This information comes directly from HHS and provides more details regarding how covered entities may directly develop and comply with completing and documenting a security risk assessment.
https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
HIPAA compliance is federally regulated by the Department of Health and Human Services and the Office of Civil Rights… Many of the same standards for patient privacy and data security are also enforced under State Consumer Protection Laws that govern medical privacy of protected health information and consumer privacy protection of personal identifiable information.
The federal standards have been in place since 2005… States have ramped up there consumer protection laws since 2020… Mostly in response to rampant cyber attacks and data breaches.
Covered entities are required to comply with HIPAA regulations, but those regulations are often not very prescriptive. Great latitude is allowed determining the best way covered entities can comply with standards under HIPAA… So there’s no one best way to do this… Some people benefit from extra support and others don’t need or want it.
The webinar offered by Patient Data Protection is best suited for health care providers who might benefit from additional support to clarify certain terms and concepts and direction to help them meet this requirement, and find value in receiving that extra help.
It’s a live webinar structured to allow all participants to finish by completing their own unique clinic SRA based on the template provided by HHS, while providing participants an opportunity to ask questions along the way.
I hope you find the HHS website information helpful…