SlideShare a Scribd company logo
1 of 7
Download to read offline
Privileged and Confidential Information
Nine HIPAA Compliance
Question to Ask Yourself
LERNER Consulting
2014
Privileged and Confidential Information
Sleep More Soundly
1
People sleep more soundly when they feel
secure. When you are well rested, your potential
grows.
Today’s enterprises face a laundry list of
challenges from ever evolving compliance
requirements to new technical environments to
cyberterrorism and extortionists.
Traditional security measures are at best response
driven or worse passive.
LERNER’s Compliance Practice helps you become
proactive towards the things that interfere with
your business.
Let us help you unlock your potential
Twitter: @RevInnovator
Privileged and Confidential Information
Food for Though Questions
1.  How do you provide solutions that address optimal Required and
Addressable clauses?
2.  Do you have or need full-time Chief Security and Privacy Officer(s)?
3.  Have you completed the Omnibus updates?
4.  Do you have a document management system that allows you to
quickly and easily retrieve the required documents?
5.  How often do you review your IT Policies and Procedures?
6.  Do you have a training program for both IT Security and HIPAA?
7.  Must our organization comply with every clause?
8.  What if we don’t (think) we handle any data? Must we be compliant?
9.  Is a Business Associate the same as a Covered Entity?
2Twitter: @RevInnovator
Privileged and Confidential Information
HIPAA Compliance Services
3
We begin with a focused risk assessment, rather than addressing the flavor of the day. Our approach is to
take an assessment of how a set of risks or compliance needs impacts your enterprise. From there we
address develop the controls that effect people, process, technology and systems.
LERNER addresses the regulatory requirements and internal handoffs, providing clients with an alignment plan
to support business objectives and IT implementation. Internally there must be clear plans that include
communication to employees and partners. The implementation of a system helps support HIPAA processes
through automated action and process controls.
Assess Advise Resolve
Ac#vi#es
§  Iden#fy	
  relevant	
  HIPAA	
  mandates	
  (E.g.,	
  CFR	
  
Title	
  45)	
  
§  Select	
  HIPAA	
  processes	
  and	
  procedures	
  for	
  
remedia#on	
  
§  Gather	
  exis#ng	
  enterprise	
  processes	
  
§  Perform	
  gap	
  analysis	
  
§  Iden#fy	
  internal	
  stakeholders	
  
§  Conduct	
  business	
  alignment	
  workshop(s)	
  
§  Define/Create	
  process	
  maps	
  
§  Iden#fy	
  controls	
  required	
  for:	
  
