Manual: Information Management Manual (Ver 6) External Reference: (TJC IM.02.01.03) (HIPAA §164.308(a)(1)(ii)(A))
MCN's customizable template, Administrative Safeguards - Risk Analysis, is taken from our Information Management Manual. MCN Healthcare's proven policy and procedure templates, competencies and compliance tools have assisted more than 20,000 health care organizations worldwide meet their regulatory compliance goals. MCN's templates save you time, money and resources, rather than developing healthcare policy and procedure manuals from scratch. Here is some sample content from Administrative Safeguards - Risk Analysis:
| | POLICY:
Hospital shall conduct an annual assessment risk analysis to identify the threats to the confidentiality, integrity and availability of electronic protected health information within the hospital.
This assessment will include:
Defining electronic protected health information
Identifying threats to the integrity of the electronic protected health information
Identifying vulnerabilities within the systems that are used to maintain electronic protected health information
Analyzing security controls
Determining the likelihood of risk to the electronic protected health information
... |
| Second excerpt: |
| | ...to protect the information
List all training and security policies used to protect the information
Identify Threats:
Threats to the electronic protected health information is something or someone that can intentionally or accidentally exploit a weakness within the information system.
This part of the risk assessment can be conducted by using assessments from local and state governments or through a security organization such as CERT, NIPC or SANS.
Threats include:
Natural:
Floods,... |
|