The HIPAA security rule requires this type of assessment. However, many healthcare organizations have never completed a risk assessment, have not kept it up to date, or have failed to address all necessary areas of risk.
Cascade Healthcare Community, a three-hospital health system headquartered in Bend, OR, was one of those CEs that found itself under the microscope.
Unfortunately for Cascade, a virus invaded part of its computer system in December 2007, exposing the data of more than 11,500 donors and landing the healthcare system in the headlines.
When breaches occur, you are required to notify the affected patients or their legal representatives. A minor child's legal representative is a parent or legal guardian.
The wireless and the wired environment are each subject to potentially significant security risks.
Aruba Networks, Inc., offers a wireless solution that significantly reduces security risks, minimizes organizational costs, and can be deployed quickly.
OCR has established privacy advisors in each of its regional offices to provide HIPAA privacy and security guidance and education. HITECH required the HHS secretary to designate an individual in each of its regional offices.