legal disclaimer - clearwater...some webinar logis2cs/ground rules 1. slide materials a. check...
TRANSCRIPT
©ClearwaterCompliance|AllRightsReserved
1
LegalDisclaimer
Theexistenceofalinkororganiza>onalreferenceinanyofthefollowingmaterialsshouldnotbeassumedasanendorsementbyClearwaterComplianceLLC.
Thisinforma2ondoesnotcons2tutelegaladviceandisforeduca2onalpurposesonly.Thisinforma2onisbasedoncurrentfederallawandsubjecttochangebasedonchangesinfederallaworsubsequentinterpreta2veguidance.Sincethisinforma2onisbasedonfederallaw,itmustbemodifiedtoreflectstatelawwherethatstatelawismorestringentthanthefederallaworotherstatelawexcep2onsapply.Thisinforma2onisintendedtobeageneralinforma2onresourceregardingthemaCerscovered,andmaynotbetailoredtoyourspecificcircumstance.YOUSHOULDEVALUATEALLINFORMATION,OPINIONSANDRECOMMENDATIONSPROVIDEDHEREININCONSULTATIONWITHYOURLEGALOROTHERADVISOR,ASAPPROPRIATE.
CopyrightNo2ceAllmaterialscontainedwithinthisdocumentareprotectedbyUnitedStatescopyrightlawandmaynotbereproduced,distributed,transmiCed,displayed,published,orbroadcastwithouttheprior,expresswriCenpermissionofClearwaterComplianceLLC.Youmaynotalterorremoveanycopyrightorotherno2cefromcopiesofthiscontent.
TheIntersec2onofHR&HIPAA
April6,2017
©ClearwaterCompliance|AllRightsReserved
3
CompanyBackground&Overview
ClearwaterComplianceisexclusivelyfocusedonassis>ngourcustomerstoopera>onalizeandmaturetheirprivacy,security,compliance,andinforma>onriskmanagementprograms.Foundedin2010andledbyveteran,C-suitehealthcareexecu>ves,Clearwaterprovidescomprehensivecapabili>esincludingby-the-regula>onsHIPAA-HITECHcompliancesoPware,professionaladvisoryandinforma>onriskmanagementservices,policyandproceduretemplatesandservices,andavarietyofeduca>onalevents,training,andresources.Wearepleasedtosaythatallofour1,000+customersareravingfans.
IndustryResourceProvider
So4wareUsedbyNSA/CAEsExclusiveEndorsement
Ranked#11for2015&2016&2017
©ClearwaterCompliance|AllRightsReserved
4
WeWishtoThankAllOurIndustryAssocia2onPartnersSampleAc2vi2es
ExclusiveEndorsement Webinars WhitePapers/
Ar2cles/BookCybersecurityBootCamp
ConferenceSpeaking
AnnualConferenceSponsor
✅ ✅ ✅ ✅ ✅
✅ ✅ ✅ ✅
✅ ✅ ✅ ✅ ✅
✅ ✅ ✅ ✅ ✅
✅ ✅ ✅ ✅ ✅
✅ ✅ ✅
✅
©ClearwaterCompliance|AllRightsReserved
5
AboutYourSpeaker:MaryChaput
• 30+yearsinHealthCare• 13yearsasCFOofapubliccompany;12+yearswithGE• FormerEVP,CFOandComplianceOfficerforHealthways,Inc.• FormerVP,CFOforClinTrialsResearch,Inc.• Businessexecu>vewithover35yearsofdomes>candinterna>onalfinancialmanagementandopera>onalexperience
• BAMathema>cs,MBA,GEFinancialManagementProgram• Exper>seandFocus:Healthcare,DueDiligence,Analy>cs,Legal,RiskManagement
MaryChaput,MBA,HCISPP,CIPP/US,CIPMChiefFinancialandComplianceOfficer
©ClearwaterCompliance|AllRightsReserved
6
OurGoal:
Thisempoweringphilosophyunderpinseverythingwedo.ü Commitmenttoeduca>onalresourcesforouraudiencesü Ongoingsupportandtrainingforourcustomers
ü Thought-,service-,methodology-andsoPware-leadership
ToHelpYouBecomeAsSelf-SufficientAsYouWishToBe
©ClearwaterCompliance|AllRightsReserved
7
SomeWebinarLogis2cs/GroundRules1. Slidematerials
A. Check“Download”areaonGoToWebinarControlPaneltocopy/pastelinkanddownloadmaterials
2. Ques>onsin“Ques>onArea”onGTWControlPanel
3. Incaseoftechnicalissues,check“ChatArea”
4. AllAdendeesarein“ListenOnly”Mode5. PleasecompleteExitSurvey,whenyouleavesession6. Recordedversionandfinalslideswithin48hours
©ClearwaterCompliance|AllRightsReserved
8
Wearenotadorneys!èEnsureCompetentCounsel
TheOmnibushasarrived!èWelcomeAboard,BAs!
Lotsofdifferentinterpreta>ons!èPlease,AskLotsofQuesOons!
ButFIRST!
©ClearwaterCompliance|AllRightsReserved
PauseandQuickPoll
BusinessAssociate
OtherCoveredEn2ty
Hospitalor
HealthSystem
Don’tKnow
Hybrid
Whattypeoforganiza>ondoyourepresent?
©ClearwaterCompliance|AllRightsReserved
HaveyouadendedanyClearwaterCompliancewebinarsbefore?
PauseandQuickPoll
©ClearwaterCompliance|AllRightsReserved
11
AGENDA
• WhyshouldHRbeinvolvedinHIPAA?
• WhatcanHRdotohelp?
• WhataboutGroupHealthPlans?
©ClearwaterCompliance|AllRightsReserved
12
WhyShouldHRbeinginvolvedwithHIPAA?Anthem
78.8MM-Phishing
Employees(andotherWorkforceMembers),NotTechnology,CauseBreaches
©ClearwaterCompliance|AllRightsReserved
13
Who’stoBlame?
CaseExamples• RefusedAccess• DisclosurewithoutAuthoriza>on• MishandledConfiden>alCommunica>ons• ImpermissibleUsesandDisclosures• MorethantheMinimumNecessary• InadequateSafeguards
MostCommonIssues,inorderoffrequency:• ImpermissibleUsesandDisclosures• Lackofsafeguards• Lackofpa>entaccess• Morethanminimumnecessary
Dotheyknowwhattodoifapa2entormembercomplainstothem?
©ClearwaterCompliance|AllRightsReserved
14
RecentBreachesbyMaliciousInsiders
©ClearwaterCompliance|AllRightsReserved
15
SnoopingCelebri>es…..• GeorgeClooney• BritneySpears• RichardCollier• NadyaSuleman• AnnePressly• MichaelJackson• GabrielleGiffords• KimKardashian
Andthenthere’sthe“X-Factor”
©ClearwaterCompliance|AllRightsReserved
16
CommonScenariosthatPromptOCRInves2ga2ons
ExamplesofSnooping:• Employeelookingatco-worker’sPHI• Managertryingto‘verify’that
employeeisactuallysickwhenhe/shecallsintowork
Ifyouareacovereden>tythatalsohasemployeesaspa>ents/membersetc..),youreallyhavetokeepyoureyesopen!
©ClearwaterCompliance|AllRightsReserved
17
PersonalFactors:Uninten2onal
• TechSupportScams• SocialEngineering
o Phishingo Piggybackingo ShoulderSurfingo Pre-texing
• Distracted• Trus>ng• InaHurry• Careless• Untrained
Fallpreyto
©ClearwaterCompliance|AllRightsReserved
18
PersonalFactors:MaliciousInsiders
• Greed• FinancialNeed• Excessivedebtoroverwhelmingexpenses
• Anger/Revenge• Problemsatwork• Ideology/Iden>fica>on• DividedLoyalty
• Adventure/Thrill• VulnerabilitytoBlackmail• Ego/Self-image• Vulnerabilitytofladeryorthepromiseofabederjob• Ingra>a>on• Compulsiveanddestruc>vebehavior• Familyproblems
©ClearwaterCompliance|AllRightsReserved
19
HRAc2vi2esthatIntersectwithHIPAA
• BackgroundChecks• Hiring–Ini>a>ngAccesstoPHI• Promo>ons/Demo>ons–ChangingAccesstoPHI• Firing–Termina>ngAccesstoPHI• PerformanceImprovementPlans(PIP)• Training• Applica>onofSanc>ons
IfithastodowithEmployees,ithastodowithHR
©ClearwaterCompliance|AllRightsReserved
20
2.WhatcanHRdotoHelp?
©ClearwaterCompliance|AllRightsReserved
21
WhatCanHRDotoHelp?
Step1
CreatetheCulture
THEHIPAAWORKINGGROUP
• Oversight/GovernanceCouncil• HIPAAWorkingGroup
CreatetheCulture
©ClearwaterCompliance|AllRightsReserved
22
Par2cipateinDevelopmentofHIPAAComplianceCharterWorkingGroup• Responsibili>es
• EnsureFunc>onalRepresenta>on• ImplementandMaturetheComplianceProgram• Iden>fyandAssessRiskstoPHI• RecommendSolu>onstoComplianceGaps• ImplementApprovedSolu>ons• EducateandProvideUpdatesto
Oversight/GovernanceCouncil
• Membership• PrivacyandSecurityOfficials• ClinicalDirector• QualityDirector• ITDirector• HRDirector• LegalDirector• FacilitySecurityDirector• InternalAuditDirector
Oversight/GovernanceCouncil• Responsibili>es
• EstablishRiskPhilosophy• RecommendStrategicDirec>on• EstablishAuthority&Qualifica>ons• ReviewRisksandRecommenda>ons• ApproveIni>a>vesandBudgets• ProvideHighLevelSupport
• MembershiporDesignee• CEO• CFO• CIO• CISO• COO• VPHR• GeneralCounsel• RiskOfficer• PrivacyandSecurityOfficials
©ClearwaterCompliance|AllRightsReserved
PauseandQuickPoll
IssomeonefromHRincludedonyourComplianceac>vi>es?
©ClearwaterCompliance|AllRightsReserved
24
WhatCanHRDotoHelp?
Step1
Step2
CreatetheCulture
DevelopMaterials
TRAINING
• Trainingthatisspecifictojobdescrip2ons• SecurityAwarenessReminders• Documenta2onofcompletedtraining
DevelopMaterialsthatSupportComplianceTrainingandSecurityAwareness
©ClearwaterCompliance|AllRightsReserved
25
OneStudy’sFindings…HowImportantisTraining?
• 2outof3admitemployeesaretheweakestlink• #1securityriskisemployeecarelessnessornegligence
• Concernsinclude:• Unleashingmalwarefromaninsecurewebsiteormobiledevice• Succumbingtotargetedphishingadacks• Usingunapprovedcloudormobileapplica>onstosendsensi>veinforma>on
• Trainingfallsshort• 43%saythattrainingconsistsofonlyonebasiccourseforallemployees• 55%saythattrainingisnotmandatoryforallemployees• 60%donotrequireemployeestoretakesecuritytrainingaPeradatabreach
• Culturedoesn’talign• 2outof3don’tprovideincen>vesforbeingproac>veinrepor>ngpoten>alissues• 1outof3saytherearenoconsequencesifanemployeeisfoundtobenegligentor
responsibleforcausingadatabreach
hdp://www.experian.com/assets/data-breach/white-papers/experian-2016-ponemon-insider-risk-report.pdf
©ClearwaterCompliance|AllRightsReserved
PauseandQuickPoll
DoesyourHRgrouphelpwithtrainingmaterialsorconducttrainingclassesandkeeptrackofcomple>on?
©ClearwaterCompliance|AllRightsReserved
27
Training
• GeneralHIPAARequirements
• ClearwaterLiveWebinars(free)
• ClearwaterOn-DemandHIPAAComplianceWebinars(free)
• OCR-QualityRiskAnalysisWorkingLab™(free)
• HIPAAandCyberRiskManagementBootCamp™
• SpecifictoFunc>onalRolesandResponsibili>es• DevelopMaterialsBasedonyourOrganiza>on’sPolicies&Procedures
• LeverageOn-lineTrainingCourses
©ClearwaterCompliance|AllRightsReserved
28
WhatCanHRDotoHelp?
Step1
Step2
Step3
CreatetheCulture
DevelopMaterials
DevelopProcesses
.
• Func2on-basedAccessControls• ProcessesforIni2a2ngandTermina2ngAccess• EstablishAuthorityforApproval
DevelopprocessestoensureMinimumAccessandAccessControls
ACCESSCONTROLS
©ClearwaterCompliance|AllRightsReserved
29
HiringandAccessProcedureControls
• WorkforceClearance(BackgroundChecksandCreden>als)
• JobDescrip>onswithAssignedSecurityResponsibility• MinimumNecessaryAccessbasedonFunc>onalRoleandResponsibili>es
• AccessNotIni>atedun>lTrainingisComplete
• AccessTermina>onProcedureswhenEmployeeLeavesCompanyorChangesJobs
• SubcontractorAccessApprovalandNo>ceofChangeinContractTerm
• AccessMonitoredandAudited
©ClearwaterCompliance|AllRightsReserved
30
BehaviorIndicatorsofInsiderThreats
• Takesproprietaryorothermaterialhome• Interestinmadersoutsidethescopeoftheirdu>es• Unnecessarilycopiesproprietarymaterial• Remotelyaccessesthecomputernetworkatodd>mes• Disregardscompanycomputerpolicies• Worksoddhourswithoutauthoriza>on• Inappropriatelyseeksproprietaryinforma>onnotjob-related• Unexplainedaffluence• Showsunusualinterestinthepersonallivesofcoworkers• Engagesinsuspiciouspersonalcontacts• Overwhelmedbylifecrisesorcareerdisappointments• Concernthattheyarebeinginves>gated
©ClearwaterCompliance|AllRightsReserved
31
WhatBadThingsCouldHappen?
hdp://resources.idgenterprise.com/original/AST-0175464_orwp_0260.pdf
©ClearwaterCompliance|AllRightsReserved
32
WhatCanHRDotoHelp?
Step1
Step2
Step3
Step4CreatetheCulture
DevelopMaterials
DevelopProcesses
ApplySanc2ons
• TieredSanc2onsdependentoninten2on,frequencyandseriousnessofdisclosure• Par2cipa2onindecision• Maintaindocumenta2on
DevelopandDocumentaSystema2cApproachtotheApplica2onofSanc2onsforNon-Compliance
SANCTIONS
©ClearwaterCompliance|AllRightsReserved
PauseandQuickPoll
DoesyourHRgroupoverseesanc>onsfornon-compliance?
©ClearwaterCompliance|AllRightsReserved
34
ExampleofSanc2onCriteriaTypeofViola2on
ExampleofUnauthorizedUseorDisclosure
Result #ofOccurrences TypesorexamplesofSanc2ons
Non-Inten2onalorAccidental
FaxtowrongnumberMailtowrongrecipientVoicemessageWrongdischargepapersLossofrecordsorfiles
Nofurtherdisclosure
1st>me Addi>onaltraining2nd>me Noteinpersonnelfileandcounseling
3rd>me ReassignmentorTermina>on
Furtherdisclosure1st>me Noteinfileandcounseling
2nd>me Reassignmentortermina>on
Inten2onal&Non-Malicious
SnoopingNofurtherdisclosure
1st>me Noteinfile,counselingorsuspension
2nd>meReassignment,suspensionorTermina>on
Furtherdisclosure 1st>me SuspensionorTermina>on
Inten2onal&Malicious
Sharingorsaleofinforma>onBusinessdisrup>on
Financial,reputa>onalorotherharmtoindividuals
1st>me
Termina>on
(ActualsancOonswilldependonorganizaOonalcultureandpolicy-MaintainsufficientflexibilityinyourPolicytoallowforundefinedsituaOons)
AboveAll|BeConsistent
©ClearwaterCompliance|AllRightsReserved
35
InadequateTraining
IncompletePolicies&Procedures
MoreThanTheMinimumNecessaryAccess
InconsistentlyAppliedSanc2ons
WhatCausesBreaches,ComplaintsandOCRInves2ga2ons
©ClearwaterCompliance|AllRightsReserved
36
3.WhatAboutGroupHealthPlans?
