Why is HIPAA good for internal auditing?
Information systems security requirements Some might call this section of HIPAA the Information Systems Auditor Full Employment Act for the new millennium. There are myriad information systems security requirements. In the past, we talked about best practices and effective controls for information systems and security. In the future, we will talk about HIPAA mandated legislation for security and control. Because, for the first time, the US Federal Government will legislate the presence, development and continuous monitoring of compliance with these information security controls. In the past, it was injudicious not to have strong and effective internal controls in the information systems environment. In the future, organizations could be held liable for losses or disclosures that result from inadequate information security practices and controls with HIPAA mandated requirements. The result will be fines and sanctions. From this perspective, HIPAA helps our internal audit control objecti