Educause Security Discussion mailing list archives

Re: Implementing risk analysis process to meet HIPAA security requirements


From: Craig Blaha <blaha () TCNJ EDU>
Date: Tue, 13 Jan 2004 08:54:17 -0500

David:

I heard a rumor that the Educause Security task force will create and
publish a risk analysis template early this year. Does anyone have
further information on this?

Craig

David Grisham wrote:

I would appreciate anyone who has already implemented a university wide or
health science center level risk analysis process at their institution to
send any observations about implementing the process.  A fairly
straightforward web form can be put into place.
Where I anticipate the problems are in the education of the owners of
Electronic Protected Health Information (EPHI) and the integration of the
process throughout the IT enterprise.
I will summarize all replies.
Cheers. --grish
David D. Grisham, Ph.D., CISM
Adjunct Faculty, Computer Science Department, UNM
Information Security Manager,
UNM Hospitals, Ph: (505) 272-5657 FAX 272-3305
1650 University Blvd, suite 500 Albuquerque, NM 87102
e-mail business: dgrisham () salud unm edu <mailto:dgrisham () salud unm edu>
other personal or academic: dave () unm edu <mailto:dave () unm edu>
********** Participation and subscription information for this
EDUCAUSE Discussion Group discussion list can be found at
http://www.educause.edu/cg/.


--

   *Craig Blaha*
   /Associate Director
   Information Policy, Security and Web Development/
   The College of New Jersey
   PO Box 7718
   Ewing, NJ 08628
   www.tcnj.edu


**********
Participation and subscription information for this EDUCAUSE Discussion Group discussion list can be found at 
http://www.educause.edu/cg/.

Current thread: