Skip to main content

How to Conduct a HIPAA Security Risk Assessment per NIST guidance


Overview
This course will cover the proper methodologies on conducting a HIPAA Risk Assessment based on the formula used by Federal auditors and via the guidelines of the NIST (National Institute of Standard for Technologies). The course will also cover the most important aspects to be aware of in terms of the Federal auditing process as well as the new risks regarding patients suing for wrongful disclosures.
Why should you attend this webinar?
Have your done a HIPAA Security Risk Assessment? What about a full scope HIPAA Security/Privacy Risk Assessment?
Do you know a risk assessment is the first thing the Feds will ask for in an OCR audit and may also be required should litigation be brought against the organization?
Is your risk assessment adequate?
Do you have written policies in place for every single one of the implementation specification of the HIPAA Security Rule (even ones that don't apply) - do you know this is required!!
I will show how to conduct a PROPER risk assessment point by point and how to also avoid scams in the market. We will also be discussing the absolute importance of doing a risk assessment and that this is the first thing the OCR will ask for. I will instruct the listeners on how to write proper policies and procedures which are to be based upon the findings of the risk assessment and how to word the policies to satisfy the Fed. We will also discuss the importance of having policies which are consistent with your procedures and also discuss the negative ramification of cookie cutter templates in the eyes of the Federal government.
Areas Covered in the Session:
  • Updates for 2018
  • Policies and Procedures
  • Risks
  • Business associates and the increased burden
  • Conduct a NIST based HIPAA Security Risk Assessment for a hypothetical organization
  • Practice managers
  • Any business associates who work with medical practices or hospitals (i.e. billing companies, transcription companies, IT companies, answering services, home health, coders, attorneys, etc)
  • MD's and other medical professionals
Who can Benefit:

  • Private practice
  • Hospitals
  • Billing companies
  • Transcriptions companies
  • Home health groups
  • Health insurance
  • Ambulatory
  • IT companies
  • Attorneys
  • Practice Managers Associations
  • Healthcare and any entities doing business with healthcare as "business associate"

Comments

Popular posts from this blog

HIPAA Compliance with the New Omnibus Rule: How to Pass an Audit to Avoid Penalties and Criminal Convictions

Compliance Key INC  -  H ipaa webinar                                           Jonathan P. Tomes Jonathan P. Tomes , J.D., is Keynote Speaker at Compliance key Inc. He is a health care attorney practicing in the greater Kansas City.   Webinar Id:   HIPHJPT001  2:30 PM PT | 03:30 PM ET    01/18/2018  Duration: 60 mins  Overview Before the HITECH Act, DHHS could audit covered entities for HIPAA compliance, but did not have to. With that Act, now the must audit those entities and business associates as well. In the first audits, the Phase I audits, DHHS came on site. The subsequent Phase II audits, however, were paper audits in which those audited had to provide documentation of their compliance. As yet, we do not know what form Phase III will take, but the necessary actions to prepar...

HIPAA Compliant Fundraising Under New Rules - 2019

Compliance Key  -  H ipaa   Compliance Training HIPAA Compliant Fundraising Under New Rules - 2019 Joel Simon Joel Simon is one of the nation's leading experts on the fund raising aspects of HIPAA. Joel has been a member of the Maryland bar for 30 years, and his professional experience includes work as the assistant general counsel of a community hospital. Joel is an editor of "Fundraising Under HIPAA" published by the Association of Fundraising Professionals. He has lectured on Fund Raising under HIPAA to national audiences since the original HIPAA regulations were first proposed 17 years ago. Read More Overview Not-for-Profit organizations that are governed by HIPAA often need or want to fund raise from their patients, clients, or families. What protocols should be in place to maximize philanthropic opportunities under HIPAA? What compliance measures need to be in place and assessed to properly use protected health information for fund raisi...

New 2019 HIPAA Guidance on De-Identifying Protected Health Information

Compliance Key  -   HIPAA Compliance Training Overview This seminar will be addressing how practice/business managers or compliance officers need to get their HIPAA house in order, as HIPAA is now fully enforced and the government is not using kid gloves anymore. It will also address major 2019 changes taking place with the Health and Human Services regarding the enforcement of the HIPAA law as well as detailed discussions on the Phase 2 audit process and current events regarding HIPAA cases (both in courtrooms and from real-life Audits). Our instructor - Mr. Brian Tuttle  has over 20 years of experience in working as Compliance auditor and has been an expert witness on multiple HIPAA cases. He`ll thoroughly explain on HOW and in WHAT scenarios patients can claim for cash remedies. More importantly, Brian will show you how to limit those risks by simply taking proactive steps and utilizing best practices. Why should you attend this seminar? This Sem...