ARTICLE
18 September 2023

HHS OCR/ONC Announce Latest Version Of Security Risk Assessment Tool

FH
Foley Hoag LLP
Contributor
Foley Hoag provides innovative, strategic legal services to public, private and government clients. We have premier capabilities in the life sciences, healthcare, technology, energy, professional services and private funds fields, and in cross-border disputes. The diverse experiences of our lawyers contribute to the exceptional senior-level service we deliver to clients.
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC) have released version 3.4...
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC) have released version 3.4 of their Security Risk Assessment (SRA) Tool.

The SRA Tool is designed to help healthcare providers conduct a risk analysis as required by the HIPAA Security Rule. Identifying and assessing potential risks and vulnerabilities to electronic protected health information (ePHI) are foundational elements in the implementation of security measures that protect ePHI. As hacking and ransomware attacks continue to increase within the health care sector, it is more important than ever for organizations to understand their risk exposure and use that understanding to improve their cybersecurity.

The downloadable SRA Tool is a desktop application that walks users through the security risk assessment process using multiple-choice questions, threat and vulnerability assessments, and asset and vendor management. References and additional guidance are given along the way. Reports are available to save and print after the assessment is completed.

The latest version contains a variety of feature enhancements based on user feedback and public input. New features include:

1) A Remediation Report to help track responses within the tool
2) A Glossary and "Tool Tips" help
3) Updated references to Health Industry Cybersecurity Practices (HICP) for 2023 Edition
4) Bug fixes and stability enhancements

To view Foley Hoag's Security, Privacy and The Law Blog please click here

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

ARTICLE
18 September 2023

HHS OCR/ONC Announce Latest Version Of Security Risk Assessment Tool

United States Technology
Contributor
Foley Hoag provides innovative, strategic legal services to public, private and government clients. We have premier capabilities in the life sciences, healthcare, technology, energy, professional services and private funds fields, and in cross-border disputes. The diverse experiences of our lawyers contribute to the exceptional senior-level service we deliver to clients.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More