Chat with us, powered by LiveChat Ashworth Five Key Groups Relevant to Healthcare Delivery Discussion - STUDENT SOLUTION USA

Section
Part 1: Understanding your environment (Two pages | 30 points)
Part 2: Outlining regulatory and governance requirements (Two pages | 70 points)
Part 3: Analyzing threats and managing risks (Three pages | 50 points)
Part 4: Raising security awareness (Two pages | 30 points)
Part 5: Responding to cyber incidents (Three pages | 50 points)
Part 6: Implementing fundamental security protection measures (Five pages | 70 points)
Part 6: Implementing fundamental security protection measures (Five pages | 70 points)
Tasks
• Discuss the five key groups relevant in healthcare delivery and describe the kinds
of data they may interact with, collect, and/or provide to your hospital.
• Identify five electronic health records or data components relevant in hospital
environments and document them in a data classification table. Discuss whether the
information is confidential, for internal company use only, or open to the public.
Explain why hackers might want to steal this information.
• Identify five examples of technology systems or devices that are relevant in
hospital environments. Discuss security and legal issues associated with each.
• Outline the regulations that are relevant to the hospital. Summarize the purpose
and core requirements of each regulation.
• Identify the information security policies that should be created and adopted by
the company. Discuss why the policies are necessary and who should adhere to
them.
• Create an official end-user agreement and an incident reporting policy for the
hospital. Example templates can be found here, https://www.sans.org/securityresources/policies/general#acceptable-use-policy
• It’s important to learn from the past. The hospital was breached a few years ago
and a summary of the incident can be found here. Identify the threat, vulnerabilities,
impacts, and mitigating controls present in the overview. Use the information you’ve
outlined to create a new risk-based decision tree. (Reference page 98 of your
textbook.) Based on the ISO 27000 family of standards, recommend an approach to
addressing the risks in the decision tree, and provide justification for your response.
(Reference page 103 of your textbook.)
• Think of five third party providers that the hospital may work with. Discuss the
risks that third parties can introduce to the business. Summarize security
considerations and security control recommendations for granting third parties
access to hospital resources. Outline additional tools that can be used to manage
third party risk. (Reference page 138 of your textbook.)
• Share five recommendations for ways to increase cybersecurity knowledge and
awareness in the company. Explain why it’s necessary to implement this. Create an
example awareness poster that educates stakeholders on the risks of ransomware
attacks against hospitals.
• You’ve been made aware that the hospital was hit with yet another cyber-attack
that exposed all of the data types you outlined in Part 1 of the project. You found
that the incident started with a phishing email that a contractor from your medical
payment system provider clicked on. Discuss the steps necessary to contain,
eradicate, and recover from this incident. (Reference page 166 of your textbook.)
• Draft an example breach notification letter that will be sent to affected patients
about the incident.
• Explain the three guiding principles of security.
• Using the NIST CSF, make a recommendation for a control that would be
valuable for the hospital to implement for each of the five components. For each
control you select, explain the ways that failing to implement the control could
impact confidentiality, integrity, and/or availability.
Points Available
Points Awarded
10
10
10
20
20
30
25
25
30
30
20
20
50
300

Purchase answer to see full
attachment

error: Content is protected !!