| |
|
| |
|
Axian' HIPAA Security Services
Security Risk Assessment
Services
At the core of complying with the Final Security
Rule is the principle of performing a risk analysis to ultimately provide
the road map for deciding how to implement the
security rule. Since this is a stated requirement in the rule, organizations
that lack the internal resources (or confidence) to conduct a thorough
risk analysis may be receptive to using an outside firm with technical
competence in this area. (In fact, the final rule indicates that covered
entities may use an "external agency" to conduct the risk analysis.)
An overall risk analysis service tailored to HIPAA security
regulations must be thorough and facilitate the development of a complete
gap analysis identifying risks and vulnerabilities to the flow and safeguarding
of electronic protected health information. Axian personnel have thorough
knowledge of the security regulations and can develop a risk assessment
process, set of tools, and deliverables to achieve this objective. The
risk analysis needs to be carefully mapped to the requirements in the
final rule, thereby appropriately covering technical and process reviews
for administrative security, application security, physical security,
and network security areas.
Security
Planning and Policy Development Services
Another core part of HIPAA security compliance is the development
and documentation of security policies and procedures in a number of areas
such as sanction policy, workforce clearance, information access, security
incidents, contingency plans for electronic PHI backup
and disaster recovery, to cite a few. For small to midsized healthcare
organizations that are covered entities, such as clinics and group practices,
the development of written policies and procedures may seem daunting.
Let Axian help you.
HIPAA
Security Remediation Services
Axian's HIPAA services work with the client organization (and, where
appropriate, the client's vendors) on design, implementation, testing
and ongoing compliance. This would cover system upgrades/replacements,
OS platforms, applications, and recurrent testing services (e.g., vulnerability
analysis, penetration testing). Axian also provides managed security services
on an outsourced basis.
Computer
Forensics Services
Axian's computer forensics experience applies well to security breaches
that have a direct bearing on HIPAA security compliance. Since security
breaches could result in litigation or a criminal lawsuit, Axian can play
a major role in capturing and securing the evidence for the client organization
and its associated attorneys. Forensic services are also afforded to law
firms that provide HIPAA legal services.
|
|