Health insurance portability and accountability act

Assignment Help Other Subject
Reference no: EM13183909 , Length: 1500 Words

Healthcare companies, like ABC Healthcare, that operate as for-profit entities are facing a multitude of challenges. The regulatory environment is becoming more restrictive, viruses and worms are growing more pervasive and damaging, and ABC Heathcare's stakeholders are demanding more flexible access to their systems.

The healthcare industry is experiencing significant regulatory pressures that mandate prudent Information security and systems management practices. Furthermore, the continued pressure to reduce cost requires that management focus on streamlining operations, reducing management overhead and minimizing human intervention. The regulatory focus at ABC Healthcare is on the Health Insurance Portability and Accountability Act (HIPAA) and Sarbanes-Oxley (SOX). Both pieces of legislation highlight the need for good systems administration and controls, but focus on different aspects of the business. The main focus of HIPAA is to protect personally identifiable health information while SOX is concerned with data that impacts financial reporting. Violations may be met with both civil and criminal penalties. Therefore, the company must be ever watchful of new threats to their systems, data, and business operations.

The most prevalent security related threat to on-going business operations is the continued development and propagation of viruses and worms. Virus and worm prevention or containment is a vital component to the overall risk mitigation strategy. Virus and worm outbreaks have multiple cost aspects for the company including lost patient charges due to system unavailability, lost productivity because of recovery efforts due to infection, and potential regulatory impacts depending on the virus or worm payload. However, the company must balance risk with opportunities to serve our stakeholders and grow the business.

ABC Healthcare's stakeholders include multiple groups that depend on or need access to clinical and/or financial systems to help support and grow the company. The access requirements and associated risk model varies by user group. The main access groups are internal only users (i.e. nurses, hourly employee, etc.), internal/remote users (i.e. salaried employees, doctors, etc.), and business partners (i.e. collection agencies, banks, etc.). Risk mitigation solutions must be developed for each user group to help ensure that the company recognizes the benefit that each brings and minimizes the risk to business operations. The high-level management goals of the network design implementation are as follows:

• Support the business and balance security requirements without introducing significant overhead and complexity
• Maintain and enhance security without significantly increasing management overhead or complexity;
• Implement systems that are industry supported (standards where appropriate), scalable, and fault-tolerant;
• Ensure that the design is implemented to help ensure compliance with any and all applicable regulations.
• Proper management of access control for legitimate users and malicious users is of the utmost importance for the security of the ABC Healthcare management system. The threat is not limited to outside malicious users but also legitimate users engaged in illegitimate activity. 

Based on the above description you are to provide a recommendation of how you would address each of the following ABC Healthcare's computer network security requirements. Note whereas cost is typically an important factor this is not a consideration for this case analysis. Therefore you do not need to include cost estimates. Your solution should have the "right feel", despite the lack of depth or details necessary to be accepted by upper management. Be specific in your answers. Write them as if you were writing a proposal to your boss. You do not need to include citations. Since you are developing a solution to a specific circumstance, material that is copied from an outside source will not likely fit so everything should be in your own words.


• Describe your vision for addressing the security requirements in the overall technical design of the ABC Healthcare network. This should include both internal and external (untrusted and trusted) aspects. Untrusted would include user connectivity to the Internet. The "trusted" network has the main purpose of supporting the business functions of known entities (i.e. partners, suppliers, etc.) which have a business relationship with the company. Note you are to concentrate on the high level and are not expected to provide low level details for your recommended design. (40 points, 1200 word limit)

• Discuss the way you will address requirements for system monitoring, logging, auditing, including complying with any legal regulations. (15 points, 500 word limit)

• Describe how you the system will identify and authenticate all the users who attempt to access ABC Healthcare information resources. (15 points, 500 word limit)

• Discuss how the system shall recover from attacks, failures, and accidents (15 points, 500 word limit)

• Discuss how the system will address User Account Management and related security improvements. (15 points, 500 word limit) 

Reference no: EM13183909

Questions Cloud

Importance of proper packaging for for seed merchandising : Discuss "The knowledge that the seed companies could potentially recoup their investment through sales will provide a strong incentive for the companies to develop new, more useful varieties that the market demands. indicating the importance of prope..
What is the conclusion : If this passage is an argument, what is the conclusion? Computers will never be able to converse intelligently through speech. A simple example proves that this is so.
Explain connection with attitude and behavior change : Critically examines the role of cognitive dissonance is social cognition and Explain how cognitive dissonance plays a role in hypocrisy, and explain connection with attitude and behavior change?
Intense physiological arousal and psychological interest : A state of intense absorption in someone that includes intense physiological arousal, psychological interest, and caring for the needs of another is called __________ love.
Health insurance portability and accountability act : Healthcare companies, like ABC Healthcare, that operate as for-profit entities are facing a multitude of challenges. The regulatory environment is becoming more restrictive, viruses and worms are growing more pervasive and damaging,
Cost and qualifications or equirements important features : Cost and qualifications/requirements are important features that would be helpful if included on a web page.
Types and amounts of advertising the store : The manager of a department store in Seattle is attempting to decide on the types and amounts of advertising the store should use. He has invited representatives from the local radio station, television station, and newspaper to make presentations in..
Report on the wireless standard called bluetooth : Write a 3000-word report on the wireless standard called Bluetooth. Answer the following questions in your report.
Address requirements for system monitoring-logging-auditing : Discuss the way you will address requirements for system monitoring, logging, auditing, including complying with any legal regulations.

Reviews

Write a Review

Other Subject Questions & Answers

  Explaining about spousal testimony

During trial, the wife of the main subject, also charged as a co-conspirator, makes an offer of cooperation in return for a lighter sentence. Apply the rules of evidence to the above situation. Maximum 200 words.

  Ssociological perspective toward crime

Illustrate out the sociological perspective toward crime, making certain that you define the three major concepts: Use examples of crime, such as from the mass media, to illustrate this perspective.

  What is the probability that miss rain got the job

What is the probability that the park gates will be opened on time. ii If the gates are opened on time, what is the probability that Miss Rain got the job.

  Shortcoming of disaster relief efforts

A common shortcoming of disaster relief efforts is that they

  Develop a series of dialogs that attendant may encounter

The gas-pump service technician has a laptop with software designed to query and control the electronic gas pump over a communication link. Develop a series of dialogs that the attendant may encounter when troubleshooting the pump.

  Global warming and cause of hiv-aids infection

Considering the threat of global warming, take a position on whether or not this could play a role in infectious disease. Provide specific examples to support your response.

  Locke and knowledge

How does Locke differentiate between knowledge of substance and general ideas? In particular, why does he think that knowledge of nature, like Newtonian physics, is really belief, while mathematics

  Diagnosis of adhd

Is there a biological test that can diagnose Attention Deficit Hyperactivity Disorder (ADHD) in a child?

  Identify cognitive stage of this child

When mother spreads food around to cool it, child becomes hysterical. Why did child become upset. Identify cognitive stage of this child.

  How to classify moral reasoning

Hani told him not to worry as Mom would understand that it was the accident. In what stage would Jean Piaget classify moral reasoning, respectively, of Jerome and Hani?

  Functions of the safety and health committee

Outline the duties and responsibilities of a registered safety and health officer Outline the composition and functions of the safety and health committee

  Reasons for civil asset forfeiture

What are specific reasons for civil asset forfeiture?

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd