Health Information Management

Tip: Look for these qualifications when designating an ISO

HIPAA Weekly Advisor, September 28, 2003

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

According to Rick Ensenbach CISSP, CISA, CISM, director of information security at GE Retail Sales Finance in St. Paul, a qualified information security officer should have the following:

  • Five to 10 years of direct information security experience, preferably with some exposure to physical security, disaster recovery/business continuity, and at the very least, the ability to understand the technical aspects of information security

  • Two to three years of health care experience

  • IT background (direct or indirect)

  • Two to three years of experience managing a security program

  • Strong understanding of non-technical security issues, including risk management, staff training, policy and procedure development, establishing tactical and strategic direction, auditing and enforcement (compliance), business development (working with senior management), ethics, privacy, existing and proposed state and federal regulations/laws

  • Credentials-Certified information systems security professional (CISSP), Certified information systems auditor (CISA), and certified information security manager (CISM)

    Editor's note: From the upcoming September 2003 issue of Healthcare Information Security.



  • Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

    • Briefings on APCs

      Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

    • Medical Records Briefing

      Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

    • Briefings on Coding Compliance Strategies

      Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

    • Briefings on HIPAA

      How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

    • APCs Weekly Monitor

      This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

    Most Popular

    Related Articles