hipaa workloads on aws - pop-up loft tel aviv

21
HIPAA Workloads on AWS

Upload: amazon-web-services

Post on 18-Jan-2017

529 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

HIPAA Workloads on AWS

Page 2: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

CVS

• In 2009 fined $2.25 million

• Disposing of protected health information in public dumpsters

• OCR Findings:

• Did not have adequate policies and safeguards

Page 3: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Alaska Department of Health and Human Services

• In 2012, fined $1.7 million

• Unencrypted employee USB drive stolen from his car

• OCR Findings:

• Failed to complete risk analysis

• Failed to implement adequate security measures

• Neglected to have security training for its employees

Page 4: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

WellPoint• In 2013, fined $1.7 million

• Protected Health Information (PHI) accessible over the internet for 5 months

• OCR Findings:

• Failed to perform an adequate technical evaluation in response to a software upgrade

• Neglected to implement user verification technology to the Web-based patient database

Page 5: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

By: Ran Rothschild

Page 6: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
Page 7: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Most frequent Violations1. Not permissible uses and disclosures of protected health

information

2. Lack of safeguards of protected health information

3. Lack of patient access to their protected health information

4. Lack of administrative safeguards of electronic protected health information

5. Use or disclosure of more than the minimum necessary protected health information

Page 8: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Most common types of covered entities that have been required to take corrective

action1. Private Practices

2. General Hospitals

3. Outpatient Facilities

4. Pharmacies

5. Health Plans (group health plans and health insurance issuers)

Page 9: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

What is PHIHIPAA regulations list eighteen different personal identifiers which, when linked together, are classed as Protected Health Information

Who has responsibility to protect PHI?︎Co︎vered Entities︎, ︎Business Associates ︎ and ︎sub contractors

Page 10: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Achieving HIPAA Compliance on AWS

Page 11: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

The 3 Pillars of HIPAA

Page 12: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Internal Procedures and Processes

Page 13: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Internal Procedures

and Processes

IT Environments

Page 14: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Internal Procedures

and Processes

IT Environments

Constant up2date

Page 15: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

HIPAA Security Rule1. Administrative Safeguards

2. Physical Safeguards

3. Technical Safeguards

4. Policies, Procedures and Documentation governance

Page 16: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

IT• Size does matter

• Complexity, capability, cost, probability and criticality of potential risk

• ‘Reasonable anticipated threats’

• Required vs. Addressable

Page 17: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Constant up2date and training• Risk analysis (part of admin. safeguards)

• HITECH

• US Department of Health and Human Services (HHS.gov)

• Office of Civil Rights (OCR)

Page 18: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

AWS & HIPAAQ: Is AWS HIPAA Compliant? A: There is no HIPAA certification for a cloud provider such as AWS

Q: Will AWS sign BAA? A: Yes…but…

Q: Are all AWS services HIPAA compliant? A: No…Yes…PHI can only be stored, processed and transmitted in: DynamoDB, EBS, EC2, EMR, ELB, Glacier, RDS (MySQL & Oracle), Redshift, S3

Q: Are you aware of the Shared Responsibility Model?

Page 19: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Do you comply?1. Administrative – to create policies and procedures designed

to clearly show how the entity will comply with the act. 2. Physical – to control physical access to areas of data storage

to protect against inappropriate access 3. Technical – to protect communications containing PHI when

transmitted electronically over open networks

* Minimum information Necessary!!!

Page 20: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv
Page 21: HIPAA Workloads on AWS - Pop-up Loft Tel Aviv

Thank You