Health Information Management

Evaluating privacy and information security governances

HIM-HIPAA Insider, June 8, 2015

Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!

As required by The Joint Commission, a board of directors should regularly assess its performance, appropriateness of board and committee processes and charter fulfillment, adequacy of meeting structures and goals, communication with management, and other governance structures and activities. Generally, boards and their committees complete this assessment through self-surveys, internal audits, or collection of results as performed by legal services. Assessment results can lead to changes in board processes, with the goal of adapting to changing risks and environmental requirements, and improvements in governance.

Boards rarely use survey questions for privacy and information security program risk assessment. The audit committee self-assessment process might include one or two questions that address this topic, but these surveys generally do not consider the board's role in enterprise-wide risk assessment processes. As privacy and information security programs become more embedded in an organization's culture, this will change.

Continue reading "Evaluating privacy and information security governance processes" on the HCPro website. This article is adapted from The Complete Guide to Healthcare Privacy and Information Security Governance by Phyllis A. Patrick, MBA, FACHE, CHC, CISM, a Briefings on HIPAA editorial advisory board member. Subscribers to Medical Records Briefing  have free access to this article in the May issue. 


Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!

    Briefings on APCs
  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • HIM Briefings

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentation can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Insider

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular