Michael Frederick, chief information security officer at Baylor Healthcare System in Dallas, is using the HITRUST Common Security Framework to help ease the task of complying with multiple regulations.\n\n
In an interview, Frederick, who heads a staff of 22, describes how the framework is helping him achieve several goals, including demonstrating 100% HIPAA compliance. He also:\n\n
Describes how Baylor developed its own "downtime viewer" system that offers read-only access to critical data during a system outage;\nOutlines why Baylor is devoting more resources to disaster recovery and business continuity;\nShares Baylor's breach notification strategy;\nDescribes efforts to create audit trails that demonstrate compliance;\nPinpoints how the organization uses encryption; and \nDiscusses how his role as CISO has evolved.\n\n
Frederick, who became Baylor's first full-time CISO two years ago, serves the entire health system, which includes 13 hospitals and more than 100 clinics.