1
00:00:00,510 --> 00:00:01,343
In this lesson,

2
00:00:01,343 --> 00:00:03,930
we're going to perform an external assessment.

3
00:00:03,930 --> 00:00:06,270
Now, the exact checklist and procedures

4
00:00:06,270 --> 00:00:08,610
that you're going to use to perform an external assessment

5
00:00:08,610 --> 00:00:09,540
are going to vary,

6
00:00:09,540 --> 00:00:12,270
depending on your organization's own governance, risk,

7
00:00:12,270 --> 00:00:13,650
and compliance practices.

8
00:00:13,650 --> 00:00:16,620
But, for the video, we will be using a sample checklist

9
00:00:16,620 --> 00:00:19,770
from the Government of San Bernardino County in California

10
00:00:19,770 --> 00:00:22,470
as a demonstration of the kind of questions asked

11
00:00:22,470 --> 00:00:24,600
during an external assessment or audit

12
00:00:24,600 --> 00:00:28,350
for an organization that must comply with HIPAA Regulations.

13
00:00:28,350 --> 00:00:30,510
To prepare for a HIPAA external assessment,

14
00:00:30,510 --> 00:00:31,830
you should go through the checklist

15
00:00:31,830 --> 00:00:33,180
provided by your assessors

16
00:00:33,180 --> 00:00:34,950
and ensure that you can answer each question

17
00:00:34,950 --> 00:00:36,150
as "Yes" or "No,"

18
00:00:36,150 --> 00:00:38,340
and then provide a link to a file

19
00:00:38,340 --> 00:00:41,310
as evidence that you meet that requirement.

20
00:00:41,310 --> 00:00:44,520
Okay, here is the "HIPAA Audit Checklist."

21
00:00:44,520 --> 00:00:47,760
For example, the first line, under the General Information,

22
00:00:47,760 --> 00:00:50,437
states that you must complete the enclosed

23
00:00:50,437 --> 00:00:54,150
"HIPAA Privacy and Security Performance Audit Survey."

24
00:00:54,150 --> 00:00:56,880
Now, if you have completed it, you just simply mark "Yes,"

25
00:00:56,880 --> 00:00:58,290
and then you'll add the link,

26
00:00:58,290 --> 00:01:00,510
the file of your organization's share drive

27
00:01:00,510 --> 00:01:04,140
or external file sharing portal like Dropbox, Google Drive,

28
00:01:04,140 --> 00:01:04,973
OneDrive,

29
00:01:04,973 --> 00:01:07,980
or wherever else that you have been asked to provide,

30
00:01:07,980 --> 00:01:10,440
your evidence files, for this assessment.

31
00:01:10,440 --> 00:01:13,140
Now, let's take a quick look at the other types of things

32
00:01:13,140 --> 00:01:14,790
that you may be asked to provide

33
00:01:14,790 --> 00:01:16,800
during your HIPAA Assessment.

34
00:01:16,800 --> 00:01:18,840
Now, if we scroll down to the HIPAA Security,

35
00:01:18,840 --> 00:01:22,140
we see we have the General Governance - HIPAA security.

36
00:01:22,140 --> 00:01:23,940
We must be able to identify

37
00:01:23,940 --> 00:01:27,840
any applicable industry guidance such as studies, practices,

38
00:01:27,840 --> 00:01:30,060
regulations, or other reference material

39
00:01:30,060 --> 00:01:32,790
used to develop any of the policies and procedures

40
00:01:32,790 --> 00:01:34,230
requested below.

41
00:01:34,230 --> 00:01:38,168
No need to provide this documentation, simply identify.

42
00:01:38,168 --> 00:01:39,990
So again, it's going to be a "Yes" or "No" question,

43
00:01:39,990 --> 00:01:41,550
and then we're going to indicate

44
00:01:41,550 --> 00:01:43,740
where that particular file or document is.

45
00:01:43,740 --> 00:01:45,270
But, per this statement,

46
00:01:45,270 --> 00:01:47,910
we don't need to provide any documentation.

47
00:01:47,910 --> 00:01:48,743
We scroll down,

48
00:01:48,743 --> 00:01:51,960
we see under General Governance - HIPAA Security;

49
00:01:51,960 --> 00:01:54,000
Security Officer contact information.

50
00:01:54,000 --> 00:01:56,340
We have name, email, phone number, address,

51
00:01:56,340 --> 00:01:58,620
and admin contact info.

52
00:01:58,620 --> 00:02:01,200
And now, we see under Administrative Safeguards,

53
00:02:01,200 --> 00:02:03,270
do we have an entity-level risk assessment?

54
00:02:03,270 --> 00:02:06,210
Do we have risk assessments for systems

55
00:02:06,210 --> 00:02:09,090
that house electronic, protected health information?

56
00:02:09,090 --> 00:02:12,390
Do we have a risk management policy, organizational chart,

57
00:02:12,390 --> 00:02:13,223
et cetera?

58
00:02:13,223 --> 00:02:16,980
So, we're going to scroll down and go to the next section.

