Why a HIPAA Security Analysis Is Not Enough

Published: Jan. 12, 2017, 8:02 p.m.

b'Although HIPAA requires healthcare organizations to conduct a periodic security risk analysis focused on systems containing PHI, larger entities should also perform more comprehensive security self-assessments, advises CISO David Loewy of SUNY Downstate Medical Center, who explains his approach.'