Five Stumbling Blocks Hinder HIPAA Compliance

Lack of a risk analysis. Organizations either haven't conducted a risk analysis or, they last conducted one in 2005 when the HIPAA rule became final, he says. A risk analysis is “the foundation for your security program,” he says. “You need that to build on.”

via Five Stumbling Blocks Hinder HIPAA Compliance.

The changing nature of governance, risk, and compliance

In my ongoing work with clients, I try as often as possible to stress the importance of flexibility in GRC programs. Internal processes and technology implementations must be able to accommodate the perpetually fluctuating aspects of business, compliance requirements, and risk factors. If GRC investments are made without consideration for likely requirements 1 to 2 years down the road, decision makers aren’t doing their job. And if vendors don’t offer that flexibility, they shouldn’t be on the shortlist.

via The Forrester Blog For Security & Risk Professionals.

More Articles

Is PCI compliance attainable in a public cloud?

3-D Secure (3DS) – Verified by Visa insecure

So What Is PCI Really About? – CSO Online – Security and Risk

Internal data breaches a rarity

Virtual Network Segmentation for PCI?

New PCI Phone Rules: A Number Spoken Is Just As Risky As One Typed

No major #PCI DSS revision expected in 2010

PCI QSAs, certifications to get new scrutiny