Sanction Policy
HIPAA, Risk, Sanction Jeremy Pickett HIPAA, Risk, Sanction Jeremy Pickett

Sanction Policy

The HIPAA Sanction Policy is a crucial component of an organization's overall HIPAA compliance strategy. It outlines the consequences for workforce members who fail to adhere to the established security policies and procedures designed to protect patient health information.

Read More
Risk Management
HIPAA, Risk Jeremy Pickett HIPAA, Risk Jeremy Pickett

Risk Management

HIPAA 164.308(a)(1)(ii)(B) requires covered entities and business associates to: "Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with [the Security Rule]."

This guide provides specific guidance for engineers, analysts, and management to effectively implement this requirement.

Read More
Risk Analysis
HIPAA, Risk Jeremy Pickett HIPAA, Risk Jeremy Pickett

Risk Analysis

“Security is always going to be a cat and mouse game because there’ll be people out there that are hunting for the zero day award, you have people that don’t have configuration management, don’t have vulnerability management, don’t have patch management.”

— Kevin Mitnick

Read More
Security Management Process
HIPAA, Management Process Jeremy Pickett HIPAA, Management Process Jeremy Pickett

Security Management Process

Governance, risk management, and policy development. This includes conducting regular risk analyses, implementing risk management plans, developing and enforcing policies (including sanctions policies), reviewing system activity, providing training, managing business associates, maintaining documentation, and ensuring continuous improvement of the security management process.

Read More