§  Administra#ve	
  Safeguards	
  
§  Physical	
  Safeguards	
  
§  Technical	
  Safeguards	
  
§  Organiza#onal	
  Requirements	
  
§  Policies	
  and	
  Procedures	
  	
  
§  Other	
  required	
  controls	
  
§  Develop	
  enterprise	
  specific	
  plans	
  
§  Iden#fy	
  metrics	
  and	
  measurements
§  Implement	
  processes	
  
§  Implement	
  system	
  implementa#on/updates	
  
§  Test	
  implementa#on	
  and	
  controls	
  
§  Provide	
  and	
  execute	
  communica#ons	
  plan	
  
and	
  change	
  management	
  
Deliverables
§  Internal	
  charter	
  
§  Gap	
  Analysis	
  
§  Implementa#on	
  roadmap	
  
§  Integra#on/overlap	
  with	
  other	
  compliance	
  
ac#vi#es
§  Finalized	
  process	
  maps	
  
§  Define	
  processes,	
  new	
  roles/responsibili#es	
  
as	
  required	
  
§  Develop	
  documenta#on	
  
§  Implementa#on	
  roadmap	
  
§  Metrics	
  for	
  success
§  Systems	
  implementa#on	
  
§  Change	
  management	
  and	
  communica#ons	
  
plan
Twitter: @RevInnovator
Privileged and Confidential Information
Case Study: Systems Integrator – HIPAA Compliance
How we solved it
•  LERNER was engaged to help the SI become HIPAA compliant. In a
seven step process we addressed key areas of compliance (e.g.,
Administrative Safeguards, Technical, Organizational, Physical
Safeguards)
–  Did a comprehensive review of management policies and
business operations
–  Wrote and implemented IT Policies and Procedures for end users
–  Revised network and desktop architectures to support compliance
needs. Implemented security polices (encryption, password
management, firewall management, network penetration test)
–  Developed physical security measures (e.g., keycards)
–  Addressed specific payer needs (e.g., mobile device management)
–  Served as Chief Security Officer for the client organization
–  Developed and implement business continuity and disaster
recovery plans
–  Worked with executive management to implement a Risk
Management plan with contingencies
4
Problem Statement
•  Client is a Systems Integrator providing IT
services to large healthcare payers
•  Client has access to both Protected Health and
Personally Identifiable Information. Access was
granted to production systems and databases
•  An initial review of security features by a
healthcare payer found that Client was lacking
overall in HIPAA compliances
What the client achieved
•  Compliance within six weeks
•  Insurer awarded client one year contract for outsourcing
•  Compliance for other Insurers
•  A secure and compliant development center
Twitter: @RevInnovator
Privileged and Confidential Information
Lawrence I Lerner – Managing Director
5
Relevant accomplishments and highlights:
§  Author of four software methodologies for product and package selection. This includes Cognizant’s Portfolio Analysis which has been recognized
by the analyst community as a ground breaking for product transformation and development
§  Lead organizational redesign and process re-engineering for all of IT at Kimberly-Clark
§  Development of IT Security Policies for multiple organizations including the American Medical Association, Motorola, a New York based Civil Right
organization and other top brand companies
§  Global practice leader for IT Security Practice at Cognizant
§  Board member for PNI Digital Media, Audit Committee Member
Lawrence has over 25 years experience as a Digital Strategist for the world’s top brands. His background includes
development of eBusiness initiatives at PricewaterhouseCoopers, development of Cognizant Technology Solution’s
Business Technology and Advanced Solutions groups and creation of strategic solutions for UST Global. Lawrence has
over fifteen years in IT and business process outsourcing/offshoring and is widely sought after security and compliance
expert.
Lawrence is well known for bringing game changing programs to companies. He has extensive experience as a both
Chief Technology Officer and Business Strategist, taking core business needs and realizing them through technology.
His process consulting work has been recognized as “best in class” by Gartner in 2009
http://eon.businesswire.com/news/eon/20100518006108/en - “UST Global Completes Next Generation BPM Solution
for Catalina Marketing.” Catalina is the global leader in shopper-driven marketing solutions, providing brand
manufacturers, retailers and healthcare providers with shopper-driven marketing solutions to meet growth objectives
Previously Lawrence lead Cognizant and PwC IT (Chicago) Security Consulting practices and was responsible for the
development of services and client audits. He has been responsible for IT Security and audits since the late 90’s.
Lawrence was previously on the board of Directors for PNI Digital Media (TSX–V: PN; Now Staples). PNI is the premier
provider of digital solutions, housing over four petabytes of online photos, for the photo industry. He was an active
Director, providing governance and new product strategies
Twitter: @RevInnovator
Thank You!
Contact Us
email: lawrence@lawrenceilerner.com
Direct: +1.630.248.0663
Twitter: @RevInnovator

More Related Content

What's hot

_4-27-davidloewyresume (2)
_4-27-davidloewyresume (2)_4-27-davidloewyresume (2)
_4-27-davidloewyresume (2)
David Loewy
 
Iso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guideIso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guide
mfmurat
 

What's hot (20)

ISO 27004- Information Security Metrics Implementation
ISO 27004- Information Security Metrics ImplementationISO 27004- Information Security Metrics Implementation
ISO 27004- Information Security Metrics Implementation
 
Cisa 2013 ch3
Cisa 2013 ch3Cisa 2013 ch3
Cisa 2013 ch3
 
Cisa 2013 ch2
Cisa 2013 ch2Cisa 2013 ch2
Cisa 2013 ch2
 
CISA Domain 3 - Information Systems Acquisition, Development and Implementation
CISA Domain 3 - Information Systems Acquisition, Development and ImplementationCISA Domain 3 - Information Systems Acquisition, Development and Implementation
CISA Domain 3 - Information Systems Acquisition, Development and Implementation
 
Cisa 2013 ch4
Cisa 2013 ch4Cisa 2013 ch4
Cisa 2013 ch4
 
(ONLINE) ITIL Indonesia Community - Manfaat Penerapan Sistem Manajemen Keaman...
(ONLINE) ITIL Indonesia Community - Manfaat Penerapan Sistem Manajemen Keaman...(ONLINE) ITIL Indonesia Community - Manfaat Penerapan Sistem Manajemen Keaman...
(ONLINE) ITIL Indonesia Community - Manfaat Penerapan Sistem Manajemen Keaman...
 
