MILESTONE 2 - RISK ANALYSIS PAPER
Milestone 2 - Risk Analysis Paper
Robert Roberts
Southern New Hampshire University
MILESTONE 2 - RISK ANALYSIS PAPER
2
Cyberlaw noncompliance
There are no "rules" to hold anybody accountable for breaking, since ABC Company is a
small company today and has never developed any standards or procedures for employees to
adhere to. It is difficult to hold employees accountable when the proper process was never
implemented in the first place. The company is violating HIPAA and HITECH standards due to
the lack of procedures for employees to follow. This puts the business in a precarious position.
Due to a lack of standards, patients of ABC business are at danger of having their private and
medical information stolen, which is a significant concern under HIPAA. This also violates
several HITEC statutes, including those regulating the security of electronic client data and the
transfer of electronic data via transactions.
Now, ABC businesses cannot claim that they have done all possible to comply with
HIPAA and HITECH requirements for the protection of patients and their personal information.
both electronically and non-electronically. The ramifications for ABC business are many; as
previously stated, they are in clear breach of several HIPAA and HITECH regulations. Both sets
of rules impose severe fines and license suspensions and will tarnish the company's reputation to
the point of insolvency. In other words, ABC is engaged in a high-stakes game that may result in
a barrage of lawsuits from the government and patients claiming that the business violated trust
and security protocols. Processes and guidelines must be developed for new technologies as well
as the day-to-day norms and procedures that employees must follow.
Their regular actions, like as discussing patients with one another without the patients
permission, also jeopardize the business. Workplace norms and standards for behavior and
technology usage must be created immediately and regularly enforced if they are to comply with
HIPAA and HITECH regulations once again.
MILESTONE 2 - RISK ANALYSIS PAPER
Acceptable use-of-technology policies
To safeguard the privacy and confidentiality of its customers, every company should have
"Acceptable use of technology guidelines" in place. This fact is particularly important for ABC
Company. With this policy, all employees and business personnel will have a thorough
knowledge of the regulations and procedures that must be followed to safeguard both their own
and their patients' data. Utilizing "work-provided" computers exclusively for the purpose of
examining client data is permissible under this policy, as is ensuring that all documents are
encrypted and available to only authorized staff members, as well as adhering to a stricter
password policy. It will also include the undesirable use limitations, such as the prohibition of
personal computers and network access, the prohibition of leaving private documents on printers,
and the appropriate disposal or destruction of sensitive objects containing patient data.
Determining why this is essential will assist employees understand how vital it is that we adhere
to HIPAA and HITECH regulations and how critical it is to safeguard patien