Effective Tips for Implementing a Successful Privacy & Information Security Program



Similar documents
Learning Objectives. Strategic Planning Concepts for Marketing Communications. Strategic Planning. Business Planning Process.

Waste Fleet Safety: Tips and Tools to Ensure Safe Driving. White Paper.

Question: 1 Which of the following should be the FIRST step in developing an information security plan?

ASAE s Job Task Analysis Strategic Level Competencies

Information Governance Management Framework

Vice President, Marketing

Federal Bureau of Investigation s Integrity and Compliance Program

Master s Certificate in Public Sector Management

(Effective as of December 15, 2009) CONTENTS

Mental Health Resources, Inc. Mental Health Resources, Inc. Corporate Compliance Plan Corporate Compliance Plan

GOVERNANCE GUIDELINES OF THE NATIONAL ASSOCIATION OF CORPORATE DIRECTORS

Building a Culture of Health Care Privacy Compliance

YOUR MARKETING CHECKLIST

5 TIPS FOR SETTING MEASURABLE SOCIAL MEDIA GOALS

Total Quality Management (TQM) presented by Dr. Eng. Abed Schokry

Elearning: Building an Effective and Engaging Solution Online

MARKETING LENS SAMPLE REPORT. Are your marketing efforts effective? September Available on

5 Tips For Setting Measurable. Social Media Goals. 5 Tips for Measurable social media goals

Competency Requirements for Executive Director Candidates

Developing Your Business Plan

How To Ensure That A Quality Control System Is Working Properly

Your Ultimate Guide To Campaigning

Linking Risk Management to Business Strategy, Processes, Operations and Reporting

Strategic Plan. Fiscal Year Julie L. Jones Executive Director. Goals Objectives Strategies Measures

APES 320 Quality Control for Firms

Marketing... are you up to speed?

HIPAA Audits and Compliance: What To Expect From Regulators and How to Comply

HIPAA and Mental Health Privacy:

2014 Customer Care Benchmark Report

Principles of Marketing Lecture 13a: Promotional Mix Decisions: Advertising and Sales Promotion. The Traditional Communication Model. Noise.

HCA ETHICS AND COMPLIANCE PROGRAM

How To Keep Up Awareness Of Compliance

MARKETING BASICS FOR START-UP BUSINESSES

COMPLIANCE PROGRAM FOR XL GROUP PLC

IT Service Desk Health Check & Action Plan

Most CPA firms understand the importance of strategic

Final. North Carolina Procurement Transformation. Governance Model March 11, 2011

SPA PERFORMANCE MANAGEMENT PROGRAM GENERAL COMPARISON OF EXPECTATION LEVELS FOR ORGANIZATIONAL VALUES

Performance planning:

EXECUTIVE BEHAVIORAL INTERVIEW GUIDE

UBS presentation Key remediation actions

Network Security Policy

UF IT Risk Assessment Standard

PRCA Communications Management Standard (CMS) for In-House Teams

BOOSTING TARGETED ACQUISITION THROUGH AN INTEGRATED ONLINE STRATEGY

Thinking Inside the Box Creative Event Planning Strategies for PCCs

Cybersecurity Awareness for Executives

GUIDANCE FOR MANAGING THIRD-PARTY RISK

REFERENCE 5. White Paper Health Insurance Portability and Accountability Act: Security Standards; Implications for the Healthcare Industry

The problem of cloud data governance

Grow. How to Authentically Grow Your List

MARKETING. The right technology can help your business increase sales by increasing consumer awareness.

HR Strategy ( )

How To Comply With The Law Of The Firm

JOB DESCRIPTION: CHARITABLE GIVING ADVISOR, DIRECT RESPONSE

Developing Your Strategic Plan

Who Should Know This Policy 2 Definitions 2 Contacts 3 Procedures 3 Forms 5 Related Documents 5 Revision History 5 FAQs 5

DEPARTMENT OF MENTAL HEALTH AND DEVELOPMENTAL DISABILITIES

20 Customer Service Best Practices SELL. SERVICE. MARKET. SUCCEED.

Overview of Performance Management. Taking Steps to Enhance Individual & Organizational Effectiveness

Social media guidelines

R345, Information Technology Resource Security 1

Education Campaign Plan Worksheet

Next Generation Compliance: Strategic Plan

Case study: developing an internal communications and engagement strategy

Applies from 1 April 2007 Revised April Core Competence Framework Guidance booklet

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

City with a Voice STRATEGIC COMMUNICATION PLAN

Saint Francis Care Patient Care Services Advancement to Clinical Excellence Program (ACE Program) INTRODUCTION

Meeting Professionals International (MPI) June 2006,

Change Management model implementation guide

CISM (Certified Information Security Manager) Document version:

MARKETING STRATEGY TEMPLATE

USBC Onboarding Program. Module 2: Orientation to the USBC Board of Directors

The Leader s Edge. How Best Practices Programs Can Be Used Most Effectively to Support the Growth of Women Leaders

Thinking Inside the Box Creative Event Planning Strategies for PCCs To listen to the recording of this presentation visit:

Arizona State University. HIPAA Compliance. Audit Report Number May 7, 2015

TEN SIMPLE WAYS TO BOOST YOUR PAYROLL GIVING PROGRAM PERFORMANCE. Creating successful payroll giving programs

IT SECURITY EDUCATION AWARENESS TRAINING POLICY OCIO TABLE OF CONTENTS

Harrah s Marketing Overview. February 2008

FinTech Webinar Series: Vendor Management Principles

Commitment Accuracy Delivered COMPANY PROFILE

Guidelines of Proper Use of Social Media for State of Vermont Government. State of Vermont

6 SECRETS TO OFFERING EXCEPTIONAL CUSTOMER SERVICE salesforce.com, inc. All rights reserved.

Effective Internal Audit in the Financial Services Sector

Strategic Plan FY FY July 10, 2014

Understanding Digital Marketing. Why Digital Marketing is your companies best friend.

