FairWarning Helps Northeastern Academic Health System Stay in Compliance with HIPAA Regulations

Similar documents
Threats From Within Are Now the #1 Concern for Most Healthcare Organizations

FairWarning Lightens Burdens, Increases Efficiency of Hospital CIO / Security Officer

Privacy Auditing in a Mixed McKesson Application Environment

Provider ICD 10 Compliant Release A S K E S I S W E B I N A R F E B R U A R Y 1 9,

WEALTH MANAGEMENT: ON YOUR TERMS

Institutional Review Board Standard Operating Procedure. Suspension and Termination of IRB Approval

The CIO Series. IT Projects Are Like Marriages in the View of Malcolm Simpkin, CIO of Aviva UK General Insurance C IO. March 2012

Ware Malcomb. Riverbed Steelhead Products Improve Collaboration and Productivity for Architecture Services Firm

Operating Committee Strategic Plan

C O R P O R AT E B R O C H U R E

Commercial/ Central IRB An independent organization that provides IRB review services

the HRPP Director will prepare a draft report within three (3) workdays after the IRB meeting at which the determination occurred.

QIC. their ICT systems business Optus Business helps to deliver greater customer value

2012 HEAT ILLNESS PREVENTION TRAINING

So you want to be a RCM

Practical Guide to ICD 10:

Questions and Answers Management Services Agreement between The Powder Horn and Troon Privé. November 15, 2015

UNIVERSITY OF TENNESSEE HEALTH SCIENCE CENTER INSTITUTIONAL REVIEW BOARD CONTINUING REVIEW OF RESEARCH

1. The Middletown Public Schools will have defibrillators in each school building.

CHAMPIONS OF OUR BRAND

12 RECOMMENDATIONS Road Improvements. Short Term (generally the next five years)

Licking County Health Department 675 Price Rd., Newark OH (740)

GUIDE TO RUNNING A BIKE SHARE. h o w t o p l a n a n d o p e r a t e a s u c c e s s f u l b i k e s h a r e p r o g r a m

ONLINE INCIDENT REPORTING SYSTEM

Creative Solutions for your compliance burdens

Accelerate Your Riverbed SteelHead Deployment and Time to Value

Progress with the Road Investment Strategy

IN-PLANT TRAINING PROGRAM KNOWLEDGE BASED TRAINING DEVELOPMENT OF PRACTICAL SKILLSL SKILLS COMPREHENSIVE REFERENCE MATERIALS

REPORT General Committee

Hazardous Waste Training Plan. Supersedes: 02/15/16 (Rev.02) Preparer: Owner: Approver: EHS Team Member EHS Team Member EHS Manager

European Hockey Federation. Strategic Plan to 2016

PRESENTATION TO THE BRITISH COLUMBIA LEGISALTIVE STANDING COMMITTEE ON FINANCE September 26, 2013

Australian Volleyball Federation

Mandatory Self-Disclosure of Product Problems to the CPSC

MINE SAFETY TARGETED ASSESSMENT PROGRAM. Ground or strata failure NSW metalliferous mines. April

Overview of Recovery and Rescue Validation, Verification and Extrapolation

New Zealand Thoroughbred Racing (NZTR) Job Description

Items 1, 2, 3, and 4: Origination, CHC-A details, Tracking status, Administrative details

Why walk? Introducing Heart Foundation Walking! What is Heart Foundation Walking? Your role. Host Organisation

FedRAMP JAB P-ATO Process PRIORITIZATION CRITERIA. VERSION 1.0 November 11, 2016

Photo by ZoomFiji. Strategic Plan. Fall Fall usa rugby 2500 arapahoe avenue, suite 200 boulder, colorado 80302

Using Social Media During an Emergency. Public Information Committee Webinar November 9, 2017

VOLLEYBALL ALBERTA - WEB PRIVACY POLICY

SUBJECT: RAPID INTERVENTION CREW (RIC) SOG DATE ADOPTED: OCTOBER 18, 2012 REVISED: PAGES: 7

AS SSA AS SSA Australian Standard. Australian Fish Names Standard. This is a free 8 page sample. Access the full version online.

November 30, Efficient Startup of Multi-site Research Studies: Central IRBs and National IRB Reliance Platforms

City of San Diego Vision Zero Draft Strategic Plan FY 2017

SOCIAL MEDIA AND CYBER SAFETY POLICY

Car Theft in Australia IAATI Training Seminar. Ray Carroll Executive Director

AEI GROUP. Whistleblowing Policy

INCIDENT COMMAND SYSTEM POSITION MANUAL DECONTAMINATION LEADER ICS-1104 JULY 2016

TENNIS BC PROVINCIAL REGROUPINGS APPLICATION FORM

#cspfuture APPRAISAL OF THE FUTURE ROLE OF CSPS ANDY REED OBE

Strategic Plan Basketball in Victoria:

Up and Comers: Building a Successful Internship Program. Kamille Ramos USGA, Manager of Inclusion & Talent Acquisition

HEALTH CARE SYSTEMS RESEARCH NETWORK

Critical Alert is an absolute necessity -Nursing Home Administrator, MA. Proudly Made in the USA

A word from the Program Administrator.

