4-3 Paper: Controls to Manage Risks to Healthcare Information
74 ◾ Information Governance for Healthcare Professionals
Chapter Summary: Key Points ◾ Information risk planning is an essential activity in IG programs ◾ Healthcare organizations face major risks from data breaches, ransomware attacks, HIPAA
compliance, and other legal risks. ◾ In identifying information requirements and risks, legal requirements trump all others. ◾ The risk profile is a high-level, executive decision input tool which helps to gauge risks. ◾ A common risk profile method is to create a prioritized or ranked “Top Ten” list of greatest
risks to information. ◾ Once a list of risks is developed, grouping them into basic categories (e.g. natural disaster,
technology, compliance) helps stakeholders better understand them. ◾ The risk mitigation plan develops risk reduction options and tasks to reduce specified risks. ◾ Expected value is a calculation to determine the relative financial impact of a specified risk. ◾ Metrics are required to measure progress in the risk mitigation plan. ◾ Audits provide feedback on the progress of the risk mitigation plan.
notes 1. Elizabeth Snell, “The Role of Risk Assessments in Healthcare,” Health IT Security, https://healthitse-
curity.com/features/the-role-of-risk-assessments-in-healthcare. 2. “Summary of the HIPAA Security Rule,” Office for Civil Rights (OCR), last reviewed July 26, 2013,
https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html. 3. Eric Basu, “Implementing A Risk Management Framework For Health Information Technology
Systems - NIST RMF,” Forbes.com, August 3, 2013, http://www.forbes.com/sites/ericbasu/2013/08/03/ implementing-a-risk-management-framework-for-health-information-technology-systems-nist- rmf/#23e63d46523a.
4. Ryan Francis, “Ransomware Makes Healthcare Wannacry,” CSOOnline, May 15, 2017, https://www. csoonline.com/article/3196827/data-breach/ransomware-makes-healthcare-wannacry.html.
5. “HIPAA Fines Listed by Year,” Compliancy Group, https://compliancy-group.com/hipaa-fines- directory-year.
6. Sarah Kuranda, “The 10 Biggest Data Breaches Of 2016 (So Far),” CRN.com, July 28, 2016, http:// www.crn.com/slide-shows/security/300081491/the-10-biggest-data-breaches-of-2016-so-far.htm/ pgno/0/1.
7. “HIPAA Fines Listed by Year,” Compliancy Group, https://compliancy-group.com/hipaa-fines- directory-year.
8. Ibid. 9. Ibid. 10. Jessica Davis, “Ransomware Accounted for 72% of Healthcare Malware Attacks in 2016,” Healthcare
IT News, April 27, 2017, http://www.healthcareitnews.com/news/ransomware-accounted-72- healthcare-malware-attacks-2016.
11. Thomas Fox-Brewster, “Medical Devices Hit by Ransomware for the First Time in US Hospitals,” Forbes.com, May 17, 2017, https://www.forbes.com/sites/thomasbrewster/2017/05/17/ wannacry-ransomware-hit-real-medical-devices/#3956264c425c.
12. Jonathan Crowe, “How One Ransomware Attack Cost Erie County Medical Center $10 Million,” Barkly. com, August 2017, https://blog.barkly.com/10-million-dollar-ecmc-hospital-ransomware-attack.
13. Ibid. 14. “Code of Federal Regulations,” U.S. Government Publishing Office (GPO), www.gpo.gov/help/
index.html#about_code_of_federal_regulations.htm.
F., S. R. (2018). Information governance for healthcare professionals : A practical approach. Productivity Press. Created from franklin-ebooks on 2022-09-07 22:14:07.
C op
yr ig
ht ©
2 01
8. P
ro du
ct iv
ity P
re ss
. A ll
rig ht
s re
se rv
ed .