SANDY ROGERS Expert Consultant Practice Leader Thought Leader Speaker

SOCIAL MEDIA BEST PRACTICES

Case Study: citizenm Hotels

Maximizing Special Event Marketing. Presented by Klamath County Chamber of Commerce and The Ross Ragland Theater

In our current competitive climate, all public schools should be building their brand Stacy Tapp

Applying a Proven Learning Strategy in Bank Acquisition Environments

Non Profits, Charities and Volunteer Organizations

Credit Union Liability with Third-Party Processors

Capacity Assessment Indicator. Means of Measurement. Instructions. Score As an As a training. As a research institution organisation (0-5) (0-5) (0-5)

Customer Service. 1 Good Practice Guide

IMPLEMENTATION PLANNING CORPORATE

Best Practices for Marketing. Monday, March 8, 2010

How To Manage Performance In North Ayrshire Council

Transcription:

Effective Tips for Implementing a Successful Privacy & Information Security Program Alexander D. Eremia, JD, LL.M. Vice President, Deputy General Counsel and Chief Privacy Officer MedStar Health, Inc. Shallie Bryant Privacy Manager, MedStar Health, Inc. Promoting Promoting Trust Trust by by Protecting Protecting Privacy Privacy

Is this your privacy and security awareness program?

About MedStar Health

Organization Affiliated Covered Entity ( ACE ) Chief Privacy and Security Officers Single Notice of Privacy Practices Enhances ability to share/use PHI across system Requires centralized governance structure Requires standardized Training and education Privacy investigations and responses Disciplinary measures ACE liability

What does security mean? What does privacy mean?

MedStar Health The Trusted Leader in Caring for People and Advancing Health

Key Objectives Infrastructure Patient trust = patient satisfaction All confidential information Compliance with laws Reputation as industry leader in privacy and information security practices

Strengths Strong privacy department leadership and technical expertise Staff informed and passionate Successful history and familiarity with using a variety of communication tools Availability of external resources External consultants to assist with communications Liaisons/champions throughout system

Weaknesses Limited staff Many priorities with overlapping deadlines Lack of infrastructure Highly regulated industry with extensive mandatory education requirements Messages may compete with other internal campaigns Technology moving faster than policy

Opportunities Internal platforms such as Intranet for expanding resources and testing new tools Email communications Privacy and Security is a big issue Growing awareness and public interest Potential to be a resource on privacy and information security to patients and other organizations

Threats Violations getting more attention Stronger enforcement of regulations Potential negative ramifications to reputation and bottom line Heightened scrutiny of privacy and security incidents and focus on patient rights Increased exposure due to new regulations Potential budget constraints

SMART Goals Publish updated corporate privacy and security policies by January 1, 2009 Develop and roll out new privacy and security training modules by June 30, 2009 Raise and maintain awareness in the MedStar community; measure annually Demonstrate effectiveness of program by monitoring: Employee test scores on mandatory training # visits to Intranet site # and type of employee violations Ordering of privacy printed materials

Using Data Analysis to Identify Trends Employee and patient complaints recorded in centralized tracking system that tracks Trends in incident New vulnerabilities

Snapshot Data Analysis Captured cont.

Tips for Nipping Non Compliance in the Bud

Strategies Communication & Awareness Memorable, high impact visuals Customize messages for audience Keep materials positive in tone, tied to promoting trust Group various materials under like themes

Strategies Training Develop role based modules that focus on concepts applicable to position Integrate visuals and messages into all communication and training materials Consistency

Steps to Success Assess Areas of confusion? concerns? frequent trouble spots? Benchmark current position Plan Mission, vision, values Major goals and objectives Strategies to accomplish goals Measurements of success

Steps to Success Implement Develop theme and key messages Utilize existing communication channels to their fullest potential Work in cooperation with your internal communications staff Support your program needs with employee task forces, volunteer committees, and/or outside consultants Evaluate

Tools & Tactics Celebrate recognition weeks Host annual roundtable Be visible Saturate the market Frequency and variety Appeal to your audience

Tools & Tactics Show employees you care Educate/inform about personal privacy issues Travel safety Online safety for kids/teens Holiday shopping

Tools & Tactics Seek feedback from your audience Tailor/improve messages and strategies Consider rewards and incentives Make resource materials readily available Be creative! Always include a call to action or a direction for more information Be as interactive as possible Be POSITIVE!

Don t have a big budget? Think big return, for small cost Lunch and learns Low cost give aways Use employees for models and ambassadors Games, trivia contests Site visits by experts Use existing communication resources Be repetitive Food is an attention getter Use supervisors/front line managers as communicators

Why do you need a budget?

DO Be positive Measure Know your audience Develop a strategy Ask for help Get buy in from senior management Ask for a budget Do s and Don t s DON T Equate campaign with program Equate awareness with training Use only one or two channels to communicate STOP This is not a one time effort!

Questions? Email: alexander.d.eremia@medstar.net or privacyofficer@medstar.net Promoting Promoting Trust Trust by by Protecting Protecting Privacy Privacy