15
Rethinking Compliance A Symposium Synopsis Provided by:

Rethinking Compliance

Embed Size (px)

Citation preview

Page 1: Rethinking Compliance

Rethinking ComplianceA Symposium Synopsis

Provided by:

Page 2: Rethinking Compliance

I attended University of the Cincinnati’s 28th Annual

Corporate Law Center Symposium- Rethinking

Compliance.

Page 3: Rethinking Compliance

The Symposium had a lot of great speakers, great information, and food for thought. Here are some

memorable quotes from the speakers:

Page 4: Rethinking Compliance

• On average, 205 days lapse between when a data security breach occurs and it is

discovered.

Page 5: Rethinking Compliance

• Staff training is not about teaching the law, it more about teaching staff to re-think.

Page 6: Rethinking Compliance

• If an unencrypted laptop is stolen, the OCR wants to talk. The laptop

should have been encrypted a long time ago.

Page 7: Rethinking Compliance

• Deliberate disregard and indifference is the same as

knowing.

Page 8: Rethinking Compliance

• If no one is following company policy, it is a red flag.

Page 9: Rethinking Compliance

• Billing and HIPAA are my biggest worries.

Page 10: Rethinking Compliance

• The health care industry sends 3% of its technology budget on security, while

all other industries spend an average 10%.

Page 11: Rethinking Compliance

• 90% of breaches are caused by failure to safeguard.

Page 12: Rethinking Compliance

• 123456 and ‘password’ are still the most common passwords

to be breached.

Page 13: Rethinking Compliance

• Encryption is not enough. It was on these surfaces and

hackers go in.

Page 14: Rethinking Compliance

• Most people want to do the right thing. It is a matter of

people knowing the right thing.

Page 15: Rethinking Compliance

Information Privacy

• Security Risk Analysis

• Training

• Assessment – Breach

Response

• Tracking – Monitoring

For health plan, providers, and Business Associates

www.gettinslaw.com 513-400-3895 [email protected]