HIPAA and GDPR are two of the most stringent privacy and security frameworks in the world today. While they are similar in many ways (both being regulatory mandates), they seem to operate in completely different industries. HIPAA is laser-focused on the privacy of personal health information within the US and applies mainly to healthcare entities,…
HIPAA (the Health Insurance Portability and Accountability Act of 1996) is a U.S. federal law that sets national standards for protecting Protected Health Information (PHI). It’s enforced by the US Department of Health and Human Services Office for Civil Rights (OCR) through rules such as the Privacy Rule (which regulates the use and disclosure of…
The protection of personal information is becoming critical for businesses worldwide in an increasingly digital world where customer data is acquired at multiple touchpoints. Global privacy laws mandate the protection of three main categories of personal data: Personally Identifiable Information (PII), Payment Card Industry (PCI) data, and Protected Health Information (PHI). The acronyms PII, PCI,…
For healthcare companies, obtaining certification from HITRUST (Health Information Trust Alliance) isn’t just about ticking a compliance box—it’s a commitment to establishing a robust standard for data protection. According to a HIMSS survey, a significant 81% of US hospitals and health systems, along with 83% of health plans, have chosen HITRUST as their primary framework…
In May 2017, hospitals across the U.K and U.S were forced to halt their operations for a few hours. Medical devices, systems, and other infrastructures were rendered inaccessible after having been hit by a series of crypto-ransomware named WannaCry. It delayed surgeries, cancelled appointments, and put the sensitive data of thousands of patients at risk. …
The most common HIPAA budgeting mistakes include underestimating the costs of certification, overlooking the need for and costs of ongoing compliance, and failing to update budgets regularly. This, in turn, poses a challenge for founders to balance HIPAA certification costs with other business priorities. From preliminary prep work to audit expenses and post-audit maintenance, the…