Execution of a self-directed risk assessment methodology to address HIPAA data security requirements

被引:1
|
作者
Coleman, J [1 ]
机构
[1] Adv Technol Inst, N Charleston, SC 29418 USA
关键词
FHPAA; privacy; security; OCTAVE; DOD; information assurance; risk assessment; risk management;
D O I
10.1117/12.480653
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper analyzes the method and training of a self directed risk assessment methodology entitled OCTAVE(sm) (Operationally Critical Threat Asset and Vulnerability Evaluation) at over 170 DOD medical treatment facilities. It focuses specifically on how OCTAVE built interdisciplinary, inter-hierarchical consensus and enhanced local capabilities to perform Health Information Assurance. The Risk Assessment Methodology was developed by the Software Engineering Institute at Carnegie Mellon University as part of the Defense Health Information Assurance Program (DHIAP). The basis for its success is the combination of analysis of organizational practices and technological vulnerabilities. Together, these areas address the core implications behind the HIPAA Security Rule and can be used to develop Organizational Protection Strategies and Technological Mitigation Plans. A key component of OCTAVE is the interdisciplinary composition of the analysis team (Patient Administration, IT staff and Clinician). It is this unique composition of analysis team members, along with organizational and technical analysis of business practices, assets and threats, which enables facilities to create sound and effective security policies. The Risk Assessment is conducted in-house, and therefore the process, results and knowledge remain within the organization, helping to build consensus in an environment of differing organizational and disciplinary perspectives on Health Information Assurance.
引用
收藏
页码:224 / 231
页数:8
相关论文
共 50 条
  • [41] Methodology of quantitative risk assessment for information system security
    Lin, MQ
    Wang, QM
    Li, JH
    COMPUTATIONAL INTELLIGENCE AND SECURITY, PT 2, PROCEEDINGS, 2005, 3802 : 526 - 531
  • [42] Do self-assessment and self-directed support undermine traditional social work with disabled people?
    Renshaw, Chris
    DISABILITY & SOCIETY, 2008, 23 (03) : 283 - 286
  • [43] Reflective journal assessment: The application of good feedback practice to facilitating self-directed learning
    Kim, Aise KyoungJin
    JOURNAL OF HOSPITALITY LEISURE SPORT & TOURISM EDUCATION, 2013, 13 : 255 - 259
  • [44] An assessment of a self-directed learning approach in a graduate Web application design and development course
    Ellis, Heidi J. C.
    IEEE TRANSACTIONS ON EDUCATION, 2007, 50 (01) : 55 - 60
  • [45] Unveiling Classroom Assessment Literacy: Does Teachers' Self-Directed Development Play Out?
    Gan, Ling
    Lam, Ricky
    EDUCATION SCIENCES, 2024, 14 (09):
  • [46] The Self-Directed Violence Classification System and the Columbia Classification Algorithm for Suicide Assessment: A Crosswalk
    Matarazzo, Bridget B.
    Clemans, Tracy A.
    Silverman, Morton M.
    Brenner, Lisa A.
    SUICIDE AND LIFE-THREATENING BEHAVIOR, 2013, 43 (03) : 235 - 249
  • [47] PILOT ASSESSMENT OF A SELF-DIRECTED PUBLIC HEALTH LEARNING MODULE FOR PRECLINICAL MEDICAL EDUCATION
    Edelman, David S.
    Karelas, Gregory
    Godfrey, Sarah
    Gordon, Rachel
    Lebwohl, Benjamin
    JOURNAL OF GENERAL INTERNAL MEDICINE, 2020, 35 (SUPPL 1) : S759 - S760
  • [48] Self-directed learning assessment practices in undergraduate health professions education: a systematic review
    Taylor, Tracey A. H.
    Kemp, Kyeorda
    Mi, Misa
    Lerchenfeldt, Sarah
    MEDICAL EDUCATION ONLINE, 2023, 28 (01):
  • [49] Self-directed reflective assessment for collective empowerment among pre-service teachers
    Yang, Yuqin
    Du, Yang
    Aalst, Jan
    Sun, Daner
    Ouyang, Fan
    BRITISH JOURNAL OF EDUCATIONAL TECHNOLOGY, 2020, 51 (06) : 1960 - 1980