13.07.2015 Views

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RFP MED-12-001 | Technical Proposal<strong>Iowa</strong> <strong>Medicaid</strong> <strong>Enterprise</strong> System Service Procurement | MMIS and Core MMIS OperationsOur solution, as depicted in Figure 7-11, is designed to protect the IME data assets from both intentionaland unintentional attacks. Our solution is flexible and can be adapted and administered to meet all thefederal, state, and local laws applicable to the contract.Figure 7-11. Team Noridian’s Security and Confidentiality Framework. We address physical andtechnical aspects of security in addition to administrative controls to protect data assets and provide asafe environment for all employees.7.8.1 Security of Facilities, Systems and DataRFP Section 5.8, Requirements a, b, c.4, c.6, and c.7Team Noridian is dedicated to adherence to HIPAA privacy and security policies, as well as a host ofother applicable industry regulations put forward by prominent standards-setting bodies. Team Noridianhas a comprehensive, enterprise-wide security and confidentiality program, which has been audited in avariety of different methods, including Statement on Auditing Standards number 70 (SAS 70) and ChiefFinancial Officer (CFO) reviews. Our program includes strict policies, procedures, employee-trainingrequirements, and a strong emphasis on information technology (IT) system security controls, whichprovide the right people with the right access at the right time to applications and data, while protectingPHI and confidential business information from unauthorized users.Our system security and confidentiality program complies with the following:• Federal Information Processing Standards Publications (FIPS PUBS)• Federal and state mandates• Federal and state legislation• Office of Management and Budget (OMB) Circular A-130• Federal Information Security Management Act (FISMA)• Applicable International Organization for Standardization (ISO) standards7 | 42

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!