How does MC4 address HIPAA concerns?
The security and privacy of personal medical information is paramount. Therefore, MC4 PMO closely adheres to rigorous security and accreditation processes when integrating medical information management systems that harvest millions of deployed Service members personal records. Specifically, MC4 follows the Department of Defense Information Assurance Certification and Accreditation Process (DIACAP), formerly known as the Defense Information Technology Security Certification and Accreditation Process (DITSCAP), to ensure system risks are identified and documented. This allows the program to coordinate between different entities to ensure concurrence and to identify acceptable risks. The DIACAP documents fall within the DIACAP artifacts, which allows information to be shared with other parties for official use only. The DIACAP artifacts provide evidence that the MC4 system has an acceptable security posture, which allows its use on DoD networks. MC4 also shares Certification and Accredit