Discuss how difficult and costly completing the assessment

Assignment Help Computer Engineering
Reference no: EM133698277

Homework

Purpose

In this homework, you will be provided a scenario in which you need to prepare for a HIPAA audit using materials found on the healthIT.gov website and using a government-provided online or downloadable tool to perform a risk assessment.

Instructions

You are the IT and Security Manager for a small five-physician medical practice that uses electronic medical records (EMR) but has never performed a HIPAA security risk assessment. You need to prepare for the upcoming HIPAA Audit, and the healthIT.gov site recommends performing a security risk assessment using their Security Risk Assessment (SRA) tool (downloadable or paper).

Based on the scenario above, review the questions in the Administrative Safeguards portion of the tool. This private practice has many written policies, but the policies are often not updated, and training new personnel on HIPAA requirements is a bit haphazard and poorly coordinated. The practice does not have a formally appointed security contact, although the office general manager is the one that most people go to. The one-person IT professional tries to protect the patient's information and access to that information as best that is possible, but people that leave the organization are often not immediately removed from having that access. Physical access to the building does require a key card access, but the building entrance is not monitored by cameras or the need to sign in. The company has not formally documented and mapped relevant business associates and has not secured business associate agreements related to patient information security. Although the receptionist area has a high counter, and patients typically cannot see the receptionist's computer screen, patients can hear the phone conversations in the receptionist area. Access to the medical records is password protected but not encrypted, and not all computer screens have automatic locks when the screens are idle.

I. Identify at least 10 Administrative Safeguard questions from the tool that are particularly relevant to this organization. Identify each by number and the specific wording of the question.

II. Discuss at least five identified threats or vulnerabilities and discuss the likelihood and overall impact of each of these vulnerabilities in a table like the one below for each threat/vulnerability (you should have five tables).

Likelihood

Impact

Low
Medium
High
Low
Low Risk
Low Risk
Low Risk
Medium
Low Risk
Medium Risk
Medium Risk
High
Low Risk
Medium Risk
High Risk

I. For each threat/vulnerability, describe one or more safeguards that could be implemented against the threat/vulnerability. Suggested safeguards can be found in the SRA tool.

II. Write a summary that discusses what you learned by participating in this exercise. Discuss how difficult and costly completing this assessment might be for the small medical practice described in this case. Recommend possible solutions to make this assessment process possible for this small practice.

Reference no: EM133698277

Questions Cloud

Define cybercrime and the categories of cybercrime : Define cybercrime and the categories of cybercrime. How understanding of differences among cultures affect your ability to make decisions within your company?
Describe each law and consequences for violation of the law : Describe each law and consequences for violation of the law. Discuss the reputational and financial impact this scenario might have on the organization.
What evidence would be needed to show compliance : What the question means? What evidence would be needed to show compliance? Whether it would be easy or difficult to achieve compliance and why?
Painless lump palpated at left vaginal opening : Appropriate hair distribution, No lesions, Small, painless lump palpated at left vaginal opening. Mild swelling noted.
Discuss how difficult and costly completing the assessment : Discuss how difficult and costly completing this assessment might be for the small medical practice described in this case.
Explain how the ssl and tls work : Read more about SSL and TLS and write a report explaining how they work. Use the following link as a starting point.
Design and implement a raytracer : CSE3PSD Professional Software Development, La Trobe University Implement a Zork-style text adventure and Design and implement a raytracer
Identify four aspects of end of life care : Identify four aspects of end of life care e.g., eligibility criteria, services provided, types of medical conditions, reimbursement models,
What have researchers learned about the negative impacts : What have researchers learned about the negative impacts of excessive social media use among teenagers, and ways to mitigate these negative impacts?

Reviews

Write a Review

Computer Engineering Questions & Answers

  List the benefits and challenges of big data

List the benefits and challenges of big data in the 21st-century globalized economy. What are some of the risks and how the risk can be mitigated. The response

  What is the history of osi model and benefits

Why you will recommend either asymmetric key encryption, symmetric key encryption, or no encryption at all for the Email correspondence.

  Define the difference between a tcp segment and an ip packet

What is the difference between a TCP segment and an IP packet, How are errors handled during transmission of segmented packets

  Compile your program into an executable called minicalc

Create a simple Makefile to compile your program into an executable called minicalc.

  Write about article related to a threat

Write at least 500 words analyzing a subject you find in this article related to a threat to confidentiality, integrity, or availability of data.

  Implement and tests the given two functions

Write a c++ program that implements and tests the following two functions related to the Calkin-Wilf enumeration of the positive fractions.

  Define it priorities and governance for it without

using a company of your choice determine the strategic business goals. develop an it strategy that aligns to the

  How would one go about finding information

How would one go about finding information for different roles in cyber security without reaching out to individuals? Find five professionals

  Demonstrate your program by applying to the shortcodes.txt

Demonstrate your program by applying to the 'ShortCodes.txt' text file on Canvas and using PROC PRINT to show that your final summary data set is correct.

  Discussion about scientific computing applications

You are required to search for research articles and related information on one of the applications of scientific computing in a selected domain, then to write.

  Write a function to input a sound then create a canvas sound

Write a function to input a sound, then create a canvas sound of the same length. Copy samples from the input into the canvas every third position.

  Write a program that will display your name

Write a program that will display your name, then when the user presses sw1 (d8) your favorite hobby or interest will be displayed. Then if they push sw1

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd