Policies, training, and access decisions
How you manage risk and guide your team.- Formal HIPAA risk assessments and risk management plans.
- Security policies, procedures, and incident response plans.
- Workforce security and background checks where appropriate.
- Role-based access to systems that contain ePHI.
- Ongoing security awareness training and phishing education.