4-3 Paper: Controls to Manage Risks to Healthcare Information

profileBaba0914
Information_Governance_for_Healthcare_Professional..._----_Section_I_IG_Program_Considerations_and_Planning.pdf

74 ◾ Information Governance for Healthcare Professionals

Chapter Summary: Key Points ◾ Information risk planning is an essential activity in IG programs ◾ Healthcare organizations face major risks from data breaches, ransomware attacks, HIPAA

compliance, and other legal risks. ◾ In identifying information requirements and risks, legal requirements trump all others. ◾ The risk profile is a high-level, executive decision input tool which helps to gauge risks. ◾ A common risk profile method is to create a prioritized or ranked “Top Ten” list of greatest

risks to information. ◾ Once a list of risks is developed, grouping them into basic categories (e.g. natural disaster,

technology, compliance) helps stakeholders better understand them. ◾ The risk mitigation plan develops risk reduction options and tasks to reduce specified risks. ◾ Expected value is a calculation to determine the relative financial impact of a specified risk. ◾ Metrics are required to measure progress in the risk mitigation plan. ◾ Audits provide feedback on the progress of the risk mitigation plan.

notes 1. Elizabeth Snell, “The Role of Risk Assessments in Healthcare,” Health IT Security, https://healthitse-

curity.com/features/the-role-of-risk-assessments-in-healthcare. 2. “Summary of the HIPAA Security Rule,” Office for Civil Rights (OCR), last reviewed July 26, 2013,

https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html. 3. Eric Basu, “Implementing A Risk Management Framework For Health Information Technology

Systems - NIST RMF,” Forbes.com, August 3, 2013, http://www.forbes.com/sites/ericbasu/2013/08/03/ implementing-a-risk-management-framework-for-health-information-technology-systems-nist- rmf/#23e63d46523a.

4. Ryan Francis, “Ransomware Makes Healthcare Wannacry,” CSOOnline, May 15, 2017, https://www. csoonline.com/article/3196827/data-breach/ransomware-makes-healthcare-wannacry.html.

5. “HIPAA Fines Listed by Year,” Compliancy Group, https://compliancy-group.com/hipaa-fines- directory-year.

6. Sarah Kuranda, “The 10 Biggest Data Breaches Of 2016 (So Far),” CRN.com, July 28, 2016, http:// www.crn.com/slide-shows/security/300081491/the-10-biggest-data-breaches-of-2016-so-far.htm/ pgno/0/1.

7. “HIPAA Fines Listed by Year,” Compliancy Group, https://compliancy-group.com/hipaa-fines- directory-year.

8. Ibid. 9. Ibid. 10. Jessica Davis, “Ransomware Accounted for 72% of Healthcare Malware Attacks in 2016,” Healthcare

IT News, April 27, 2017, http://www.healthcareitnews.com/news/ransomware-accounted-72- healthcare-malware-attacks-2016.

11. Thomas Fox-Brewster, “Medical Devices Hit by Ransomware for the First Time in US Hospitals,” Forbes.com, May 17, 2017, https://www.forbes.com/sites/thomasbrewster/2017/05/17/ wannacry-ransomware-hit-real-medical-devices/#3956264c425c.

12. Jonathan Crowe, “How One Ransomware Attack Cost Erie County Medical Center $10 Million,” Barkly. com, August 2017, https://blog.barkly.com/10-million-dollar-ecmc-hospital-ransomware-attack.

13. Ibid. 14. “Code of Federal Regulations,” U.S. Government Publishing Office (GPO), www.gpo.gov/help/

index.html#about_code_of_federal_regulations.htm.

F., S. R. (2018). Information governance for healthcare professionals : A practical approach. Productivity Press. Created from franklin-ebooks on 2022-09-07 22:14:07.

C op

yr ig

ht ©

2 01

8. P

ro du

ct iv

ity P

re ss

. A ll

rig ht

s re

se rv

ed .