CISA Training - Chapter 2 - 2016
CISA Training - Chapter 2 - 2016CISA Training - Chapter 2 - 2016
CISA Training - Chapter 2 - 2016
 
_4-27-davidloewyresume (2)
_4-27-davidloewyresume (2)_4-27-davidloewyresume (2)
_4-27-davidloewyresume (2)
 
Information System Audit and Control
Information System Audit and ControlInformation System Audit and Control
Information System Audit and Control
 
It governance
It governanceIt governance
It governance
 
FRSecure Sales Deck
FRSecure Sales DeckFRSecure Sales Deck
FRSecure Sales Deck
 
ISO 27001 Implementation using Force Field Analysis
ISO 27001 Implementation using Force Field AnalysisISO 27001 Implementation using Force Field Analysis
ISO 27001 Implementation using Force Field Analysis
 
Iso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guideIso 27001 metrics and implementation guide
Iso 27001 metrics and implementation guide
 
Solution Architecture And Solution Security
Solution Architecture And Solution SecuritySolution Architecture And Solution Security
Solution Architecture And Solution Security
 
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
(ONLINE) ITIL Indonesia Community - An Introduction to IT Change Management
 
How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?How to determine a proper scope selection based on ISO 27001?
How to determine a proper scope selection based on ISO 27001?
 
CISA Domain- 1 - InfosecTrain
CISA Domain- 1  - InfosecTrainCISA Domain- 1  - InfosecTrain
CISA Domain- 1 - InfosecTrain
 
CISSP - Chapter 1 - Security Concepts
CISSP - Chapter 1 - Security ConceptsCISSP - Chapter 1 - Security Concepts
CISSP - Chapter 1 - Security Concepts
 
Agile in a highly regulated organization 2014
Agile in a highly regulated organization 2014Agile in a highly regulated organization 2014
Agile in a highly regulated organization 2014
 
3 Reasons Why Manufacturing Companies are Moving to Dynamics 365FO
3 Reasons Why Manufacturing Companies are Moving to Dynamics 365FO3 Reasons Why Manufacturing Companies are Moving to Dynamics 365FO
3 Reasons Why Manufacturing Companies are Moving to Dynamics 365FO
 

Similar to Nine HIPAA Compliance Questions to ask Yourself

Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015
Bill Haase
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdf
SALES97
 
Create a Winning BPI Playbook
Create a Winning BPI PlaybookCreate a Winning BPI Playbook
Create a Winning BPI Playbook
Info-Tech Research Group
 
ICD-10: Short-Term Challenges and Long-Term Gains
ICD-10: Short-Term Challenges and Long-Term GainsICD-10: Short-Term Challenges and Long-Term Gains
ICD-10: Short-Term Challenges and Long-Term Gains
Perficient, Inc.
 
Senior Manager - IT, Deepak
Senior Manager - IT, DeepakSenior Manager - IT, Deepak
Senior Manager - IT, Deepak
Deepak Sharma
 
Senior Manager - IT, Deepak
Senior Manager - IT, DeepakSenior Manager - IT, Deepak
Senior Manager - IT, Deepak
Deepak Sharma
 
Governing IT | TechExpress.co
Governing IT | TechExpress.coGoverning IT | TechExpress.co
Governing IT | TechExpress.co
TechExpressTools
 
Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2
Smart ERP Solutions, Inc.
 
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
Barun Kumar
 

Similar to Nine HIPAA Compliance Questions to ask Yourself (20)

Cobit 41 framework
Cobit 41 frameworkCobit 41 framework
Cobit 41 framework
 
Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015Bill_Haase_Resume Dec 2015
Bill_Haase_Resume Dec 2015
 
2016 Risk Management Workshop
2016 Risk Management Workshop2016 Risk Management Workshop
2016 Risk Management Workshop
 
Info-Tech Research Group & Boardroom Events Value Prop Presentation
Info-Tech Research Group & Boardroom Events Value Prop PresentationInfo-Tech Research Group & Boardroom Events Value Prop Presentation
Info-Tech Research Group & Boardroom Events Value Prop Presentation
 
WLS Services Brochure March 2013
WLS Services Brochure March 2013WLS Services Brochure March 2013
WLS Services Brochure March 2013
 
Use of the COBIT Security Baseline
Use of the COBIT Security BaselineUse of the COBIT Security Baseline
Use of the COBIT Security Baseline
 
Introduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdfIntroduction to IT compliance program and Discuss the challenges IT .pdf
Introduction to IT compliance program and Discuss the challenges IT .pdf
 
Build an Information Security Strategy
Build an Information Security StrategyBuild an Information Security Strategy
Build an Information Security Strategy
 
Create a Winning BPI Playbook
Create a Winning BPI PlaybookCreate a Winning BPI Playbook
Create a Winning BPI Playbook
 
ICD-10: Short-Term Challenges and Long-Term Gains
ICD-10: Short-Term Challenges and Long-Term GainsICD-10: Short-Term Challenges and Long-Term Gains
ICD-10: Short-Term Challenges and Long-Term Gains
 
gray_audit_presentation.ppt
gray_audit_presentation.pptgray_audit_presentation.ppt
gray_audit_presentation.ppt
 
IllustroTech Introduction to IT Governance Principles
IllustroTech Introduction to IT Governance PrinciplesIllustroTech Introduction to IT Governance Principles
IllustroTech Introduction to IT Governance Principles
 
Senior Manager - IT, Deepak
Senior Manager - IT, DeepakSenior Manager - IT, Deepak
Senior Manager - IT, Deepak
 
02-Assess-and-Raise-Your-Digital-Maturity--Phases-1-2.pptx
02-Assess-and-Raise-Your-Digital-Maturity--Phases-1-2.pptx02-Assess-and-Raise-Your-Digital-Maturity--Phases-1-2.pptx
02-Assess-and-Raise-Your-Digital-Maturity--Phases-1-2.pptx
 
Senior Manager - IT, Deepak
Senior Manager - IT, DeepakSenior Manager - IT, Deepak
Senior Manager - IT, Deepak
 
Governing IT | TechExpress.co
Governing IT | TechExpress.coGoverning IT | TechExpress.co
Governing IT | TechExpress.co
 
Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2Navigating HCM Compliance Through Managed Services Part 2
Navigating HCM Compliance Through Managed Services Part 2
 
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
 
Hans Eckman: 7 Agile and DevOps Insights I Wish I Knew Earlier
Hans Eckman: 7 Agile and DevOps Insights I Wish I Knew EarlierHans Eckman: 7 Agile and DevOps Insights I Wish I Knew Earlier
Hans Eckman: 7 Agile and DevOps Insights I Wish I Knew Earlier
 
PECB Webinar: Aligning COBIT 5.0 and ISO/IEC 38500
PECB Webinar: Aligning COBIT 5.0 and ISO/IEC 38500PECB Webinar: Aligning COBIT 5.0 and ISO/IEC 38500
PECB Webinar: Aligning COBIT 5.0 and ISO/IEC 38500
 

More from LERNER Consulting

More from LERNER Consulting (20)

How to talk to your generative AI r2.pptx
How to talk to your generative AI r2.pptxHow to talk to your generative AI r2.pptx
How to talk to your generative AI r2.pptx
 
Blochchain's Impact on Finance 01-2019
Blochchain's Impact on Finance 01-2019Blochchain's Impact on Finance 01-2019
Blochchain's Impact on Finance 01-2019
 
Presentation to Legislative Committee on Economic Development & International...
Presentation to Legislative Committee on Economic Development & International...Presentation to Legislative Committee on Economic Development & International...
Presentation to Legislative Committee on Economic Development & International...
 
RChain Developer Conference pithia investments 04-2018
RChain Developer Conference   pithia investments 04-2018RChain Developer Conference   pithia investments 04-2018
RChain Developer Conference pithia investments 04-2018
 
Crypto Traders event at Atlas Workspace 04-2018
Crypto Traders event at Atlas Workspace 04-2018Crypto Traders event at Atlas Workspace 04-2018
Crypto Traders event at Atlas Workspace 04-2018
 
Leadership: A Journey Planner
Leadership: A Journey PlannerLeadership: A Journey Planner
Leadership: A Journey Planner
 
CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018CFOs and Cryptocurrency 01-2018
CFOs and Cryptocurrency 01-2018
 
SVIA InsurTech Summit Dec 5 - 6th 2017
SVIA InsurTech Summit Dec 5 - 6th 2017SVIA InsurTech Summit Dec 5 - 6th 2017
SVIA InsurTech Summit Dec 5 - 6th 2017
 
Bitcoin + blockchain transaction 07 2017
Bitcoin + blockchain transaction 07 2017Bitcoin + blockchain transaction 07 2017
Bitcoin + blockchain transaction 07 2017
 
