HIPAA – HITECH, Aligning Secure Host Baselines According to Common Security Framework CSF
CHALLENGE RECAP
Reputation is the new target for cyber attacks
- Criminals value information – financial, health, critical infrastructure
- Data Breaches in Healthcare totaled over 112 Million Records in 2015
- breaches cost the healthcare industry about $5.6 billion annually
The safeguarding of electronic protected health information (EPHI) is legal mandate

ISMS Standard, SIMM 5305-A, Information Technology Management is responsible for oversight … ensuring the protection of the state entity’s information assets and state entity compliance with security policies, standards, and procedures.
Information Technology Management is accountable to:
- Implementing the necessary technical controls to preserve the confidentiality, integrity, and availability of the state entity’s information assets.
- Managing the risks associated with those assets.
- Monitoring for and reporting to the Information Security Officer any actual or attempted security incidents.
Why comply with HIPAA HITECH?
As summarized by An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act; NIST Special Publication 800-66, “in addition to being subject to the Federal Information Security Management Act of 2002 (FISMA), [agencies] are also subject to similar requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule (the Security Rule), if the agency is a covered entity as defined by the rules implementing HIPAA.
The HIPAA Security Rule specifically focuses on the safeguarding of electronic protected health information (EPHI). Although FISMA applies to all federal agencies and all information types, only a subset of agencies is subject to the HIPAA Security Rule based on their functions and use of EPHI. All HIPAA-covered entities, which include some federal agencies, must comply with the Security Rule, which specifically focuses on protecting the confidentiality, integrity, and availability of EPHI, as defined in the Security Rule. The EPHI that a covered entity creates, receives, maintains, or transmits must be protected against reasonably anticipated threats, hazards, and impermissible uses and/or disclosures.
EnterpriseGRC Solutions Security and Compliance solutions are uniquely tailored to manage both FISMA and HIPAA as it relates to Health and Government Regulated Industries. (This image is scheduled for an update. We use NIST SP 800-53 R5, but the underlying process is still the same. You might want to also read LSHC & MDM Cybersecurity Strategy.
Avoiding Security Breaches
HIPAA Rules places a burden on health staff and IT. Mismanagement of these disparate administrative, physical and technical requirements exposes entities to data breaches. One such example is found in implementing HIPAA specific policy packs that report alignment with configuration and system policy guidance, including comprehensive ISO27002:2013 customizable policy enforcement. This type of solution can also be implemented on a system by system basis using the CIS-CAT Pro solution offered by the Center For Internet Security.
The Office for Civil Rights (OCR) released a crosswalk between the HIPAA Security Rule and the NIST Framework for Improving Critical Infrastructure Cybersecurity (Cybersecurity Framework). EnterpriseGRC Security and Compliance has leveraged all available resources to make your reporting applicable for most, if not all health related technology compliance events.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics