Reference no: EM133985030
Question
"Salinas Valley Health undergoes a third-party audit of its systems security program to ensure compliance with best practices, Health Insurance Portability and Accountability Act (HIPAA) regulations and Centers for Medicare and Medicaid Services (CMS's) Promoting Interoperability program requirements. We assess our program against HIPAA security standards and in recent years, the cybersecurity framework standards by the National Institute of Standards and Technology (NIST).
We previously used Cynergistek. As with any third-party assessor, a good practice is to change assessors to ensure a fresh review of our security program and another assessor's opinion. Impact Advisors is rated best in KLAS for systems security for three years running and we are confident they bring relevant knowledge and strong experience to the table.
We are seeking a three-year engagement at $49,000/year plus out-of-pocket expenses estimated at $9,800/year. This represents a 25% decrease from last year's annual fee. We will finalise a full risk assessment in year one, and a health check in years two and three of this agreement."
the above memo is an example
Can we write one Memo similar to the above memo in the quote, our current supplier is Trustwave a company we are replacing Trustwave with Impact Advisors? Currently, Trustwave provide the services below :
1. Fusion
2. Vulnerability Management
3, Colony (learning centre)
4. their service is short of the SIEM as that was the engagement from the initial contract 2 years ago and we are not keeping them as they are gaps in their services that we have identify.
The Memo should motivate why we should the new supplier called Impact advisors.