health information technology
1
IT 4533 Health Information Security & Privacy Summer 2016
Team or Individual Project Health First Case Study
Completed workbook due in Dropbox by 7/13/2016 (If working in a team, only one submission is required. Each team member needs to fill out the peer evaluation form)
Overview
In the US, many doctor’s offices or clinics are considered small businesses, as the Health First clinic introduced in the case study. These clinics must also adhere to federal laws governing privacy and security of patient information including the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its related security and privacy rules.
To help lead us through the case studies, a Security Workbook has been developed that guides small businesses through the process of organizing a security program. The Security Workbook provides a procedure for building security plans for a generic small business. In combination, the Health First Case Study and Security Workbook introduce a realistic organizational setting.
For this project:
We will only take two components of the Security Workbook to work with – HIPAA and Security Metrics. Two sets of slides as supplementary information are available. Materials are based on the information provided in ISACA’s CISA and CISM exam review books
Two components of the project:
HIPAA Adherence: HIPAA compliance is a necessary aspect of being in the medical profession. Summarize what all employees shall do, according to which HIPAA rule or standard, to maintain privacy of a patient’s health information, patient’s rights, and PHI disclosure. The workbook on “HIPAA Adherence” is on page 2.
Defining Security Metrics: Metrics are part of the Monitoring and Compliance function, and help to indicate whether controls and compliance are effective or not. While metrics are not absolutely necessary for the average small organization, any organization that is subject to regulation (e.g., HIPAA, SOX, FISMA) should take this section very seriously. In fact, most organizations would benefit from a few carefully selected metrics. The workbook on “Metrics” is on page 3-4.
Introduction to Health First:
Health First Organizational Chart
Health First
Jamie Ramon MD
Partner
Terry Winkler
Nurse
Tara Schultz
Medical Administrator
Sonia Jones
Temporary Assistant
Chris Ramon RD
Partner
Kenosha Software Consulting
Pat Carlson
Systems Analyst
Adrian Francois
Systems Administrator
2
To Be Completed and Submitted Use font color RED for your answers inserted in this document
HIPAA Adherence
Question: HIPAA compliance is a necessary aspect of being in the medical profession. Summarize what all employees shall do, according to which HIPAA rule or standard, to maintain privacy of a patient’s health information, patient’s rights, and PHI disclosure. Cite your sources.
Standard: Privacy Rule Privacy Implementation
Each medical officer shall:
When working with patient(s), shut door
…
…
…
…
…
…
Standard: Privacy Rule Patients’ Rights
Patient has the right to:
…
…
…
…
…
…
…
…
Standard: Privacy Rule Computer System Requirements
The Notice of Privacy Practices must be ……
The Notice of Privacy Practices must be emailed after ……
Standard: Privacy Rule: PHI Disclosure
Required Disclosure:
……
……
Permitted Disclosure:
Minimum-Necessary PHI ……
ID must be ……
Routine Disclosure
Disclosures that happen periodically may include……
Non-routine Disclosure
If a non-routine PHI disclosure is requested, ……
Your Solution may vary, but should be organized and written well.
3
Defining Security Metrics
Metrics are part of the Monitoring and Compliance function, and help to indicate whether controls and compliance are effective or not. While metrics are not absolutely necessary for the average small organization, any organization that is subject to regulation (e.g., HIPAA, SOX, FISMA) should take this section very seriously. In fact, most organizations would benefit from a few carefully selected metrics.
Strategic metrics include risk (ALE), budget, disaster recovery test results, and regulatory compliance.
Tactical metrics include policy compliance/non-compliance, incident management effectiveness, and risk changes resulting from system changes.
Operational metrics include firewall, IDS, or system log analysis, vulnerability test results, patch management status.
Here are some sample metrics, which may or may not apply to your organization.
Table 1: Example Metrics
Risk: The aggregate ALE % of risk eliminated, mitigated, transferred # of open risks due to inaction
Cost Effectiveness: Cost of workstation security per user Cost of email spam and virus protection per mailbox
Operational Performance: Time to detect and contain incidents Quantity & severity of incidents % of systems audited in last quarter
Organizational Awareness: % of employees passing quiz, after training vs. 3 months later % of employees taking training
Technical Security Architecture: # of malware identified and neutralized Types of compromises, by severity & attack type Attack attempts repelled by control devices Volume of messages, KB processed by communications control devices
Security Process Monitoring: Last date and type of BCP, DRP, IRP testing Last date asset inventories were reviewed & updated Frequency of executive management review activities compared to planned
Security Management Framework: Completeness and clarity of security documentation Inclusion of security in each project plan Rate of issue recurrence
Compliance: Rate of compliance with regulation or policy Rate of automation of compliance tests Frequency of compliance testing
Secure Software Development: Rate of projects passing compliance audits Percent of development staff certified in security Rate of teams reporting code reviews on high-risk code in past 6 months
Incident Response Metrics: # of Reported Incidents # of Detected Incidents Average time to respond to incident Average time to resolve an incident Total number of incidents successfully resolved Total damage from reported or detected incidents Total damage if incidents had not been contained in a timely manner
4
Step 1 Question. What are the most important areas to monitor in your organization? What threats and legislation are you most concerned with? You may want to review risk and policies to help define the most important areas to monitor.
Step 2 Question. After listing the most important threats, consider which metrics make the most sense to collect. Since automated metrics are doable in a busy world, is there an easy way to collect these metrics?
Step 3 Question. Consider the following three perspectives and different audiences:
Strategic: Management level: audit, policy; may discuss annually. Tactical: Observe how you are performing; view trends; may discuss every six months. Operational: Gather metrics and look at them; may discuss weekly or monthly.
After considering these three questions, complete the table below. You can add more rows if needed.
Table 2: Selected Metrics
Category Metric Calculation and Collection Method Period of Reporting
Strategic
Tactical
Operational
A competent system administrator can help to automate the collection of computer-generated metrics.