Search the web
Sign In
New User? Sign Up
ShareHIPAA · Share HIPAA
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want your group to be featured on the Yahoo! Groups website? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Risk Analysis - 1st Step in HIPAA Security   Message List  
Reply | Forward Message #247 of 641 |
I have attached a white paper that was finalized November 16, 2004 on 45 CFR
Administrative Safeguard 164.308 Risk Analysis.  It mainly covers methods to
measure risk.

Risk assessment is just the first step, but very important step, in a HIPAA security
compliance program.  It will be the foundation of your mitigation work plan and
budget development which will need to be monitored and audited.

John Parmigiani, a key person in the drafting of the Final Security Rule, co-
authored this paper, wanting covered entities to understand qualitative and
quantitative.  He knows the importance of understanding and applying the results of
the risk assessment, having spent money on an algorithm risk assessment while at
DHHS and finding it unhelpful.  From my discussions with John, I would say that he
is a strong proponent of the NIST enterprise-wide risk management program. 

I am trying to set up a free interactive audio/video conference for presentation of
the concepts in the attached paper.  If I can beg and borrow the required bandwidth
and conference support, it will be conducted December 17, 2004.  I would say right
now, the chances are 50/50 so you might want to pencil in the date for 2:00 PM ET.
I will let you know if I was successful no later than December 10 and provide
additional information if so.
 
Wishing you a safe and happy Thanksgiving,
Barbara McGowin, CPC
Executive Recruiting
HIT Recruiting
(843) 824-8537
Connecting Healthcare Organizations with People,
Products and Services to Achieve HIPAA Compliance.



Mon Nov 22, 2004 3:27 pm

hitrecruiting
Offline Offline
Send Email Send Email

Attachment
Risk Analysis-Qual&Quan final.doc
Type:
application/msword
Forward
Message #247 of 641 |
Expand Messages Author Sort by Date

I have attached a white paper that was finalized November 16, 2004 on 45 CFR Administrative Safeguard 164.308 Risk Analysis. It mainly covers methods to ...
Barbara McGowin
hitrecruiting
Offline Send Email
Nov 22, 2004
3:45 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help