HIPAA and information security risk: implementing an enterprise-wide risk management strategy

Christopher Alberts, Audrey Dorofee · Proceedings of SPIE, the International Society for Optical Engineering/Proceedings of SPIE · 2001

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 effectively establishes a standard of due care for healthcare information security. One of the challenges of implementing policies, procedures, and practices consistent with HIPAA requirements in the Department of Defense Military Health System is the need for a method that can tailor the requirements to a variety of organizational contexts. This paper will describe a self- directed information security risk evaluation that will enable military healthcare providers to assess their risks and to develop mitigation strategies consistent with HIPAA guidelines.

Read the paper · More papers on PaperTik