Building a HIPAA-Compliant Cybersecurity Program

  • Thompson E
N/ACitations
Citations of this article
36Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Intro -- Table of Contents -- About the Author -- About the Technical Reviewer -- Acknowledgments -- Introduction -- Part I: Why Risk Assessment and Analysis? -- Chapter 1: Not If, but When -- Evolving Regulations and~Threat Landscape -- A New Kind of~Adversary -- Proliferation of~Ransomware -- Malware for~Sale -- It Costs Money When Things Go~Wrong -- The Approach Must Change -- Comply, but Not for~the~Sake of~Compliance -- Going on~the~Offensive -- Creating and~Trusting the~Process -- Summary -- Chapter 2: Meeting Regulator Expectations -- Introduction of~a~Proactive Audit Program -- Does Language and~Tone Lead to~Inaction? -- Why Does This Language Exist in~the~Guidance? -- Risk Analysis Methodology -- Scope and~Data Collection -- Threats -- Implement and~Assess Security Measures -- Vulnerabilities -- Risk Identification -- Likelihood and~Impact -- Other Risk Analysis Guidance and~Methodology -- HITRUST -- OCTAVE -- Choosing a~Framework Is Not Permanent -- Summary -- Chapter 3: Selecting Security Measures -- Cybersecurity Frameworks to~the~Rescue -- The NIST Cybersecurity Framework -- Identify -- Protect -- Detect -- Respond -- Recover -- Implementing Internal Controls Aligned with Subcategories -- The Cybersecurity Policy -- Measuring the~Cybersecurity Program -- Capability Maturity Model -- PRISMA -- Addressing Compliance Requirements -- HIPAA Security Rule -- Administrative Safeguards -- Physical Safeguards -- Technical Safeguards -- Summary -- Part II: Assessing and Analyzing Risk -- Chapter 4: Inventory Your ePHI -- Take a~Step Back and~Break Down the~Process -- Healthcare Provider Example -- Healthcare Plan/Payer Example -- Business Associate Example -- Create the~Asset List -- Summary -- Chapter 5: Who Wants Health Information? -- NIST Threat Guidance -- Inputs and~Threat Source Identification -- Types of~Adversaries State-Sponsored Attackers -- Organized Cybercriminals -- What Makes These Groups Sophisticated? -- Malicious Insiders -- Hacktivists -- Summary -- Chapter 6: Weaknesses Waiting to~Be~Exploited -- Predisposing Conditions -- Documenting Vulnerabilities -- Vulnerability Buckets Based on~the~NIST CSF -- Summary -- Chapter 7: Is It Really This Bad? -- Risk Statements -- Likelihood -- Impact -- Measuring Risk -- Creating the~Risk Register -- Risks Identified to~ePHI -- Graphical Representation of~Risks -- Reevaluation of~Risks Based on~a~Chaining of~Events -- Very High Risks -- High Risks -- Moderate -- Putting These Things into Business Terms -- Operational Impacts -- Financial Statement Impacts -- Summary -- Chapter 8: Increasing Program Maturity -- Moving from~Ad Hoc to~Operational -- Identify -- Protect -- Detect -- Respond -- Recover -- Addressing Very High and~High Risks -- Very High Risks -- Summary -- Chapter 9: Targeted Nontechnical Testing -- The Nontechnical {\textquotedbl}Eye Test{\textquotedbl} -- Access Management -- Privileged Access -- Reviewing Privileged Access -- Application Access -- Change Control -- Code and~Other Changes to~Functionality -- Patches -- How to~Test the~Change Management Process -- Training and~Awareness -- Incident Management -- Third-Party (Vendor) Risk Management -- Updating the~Risk Analysis and~Risk Register -- Summary -- Chapter 10: Targeted Technical Testing -- The Technical {\textquotedbl}Eye Test{\textquotedbl} -- Assessing Directory Services -- Data Loss Prevention -- Cloud Discovery and~Governance -- Vulnerability Identification and~Management -- Attack and~Penetration/Red Team Testing -- Testing Results and~Risk Updates -- Access Management Testing -- Data Protection Testing -- Vulnerability Management and~Attack Detection Testing -- Summary -- Part III: Applying the Results to Everyday Needs -- Chapter 11: Refreshing the~Risk Register Updating the~Risk Register -- Identify -- Protect -- Detect -- Respond -- Recover -- Risk Heat Map Updated -- Summary -- Chapter 12: The Cybersecurity Road Map -- Defining the~Cybersecurity Strategy -- The Three-Year Road Map -- Foundational -- How to~Measure Cybersecurity Capabilities Against~Foundational Requirements? -- Identify -- Protect -- Detect -- Respond -- Recover -- Focused Improvement -- Revisiting the~Kill Chain -- Training and~Awareness -- Baseline Configurations -- Boundary Security -- Monitoring End-User Activity -- Intelligence and~Analytics-Driven Security -- Threat Intelligence -- Machine Learning and~Artificial Intelligence -- Threat Analysis