE International Symposium, 1999, 9 (01): : 644 - 650