© Eric C. Thompson 2017

Eric C. Thompson, Building a HIPAA-Compliant Cybersecurity Program, https://doi.org/10.1007/978-1-4842-3060-2_2

2. Meeting Regulator Expectations

Eric C. Thompson

(1)Lisle, Illinois, USA

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) enforces HIPAA and investigates breaches, responds to patient complaints, and establishes resolution agreements, where necessary. Patients expect that safeguards designed to secure the confidentiality, integrity, and availability of healthcare records are in place. Briefly, HIPAA has been in existence since 1996. Enforcement of the HIPAA Privacy Rule took effect in April 2003, and Security Rule enforcement took effect in April 2005. Breach investigations are not ...

Get Building a HIPAA-Compliant Cybersecurity Program: Using NIST 800-30 and CSF to Secure Protected Health Information now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.