Blog
Assignment: Technical Safeguards Audit
This week you will conduct the second desk audit for your security plan involving technical safeguards. You will conduct your audit using the Security Risk Assessment (SRA) Tool, which was developed by the federal government to assist health care organizations in meeting privacy and security regulations. As you recall from Module 2 (please refer to order E-200306132502), there are web-based tools for conducting these audits, which you will find useful in a real-world scenario. However, for this course, we will use the paper-based, document version of the tool. The technical safeguards audit focuses on access controls, audit controls, integrity, person or entity authentication, and transmission security. To conduct your technical safeguards desk audit, you will need to start by reading the case study below that began in Module 2 (please refer to order E-200306132502). You may need to ask your instructor for further clarification or additional information to augment the case study (let me know if you have any additional questions, I will email the professor your questions). Read the directions contained in the Technical Safeguards Audit tool below and be sure to use the calculated risk score matrix provided. Include a brief narrative (explanation) of how to remediate any technical safeguard deficiencies where applicable. Follow the steps below to complete this assignment: 1. Review the information provided in the Case Study (attached). 2. Complete the Technical Safeguards Security Risk Assessment (SRA) Tool (attached) based on the information from the case study. Use the optional document, Security Standards: Technical Safeguards (attached) from the Centers for Medicare and Medicaid Services as a resource to help you as you conduct your technical security audit. Make sure you address all areas of the Technical Safeguards SRA Tool accurately based on the information provided in the case study. Please review the Scoring Rubric (attached) to understand how your work will be assessed.
