Cybersecurity Risk Management – From HIPAA to HITRUST
Rich Curtiss, Director, Healthcare Risk Assurance Services
Cybersecurity risk management for healthcare organizations continues to be a perplexing issue. While it is explicit in the security management standard of the HIPAA Security Rule that a Covered Entity and their Business Associates must conduct an “accurate and thorough” risk analysis teamed with a plan to “implement security measures to reduce risks,” it is not immediately clear how this is to be accomplished.
Minimize Business Disruption and Move Forward with Solid Assessment Guidance
Dixon Wright, VP SOC, ISO, and Healthcare Services, Coalfire
COVID-19 has seized the world’s attention by disrupting the economy, the workforce, and our personal lives. While no one knows when this pandemic is going to end or its lasting impact, Coalfire is listening closely to our customers and doing everything we can to minimize disruption to their businesses. We are keenly aware that businesses must move forward with selling products and services and still have a need – albeit not “mission critical” – for third-party assurance.
Controlling Cyber Risk for Teleworkers with HITRUST
Jason Kor, Senior Manager, Healthcare Risk Assurance Services, Coalfire
Organizations across the globe have sent workers home to avoid spreading the Coronavirus and, as a result, technology leaders are hard-pressed to create cyber-safe work-from-home environments. Organizations must quickly identify and treat new cybersecurity risks introduced by the newly formed remote workforce.
The HITRUST Shared Responsibility Matrix – the Assessor’s Point of View
Mark Weech, Director, Healthcare Certification, Coalfire
HITRUST® announced the availability of the new Shared Responsibility Program and MatrixTM Version 1.0 to help communicate and assign security and privacy responsibilities between cloud service providers (CSPs) and their customers. Coalfire is proud that we helped develop the Matrix as part of the Shared Responsibilities Working Group and we appreciate the opportunity to offer some thoughts from the assessor’s perspective.
Quality is Job One When it Comes to the HITRUST CSF Assurance Program
Zach Shales, Principal, Healthcare Certification, Coalfire
The HITRUST CSF® remains an essential security and privacy controls framework that addresses the multitude of security, privacy, and regulatory challenges facing both public and private sector organizations. As framework adoption increases across all industries, maintaining integrity is crucial, and continuous improvement should always be top of mind with any endeavor. This was HITRUST’s clear intent when they announced the formation of an Assessor Council back in 2016 and a Quality Subcommittee in 2017. Read more