BSAC Strategic Plan. January 2016 December National Governing Body for scuba diving and snorkelling

Chapter 4 Institutional Review Board (IRB) Roles and Authorities

University of Iowa External/Central IRB Reliance Process Standard Operating Procedure (SOP)

Signature Date Date First Effective: Signature Date Revision Date: 07/18/2011

Valve Replacement: Using Non-Intrusive Isolation Technology to Minimize Production Downtime


6/19/2014. Children s Hospital of Philadelphia: Recent Changes. Recent Changes in CHOP IRB Procedures

CONTINUING REVIEW OF APPROVED IRB PROTOCOLS

10-Hour OSHA Training

Wayne State University Institutional Review Board

Guidance Note. NXT Advisors

The primary purpose of the TFF is to help promote a healthy farm tenanted sector in Scotland. It aims to fulfil this purpose by:

Policy Contact Melissa Chaney, Director, Human Resources Department, (916)

NONCOMPLIANCE. 1. Overview

2011 ScheduALL FOXTEL

Skillsoft Course Catalog. Legal Collection

Corporate Partner Packet

ADDIS ABABA ROAD SAFETY STRATEGY

2016 Lady Warrior. Soccer Handbook

Community Development and Recreation Committee. General Manager, Parks, Forestry and Recreation. P:\2015\Cluster A\PFR\CD AFS#22685

Sport and Sports Betting Integrity Action Plan 2017

Swim Ontario Strategic Plan. World Leader in swimming development at all levels

RESEARCH PROTECTIONS OFFICE

Encouragement. Chapter 4. Education Encouragement Enforcement Engineering & Facilities Evaluation & Planning. Encouragement Chapter 4

IMD Governance Review at a glance

OVA Privacy Policy. a) Arranges and encourages volleyball matches and competitions within Ontario;

MONOPLACE HYPERBARIC CHAMBER EMERGENCY PROCEDURES April 2006

SOP 801: Investigator Qualifications and Responsibilities

SPONSORSHIP OPPORTUNITIES

Your Roadmap to Single IRB Review Serving as a Reviewing IRB

Strategic Plan. Aorangi Golf Strategic Plan

USOC ATHLETE ADVERTISING WAIVER SYSTEM. User Guide October 2015

Office of Inspector General The School District of Palm Beach County

Position Description

WHITE PAPER A Framework for Cyber Threat Hunting

Raise Your Hand If. Todays Cybersecurity Risks. June 14, WBA BOLT Summer Leadership Summit 1. May 4, 2018

Division of Occupational Safety and Health (Cal/OSHA) Southern California Trade Contractors Association Heat Illness Prevention Training

PRINTED COPY IS NOT CONTROLLED Page 1 of 22

CURRENT STATE OF U.S. AED LAWS

Materials Performance November Nitrogen generator inhibits corrosion within fire protection systems

Chief Firearms Office of Ontario

Industry update on Ontario s Public Pools and Recreational Camps Regulations under the Health Protection and Promotion Act

Transcription:

Northeastern System Client Profile This Northeastern System located in the United States is one of the largest healthcare organizations in its region, offering the most sophisticated medical technology & support. Challenge After experiencing two significant privacy breaches, this health system was looking for a proactive approach to regulatory compliance and prevention of future incidents. Solution FairWarning Managed Privacy Services (MPS) Results Maintains a proactive privacy monitoring program Augments available tools and resources used by staff Increases privacy policy awareness Experiences excellent customer service FairWarning Helps Northeastern System Stay in Compliance with HIPAA Regulations One of the largest healthcare systems in the Northeast United States, needed a proactive approach to regulatory compliance relating to protected health information.

Overview As a large healthcare system, it was important for the organization to constantly be vigilant about compliance with federal and state regulations relating to protected health information. After two significant privacy breaches, a solution was needed that would help the organization take a proactive approach to monitoring patient record access and respond quickly to access privilege violations. The Challenges Like many enterprise health systems, the organization operates in a very intense regulatory landscape with limited staff and resources. The goal of their initial investment with FairWarning was to implement a proactive monitoring solution to automatically identify privacy and security breaches that could possibly turn into HIPAA violations. The challenge was that their existing staff and resources had to compete with other timeconsuming priorities making it difficult to reach their desired monitoring state. 2 We needed a solid system with good recommendations from other users that could be implemented fairly quickly, giving us the efficiency we were looking for. We found that with FairWarning Managed Privacy Services. Chief Privacy Officer One of the most important precursors to us searching for a more robust solution and revising our privacy-related policies was that we had two major internal breaches that caused us to have to make notifications to patients as well as to the state Attorney General and the federal government, explains the Chief Privacy Officer. So, my first priority was to make certain that we had implemented everything that we told the government that we were going to do That included FairWarning Managed Privacy Services.

