+353-1-416-8900REST OF WORLD
+44-20-3973-8888REST OF WORLD
1-917-300-0470EAST COAST U.S
1-800-526-8630U.S. (TOLL FREE)

Conducting a Risk Analysis to Comply with Meaningful Use, HIPAA and HITECH

  • Training

  • 90 Minutes
  • Compliance Online
  • ID: 5975331
This webinar will discuss how to do a security risk analysis to meet the requirements of HIPAA, HITECH and Meaningful Use attestation. It will describe ways for effectively completing a risk analysis at the organizational level, the network level and the application level.

Why Should You Attend:

Risk analysis and risk management plans are the foundation of a HIPAA compliance program and should be complete and provide the documentation that an examiner may ask for. Risk assessments are a key part of effective risk management and facilitate decision making at all three tiers in the risk management hierarchy including the organization level, network level, and information system level. Completing a risk analysis will guide an organization to make cost effective, risk based decisions and provide an enhanced security environment to protect data and reduce the risk of a reportable security breach.

This webinar will guide the user on the principles of risk analysis and risk management to prioritize risks. It will rely heavily on the NIST 800-30 which is mentioned in the preamble of the original rule and the OCR issued guidance on risk analysis (as revised and finalized on 09/18/2012.)

This session will:
  • Focus on the key factors in determining and documenting the controls to be implemented regardless of the size of the organization.
  • Explore the processes and methods that can assist organizations prioritize IT security projects by addressing the highest risks to the organization.
  • Review the regulatory requirements for security risk analysis and management.
  • Provide an overview of the types of risk analysis that can be performed.
  • Offer a practical approach on how to comply with regulatory requirements for security risk analysis.
  • Provide information about how to determine where the risks to the organization exist and point organizations to where to look for this information.

Areas Covered in the Webinar:

  • Requirements of the HIPAA risk analysis security rule
  • Meaningful use requirements and application certification criteria.
  • How risk analysis helps a business make risk based decisions to prioritize security controls and make decisions.
  • How to conduct a HIPAA security risk analysis using NIST 800-30 as a guide
  • How to locate and document the location of protected data
  • How to conduct a risk analysis and how to accomplish the requirement
  • Risk Analysis Steps
  • Identify the scope of the specific analysis;
  • Gather data;
  • Identify and document potential threats and vulnerabilities;
  • Assess and document current security measures;
  • Determine the likelihood of threat occurrence;
  • Determine the potential impact of threat occurrence;
  • Determine the level of risk;
  • Identify potential security measures and finalize documentation.
  • Risk Management Steps
  • Develop and implement a risk management plan;
  • Implement security measures; and
  • Evaluate (monitor) and maintain security measures.
  • Risk Mitigation or Acceptance Options
  • Define Reasonable by Using the HIPAA Regulation as a Guide:
  • Size, complexity, and capabilities of the covered entity
  • The covered entity's technical infrastructure, hardware, and software security capabilities
  • Costs of security measures
  • Probability and criticality of potential risks to EPHI

Who Will Benefit:

This webinar will provide valuable assistance to all personnel in medical offices, practice groups, hospitals, academic medical centers, insurers, business associates (shredding, data storage, systems vendors, billing services, etc). The titles are:
  • Compliance Officer
  • Chief Information Officer
  • CEO, CFO
  • Privacy Officer
  • Security Officer
  • Information Systems Managers (Network and Applications)
  • HIPAA Officer
  • Health Information Manager
  • Healthcare Counsel/lawyer
  • Office Manager

Course Provider

  • William Miaoulis
  • William Miaoulis,