HIPAA Privacy, Security, and Breach Notification Audit Program

HIPAA Privacy, Security, and Breach Notification Audit Program

OCR senior advisor Linda Sanches said at the recent HIMSS and Healthcare IT News Privacy & Security Forum “We will be conducting a small number of on-site audits in 2017,” Sanches added.  [1]

 

 

What is the OCR Audit Phase 2?[2]

 

 Program Objectives: 

The audit program is an important part of OCR’s overall health information privacy, security, and breach notification compliance activities. OCR uses the audit program to assess the HIPAA compliance efforts of a range of entities covered by HIPAA regulations. The audits present an opportunity to examine mechanisms for compliance, identify best practices, and discover risks and vulnerabilities that may not have come to light through OCR’s ongoing complaint investigations and compliance reviews [3]

 

Are you ready?  

GTB’s Healthcare Data Risk & Audit Assessment offers unparalleled, intelligent search for both structured e.g. Personal Identifiable Information (PII) and unstructured e.g. Intellectual Property (IP) data assets.

Try GTB’s free Healthcare Data Risk & Audit Preparedness Assessment

 

https://gttb.com/hipaa-risk-assessment/

[1] http://www.healthcareitnews.com/news/ocr-onsite-hipaa-audits-coming-2017

[2] https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/

[3] https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/

Visibility: Accurately, discover sensitive data; detect and address broken business process, or insider threats including sensitive data breach attempts.

Protection: Automate data protection, breach prevention and incident response both on and off the network; for example, find and quarantine sensitive data within files exposed on user workstations, FileShares and cloud storage.

Notification: Alert and educate users on violations to raise awareness and educate the end user about cybersecurity and corporate policies.

Education: Start target cyber-security training; e.g., identify end-users violating policies and train them.

  • Employees and organizations have knowledge and control of the information leaving the organization, where it is being sent, and where it is being preserved.
  • Ability to allow user classification to give them influence in how the data they produce is controlled, which increases protection and end-user adoption.
  • Control your data across your entire domain in one Central Management Dashboard with Universal policies.
  • Many levels of control together with the ability to warn end-users of possible non-compliant – risky activities, protecting from malicious insiders and human error.
  • Full data discovery collection detects sensitive data anywhere it is stored, and provides strong classification, watermarking, and other controls.
  • Delivers full technical controls on who can copy what data, to what devices, what can be printed, and/or watermarked.
  • Integrate with GRC workflows.
  • Reduce the risk of fines and non-compliance.
  • Protect intellectual property and corporate assets.
  • Ensure compliance within industry, regulatory, and corporate policy.
  • Ability to enforce boundaries and control what types of sensitive information can flow where.
  • Control data flow to third parties and between business units.