HIPAA Risk Analysis and Risk Management - HHS/NIST Process Explained Step-by-Step Recorded Webinar | Paul R. Hales | From: May 25, 2021 - To: Dec 31, 2021 |
This webinar explains the NIST/HIPAA RA-RM procedures in easy-to-follow steps and correct terms - Risk, Threat, Vulnerability, etc. You should attend this webinar to learn why you must worry about not doing a HIPAA RA-RM properly - and how you can stop worrying by simply doing a HIPAA RA-RM as required every year.
Risk Analysis and Risk Management (RA-RM) are OCR's top enforcement priority and the basis for every HIPAA Compliance program. However, the biggest and most important nationwide HIPAA violation is failure to perform RA-RM in compliance with OCR requirements. OCR published shocking results of its Phase 2 HIPAA Compliance Audit on December 17, 2020, revealing that:
They failed despite the fact that they had been provided with all the audit questions and a list of the documents they would be required to provide well in advance and knew they were short-listed to be audited!
The HIPAA Rules do not explain the procedures required to perform RA-RM. However, OCR issued guidance explaining the required steps with specific reference to procedures created by the National Institute of Standards and Technology (NIST) and published in manuals that are free to download.
The problem many encounters is that NIST manuals, created by its Computer Security Division, are lengthy and technical.
This webinar explains, step-by-step, the exact RA-RM procedures OCR requires using NIST methodology and NIST defined terms such as Risk, Threat, Vulnerability, Impact, and Likelihood.
The steps are easy to follow when you know the steps. But there is more – that is why the webinar is titled OCR Compliance Plus.
While RA-RM required by the HIPAA Security Rule applies only to Protected Health Information (PHI) that is transmitted or maintained Electronically (EPHI), the NIST procedures are easily applicable to PHI in any form or format. And every organization has that kind of PHI, for example, paper records, forms, schedules, etc. This webinar explains how to protect your organization by identifying the risks and managing those risks to all PHI in every form and format. It will turn HIPAA RA-RM mystery into mastery. You'll learn how to perform the steps and create the documentation you need to pass an OCR audit. Most important, however, you'll see how to identify and manage Risks to the Privacy and Security of protected health information (PHI) maintained and transmitted in any form that seriously endangers your organization's well-being. You'll see HIPAA RA-RM is easy to do step-by-step – when you know the steps.
Areas Covered in the Session:-
Why you should Attend:-
Failure to do HIPAA RA-RM puts your organization in grave danger. RA-RM is the foundation of every HIPAA compliance program. Documentation of your RA-RM is the first thing HHS/OCR investigators ask to see.
This webinar will show you how to do a complete HIPAA RA-RM step-by-step and how easy it is to follow those steps when they are explained.
You should attend this webinar to learn why you must worry about not doing a HIPAA RA-RM properly - and how you can stop worrying by simply doing a HIPAA RA-RM as required every year.
Who Will Benefit:-
All Health Care Covered Entities
All Business Associates
Paul R. Hales received his Juris Doctor degree from Columbia University Law School and is licensed to practice law before the Supreme Court of the United States. He is an expert on HIPAA Privacy, Security, Breach notification and Enforcement Rules with a national HIPAA consulting practice based in St. Louis. Paul is the author of all content in The HIPAA E-Tool, an Internet-based, Software as a Service product for health care providers and business associates.