How are you going to reduce your risk

Assignment Help Operation Management
Reference no: EM133441304

SCENARIO: A health care system executive left their work-issued laptop, which had access to over 40,000 medical records, in a locked car while running an errand. The car was broken into, and the laptop stolen. ATTACK: Physical theft of an unencrypted device. Encryption is the process of scrambling readable text so it can only be read by the person who has the decryption key. It creates an added layer of security for sensitive information. RESPONSE: The employee immediately reported the theft to the police and to the health care system's IT department who disabled the laptop's remote access and began monitoring activity. The laptop was equipped with security tools and password protection. Data stored on the hard drive was not encrypted - this included sensitive, personal patient data. The hospital had to follow state laws as they pertain to a data breach. The U.S. Department of Health and Human Services was also notified. Personally Identifiable Information (PII) and Protected Health Information (PHI) data require rigorous reporting processes and standards. After the theft and breach, the health care system began an extensive review of internal policies; they created a discipline procedure for employees who violate security standards. A thorough review of security measures with internal IT staff and ancillary IT vendors revealed vulnerabilities. IMPACT: The health care system spent over $200,000 in remediation, monitoring, and operational improvements. A data breach does impact a brand negatively and trust has to be rebuilt. LESSONS LEARNED: 1 Companies must establish and train employees on secure handling of work-issued devices. 2 Devices must be safely stored when not in the immediate presence of the employee. 3 Companies must take steps to encrypt data wherever it is stored or transmitted. Employees should have a clear understanding of the importance of encryption and how to use it. 4 Companies must understand and know their responsibilities under the data breach notification laws of the state(s) in which they operate. 5 A regular review of the company's security practices is imperative in modern organizations to prevent incidents, discover vulnerabilities, and to reduce impact of incidents.

Questions: DISCUSS:

• Knowing how the firm responded, what would you have done differently?

• What are some steps you think the firm could have taken to prevent this incident?

• Is your business susceptible to this kind of attack? How are you going to reduce your risk?

Reference no: EM133441304

Questions Cloud

How many pounds of cod are applied to aeration basin daily : If the COD concentration of the wastewater is 160 mg/L, how many pounds of COD are applied to the aeration basin daily?
How did crowdsourcing affect the customer experience : How did crowdsourcing affect the customer experience with the Coke brand? Why did such a simple action as putting a name on a Coke bottle/can have such an
Discuss the range of ethical-csr issues : Discuss the range of ethical/ CSR issues and unique challenges that food restaurant faces?
What is mexico city underlying lesson : According to book Daniel Hernandez Down and Delirious in Mexico city in Chapter 2(point of Arrival), what is Mexico City's "underlying lesson"?
How are you going to reduce your risk : What are some steps you think the firm could have taken to prevent this incident? Is your business susceptible to this kind of attack? How are you going
What are your thoughts on the various options employers : What are your thoughts on the various options employers can take? In your opinion, what do you believe is the best approach an employer should take when contest
Discuss a monopoly with a constant marginal cost : Consider a monopoly with a constant marginal cost of 10 that faces the following inverse demand function from senior citizens.
What would you do the staff associated in this situation : What would you do the staff associated in this situation? Why? What are the risks of telling the truth for you? What are the benefits? Explain.
Impact of the environment on the development of individuals : Humans are a product of their environment. Using two (2) of the following theories, discuss the impact of the environment on the development of individuals.

Reviews

Write a Review

Operation Management Questions & Answers

  Knowledge management and operational performance

How does innovation meditate the relationship between Knowledge management and operational performance?

  Taking action to reduce the damage caused

Taking action to reduce the damage caused by security incidents can be referred as ______ security control.

  Illustrate sources also forms of his authority

Illustrate explain how you believe of a person will have to proceed in establishing herself as legitimate possessor of supervisory authority on unit also illustrate sources also forms of his authority that he can use it.

  Health maintenance organization

Health maintenance organization (HMOs), Preferred provider organization (PPOs), Individual Practice Association (IPAs),

  Considering process of revising paper the introduction

Considering the process of revising a paper the introduction and literature review.

  Fundamentally different from product marketing

Some service marketers maintain that service marketing is fundamentally different from product marketing and that different skills are involved. Some traditional product marketers disagree, saying that “good marketing is good marketing”.

  Explain the core cultural dimensions

Explain the core cultural dimensions. Discuss the central tendencies in the Anglo, East/Southeast Asian, Germanic and Latin Europe clusters.

  How can the current process be improved

In your work experiences and perhaps your undergrad degree you've been exposed to and studied continuous improvement.

  Focuses on written persuasive messages

This question focuses on WRITTEN persuasive messages only. How can you increase your own credibility when writing persuasive messages in the post-trust era?

  How bapco bahrain employs knowledge management

Explain how Bapco Bahrain employs knowledge management in order to train and develop its employees? Enhance your answer with examples

  How do politics affect program management process

How do politics affect program management and the policy process? How can public administrators help to lessen obstacles created by politics?

  What exactly is the practice of public relations

What exactly is the practice of public relations?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd