If the NPRM Becomes Law, Will Your Security Risk Analysis Hold Up?

NPRM Carrot with Stick Security Risk Analysis

Let’s look at the historical approach from OCR when it comes to HIPAA Security Rule enforcement. Since 2005, the Office for Civil Rights (OCR) has relied on the carrot approach rather than the stick. The existing Security Rule defines risk analysis as the first required implementation of the first required standard. But the existing language … Read more