©ClearwaterCompliance|AllRightsReserved
37
GroupHealthPlansonthe“WallofShame”Name of Covered Entity # of IndividualsSubmit Date Type of Breach Location of Breached InformationState of Tennessee Sponsored Group Health Plan 1,770 11/28/2011 Unauthorized Access/Disclosure Paper/FilmsSuperior HealthPlan, Inc. 6,284 11/01/2013 Other Paper/FilmsSony Pictures Entertainment Health and Welfare Benefits Plan (the Plan)30,000 12/12/2014 Hacking/IT Incident Desktop Computer, Laptop, Network ServerWillis North America Inc. Medical Expense Benefit Plan 4,830 04/24/2014 Unauthorized Access/Disclosure EmailGroup Health Plan of Hurley Medical Center 2,289 06/16/2014 Unauthorized Access/Disclosure EmailBurlington Northern Santa Fe Group Benefits Plan 507 10/28/2014 Loss Other Portable Electronic DeviceAT&T Group Health Plan 50,000 03/23/2015 Hacking/IT Incident Network ServerMcDermott Will & Emery LLP is the plan sponsor for the McDermott medical plan880 03/24/2015 Hacking/IT Incident Network Server7-Eleven, Inc. Comprehensive Welfare Benefits Plan No. 525 1,688 03/25/2015 Hacking/IT Incident Network ServerHealth Plan sponsored by Covenant Ministries of Benevolance 782 04/03/2015 Hacking/IT Incident Network ServerSUPERVALU Group Health Plan 10,946 04/03/2015 Hacking/IT Incident Network ServerADT LLC Group Health & Welfare Plan 3,074 04/07/2015 Hacking/IT Incident Network ServerEcolab Health and Welfare Benefits Plan 1,550 02/26/2016 Hacking/IT Incident Network ServerPublic Education Employees' Health Insurance Plan 1,349 09/09/2016 Unauthorized Access/Disclosure Network ServerGroup Health 668 09/23/2016 Unauthorized Access/Disclosure Paper/FilmsGroup Health Incorporated 81,122 11/22/2016 Unauthorized Access/Disclosure Network Server, Other, Paper/FilmsVeritiv Co. Health & Welfare Plan 955 01/31/2017 Unauthorized Access/Disclosure Paper/Films
198,694
©ClearwaterCompliance|AllRightsReserved
38
WhichRegula2onsApplytoYourGHP?
• WhichServicesarebeingprovidedbyyourBenefitsTeam?• Whatdatadoyouhaveinyourenvironmentorunderyoucontrol?• Whatinforma>ondoesyourPlanSponsor(Employer)receive?
©ClearwaterCompliance|AllRightsReserved
39
PlanAdministra2onFunc2onsPerformedbythePlanSponsoronbehalfoftheGHP
• QualityAssurance• ClaimsProcessing• Audi>ng• Monitoring• Managementofcarve-outplansThen:• InordertodisclosethePHItotheplansponsor,theGHPmustobtainavalidauthoriza>onfromtheemployee
©ClearwaterCompliance|AllRightsReserved
40
IfthePlanSponsor…
CreatesorreceivesfromtheheathinsuranceissuerorHMOonly:• Summaryhealthinforma>onor• Informa>onre:par>cipa>onorenrollment/disenrollment
ThentheGHP:• Issubjecttoreducedadministra>verequirements• Andthereisnoobliga>ontoamendPlanDocuments
©ClearwaterCompliance|AllRightsReserved
41
“SeCler”Func2onsbyPlanSponsor
• Modifying,amending,ortermina>ngtheGHPand/or
• Obtainingpremiumbids?
Then:• NoAuthoriza>onisneededforSummaryHealthInforma>on
but• Plandocumentsmustbeamendedunlesstheinforma>on
hasbeende-iden>fied
©ClearwaterCompliance|AllRightsReserved
42
MorePHIthanthat…
ThentheGroupHealthPlanmust:• ComplywithallAdministra>verequirements• ProvideNo>ceofPrivacyPrac>ces• EnterintoBAAgreementswithBusinessAssociates• Receivecer>fica>onfromthePlanSponsorthatthePlanhasbeenamendedtoensurethat…
©ClearwaterCompliance|AllRightsReserved
43
ThePlanSponsorwillcer2fythatthePlanDocuments
• RestrictusesanddisclosuresofPHIwithoutauthoriza>on,• Implementadministra>ve,physical,andtechnicalsafeguardstoprotectPHI• Ensuresubcontractorsagreetothesamerestric>onsthatapplytotheplansponsor• Notusetheinforma>onforemployment-relatedac>onsorotherbenefitdecisions• ReportimpermissibleusesordisclosurestotheGHP
• Providefortherightsofindividuals(access,amendments,accoun>ng)
• Makeinforma>onavailabletotheSecretaryfordeterminingcompliance,
• Provideforthereturnordestruc>onofPHIreceivedfromtheGHP
• Ensureadequatesepara2onbetweentheGHPandPlanSponsor
©ClearwaterCompliance|AllRightsReserved
44
AWordaboutGHPBAAgreements
• RequiredforallserviceproviderswithaccesstoPHI
• Mustcontainanumberofveryspecificprovisionsincludingthesamerestric>onsandcondi>onswithrespecttoPHIthatapplytotheplansponsor.
• EnsurethatanyagentstowhomitprovidesGHPPHIalsoagreetothesamerestric>onsandcondi>onsthatapplytotheplansponsor
BAAgreementsNotRequired:• BetweentheGHPandtheHealthInsuranceIssuerorHMOfortheprovisionofinsuranceor
coverage• BetweentheGHP(oraHealthInsuranceIssuerorHMO)andtheplansponsor,IF
(a) thegrouphealthplan’sdocumentshavebeenamendedtolimitthedisclosuresor(b) thedisclosureislimitedtosummaryinforma>onorinforma>ononwhetheranindividual
ispar>cipa>ng,orisenrolledordisenrolledintheplan.
©ClearwaterCompliance|AllRightsReserved
45
AliClemoreaboutBAsforGHPs-theycaninclude….
• Enrollment/Disenrollment • Eligibility • EmployeeAssistanceProgram • DataforAmendingPlanDocuments(e.g.evaluateadrugformulary)• DataforObtainingBidsforInsuranceCoverage • ClaimsManagement/Payment • Collec>ons • MemberAdvocate• 1stand2ndlevelappealsdecisions • Conduc>ngorarrangingformedicalreviews • Conduc>ngorarrangingforlegalservices • Conduc>ngaudi>ngfunc>ons
©ClearwaterCompliance|AllRightsReserved
PauseandQuickPoll
DoesyourGroupHealthPlanknowtheirHIPAARequirements?
