Road to HIPAA Compliance: Privacy Rule – Privacy Notices and Consumer Complaints

by KirkpatrickPrice / December 19, 2022

What is the Privacy Rule? If you’ve been following along with our Road to HIPAA Compliance webinar series, congratulations - we’ve made it to the middle of the road! We are halfway to knowing all about HIPAA compliance. In this session, we’re covering the Privacy Rule, Notice of Privacy Practices, and handling consumer complaints.  The Privacy Rule exists so that patients know they have rights, and that those rights…

business people walking

PCI Readiness Series: PCI Requirement 9

by KirkpatrickPrice / December 19, 2022

PCI Requirement 9: Restrict Physical Access to Cardholder Data PCI Requirement 9 evaluates all aspects of physical security controls to cardholder data – updated devices, visitor badges, security cameras, etc. The PCI DSS states, "Any physical access to data or systems that house cardholder data provides the opportunity for individuals to access devices or data and to remove systems or hardcopies, and should be appropriately restricted."  There are ten sub-requirements…

PCI Readiness Series: Penetration Testing

by KirkpatrickPrice / December 19, 2022

Building a Comprehensive Penetration Testing Methodology We often see clients struggling with the new requirements for penetration testing with regard to PCI compliance. The intent behind the new penetration testing methodology is to define the means and the methods by which a penetration test will be executed in your organization’s environment. Your organization’s penetration testing methodology should define the things that a penetration tester needs to do in order for…

Road to HIPAA Compliance: Policies and Procedures

by KirkpatrickPrice / December 19, 2022

How Policies and Procedures Can Help You Ace an OCR Audit This webinar gives insight into the purpose and the concepts of effective policies and procedures and what the Office for Civil Rights (OCR) is looking at when evaluating policies and procedures. Updated, well-documented and implemented policies and procedures are the basics of any regulatory compliance program. Outdated policies and procedures are the most common gap that we see when…

PCI Readiness Series: PCI Requirement 8

by KirkpatrickPrice / December 19, 2022

This session in our PCI Readiness Series dives into PCI Requirement 8, specifically about identifying and authenticating access to system components. In this webinar, we will cover strong, secure passwords in transmission and storage, disabling accounts for terminated employees and unused accounts, changing default passwords, and disabling generic accounts with shared usernames and passwords.  PCI Requirement 8 establishes non-refutability and authentication security, covers all systems and applications, and has…