Question: You client, a local hospital is implementing a new electronic medical record system. The system provide access to PII about patients and will be accessible
You client, a local hospital is implementing a new electronic medical record system. The system provide access to PII about patients and will be accessible to physicians both in the hospital, at the physician's individual practices, and to the patients via the internet. The CIO of the hospital is concerned about the confidentiality, integrity, and availability of the PII that is part of the EMR system. Advise the CIO on the most effective approach to developing appropriate controls for the EMR system. Make sure to discuss administrative, technical, and physical control types as well as in-place and planned control differences, and finally preventative, detective, and corrective categories of controls.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
