Reference no: EM133751577
Problem
You are the chief privacy officer (CPO) at WGU Hospital, a large teaching facility. A doctor brought a mobile device when going on break, during which the device was stolen from the doctor's car. The mobile device has access to the hospital's electronic health record (EHR).
As the CPO, you must determine how many patients' information was breached. Additionally, you must conduct a focused risk analysis of the breach to see which safeguards should be implemented to prevent future breaches, as well as identify which software should be implemented to ensure all regulatory concerns are appropriately addressed. Furthermore, you must craft a letter notifying all the patients affected in the breach.
Using the scenario above, complete the following:
A. Develop a plan to determine the number of patients whose information was breached.
B. Describe the steps that should be taken to perform the focused risk analysis of the breach.
C. Recommend an administrative safeguard that should be reviewed and updated to prevent future breaches from occurring.
D. Recommend a technical safeguard that should be reviewed and updated to prevent future breaches from occurring.
E. Recommend a physical safeguard that should be reviewed and updated to prevent future breaches from occurring.
F. Discuss two safekeeping practices the physician in the scenario should follow to prevent a future breach.
G. Discuss the applicable fines and penalties that could be imposed on the facility for this disclosure.
H. Describe a software the hospital should implement to make accessing mobile devices safer in the future.