Published: 23 July 2013
Summary
CISOs, CROs and compliance leaders need to realize that there is no safe harbor for HIPAA compliance and cloud services. Moving protected health information into the cloud requires due diligence, defensible decision making and the acceptance of risk.
Included in Full Research
- Perform a Risk Assessment Before Considering ePHI Cloud Services
- Rank the Risk Level of SaaS Providers by Controls and Your Ability to Defend Your Decision
- Take a Pragmatic Approach in Defining Levels of Effort for Data Classification; Base the Level of Effort on Use Cases for Volume and Persistence of ePHI Requirements
- Protect ePHI in Transit, in Storage and in Use