©ClearwaterCompliance|AllRightsReserved
47
©ClearwaterCompliance|AllRightsReserved
AtClearwaterCompliance,wehaveapassionforeduca>on.ThisiswhyweoffersomanycomplimentaryHIPAAcomplianceandcyberriskmanagementresourcestoanyoneinterested
regardlessifyouareaHIPAA
UpcomingEduca2onalLiveWebEvents
April20Complimentary
Webinar
HowToAdopttheNISTCybersecurityFramework(CSF)
April24Complimentary
Workshop
Intel&ClearwaterHealthcareSecurityReadinessProgram
Session1of2
*Session2onMAY23
Formoreinforma>on&acompletelistofupcomingwebeventspleasevisit:hdp://bit.ly/clearwaterlivewebevents
April27Complimentary
Webinar
HIPAA101
ClearwaterComplianceispassionateabouteduca>on.Thisiswhyweofferawidevarietyofindustry-leading,expert-led,complimentary
HIPAAcomplianceandcyberriskmanagementresourcesforindustryprofessionalsandHIPAArookiesalike.
April5,12,19&26,2017
ComplimentaryWorkingLab™
OCR-QualityRiskAnalysis
4Unique,Hands-OnSessions
*MissedSession1?NoProblem.Joinusforsession2!
©ClearwaterCompliance|AllRightsReserved
HIPAACompliance&CyberRiskManagementBootcamp™
Opera2onalizeYourHIPAAandCyberRiskManagementPrograms
VirtualEduca>on|DesignedForBusyProfessionals|3Days|9HoursTotal|EarnUpTo10.8CPEs
UniquePanelDiscussion:Amarquisorindustryprivacy&securityprofessionalswilljoinpartofasessiontodiscusskeyissuesaround“AddressingHealthcareCybersecurityStrategically.”KeyBootCampTake-Aways:• Dis>llthecri>calinforma>onneededtoknowabouttheHIPAAPrivacy,SecurityandBreachNo>fica>onRules• Learnbestprac>cestoestablish,implementandmatureyourcyberriskmanagementprogram• Garnerbestprac>cestomakecomplianceandcyberriskmanagementaBoardand/orC-Suiteagendaitem
May4,11,&18,201712:00–3:00pmET
$595*CustomerDiscountsAvailable|CHIME,AEHIS&AHIAMemberDiscountsAvailable
hdp://bit.ly/ClearwaterBootCamps
©ClearwaterCompliance|AllRightsReserved
Presents:CHIME&AEHIS2017VirtualCybersecuritySymposia™
ClearwaterComplianceispleasedtooffertwouniqueHIPAAcomplianceandcyberriskmanagementeduca>onaleventsexclusivelyforCHIME&AEHISMembers
NotaCHIMEorAEHISmemberyet?Joinat:hdp://bit.ly/joinCHIMEorhdp://bit.ly/joinAEHIS
(AEHISmembershipiscurrentlyfree!)
AEHISCISO2017VirtualCybersecuritySymposium™
7/6,7/13,7/20,7/27,8/3|12-2pmET
LearnMoreat:hdp://bit.ly/ClearwaterAEHISSymposium
CHIMECIO2017VirtualCybersecuritySymposium™
6/15,6/22,6/29|12-2pmET
LearnMoreat:hdp://bit.ly/ClearwaterCHIMESymposium
©ClearwaterCompliance|AllRightsReserved
HoldTheDateFor:HIPAACompliance&CyberRiskManagementLive&InPersonBootCamp™
Opera2onalizeYourHIPAAandCyberRiskManagementPrograms
1FullDay|BOSTON,MA|Earnupto10.8CPEs
KeyBootCampTake-Aways:• Dis>llthecri>calinforma>onneededtoknowabouttheHIPAAPrivacy,SecurityandBreachNo>fica>onRules• Establish,implementandmatureyourcyberriskmanagementprogram• Garnerbestprac>cestomakecomplianceandcyberriskmanagementaBoardand/orC-Suiteagendaitem
August27,2017$595*AHIAMEMBERDiscountsAvailable
Registra>onDetails&MoreInforma>onComingSoon
©ClearwaterCompliance|AllRightsReserved
52
MaryChaput,MBA,HCISPP,CIPP,CIPM
Contact
Exit Survey, Please
hCp://www.ClearwaterCompliance.commary.chaput@ClearwaterCompliance.comPhone:800-704-3394ClearwaterComplianceLLC
Ques>[email protected]