13.07.2015 Views

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

Part 4 - Iowa Medicaid Enterprise

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

RFP MED-12-001 | Technical Proposal<strong>Iowa</strong> <strong>Medicaid</strong> <strong>Enterprise</strong> System Service Procurement | MMIS and Core MMIS OperationsThe Incident Response Plan includes timelines and escalation procedures, including automated alerts aftera certain amount of time. These automated alerts will ensure we notify appropriate staff authorities ofinappropriate disclosures of sensitive information. In addition, our structured incident response processand escalation procedures will ensure we are timely in reporting security or confidentiality breaches tothe Department.Team Noridian's security and confidentiality policies also include the ability for employees andstakeholders to report any complaints that may indicate the misuse of sensitive program information. Wewill provide a complaint e-mail address and telephone number where concerned parties can reportsuspected abuse. These complaints will be processed in the same manner as other security incidents,following our standard Incident Response Plan and escalation procedures.7.8.4 Department Assets and Back-upsRFP Section 5.8, Requirements c.5 and dTeam Noridian will maintain a listing of all Department-controlled IME assets through our configurationmanagement tool. Within this tool, we will be able to readily identify any assets that are part of the IME.Our configuration management tool also lets us readily identify potentially related systems in the case of afailure or security breach.Team Noridian recognizes the Department has the right to establish back-up security for IME data. If theDepartment so chooses, Team Noridian will work with the Department to provide back-up data files.Those files will be turned over to the Department to be kept in their possession. Team Noridianrecognizes this will not relieve Team Noridian of its responsibilities.7.8.5 Security StaffRFP Section 5.8.1In keeping with our dedication to HIPAA privacy and security compliance, Team Noridian employs acorporate systems security officer. The security officer has the responsibility to oversee all newregulations, determine impact to the organization, and modify existing policies or develop new policies.The security officer is also responsible for conducting reviews of our operations, which includes internalcontrols as well as subcontractor and employee system access and rights, on an ongoing basis to preventand detect fraud. This program encompasses all sensitive systems, such as automated and manual,physical and logical. It includes the policies, procedures, guidelines, safeguards, and audit controls thatprotect data confidentiality, data integrity, privacy rights, and ensure the integrity, security, andavailability of these systems. More specifically, the security officer provides direct management oversightto the systems security unit and is responsible for:• Development and maintenance of policies, procedures, and standards• Employee awareness and training• Identification and review of the security infrastructure• Maintaining a communication plan• Developing data release and non-disclosure agreements to ensure sensitive and confidentialinformation is handled appropriatelyAnother driver in the development of our plan is an awareness of all state and federal security andconfidentiality regulations to ensure systems continue to meet all requirements. The security officer isresponsible for oversight of the plan maintenance process. The security officer and systems security unitmonitor changes in the environment, as well as legislative and mandated changes, to ensure necessaryupdates are made to the Security and Confidentiality Plan. Designated plan coordinators from eachbusiness unit are responsible for updating procedures, making changes to their assigned plans whereappropriate and submitting modifications when needed.7 | 49

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!