A Look at Risk Analysis—9 Steps for Getting it Right

A Look at Risk Analysis—9 Steps for Getting it Right

Understanding the Drivers for a HIPAA-Compliant Risk Analysis A lot of healthcare organizations today struggle with effectively meeting HIPAA Security Rule requirements because they don’t understand which assessments they need to do or how to conduct them. In...
Making it Easier to Identify Your Most Critical Risks

Making it Easier to Identify Your Most Critical Risks

As challenging as risk analysis and risk management can be, they’re critical parts of your overall cybersecurity program that can’t be overlooked. A comprehensive risk analysis helps you meet all of your regulatory and compliance requirements, and it also...
A Multi-Tiered Approach to Risk Monitoring Strategy

A Multi-Tiered Approach to Risk Monitoring Strategy

The HIPAA Security Rule, as well as NIST and other standards, stipulate that a risk analysis and risk management process should be ongoing, and not a once and done process. The Office for Civil Rights “Guidance on Risk Analysis Requirements Under the HIPAA Security...
A Thoughtful Approach to Managing Cyber Risk

A Thoughtful Approach to Managing Cyber Risk

As my colleague Alex Masten did an excellent job of describing in another recent Clearwater blog, the HIPAA Security Rule maintains that a risk analysis must be performed as new systems and technologies are implemented, or there are any material environmental changes....
Making Cyber Risk Management an Ongoing Process

Making Cyber Risk Management an Ongoing Process

The HIPAA Security Rule1, as well as the National Institute of Standards and Technology (NIST) and other standards, stipulate that a risk analysis and risk management process should be ongoing, and not performed at a single point in time. However, many healthcare...