• Home
  • Southern New Hampshire University
  • Cyberlaw and Ethics IT412
  • Cyberlaw and Ethics IT412

Cyberlaw and Ethics IT412

IT-412 Cyberlaw and Ethics: Milestone Two IT-412: Cyberlaw and Ethics Final Project -- Milestone Two: Draft of Risk Analysis Romyr DelRosario Southern New Hampshire University IT-412 Cyberlaw and Ethics: Milestone Two Cyberlaw Noncompliance ABC Healthcare are noncompliance in several areas as a company. The main violation is that they are noncompliant in the Privacy Rule of the Heath Insurance Portability and Accountability Act (HIPAA). "The Privacy Rule stats that it will ensure individuals' health information is properly protected while allowing the flow of health information needed to provide high quality healthcare and to protect the public's health and well-being."(CDC, 2018) ABC Healthcare has precariously stored patient and employee files unsecured in a common area that is easily accessible by anyone without proper credentials. HIPAA's Security Rule is also in violation by ABC Healthcare as well. "The Security Rule is basically all individually identifiable health information a covered entity creates, receives, maintains, or transmits in electronic form."(CDC, 2018) ABC needs to have a plan in place to migrate all existing hard/papercopy patient information to electronic format and stored securely on a secure server or file storage system. Security measures will need to be enacted so that only proper individuals with the correct level of access can access this information. Another area that ABC Healthcare is in noncompliance is its financial practices. With the current layout of the office the billing department as well as all the other departments are in close proximity to each other, and billing information can easily be stolen or recorded by anyone in the office since there is very little privacy. The Gramm-Leach Bliley Act (GLBA) would be the law that they would be in violation of. "The GLBA states that financial institutions must protect the privacy of consumers personal financial information."(FTC, 2016) ABC Healthcare's infrastructure is also in noncompliance with the way their information security is being handled. Very basic security practices are being used with very little in the way of information security. Leaving the companies systems 2 IT-412 Cyberlaw and Ethics: Milestone Two unsecured and without adequate technology policies in place the company could be in a potential position to be hacked or breached. If their data is compromised, they could face severe fines and lawsuits. Along with these fines the companies' employees can face imprisonment for these violations. All these factors can significantly hinder any future that the company would have if they came to light Acceptable Use Polices and Adaptation Acceptable Use Polices (AUP) are terms and conditions for users/employees accept when they use company resources. These are typically associated with the company network and internet use. They usually appear on a computer terminal at the time of login and require the user to accept the terms and conditions of use or they can not gain access to network resources. Currently the ABC Healthcare doesn't have an active AUP for its organization. A good place to start for ABC Healthcare to start building their AUP would be the SANS Institute. They have