Great Places to Work LarsonAllen LarsonAllen
Spacer Spacer

line

Strengthen Your Security Strategy Prior to Onset of HIPAA Regulators

line To address threats to health care data and information system vulnerabilities, the government is gearing up to conduct HIPAA security audits in 2008.

How would your organization hold up if audited or attacked by criminals? Don’t wait to find out.

Are you a target? What you can do How LarsonAllen
can help


Targets for HIPAA security audits
The Centers for Medicare & Medicaid Services (CMS) may review the security practices of approximately 10 to 20 hospitals, according to GovernmentHealthIT. They hired third party auditors to check for compliance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996.

Initial audits will focus on the largest entities, as well as those with complaints registered with CMS.

Targets for crime
Hackers, organized crime groups, and internal employees view health care organizations as a prime mark for profits. They want access to patient and non-patient data (especially executives), which they use for identity theft and fraud.

Today, cyber thieves focus on:

  • Penetrating wireless networks, Web sites, and modems (an unpatched Windows XP computer can be compromised in 20 minutes)
  • How employees use email and the Internet via email spear phishing and social engineering (tricking staff into bypassing otherwise adequate controls allowing criminals to obtain remote access)
  • Physical intrusions to gain access to networks or steal laptops, back up tapes, CDs, USB/thumb drives, etc.

Access our presentations to learn more about these threats.

What you can do to safeguard data
Understanding the flow of information within your organization will better position your leadership team to manage risks while withstanding scrutiny from HIPAA regulators and criminals.

  • Build a sound business strategy: Include steps to protect, detect, test, and validate your information security systems as well as respond to an attack and remediate, so it doesn’t happen again.

    Through standards you can establish the protective foundation to maintain your organization’s data (confidentiality, integrity, and availability). These standards must cover how people will use information and how the systems will manage and enforce the use of it.

  • Test and manage your information systems: Once the standards are established, processes for detecting problems, issues, and breaches need to be managed. And they should encompass a variety of automated and manual methods.

    A key component of a sound security strategy includes periodic testing to validate that systems are performing as expected. This includes the configurations of the technical systems, the response to events and attacks, and the processes that support the identification, response, and remediation.

    Such testing and validation should be done by entities that are independent of the functions being audited. Information security and information systems administration are different domains, requiring specialized knowledge and expertise.

    We recommend you engage security professionals who understand how to conduct true penetration tests to validate system security.

How LarsonAllen can help
Information security services
LarsonAllen’s certified security professionals prepare organizations for HIPAA security audits and identify and develop strategies to establish robust layers of defense.

For more information, contact Randy Romes, information security services principal, or learn about our full array of information security services.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Information Security
LarsonAllen
Spacer


Name:
Email:
 
What do you consider the biggest security threat for 2008?
 
Data leakage through USB ports
 
Targeted phishing attacks
 
Unpatched insider threats
 
Wireless vulnerabilities
 
Social engineering
   

Spacer Spacer
Spacer

line

mail Share this with a friend   


About us - Careers - Contact us - Media - EFFECT - Site map - Home

Disclaimer - Web site terms of use - Privacy policy - Copyright policy
© 2000-2008 LarsonAllen® LLP  Equal Opportunity/Affirmative Action Employer
This site is best viewed with 5.0+ browsers at a resolution of 1024 x 768. To download a more recent version of your browser, click below.
Internet Explorer   Firefox