and~Reverse Engineering -- Decoys -- Addressing HIPAA Security Rule Requirements -- Summary -- Part IV: Continuous Improvement -- Chapter 13: Investing for~Risk Reduction -- Arbitrary Benchmarks and~Other Budget Fallacies -- Cybersecurity As~a~Percentage of~Total IT Spend -- How Much Does Cybersecurity Cost? -- Remembering the~Human Factor of~Budgeting -- A Risk-Based Approach to~Cyber Budgeting -- The Updated Risk Analysis -- Cybersecurity Objectives and~Road Map -- Investing in~the~Fundamentals -- Targeted Improvements of~the~Program -- Intelligence and~Analytic-Driven Program -- Summary -- Chapter 14: Third-Party Risk: Beyond the~BAA -- Analyzing Third-Party Risk -- Governing Third-Party Risk Management -- Evaluating Security Controls -- Gathering Relevant Information -- SOC 2-Common Criteria -- CC 1.0: Common Criteria Related to~Organization and~Management -- CC 2.0: Common Criteria Related to~Communications -- CC 3.0: Common Criteria Related to~Risk Management and~Design and~Implementation of~Controls -- CC 4.0: Common Criteria Related to~Monitoring Controls -- CC 5.0: Common Criteria Related to~Logical and~Physical Access Controls -- CC 6.0: Common Criteria Related to~System Operations CC 7.0: Common Criteria Related to~Change Management -- ISO Certification -- HITRUST Certification -- Cybersecurity Questionnaire -- Gathering Additional Details -- Evaluate Security Controls and~Identify Risks -- Evaluating Threats to~ePHI Held at the~Third Party -- Identifying Vulnerabilities at the~Third Party -- Measuring Risk at the~Third Party -- Risk Statements -- Third-Party Risk Integration -- A Word on~Cloud Solutions -- Summary -- Chapter 15: Social Media, BYOD, IOT, and~Portability -- Social Media -- Business Needs vs. Risks -- Danger Lurks Around the~Corner -- Addressing Social Media Risks -- Internet of~Things (IoT) -- Bring Your Own Device (BYOD) -- Portable Devices -- Summary -- Chapter 16: Risk Treatment and~Management -- Creating the~Risk Treatment and~Management Plan -- Very High Risks -- High Likelihood and~Very High Impact Risks -- Moderate-High Likelihood and~Moderate Impact -- Moderate-Moderate Likelihood and~Very High Impact -- Moderate-Moderate Likelihood and~High Impact -- Summary -- Chapter 17: Customizing the~Risk Analysis -- Risk Analysis Parameters -- Likelihood -- Assessing the~Level of~Maturity -- Assigning Impact Values -- Very Low -- Low -- Moderate -- High -- Very High -- Risk Analysis Walkthrough: Two Examples -- Access Management Risk -- Evaluating Likelihood -- Evaluating Impact -- Monte Carlo Simulations of~Likelihood and~Impact -- Insecure Development and~Quality Assurance Environments -- Evaluating Likelihood -- Evaluating Impact -- Monte Carlo Simulation Assumptions -- Comparing the~Results -- Summary -- Chapter 18: Think Offensively -- The Risk Analysis Journey -- Threat Actors and~Scenarios -- Vulnerabilities -- Impact -- Get Offensive -- The HIPAA Compliant Program -- Take Ten Minutes Each Day and~Get the~Process Started -- Month One: Identifying All Instances of~ePHI -- Month Two: Vulnerabilities Month Three: Threat Actors and~Vulnerability Mapping -- Month Four: Measure the~Likelihoods -- Month Five: Measure the~Impacts -- Month Six: Identify Cybersecurity Controls -- Get Better -- Summary -- Appendix A NIST CSF Internal Controls -- Appendix B NIST CSF to~HIPAA Crosswalk -- Identification: Asset Management -- Identification: Business Environment -- Identification: Governance -- Identification: Risk Assessment -- Identification: Risk Management -- Protect: Access Control -- Protect: Awareness and~Training -- Protect: Data Security -- Protect: Information Protection -- Protect: Maintenance -- Protect: Protective Technology -- Detect: Anomalies and~Events -- Detect: Continuous Monitoring -- Detection: Detection Processes -- Response: Response Planning -- Response: Communications -- Response: Analysis -- Response: Mitigation -- Response: Improvement -- Recovery: Recovery Planning -- Recovery: Improvements -- Recovery: Communications -- Appendix C Risk Analysis Templates -- Risk Analysis Template -- Instances of ePHI -- Threats -- Vulnerabilities -- Risk Ratings and Graph -- Risk Heat Map -- Third-Party Risk Template -- Cover Sheet -- Threats -- Potential Vulnerabilities -- Third-Party Controls -- Third-Party Risk Analysis -- Index

Cite

CITATION STYLE

APA

Thompson, E. C. (2017). Building a HIPAA-Compliant Cybersecurity Program. Building a HIPAA-Compliant Cybersecurity Program. Apress. https://doi.org/10.1007/978-1-4842-3060-2

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free