Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

What types of “significant events” would trigger a risk assessment? What types of things should an organization consider when conducting a risk assessment involving portable media?

0
Posted

What types of “significant events” would trigger a risk assessment? What types of things should an organization consider when conducting a risk assessment involving portable media?

0

Response: Examples of a “significant event” as indicated in HS 2(a)(i), include a breach of information systems security, system reconfiguration or software update and merging information systems with another company. This standard is consistent with the requirements set forth by the Center for Medicare/Medicaid Services (CMS); however, it is more stringent. Organizations must be aware of their exposure to risk regarding portable media. Either these devices should not contain personal health information or the devices should be encrypted. Given that operating systems often allow for auto-populating passwords, devices containing personal health information, including portable media, should require end-users to enter a password or organizations should, at a minimum, implement second factor authentication.

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123