4A Healthcare Data Security & Privacy



Similar documents
THE AMERICAN LAW INSTITUTE Continuing Legal Education

HPC IN Cybersecurity Annual Technical Meeting. Venue: Schlumberger Richmond Ave, Houston, TX 77042


Put your Head in the Cloud at Phorum

DOD Medical Device Cybersecurity Considerations

Executive Order 13636: The Healthcare Sector and the Cybersecurity Framework. September 23, 2014

THE SECURITY OF THINGS

Cybersecurity and the AICPA Cybersecurity Attestation Project

An Independent Member of Baker Tilly International

HIPAA Compliance: Efficient Tools to Follow the Rules

Adopting a Cybersecurity Framework for Governance and Risk Management

Brief. The BakerHostetler Data Security Incident Response Report 2015

Cyber Liability Insurance:

Cyber Insurance: How to Investigate the Right Coverage for Your Company

Art Gross President & CEO HIPAA Secure Now! How to Prepare for the 2015 HIPAA Audits and Avoid Data Breaches

Data Breach Response Planning: Laying the Right Foundation

Testimony of Dan Nutkis CEO of HITRUST Alliance. Before the Oversight and Government Reform Committee, Subcommittee on Information Technology

How Cybersecurity Initiatives May Impact Operators. Ross A. Buntrock, Partner

Essential Conference Navigator

Corporate Perspectives On Cybersecurity: A Survey Of Execs

OVERSIGHT & COMPLIANCE

Connecting the dots: A proactive approach to cybersecurity oversight in the boardroom. kpmg.bm

A HEALTHCARE INDUSTRY EDI AND HIPAA COLLABORATIVE EVENT

Defining the Gap: The Cybersecurity Governance Study

States at Risk: Cyber Threat Sophistication, Inadequate Budget and Talent

Vendor Management Challenges and Solutions for HIPAA Compliance. Jim Sandford Vice President, Coalfire

presents Energy Summit 2015 STOCKHOLM SEPTEMBER SPONSORSHIP PROSPECT The conference is organized and arranged by:

Access is power. Access management may be an untapped element in a hospital s cybersecurity plan. January kpmg.com

FFIEC Cybersecurity Assessment Tool Overview for Chief Executive Officers and Boards of Directors

Seamus Reilly Director EY Information Security Cyber Security

Arizona Physicians Group To Pay $100,000 To Settle HIPAA Charges

Tuesday, August 16, :30 a.m. 6 p.m. The George Washington University 1957 E Street, NW Washington, D.C.

October 24, Mitigating Legal and Business Risks of Cyber Breaches

Cybersecurity in the Utilities Sector Best Practices and Implementation 2014 Canadian Utilities IT & Telecom Conference September 24, 2014

Privacy and Security Awareness, Education and Training Policy

Director and Officer Liability Trends and D&O Insurance Advanced Issues

CES 2016 AGENDA. Bally s Skyview Conference Center. Bally s, Las Vegas. Government Business Executive Forum. Ramsey Pub and Grill

Conducting due diligence and managing cybersecurity in medical technology investments

Privacy and Security requirements, OCR HIPAA Audits and the New Audit Protocol

Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission. June 25, 2015

InfoGard Healthcare Services InfoGard Laboratories Inc.

The Legal Pitfalls of Failing to Develop Secure Cloud Services

Law Firm Cyber Security & Compliance Risks

Cybersecurity. Shamoil T. Shipchandler Partner, Bracewell & Giuliani LLP

2015 Shriners Hospitals for Children Annual Healthcare IT Symposium

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

CYBER RISK INTERNATIONAL COMPANY PROFILE

IRS/Tax Practitioners Symposium The Illinois CPA Society

AHLA. B. HIPAA Compliance Audits. Marti Arvin Chief Compliance Officer UCLA Health System and David Geffen School of Medicine Los Angeles, CA

Enhancing NASA Cyber Security Awareness From the C-Suite to the End-User

Driving change through health care innovation

JAMIE L. SHELLER SHELLER, P.C Walnut Street, Fourth Floor Philadelphia, PA (215)

IAPP Global Privacy Summit Protecting Privacy Under the Cybersecurity Microscope

Partnership prospectus

Introducing our Chair for the Forum...

How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment

8/3/2015. Integrating Behavioral Health and HIV Into Electronic Health Records Communities of Practice

CYBERSECURITY IN HEALTHCARE: A TIME TO ACT

Cyberprivacy and Cybersecurity for Health Data

Transcription:

4A Healthcare Data Security & Privacy Symposium 2015 Banner Program Leaders Ben Goodman Developed in collaboration with Lisa Clark Conference Mission Health and medical regulators are promising audits and tougher enforcement while law enforcement warns that health data is under attack. Meanwhile, there is no shortage of solutions promising to protect data and prevent breaches, but not enough resources or even time in the day to review all the options. Of course, cyber security is not just an IT problem. It is a risk management problem that requires an interdisciplinary team approach. And that s what inspired the mission for this event. Ben Goodman, 4A Security & Compliance V11

Chairs & Speakers Ben Goodman Lisa W. Clark CEO 4A Security & Compliance Partner, Head of Firm s mhealth Interdisciplinary Group Duane Morris LLP Samantha Billy Pamela E. Clarke Senior Professional Risk Broker Aon Risk Solutions Dir. Member Services & Policy HealthShare Exchange of Southeastern Pennsylvania Noelle P. Conners Patricia Q. Connolly Hospital Compliance Officer St. Christopher s Hospital for Children Dr. Tama Copeman Founder & CEO Alcyone*7 Alcyone*7 John M. Neclerio Partner Duane Morris LLP Executive Director Center for Corporate Governance Drexel University LeBow College of Barbara Holland Regional Manager Office for Civil Rights U.S. Department of Health & Human Services Winston Krone Managing Director KIVU Consulting Inc.

