Case Study
October 26, 2021

A Mental Healthcare Organization and HIPAA Compliance

No items found.

Table of Contents

Share with network

Related Insights

How a healthcare organization scaled IT leadership through Office of the CIO servicesHow a healthcare organization scaled IT leadership through Office of the CIO services

How a healthcare organization scaled IT leadership through Office of the CIO services

Lorem ipsum dolor set

Your next CFO probably isn't looking for a jobYour next CFO probably isn't looking for a job

Your next CFO probably isn't looking for a job

Lorem ipsum dolor set

Replay: Responsible AI Starts Here: Governance & Controls in ActionReplay: Responsible AI Starts Here: Governance & Controls in Action

Replay: Responsible AI Starts Here: Governance & Controls in Action

Lorem ipsum dolor set

What a recent high-profile cybersecurity incident reveals about healthcare cyber riskWhat a recent high-profile cybersecurity incident reveals about healthcare cyber risk

What a recent high-profile cybersecurity incident reveals about healthcare cyber risk

Lorem ipsum dolor set

Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)

Managing state tax exposure for growing businesses: When to consider a voluntary disclosure agreement (VDA)

Lorem ipsum dolor set

Executive Management asked Elliott Davis to help answer, "What is our compliance with HIPAA security compliance?"

Context

Wanted to gain a detailed understanding of:

  • Applicable regulatory requirements (e.g. HIPAA, PCI, CCPA) including efforts/costs to achieve compliance
  • Cybersecurity risks, including estimated remediation efforts/costs pre and post-close
  • IT landscape from the perspective of people, process, and technology with estimated remediation and integration efforts/costs

Our Approach

  • Detailed HIPAA Privacy and Security Due Diligence
  • Detailed Cybersecurity Due Diligence
  • Baseline Due Diligence
  • Detailed IT Due Diligence

Customer Impact

  • Received final report of threat risk for each asset that creates, stores, receives, or transmits ePHI
  • Identified gaps associated with compliance with HIPAA Privacy Rule including roadmap to meet the Privacy Rule requirements.
  • Understands overall cyber maturity and steps to improve the overall posture

We Can Help

For more information on this and other topics, contact a member of our team.

The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.

contact our team

contact our team

contact our team.