IT-412 Cyberlaw and Ethics: Milestone Two
IT-412: Cyberlaw and Ethics
Final Project -- Milestone Two: Draft of Risk Analysis
Romyr DelRosario
Southern New Hampshire University
IT-412 Cyberlaw and Ethics: Milestone Two
Cyberlaw Noncompliance
ABC Healthcare are noncompliance in several areas as a company. The main violation is
that they are noncompliant in the Privacy Rule of the Heath Insurance Portability and
Accountability Act (HIPAA). "The Privacy Rule stats that it will ensure individuals' health
information is properly protected while allowing the flow of health information needed to
provide high quality healthcare and to protect the public's health and well-being."(CDC, 2018)
ABC Healthcare has precariously stored patient and employee files unsecured in a common area
that is easily accessible by anyone without proper credentials. HIPAA's Security Rule is also in
violation by ABC Healthcare as well. "The Security Rule is basically all individually
identifiable health information a covered entity creates, receives, maintains, or transmits in
electronic form."(CDC, 2018) ABC needs to have a plan in place to migrate all existing
hard/papercopy patient information to electronic format and stored securely on a secure server or
file storage system. Security measures will need to be enacted so that only proper individuals
with the correct level of access can access this information. Another area that ABC Healthcare is
in noncompliance is its financial practices. With the current layout of the office the billing
department as well as all the other departments are in close proximity to each other, and billing
information can easily be stolen or recorded by anyone in the office since there is very little
privacy.
The Gramm-Leach Bliley Act (GLBA) would be the law that they would be in violation
of. "The GLBA states that financial institutions must protect the privacy of consumers personal
financial information."(FTC, 2016) ABC Healthcare's infrastructure is also in noncompliance
with the way their information security is being handled. Very basic security practices are being
used with very little in the way of information security. Leaving the companies systems
2
IT-412 Cyberlaw and Ethics: Milestone Two
unsecured and without adequate technology policies in place the company could be in a potential
position to be hacked or breached. If their data is compromised, they could face severe fines and
lawsuits. Along with these fines the companies' employees can face imprisonment for these
violations. All these factors can significantly hinder any future that the company would have if
they came to light
Acceptable Use Polices and Adaptation
Acceptable Use Polices (AUP) are terms and conditions for users/employees accept when
they use company resources. These are typically associated with the company network and
internet use. They usually appear on a computer terminal at the time of login and require the
user to accept the terms and conditions of use or they can not gain access to network resources.
Currently the ABC Healthcare doesn't have an active AUP for its organization.
A good place to start for ABC Healthcare to start building their AUP would be the SANS
Institute. They have