IS3230 Ch.4 Access Control Policies, Standards, Procedures, and Guidelines

22 cards   |   Total Attempts: 188
  

Related Topics

Cards In This Set

Front Back
What does HIPAA stand for and who does it apply to?
Health Insurance Portability and Accountability, applies to Health Care industry
What does SOX stand for and who does it apply to?
Sarbanes-Oxley, applies to public companies
What does GLBA stand for and who does it apply to?
Gramm-Leach-Bliley act, applies to financial service industry
What are the 5 Title II rules under HIPAA that directly affect the IT department?
Privacy Rule
Transaction and Codes Set Rule
Unique Identifer Standards Rule
Security Rule
Enforcement Rule
Describe "Transactions and Codes Set Rule"
A common standard for the transfer of all health information between health care providers and the organizations that process payment for these services.
Describe "The Privacy Rule"
It regulates the use and disclosure of protected information held by covered entities.
Describe "Unique Identifier Standards rule"
Handles the creation and use of unique identifiers for providers, health plans, employers, and patients.
Describe the "security rule"
A complement to the privacy rule that covers how PHI is secured. Deals specifically with elecronic protected health information (EPHI)
The "security rule" lays ourt 3 layers of security safeguards required for compliance. What are they?
Administrative, physical, technical
Describe the "Enforcement Rule"
The final rule that details the basis and procedures for imposing civil monetary penalties on covered entites that violate HIPAA.

A unification of the patchwork of existing rules and regulations that governed the enforcement of different parts of HIPAA.
What does FERPA stand for and who does it apply to?
Family Educational Rights and Privacy Act, applies to educational institutions
What are the two types of education records under FERPA?
Directory information
Non-Directory information
What does CIPA stand for and who does it apply to?
Children's Internet Protection Act, applies to any school or library using the federal E-Rate program
What does NERC stand for and who does it apply to?
North American Reliability Council, applies to energy and itility companies.
What is an authorization policy?
High-level document that defines how an organization will assign and enforce access control rights.