What should the risk analysis include

Assignment Help Other Subject
Reference no: EM133265841

Case: In 2014, the Department of Health and Human Services reported on its website a $4.8 million HIPAA settlement with New York and Presbyterian Hospital (NYP) and Columbia University following the 2010 breach of thousands of patients' e-PHI. A Columbia University physician, who was an attending physician at NYP, tried to deactivate a computer server that he owned on the network that contained NYP patient e-PHI. The e-PHI became accessible to the public on Internet search engines because technical safeguards were lacking. A patient's loved one found e-PHI about the patient on the Internet and filed a complaint.

In addition to the impermissible disclosure, both entities were noncompliant in other ways: (1) no attempts had been made to assure the server was secure; (2) a thorough risk analysis had never been completed that identified all systems able to access the e-PHI of NYP patients and therefore no plan to address potential threats and hazards existed; (3) no appropriate policies and procedures existed regarding authorizing access to its databases; and (4) they did not follow their own policies on information access management (HHS 2014).
This costly mistake, both monetarily and from a reputation standpoint, highlights the negative outcomes that can happen when both technical and administrative safeguards are not followed. It also emphasizes the importance of inventorying all systems and devices that can access an organization's e-PHI to address threats and an organization's vulnerabilities. This is not an easy task given the number of personal and mobile devices that access e-PHI, but it is critical.

Question 1. A risk analysis should include an inventory of all systems and devices that can access an organization's ePHI (in this case, the breach occurred via a physician's personal computer server). How can an organization account for all systems and devices on which PHI may be accessed or otherwise present?

Question 2. What should the risk analysis include?

Question 3. Should the physician have been the one to deactivate the server? Why or why not?

Reference no: EM133265841

Questions Cloud

Sense to build software without define software process : Does it ever make sense to build software without a define software process? ?Why or why not?
Review how asthma is diagnosed and current national standard : Review how asthma is diagnosed and current national standards (guidelines). Pick one screening test and review its sensitivity, specificity, predictive value
What role does change management play with regards : What role does change management play with regards to an EHR implementation? Why is change management important? What are some key strategies for successful
CPU can access main memory-CPU accessing eripheral devices : Which of these statements about the way the CPU can access main memory, vs. the CPU accessing eripheral devices, is not true?
What should the risk analysis include : What should the risk analysis include and Should the physician have been the one to deactivate the server? Why or why not
Six basic operators of relational algebra : After listing the six basic operators of the relational algebra, express r n s using the basic operator.
How will you apply what you have learned from this research : How will you apply what you have learned from this research to your recommendations for your own facility?
Apply the joint commission''s definition of sentinel event : HEALTH 467 University of Wisconsin, Madison Apply the Joint Commission's definition of sentinel event to determine if the following are clinical snippet
Identify and analyze the legal and ethical issues implicated : Health 1051 St. John's University Identify and analyze the legal and ethical issues implicated by the patient letter below. Offer assessments of claim success

Reviews

Write a Review

Other Subject Questions & Answers

  Cross-cultural opportunities and conflicts in canada

Short Paper on Cross-cultural Opportunities and Conflicts in Canada.

  Sociology theory questions

Sociology are very fundamental in nature. Role strain and role constraint speak about the duties and responsibilities of the roles of people in society or in a group. A short theory about Darwin and Moths is also answered.

  A book review on unfaithful angels

This review will help the reader understand the social work profession through different concepts giving the glimpse of why the social work profession might have drifted away from its original purpose of serving the poor.

  Disorder paper: schizophrenia

Schizophrenia does not really have just one single cause. It is a possibility that this disorder could be inherited but not all doctors are sure.

  Individual assignment: two models handout and rubric

Individual Assignment : Two Models Handout and Rubric,    This paper will allow you to understand and evaluate two vastly different organizational models and to effectively communicate their differences.

  Developing strategic intent for toyota

The following report includes the description about the organization, its strategies, industry analysis in which it operates and its position in the industry.

  Gasoline powered passenger vehicles

In this study, we examine how gasoline price volatility and income of the consumers impacts consumer's demand for gasoline.

  An aspect of poverty in canada

Economics thesis undergrad 4th year paper to write. it should be about 22 pages in length, literature review, economic analysis and then data or cost benefit analysis.

  Ngn customer satisfaction qos indicator for 3g services

The paper aims to highlight the global trends in countries and regions where 3G has already been introduced and propose an implementation plan to the telecom operators of developing countries.

  Prepare a power point presentation

Prepare the power point presentation for the case: Santa Fe Independent School District

  Information literacy is important in this environment

Information literacy is critically important in this contemporary environment

  Associative property of multiplication

Write a definition for associative property of multiplication.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd