Developing an information security program for HIPAA compliance

  • Authors:
  • Jeremy McDaniel

  • Affiliations:
  • Kennesaw State University, Kennesaw, GA

  • Venue:
  • 2009 Information Security Curriculum Development Conference
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Health Information Portability and Accountability Act (HIPAA) of 1996 mandates several policy and technology security standards that must be implemented for healthcare organizations that deal, store and process electronic patient medical records. The enforcement of this law can present many organizational and technical challenges to healthcare providers with no formal information security program processes in place. The use of security models, such as NIST SP 800-66 and the formal SecSDLC security program methodology, can help healthcare providers put an information security program in place that enforces HIPAA compliance and ensures the protection of their health information systems.