Preview

Lab: Align Compliance Requirements to FISMA, SOX, HIPPAA, GLBA, PCI DSS and AICPA

Satisfactory Essays
Open Document
Open Document
271 Words
Grammar
Grammar
Plagiarism
Plagiarism
Writing
Writing
Score
Score
Lab: Align Compliance Requirements to FISMA, SOX, HIPPAA, GLBA, PCI DSS and AICPA
Lab 6
Align compliance requirements to FISMA, SOX, HIPPAA, GLBA, PCI DSS and AICPA
Hyung Ryu
ITT Technical College, Everett Campus

Author Note This assignment is being submitted on July 22, 2014, for Even Anderson introduction to project management PM3110

1. What are the five principles of the AICPA Trust Services & principles criteria?
2. What does the AICPA Trust Services & Principles Criteria recommend for concerning inactive user accounts on a web site?
3. With what section of SOX would the IT professional deal the most and why?
4. In HIPAA, under what scenario is a healthcare provider required to notify all patients and the department of health and human services when a security breach is discovered?
5. Where would someone go in order to find the quarterly and annual reports for a publicly-traded company to verify SOX compliance?
6. Describe the various levels of PCI DSS compliance as defined by VISA
7. In HIPAA, what information is protected and who is covered by the Security Rule?
8. For the 12 core requirements of the PCI DSS standard, what are the 3 steps or phases for assessing and reviewing compliance with the PCI DSS standard?
9. What are the fines associated with violating HIPAA compliance requirements?
10. What are the PCI DSS Procedures used when auditing an organization for security?
11. What are the 11 titles of mandates and requirements for SOX compliance?
12. What purpose may COBIT serve to help maintain compliance for regulations such as Sarbanes-Oxley?
13. What is the Safeguard Rule as it relates to GLBA?
14. What is the purpose of the PCI security audit procedures?
15. Describe the process to still obtain/maintain PCI DSS compliance even though a required security control/process is unrealistic for an organization?

You May Also Find These Documents Helpful

  • Powerful Essays

    Sarbanes Oxley Memo

    • 1426 Words
    • 6 Pages

    As consultants for Ancher Public Trading (APT), Learning Team A would like to discuss the implications of the Sarbanes-Oxley (SOX) legislation. This memorandum provides a brief history of SOX¡¦s creation, explains the relationship amongst the FASB, SEC and PCAOB, describes the pros and cons of SOX, assesses the impacts of SOX, and lists ethical considerations of SOX.…

    • 1426 Words
    • 6 Pages
    Powerful Essays
  • Best Essays

    Sarbanes Oxley Act

    • 3132 Words
    • 13 Pages

    Financial reporting has been dissected over and over again by legislation. The U.S. Securities and Exchange Commission (SEC) hold the key to providing protection and integrity when companies are submitting their financial statements. Although their mission is to provide order and efficiency for financial markets, insidious plans are still developed by companies which ultimately result in turmoil to the economy. To provide a safeguard to investors, the Sarbanes-Oxley Act (SOX) was passed by congress in 2002, which was constructed because of fraudulent acts of well-known companies such as Enron. Before the SOX was inaugurated, two sets of accounting rules were used as guides for CPA firms.…

    • 3132 Words
    • 13 Pages
    Best Essays
  • Satisfactory Essays

    In this week’s assignment, you are asked to research HIPAA and how it has provided…

    • 351 Words
    • 2 Pages
    Satisfactory Essays
  • Satisfactory Essays

    HIPAA Security Rule

    • 170 Words
    • 1 Page

    With so many health organizations turning to electronic transfer and receiving of individual health information, certain rules must be in place to ensure health information is kept confidential. In the article “Summary of the HIPAA Security Rule” defines the different roles that the rule covers. Here are some examples of what the HIPAA security rule covers: administrative safeguards, physical and technical safeguards, policies and procedure requirements and much more.…

    • 170 Words
    • 1 Page
    Satisfactory Essays
  • Powerful Essays

    HIPAA allows patients’ health information to be disclosed under some circumstances, such as 1) to meet law requirements; 2) for reporting of abuse, neglect, and domestic violence; 3) for monitoring of healthcare operations; 4) to be presented as evidence in legal proceedings; 5) for assistance with police investigation; 6) for medical examinations and funerals; 7) for organ donation; 8) for research; 9) to avoid a significant threat to health or safety; 10) for workers’ compensation payments; 11) to execute government…

    • 81 Words
    • 1 Page
    Powerful Essays
  • Satisfactory Essays

    Lab 9

    • 1001 Words
    • 3 Pages

    7. In order to perform a PCI DSS compliance audit on your e-commerce website, what should you incorporate into Requirement #6 regarding “Develop and Maintain Secure…

    • 1001 Words
    • 3 Pages
    Satisfactory Essays
  • Good Essays

    HIPAA Privacy Manual

    • 47886 Words
    • 192 Pages

    engaging in reasonable opposition to any act or practice that the person in good faith believes to be unlawful…