Solution 3 It was important for the organization's privacy team to find a solution that would help the healthcare system evaluate its privacy monitoring processes from good to great as fast as possible. We needed assistance with the massive analysis and reporting burden, shares the Chief Privacy Officer. And, FairWarning Managed Privacy Services offered the most effective solution. FairWarning Managed Privacy Services (MPS) is an affordable solution for health care providers of all sizes. FairWarning s expert team of HIPAA compliance, security, and product analysts provide worry-free experts, thereby freeing up internal privacy teams to work on higher value projects. Results After a smooth implementation, the organization began to experience a range of benefits right away. FairWarning Managed Privacy Services permits us to proactively monitor for instances of inappropriate access. Without it, we would not have the ability to do that. Maintains a Proactive Privacy Program By offboarding alert monitoring, analysis, and reporting to the specialists at FairWarning, the organization has a privacy system that helps keep them in compliance with HIPAA regulations and helps keep staff in compliance with internal policies relating to patient information. MPS permits us to proactively monitor for instances of inappropriate access, says the CPO. This technology has made it so much easier for us to do that. Maximizes Existing Staff and Resources Given the size of the healthcare system, working with a small staff was a major concern. Now the privacy team is able to maximize existing staff and resources by utilizing MPS as their solution. Having MPS has greatly enhanced what we can do as a team, says the CPO. That s because MPS frees up the existing staff s time, allowing them to focus on other important privacy-related activities such as ongoing awareness and education programs that help to reduce the risk of privacy breaches.

Conducts More Efficient Investigations 4 Investigations of possible privacy breaches are now much more efficient. That s because FairWarning specialists monitor all system alerts and provide the privacy team with a fully documented investigation report that contains information about what types of access occurred and what specific follow-up steps are necessary. MPS streamlines our investigation process, explains the CPO. Now, it takes much less time for us to pinpoint where the inappropriate access occurred and when it occurred. From there we can skip a couple of steps and immediately identify who the employee is, and who their supervisor is, so that we can address the issue quickly. Increases Privacy Policy Awareness With MPS in place, the privacy team can partner with the HR department to increase awareness among existing employees, and educate new employees about its privacy policies. The use of FairWarning has helped us heighten employee awareness about privacy concerns. says the CPO. We believe the fact that we can effectively communicate with managers about pending investigations related to staff they supervise has had a positive effect by lowering the number of occurrences. Experiences Excellent Service from the FairWarning Team The CPO continues to be impressed by the team of specialists at FairWarning. No question or request for assistance is too problematic for them, they share. Having a single contact person who is able to address our issues on the spot is a huge benefit. When I need a report that has to be specifically crafted for my leadership team, all I need to do is ask for it. I'm definitely happy with the level of support that we get. Having MPS has greatly enhanced what we can do as a team. The information that FairWarning produces is voluminous. Thankfully, MPS is there to help us weed through it all. I can t imagine doing what we are able to do now without a much larger staff. When asked about her overall satisfaction with MPS, the CPO was full of praise. We needed a solid system with good recommendations from other users that could be implemented fairly quickly and would give us the efficiency we were looking for. We found that with MPS.

Northeastern System About this Northeastern System This healthcare system is the clinical partner of a university in the Northeastern region of the United States, and one of the largest healthcare systems in the area. The system is a non-profit healthcare network providing primary through quaternary care. 5 About FairWarning FairWarning strives to protect the health, wealth, and personal information for every person on Earth. The company s industry-leading, affordable application security solutions provide data protection and governance for Electronic Health Records (EHRs), Salesforce, Office 365, and hundreds of other applications. FairWarning solutions protect organizations of all sizes against data theft and misuse through real-time and continuous user activity monitoring and improve compliance effectiveness with complex federal and state privacy laws such as HIPAA, PCI, FINRA, SOX, FISMA and EU Data Protection Act. FairWarning catches people stealing your data. 13535 Feather Sound Drive, Suite 600 Clearwater, Florida 33762 USA For more information, please visit www.fairwarning.com 727-576-6700 Solutions@FairWarning.com Copyright 2004-2017 FairWarning, Inc. All rights reserved. Various trademarks held by their respective owners.