04.01.2015 Views

Steven Baruch - Health Care Compliance Association

Steven Baruch - Health Care Compliance Association

Steven Baruch - Health Care Compliance Association

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Once these steps are completed, the process should be<br />

repeated on a regular basis to ensure that the decisions<br />

made and controls implemented remain effective in<br />

reducing risk and meeting business needs and goals.<br />

The Risk Assessment Phases include:<br />

Phase I: Inventory of Systems and Processes<br />

Phase II: Threat and Vulnerability Assessment<br />

Phase III: Evaluation of Controls<br />

Phase IV: Decision<br />

Phase V: Communication and Monitoring<br />

The Incident Preparedness Plan<br />

With the risks as high as they are in some cases, it is<br />

vital that healthcare organizations conduct Incident<br />

Preparedness Planning in conjunction with the Risk<br />

Assessment Plan. This plan should be re-evaluated on<br />

an annual basis. Here are some key considerations for<br />

what should be included in your organization’s Incident<br />

Preparedness Plan:<br />

• Create an Incident Response Team<br />

• Conduct Breach Preparedness Training<br />

• Engage an experienced Data Breach Service<br />

• Choose a provider that will be prepared to handle<br />

the following when a data breach occurs:<br />

3 Handle notification of the breach<br />

3 Conduct Fraud Resolution<br />

3 Provide Call Center Support<br />

3 Provide Reporting<br />

3 Provide Credit Monitoring/Identity Protection<br />

Products and Solutions that include things<br />

such as: Internet Scan and Lost Wallet<br />

solutions that help consumers report,<br />

cancel and reissue items such as, credit, debit<br />

and medical and dental insurance cards<br />

To read the whitepaper in its entirety, please go to<br />

www.experian.com/dbhcca.<br />

Know the Facts<br />

Of the 385 organizations that experienced data<br />

breaches so far this year, 113 were in healthcare. 2<br />

How will your company respond if it happens to you<br />

Know Who to Call<br />

Twenty-five percent of the breaches we have<br />

serviced this year alone have been in healthcare.<br />

With a proven track record of servicing over 1,600<br />

data breach incidents, Experian has the experience<br />

and resources to help you steer the way to calm waters.<br />

READ MORE visit our website<br />

www.experian.com/dbhcca<br />

CALL 866 751 1323 for a FREE consultation<br />

RISK ASSESSMENT IN A HITECH WORLD Written in Collaboration By:<br />

1: NIST Risk Management Guide for Information Systems Special<br />

Publication 800-30<br />

2: Identity Theft Resource Center’s report for July 28, 2010<br />

<strong>Health</strong> <strong>Care</strong> <strong>Compliance</strong> <strong>Association</strong> • 888-580-8373 • www.hcca-info.org<br />

December 2010<br />

21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!