health information technology

profileeboraps
IT4533_HealthFirstCaseStudy_ProjectReq2.pdf

1

IT 4533 Health Information Security & Privacy Summer 2016

Team or Individual Project Health First Case Study

Completed workbook due in Dropbox by 7/13/2016 (If working in a team, only one submission is required. Each team member needs to fill out the peer evaluation form)

Overview

In the US, many doctor’s offices or clinics are considered small businesses, as the Health First clinic introduced in the case study. These clinics must also adhere to federal laws governing privacy and security of patient information including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its related security and privacy rules.

To help lead us through the case studies, a Security Workbook has been developed that guides small businesses through the process of organizing a security program. The Security Workbook provides a procedure for building security plans for a generic small business. In combination, the Health First Case Study and Security Workbook introduce a realistic organizational setting.

For this project:

We will only take two components of the Security Workbook to work with – HIPAA and Security Metrics. Two sets of slides as supplementary information are available. Materials are based on the information provided in ISACA’s CISA and CISM exam review books

Two components of the project:

HIPAA Adherence: HIPAA compliance is a necessary aspect of being in the medical profession. Summarize what all employees shall do, according to which HIPAA rule or standard, to maintain privacy of a patient’s health information, patient’s rights, and PHI disclosure. The workbook on “HIPAA Adherence” is on page 2.

Defining Security Metrics: Metrics are part of the Monitoring and Compliance function, and help to indicate whether controls and compliance are effective or not. While metrics are not absolutely necessary for the average small organization, any organization that is subject to regulation (e.g., HIPAA, SOX, FISMA) should take this section very seriously. In fact, most organizations would benefit from a few carefully selected metrics. The workbook on “Metrics” is on page 3-4.

Introduction to Health First:

Health First Organizational Chart

Health First

Jamie Ramon MD

Partner

Terry Winkler

Nurse

Tara Schultz

Medical Administrator

Sonia Jones

Temporary Assistant

Chris Ramon RD

Partner

Kenosha Software Consulting

Pat Carlson

Systems Analyst

Adrian Francois

Systems Administrator

2

To Be Completed and Submitted Use font color RED for your answers inserted in this document

HIPAA Adherence

Question: HIPAA compliance is a necessary aspect of being in the medical profession. Summarize what all employees shall do, according to which HIPAA rule or standard, to maintain privacy of a patient’s health information, patient’s rights, and PHI disclosure. Cite your sources.

Standard: Privacy Rule Privacy Implementation

Each medical officer shall:

 When working with patient(s), shut door

 …

 …

 …

 …

 …

 …

Standard: Privacy Rule Patients’ Rights

Patient has the right to:

 …

 …

 …

 …

 …

 …

 …

 …

Standard: Privacy Rule Computer System Requirements

 The Notice of Privacy Practices must be ……

 The Notice of Privacy Practices must be emailed after ……

Standard: Privacy Rule: PHI Disclosure

Required Disclosure:

 ……

 ……

Permitted Disclosure:

 Minimum-Necessary PHI ……

 ID must be ……

Routine Disclosure

 Disclosures that happen periodically may include……

Non-routine Disclosure

 If a non-routine PHI disclosure is requested, ……

Your Solution may vary, but should be organized and written well.

3

Defining Security Metrics

Metrics are part of the Monitoring and Compliance function, and help to indicate whether controls and compliance are effective or not. While metrics are not absolutely necessary for the average small organization, any organization that is subject to regulation (e.g., HIPAA, SOX, FISMA) should take this section very seriously. In fact, most organizations would benefit from a few carefully selected metrics.

 Strategic metrics include risk (ALE), budget, disaster recovery test results, and regulatory compliance.

 Tactical metrics include policy compliance/non-compliance, incident management effectiveness, and risk changes resulting from system changes.

 Operational metrics include firewall, IDS, or system log analysis, vulnerability test results, patch management status.

Here are some sample metrics, which may or may not apply to your organization.

Table 1: Example Metrics

Risk: The aggregate ALE % of risk eliminated, mitigated, transferred # of open risks due to inaction

Cost Effectiveness: Cost of workstation security per user Cost of email spam and virus protection per mailbox

Operational Performance: Time to detect and contain incidents Quantity & severity of incidents % of systems audited in last quarter

Organizational Awareness: % of employees passing quiz, after training vs. 3 months later % of employees taking training

Technical Security Architecture: # of malware identified and neutralized Types of compromises, by severity & attack type Attack attempts repelled by control devices Volume of messages, KB processed by communications control devices

Security Process Monitoring: Last date and type of BCP, DRP, IRP testing Last date asset inventories were reviewed & updated Frequency of executive management review activities compared to planned

Security Management Framework: Completeness and clarity of security documentation Inclusion of security in each project plan Rate of issue recurrence

Compliance: Rate of compliance with regulation or policy Rate of automation of compliance tests Frequency of compliance testing

Secure Software Development: Rate of projects passing compliance audits Percent of development staff certified in security Rate of teams reporting code reviews on high-risk code in past 6 months

Incident Response Metrics: # of Reported Incidents # of Detected Incidents Average time to respond to incident Average time to resolve an incident Total number of incidents successfully resolved Total damage from reported or detected incidents Total damage if incidents had not been contained in a timely manner

4

Step 1 Question. What are the most important areas to monitor in your organization? What threats and legislation are you most concerned with? You may want to review risk and policies to help define the most important areas to monitor.

Step 2 Question. After listing the most important threats, consider which metrics make the most sense to collect. Since automated metrics are doable in a busy world, is there an easy way to collect these metrics?

Step 3 Question. Consider the following three perspectives and different audiences:

Strategic: Management level: audit, policy; may discuss annually. Tactical: Observe how you are performing; view trends; may discuss every six months. Operational: Gather metrics and look at them; may discuss weekly or monthly.

After considering these three questions, complete the table below. You can add more rows if needed.

Table 2: Selected Metrics

Category Metric Calculation and Collection Method Period of Reporting

Strategic

Tactical

Operational

A competent system administrator can help to automate the collection of computer-generated metrics.