59
00:02:16,980 --> 00:02:18,390
We already looked at the category

60
00:02:18,390 --> 00:02:19,920
of Administrative Safeguards.

61
00:02:19,920 --> 00:02:21,300
Now, the Physical Safeguards.

62
00:02:21,300 --> 00:02:23,915
Do we have physical security policies and procedures,

63
00:02:23,915 --> 00:02:27,859
data destruction and media reuse procedures,

64
00:02:27,859 --> 00:02:31,110
a list of roles based access, job level,

65
00:02:31,110 --> 00:02:33,420
and level of protected health information access

66
00:02:33,420 --> 00:02:34,770
needed for function,

67
00:02:34,770 --> 00:02:35,880
a log of employees

68
00:02:35,880 --> 00:02:39,240
based on their protected health information access type?

69
00:02:39,240 --> 00:02:41,040
And then, if we look at the other category

70
00:02:41,040 --> 00:02:42,300
of Technical Safeguards,

71
00:02:42,300 --> 00:02:45,150
do we have encryption policies and procedures?

72
00:02:45,150 --> 00:02:48,630
Do we have management's internal control/internal audit

73
00:02:48,630 --> 00:02:52,680
policies and procedures related to monitoring IT safeguards?

74
00:02:52,680 --> 00:02:55,200
Also, do we have system generated user access

75
00:02:55,200 --> 00:02:56,490
listing up all individuals

76
00:02:56,490 --> 00:02:59,100
with access to the system housing the PHI?

77
00:02:59,100 --> 00:03:01,410
Now, let's scroll down again to the Privacy section.

78
00:03:01,410 --> 00:03:02,460
Now we see a category

79
00:03:02,460 --> 00:03:04,560
for General Governance and HIPAA Policy.

80
00:03:04,560 --> 00:03:05,827
The first question says,

81
00:03:05,827 --> 00:03:08,910
"Identify any applicable industry guidance against studies,

82
00:03:08,910 --> 00:03:12,120
practices, regulations, or other reference materials

83
00:03:12,120 --> 00:03:14,330
used to develop any of the policies and procedures

84
00:03:14,330 --> 00:03:16,380
requested below."

85
00:03:16,380 --> 00:03:18,240
Again, on this particular section,

86
00:03:18,240 --> 00:03:21,210
no need to provide documentation; simply identify.

87
00:03:21,210 --> 00:03:23,040
So, do we have compliance, privacy,

88
00:03:23,040 --> 00:03:25,950
officer contact information, email, phone number,

89
00:03:25,950 --> 00:03:27,840
address, et cetera?

90
00:03:27,840 --> 00:03:32,430
I'll just scroll down here, just to see other documentation.

91
00:03:32,430 --> 00:03:33,810
In the last section we have here,

92
00:03:33,810 --> 00:03:37,005
it's the HITECH Organization Process-Based Capabilities.

93
00:03:37,005 --> 00:03:39,420
And now, the acronym HITECH

94
00:03:39,420 --> 00:03:41,520
stands for Health Information Technology

95
00:03:41,520 --> 00:03:43,560
for Economic and Clinical Health.

96
00:03:43,560 --> 00:03:45,420
Now, the HITECH Act was created

97
00:03:45,420 --> 00:03:48,870
to motivate the implementation of electronic health records

98
00:03:48,870 --> 00:03:51,450
and supporting technologies for the United States.

99
00:03:51,450 --> 00:03:53,430
That's just a general background about HITECH.

100
00:03:53,430 --> 00:03:55,147
So again, it's just going to ask;

101
00:03:55,147 --> 00:03:57,510
"Do we have breach notification processes,

102
00:03:57,510 --> 00:03:59,310
entity level risk assessment documentation,

103
00:03:59,310 --> 00:04:00,990
and capabilities?"

104
00:04:00,990 --> 00:04:03,060
And of course, if yes, say "Yes."

105
00:04:03,060 --> 00:04:05,550
If no, say "No," and then provide the file location

106
00:04:05,550 --> 00:04:07,380
for that particular information.

107
00:04:07,380 --> 00:04:08,970
So, as you can see,

108
00:04:08,970 --> 00:04:11,850
these external assessments can be pretty broad

109
00:04:11,850 --> 00:04:13,890
and they are seeking to get a quick overview

110
00:04:13,890 --> 00:04:16,170
of your organization's current risk posture

111
00:04:16,170 --> 00:04:19,680
through a truly independent, third-party assessor.

112
00:04:19,680 --> 00:04:22,260
These assessments and audits will not do anything

113
00:04:22,260 --> 00:04:23,700
to fix your security issues,

114
00:04:23,700 --> 00:04:26,455
but instead, they are used as a validation function

115
00:04:26,455 --> 00:04:28,110
to prove that your organization

116
00:04:28,110 --> 00:04:29,820
is meeting a certain level of compliance

117
00:04:29,820 --> 00:04:32,100
to attempt to minimize its attack surface,

118
00:04:32,100 --> 00:04:34,350
and that is prepared to defend itself

119
00:04:34,350 --> 00:04:36,663
against known cybersecurity threats and risk.