    • 47886 Words
    • 192 Pages
    Good Essays
  • Good Essays

    U.S. Department of Health and Human Services. (2012). Health Information Privacy. Retrieved from California. (2012) Retrieved from…

    • 827 Words
    • 4 Pages
    Good Essays
  • Good Essays

    HIPAA CIA And Safeguards

    • 599 Words
    • 3 Pages

    HIPAA, CIA, and Safeguards Medical data are increasingly computerized, which means, inevitably, medical data are increasingly subject to the risks associated with computer security, namely: •Confidentiality: data revealed to people not authorized to see them •Integrity: unauthorized changes to data, intentional or otherwise •Availability: access to data denied by persons or events…

    • 599 Words
    • 3 Pages
    Good Essays
  • Powerful Essays

    Providers of health care should be acquainted with the rules and regulations that guide HIPAA and the subsequent violations. Information is necessary to provide adequate and correct patient care. The guidelines to protect patient privacy should be followed but are open for interpretation. Providers should be steered by professional principals and ethics (Lo, Dornbrand, Dubler 2005). Health care providers must understand the difference between privacy and confidentiality. Privacy is the right of individuals to keep personal information restricted. Patients decide who has access to their information. Confidentiality is how…

    • 1599 Words
    • 7 Pages
    Powerful Essays
  • Good Essays

    The Health Insurance Portability and Accountability act of 1996 or HIPAA, was put in place as an attempt to reform health care during the Clinton administration by making it possible for workers, of any profession, to change jobs regardless if the worker, or any member of their family, have a pre-existing medical condition, decreasing paperwork which is associated with the processing of health claims, and by reducing health care abuse and fraud, and by assuring the privacy and security of health information. HIPAA’s standards for privacy of individually identifiable health information or privacy rule includes restrictions which protect the confidentiality and security of health information, and determines a criterion to protect the confidentiality of individually identifiable health information that is maintained or transmitted through electronic means in association with certain administrative and financial transactions such as electronic transfer of health insurance claims. The covered entity, in most cases, is required to obtain an individual’s authorization prior to disclosing any health information. And in most circumstances the patient or a legal representative of the patient controls the disclosure of PHI to any third party.…

    • 1028 Words
    • 5 Pages
    Good Essays
  • Powerful Essays

    Hippa Privacy

    • 1433 Words
    • 6 Pages

    Privacy is the right of an individual to keep his/her individual health information from being disclosed.…

    • 1433 Words
    • 6 Pages
    Powerful Essays
  • Powerful Essays

    HIPAA is divided into five titles or categories covering different aspects of healthcare. The highlights of these five titles are (i) continuous health care insurance coverage for most people, (ii) preventing health care fraud and abuse and protecting patient’s personal information, (iii) tax-related health provisions governing medical savings accounts, (iv) application and enforcement of group health insurance requirements, (v) revenue offset governing tax deductions for employers. Title II of HIPAA deals with Fraud/Abuse in healthcare, Administrative Simplification via standardization of electronic exchange and privacy and security of protected health information (PHI). PHI is individually identifiable information of patient’s health record that covered entities and their business associates maintain or share. As defined by HIPAA a covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider. Business associates are individuals or organizations that perform work on the behalf of the covered entities. The title II provision of ‘Administrative Simplification’ include rules for protecting privacy and security of PHI. The US Department of Health and Human Services Office for…

    • 1261 Words
    • 6 Pages
    Powerful Essays
  • Good Essays

    Privacy In Healthcare

    • 457 Words
    • 2 Pages

    The health information probability and accountability act has five sections that hold health professionals accountability. Title two: fraud and abuse /administrative simplification are in place to protect the security and privacy of their patients. Title two also improves the efficiency of the business process, which decrease cost. All health care facility has to meet the covered entities which includes a health plan, healthcare provider, and a healthcare clearinghouse. HIPAA address covered transactions such as claims, payments, eligibility, and more. However, there are some exceptions to the covered entity rule for the health care facilities that have less than twenty- five employees. HIPAA has put more emphasis on security and privacy which has changed the processes on how HIM professionals deal with patient’s health information. Transaction and code sets are rules that are another part of the HIPAA regulations which was designed to put a standard on the transactions performed by healthcare facilities, which affected the supply of electronic transactions. Another rule is the privacy rule which was put in place to control how PHI can be used by covered entities. Privacy and security was once taking care of the state level but this became a huge problem which cause the federal government to get involved. Even though, privacy and security has all ways been a priority it has become even more important that the HIM professional take the privacy and security of every patient with care and…

    • 457 Words
    • 2 Pages
    Good Essays
  • Satisfactory Essays

    The Sarbanes-Oxley Act of 2002, requires public companies to certify the adequacy of their internal controls for financial reporting purposes. Because of the Sarbanes –Oxley Act of 2002 companies are required to fully comply with their certification and reporting obligations and responsibilities by assuring that any financial…

    • 340 Words
    • 2 Pages
    Satisfactory Essays