Speakers J. Mark Eggleston Josh Ladeau Vice President, CISO & Privacy Officer Health Partners Plans Practice Lead Privacy & Network Security Allied World Assurance Co. Colin Morgan Global Information Security Manager & Information Security Officer Johnson & Johnson Jay Orler Vice President Infrastructure & Security Lightbeam Health Solutions Dave Snyder Chief Information Security Leader, Director of Information Security & Risk Management Offices Independence Blue Cross Jaime L. Sheller Product Manager for the Breach Coach Cyber Portal & Privacy Ethics Consultant NetDiligence Ben Stone Adrian Talapan Supervisory Special Agent Federal Bureau of Investigation Haystack Informatics Co-Founder and CEO A CHOP & DreamIt Ventures Company Nikhil Thakur Steve Alderfer Regulatory Policy Advisor Food & Drug Administration Director, IT Security Audit 4A Security

Agenda Time Topic Speakers 07:30 Registration & Breakfast 08:45 Opening Remarks Ben Goodman 4A Security & Compliance 09:00 10:00 Health & Human Services: Office of Civil Rights Update HHS OCR has seen significant change and a great deal of activity since the HIPAA Omnibus Final Rule came into effect. This year, pre-audit screening surveys were sent out to 350 covered entities and 50 business associates as part of Phase 2 of the HIPAA Audit Program. This session will provide an update on recent activity and what s on the horizon, and will explain impacts to Covered Entities, Business Associates and other stakeholders. n their value? Big Data & Population Health: Security & Privacy Challenges & Solutions Big data and population health are critical to the success of the Federal Health IT Strategic Plan 2015-2020, and yet, there are major security and privacy challenges that are only beginning to be addressed. This panel will consider how big data is being used and some of the key security and privacy implications for population health as well as some of the solutions that address them. than their value? Barbara Holland Office of Civil Rights U.S. Department of Health & Human Services Lisa Clark, moderator Duane Morris Dave Snyder Independence Blue Cross Jay Orler Lightbeam Health Solutions Pamela Clarke HealthShare Exchange of Southeastern Pennsylvania HHS Office of National Coordinator for Health Information - Pending confirmation 11:00 Break 11:15 12:00 Law Enforcement Update: Cybercrime & Healthcare Ten months before Anthem disclosed it was breached, the FBI warned the healthcare industry that they were under heightened risk of being the target of cyber attacks. This update from law enforcement will cover the most important past and current cybercrime activity from the law enforcement perspective. Lunch Ben Stone Federal Bureau of Investigation

Agenda Time Topic Speakers 01:00 Mobile Health, Apps & HIT Innovation: Security & Privacy by Design With $7B invested in healthcare IT ventures last year, innovation in mobile health, healthcare apps & healthcare IT is burgeoning. Too often data security and privacy is an afterthought, as the FDA s Safety Communication concerning cybersecurity vulnerabilities in the Symbiq Infusion System illustrates. Speakers will discuss how they are innovating & protecting data at the same time. These are models for innovation & product development that every investor should insist upon. Winston Krone Kivu Consulting Dr. Tama Copeman Alcyone*7 Adrian Talapan Haystack Informatics Nikhil Thakur Food & Drug Administration 02:00 Security & Privacy Controls: Implementation in the Real World On paper, security plans can be compelling, but the reality of constrained resources and the human factor makes implementing and maintaining the required controls a challenge. This is especially true when you factor in company culture, human resource policy, training and issues of employment law. This panel discusses real world solutions that bridge the gap between security and privacy plans and how they are implemented in the real world. Ben Goodman, moderator 4A Security Noelle Conners St. Christopher s Hospital for Children Mark Eggleston Health Partners Plans Colin Morgan Johnson & Johnson Steve Alderfer 4A Security 03:00 Break 03:15 CIOs & Healthcare Cyber Risk Management: Another New Cyber Liability Insurance Frontier CIOs generally should expect to be sued in increasing numbers over cybersecurity issues, says an attorney quoted in a recent Wall Street Journal article. How do cyber liability insurance solutions respond? Do they fill in for D&O exclusions? This panel discussion between insurance carriers, attorneys and brokers will discuss these and other important new questions healthcare organizations and their CIO s should be asking. Josh Ladeau Allied World Assurance Company John Neclerio Duane Morris LLP Samantha Billy Aon Risk Solutions

Agenda Time Topic Speakers 04:00 Live Tabletop Exercise: Healthcare Data Security Incident Response t This final panel of the day will step through an Incident Response Tabletop Exercise, based on a healthcare data security / privacy incident scenario. The interactive exercise will engage the audience in the process and challenge the panel members as they run through the decision-making process as a security / privacy incident unfolds. Attendees will have the chance to ask questions as participants make decisions based on imperfect information and identify areas of concern for organizations dealing with protected healthcare information. Ben Goodman, moderator 4A Security & Compliance Lisa Clark Duane Morris Winston Krone Kivu Consulting Patricia Connolly LeBow College of Business Jamie L. Sheller NetDiligence Mark Eggleston Health Partners Plans 05:00 Adjourn 05:01 Reception 4A & HB wishes to thank the sponsors and hosts!