+1 844-445-3653 cs@usconferencestime.com
Healthcare

How to Conduct a HIPAA HITECH Security Risk Assessment – Consistent with New Federal Updates

Recorded Webinar
Presented by - Brian L. Tuttle
Brian L. Tuttle
Description:

This course will cover the proper methodologies for conducting a HIPAA Risk Assessment based on the formula used by Federal auditors and via the guidelines of the NIST (National Institute of Standard for Technologies), including the new Notice of Proposed Rulemaking soon to be finalized 

The course will also include policy templates written based on the findings of the “mock” risk assessment.

The course will also cover the most important aspects to be aware of in terms of the Federal auditing process as well as the new risks regarding patients suing for wrongful disclosures.

Areas Covered:-

  • Updates for 2026 (NPRM’s)
  • How to answer questions specific to the HIPAA Security Rule for different entities (i.e., medical practices, billing companies, software companies, managed IT service providers, insurance plans, etc)
  • Policies and Procedures (how to write – with templates)
  • Risks
  • Business associates and the increased burden

Why Should You Attend:-

Have you done your HIPAA HITECH Security Risk Assessment?
Is it current? 
Do you know a risk assessment is the first thing the OCR will ask for in an audit or in the event of a breach?  
Is your risk assessment adequate?
 
Do you have written policies in place for all 18 Standards and 44 Implementation Specifications of the HIPAA Security Rule (even ones that don’t apply) – do you know this is required per the new Notice of Proposed Rulemaking soon to be finalized?
 
I will show you how to conduct a PROPER risk assessment by going through all current HIPAA Security Rule Standards along with the new “soon to be finalized” updates. 
I will instruct the listeners on how to write proper policies and procedures which are to be based upon the findings of the risk assessment and how to word the policies to satisfy the OCR or potential client requests (for business associates).

Who Should Attend:-

  • Practice managers
  • Any business associates who work with medical practices or hospitals (i.e. billing companies, transcription companies, IT companies, answering services, home health, coders, attorneys, etc)
  • MD’s and other medical professionals.

Select Training Options

Selected Total
$0

Plan Your Learning

with
Event Calender

Explore Calendar
Meet Your Expert
Brian L. Tuttle
Brian L. Tuttle

Brian L Tuttle is a Certified Professional in Health IT (CPHIT), Certified HIPAA Professional (CHP), Certified HIPAA Administrator (CHA), Certified Business Resilience Auditor (CBRA), Certified Information Systems Security Professional (CISSP) with over 17 years of experience in Health IT and Compliance Consulting.

With vast experience in health IT systems (i.e. practice management, EHR systems, imaging, transcription, medical messaging, etc.) as well as over 22 years of experience in standard Health IT with multiple certifications and hands-on knowledge, Brian serves as a compliance consultant and has conducted onsite and remote risk assessments for over 1000 medical practices, hospitals, health departments, insurance plans, and business associates throughout the United States.

In addition, Mr Tuttle has served in multiple litigated court cases serving as an expert witness offering input related to best practices and requirements for securing and providing patient access to protected health information. Mr. Tuttle has also worked directly with the Office of Civil Rights (OCR) both in defending covered entities and business associates as well as being asked by the Federal government to audit covered entities and business associates on behalf of the OCR.

Almost all of Brian’s clients are earned by referral with little or no advertising.

Brian is well known and highly regarded in medical circles throughout the United States for his quality work and down-home southern charm Mr Tuttle has a Master’s Degree in The Study of Law from the University of Georgia and operates nationally out of Swainsboro, GA.

//