Business of Blockchain LERNER Consulting 05 2017
Business of Blockchain LERNER Consulting 05 2017Business of Blockchain LERNER Consulting 05 2017
Business of Blockchain LERNER Consulting 05 2017
 
Lawrence I Lerner Executive Bio 11 2016
Lawrence I Lerner Executive Bio 11 2016Lawrence I Lerner Executive Bio 11 2016
Lawrence I Lerner Executive Bio 11 2016
 
Change Management: A Journey Planner
Change Management: A Journey Planner Change Management: A Journey Planner
Change Management: A Journey Planner
 
ERM Symposium Agenda FINAL
ERM Symposium Agenda FINALERM Symposium Agenda FINAL
ERM Symposium Agenda FINAL
 
SR Developer Job Posting
SR Developer Job PostingSR Developer Job Posting
SR Developer Job Posting
 
There's always room for Growth
There's always room for GrowthThere's always room for Growth
There's always room for Growth
 
Seattle Biz-Tech Summit 10-2015 CyberSecurity and the Board
Seattle Biz-Tech Summit 10-2015 CyberSecurity and the BoardSeattle Biz-Tech Summit 10-2015 CyberSecurity and the Board
Seattle Biz-Tech Summit 10-2015 CyberSecurity and the Board
 
Seattle Biz-Tech Summit 10-2015 CyberSecurity and the Board
Seattle Biz-Tech Summit 10-2015 CyberSecurity and the BoardSeattle Biz-Tech Summit 10-2015 CyberSecurity and the Board
Seattle Biz-Tech Summit 10-2015 CyberSecurity and the Board
 
Alternative payment methods 03 2015 LERNER Consulting
Alternative payment methods 03 2015 LERNER ConsultingAlternative payment methods 03 2015 LERNER Consulting
Alternative payment methods 03 2015 LERNER Consulting
 
Block Chain as a Platform February 2015 - LERNER Consulting
Block Chain as a Platform February 2015 - LERNER ConsultingBlock Chain as a Platform February 2015 - LERNER Consulting
Block Chain as a Platform February 2015 - LERNER Consulting
 
Client Case Study/Citations Template
Client Case Study/Citations TemplateClient Case Study/Citations Template
Client Case Study/Citations Template
 

Recently uploaded

Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
amitlee9823
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
amitlee9823
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
amitlee9823
 

Recently uploaded (20)

Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 

Nine HIPAA Compliance Questions to ask Yourself

  • 1. Privileged and Confidential Information Nine HIPAA Compliance Question to Ask Yourself LERNER Consulting 2014
  • 2. Privileged and Confidential Information Sleep More Soundly 1 People sleep more soundly when they feel secure. When you are well rested, your potential grows. Today’s enterprises face a laundry list of challenges from ever evolving compliance requirements to new technical environments to cyberterrorism and extortionists. Traditional security measures are at best response driven or worse passive. LERNER’s Compliance Practice helps you become proactive towards the things that interfere with your business. Let us help you unlock your potential Twitter: @RevInnovator
  • 3. Privileged and Confidential Information Food for Though Questions 1.  How do you provide solutions that address optimal Required and Addressable clauses? 2.  Do you have or need full-time Chief Security and Privacy Officer(s)? 3.  Have you completed the Omnibus updates? 4.  Do you have a document management system that allows you to quickly and easily retrieve the required documents? 5.  How often do you review your IT Policies and Procedures? 6.  Do you have a training program for both IT Security and HIPAA? 7.  Must our organization comply with every clause? 8.  What if we don’t (think) we handle any data? Must we be compliant? 9.  Is a Business Associate the same as a Covered Entity? 2Twitter: @RevInnovator
  • 4. Privileged and Confidential Information HIPAA Compliance Services 3 We begin with a focused risk assessment, rather than addressing the flavor of the day. Our approach is to take an assessment of how a set of risks or compliance needs impacts your enterprise. From there we address develop the controls that effect people, process, technology and systems. LERNER addresses the regulatory requirements and internal handoffs, providing clients with an alignment plan to support business objectives and IT implementation. Internally there must be clear plans that include communication to employees and partners. The implementation of a system helps support HIPAA processes through automated action and process controls. Assess Advise Resolve Ac#vi#es §  Iden#fy  relevant  HIPAA  mandates  (E.g.,  CFR   Title  45)   §  Select  HIPAA  processes  and  procedures  for   remedia#on   §  Gather  exis#ng  enterprise  processes   §  Perform  gap  analysis   §  Iden#fy  internal  stakeholders   §  Conduct  business  alignment  workshop(s)   §  Define/Create  process  maps   §  Iden#fy  controls  required  for:   §  Administra#ve  Safeguards   §  Physical  Safeguards   §  Technical  Safeguards   §  Organiza#onal  Requirements   §  Policies  and  Procedures     §  Other  required  controls   §  Develop  enterprise  specific  plans   §  Iden#fy  metrics  and  measurements §  Implement  processes   §  Implement  system  implementa#on/updates   §  Test  implementa#on  and  controls   §  Provide  and  execute  communica#ons  plan   and  change  management   Deliverables §  Internal  charter   §  Gap  Analysis   §  Implementa#on  roadmap   §  Integra#on/overlap  with  other  compliance   ac#vi#es §  Finalized  process  maps   §  Define  processes,  new  roles/responsibili#es   as  required   §  Develop  documenta#on   §  Implementa#on  roadmap   §  Metrics  for  success §  Systems  implementa#on   §  Change  management  and  communica#ons   plan Twitter: @RevInnovator
  • 5. Privileged and Confidential Information Case Study: Systems Integrator – HIPAA Compliance How we solved it •  LERNER was engaged to help the SI become HIPAA compliant. In a seven step process we addressed key areas of compliance (e.g., Administrative Safeguards, Technical, Organizational, Physical Safeguards) –  Did a comprehensive review of management policies and business operations –  Wrote and implemented IT Policies and Procedures for end users –  Revised network and desktop architectures to support compliance needs. Implemented security polices (encryption, password management, firewall management, network penetration test) –  Developed physical security measures (e.g., keycards) –  Addressed specific payer needs (e.g., mobile device management) –  Served as Chief Security Officer for the client organization –  Developed and implement business continuity and disaster recovery plans –  Worked with executive management to implement a Risk Management plan with contingencies 4 Problem Statement •  Client is a Systems Integrator providing IT services to large healthcare payers •  Client has access to both Protected Health and Personally Identifiable Information. Access was granted to production systems and databases •  An initial review of security features by a healthcare payer found that Client was lacking overall in HIPAA compliances What the client achieved •  Compliance within six weeks •  Insurer awarded client one year contract for outsourcing •  Compliance for other Insurers •  A secure and compliant development center Twitter: @RevInnovator
  • 6. Privileged and Confidential Information Lawrence I Lerner – Managing Director 5 Relevant accomplishments and highlights: §  Author of four software methodologies for product and package selection. This includes Cognizant’s Portfolio Analysis which has been recognized by the analyst community as a ground breaking for product transformation and development §  Lead organizational redesign and process re-engineering for all of IT at Kimberly-Clark §  Development of IT Security Policies for multiple organizations including the American Medical Association, Motorola, a New York based Civil Right organization and other top brand companies §  Global practice leader for IT Security Practice at Cognizant §  Board member for PNI Digital Media, Audit Committee Member Lawrence has over 25 years experience as a Digital Strategist for the world’s top brands. His background includes development of eBusiness initiatives at PricewaterhouseCoopers, development of Cognizant Technology Solution’s Business Technology and Advanced Solutions groups and creation of strategic solutions for UST Global. Lawrence has over fifteen years in IT and business process outsourcing/offshoring and is widely sought after security and compliance expert. Lawrence is well known for bringing game changing programs to companies. He has extensive experience as a both Chief Technology Officer and Business Strategist, taking core business needs and realizing them through technology. His process consulting work has been recognized as “best in class” by Gartner in 2009 http://eon.businesswire.com/news/eon/20100518006108/en - “UST Global Completes Next Generation BPM Solution for Catalina Marketing.” Catalina is the global leader in shopper-driven marketing solutions, providing brand manufacturers, retailers and healthcare providers with shopper-driven marketing solutions to meet growth objectives Previously Lawrence lead Cognizant and PwC IT (Chicago) Security Consulting practices and was responsible for the development of services and client audits. He has been responsible for IT Security and audits since the late 90’s. Lawrence was previously on the board of Directors for PNI Digital Media (TSX–V: PN; Now Staples). PNI is the premier provider of digital solutions, housing over four petabytes of online photos, for the photo industry. He was an active Director, providing governance and new product strategies Twitter: @RevInnovator
  • 7. Thank You! Contact Us email: lawrence@lawrenceilerner.com Direct: +1.630.248.0663 Twitter: @RevInnovator