A Framework for Evaluation of Risk Management Models for HIPAA Compliance for Electronic Personal Health Information used by Small and Medium Businesses using Cloud Technologies

dc.access.optionOpen Access
dc.contributor.advisorLesko, Charles J. Jr.
dc.contributor.authorLuna, Raymond Brett
dc.contributor.departmentTechnology Systems
dc.date.accessioned2018-08-14T14:19:51Z
dc.date.available2018-08-14T14:19:51Z
dc.date.created2018-08
dc.date.issued2018-07-18
dc.date.submittedAugust 2018
dc.date.updated2018-08-09T20:00:17Z
dc.degree.departmentTechnology Systems
dc.degree.disciplineMS-Network Technology
dc.degree.grantorEast Carolina University
dc.degree.levelMasters
dc.degree.nameM.S.
dc.description.abstractOur societal quest for collaboration and openness has always been in direct conflict with our desire to maintain our personal privacy. Those conflicting goals are more prominent than ever for healthcare, due to its rapid Digital Transformation and coupled with risk related to the exploitation of Protected Health Information (PHI) that is processed on cloud-based technologies by healthcare Small and Midsize Businesses (SMB). Healthcare SMBs are at higher risk because they often have limited resources to identify and assess risk. This study focused on this issue through an exploratory inquiry using survey statistics, scholarly research, regulatory requirements, and best practices to develop a framework that can be used by healthcare SMBs to evaluate and select a risk assessment model. As illustrated in this study, the selected model can be leveraged to identify and assess risk associated with PHI that is processed in the cloud. This study included four key phases: confirmation of risk for PHI in the cloud, an investigation of HIPAA requirements and best practices for risk assessment, an evaluation of risk assessment models, and a risk assessment model selection process. As a result, healthcare SMB entities with limited resources can improve their ability to achieve HIPAA compliance through risk assessment and contribute to improvements for the overall patient care experience.
dc.format.mimetypeapplication/pdf
dc.identifier.urihttp://hdl.handle.net/10342/6940
dc.language.isoen
dc.publisherEast Carolina University
dc.subjectBusiness Associates
dc.subjectCovered Entities
dc.subjectData Breach
dc.subjectDefense in Depth (DiD)
dc.subjectElectronic Protected Health Information (ePHI)
dc.subjectHealthcare Stakeholders
dc.subjectHIPAA
dc.subjectHIPAA Privacy Rule
dc.subjectHIPAA Security Rule
dc.subjectInternet of Things (IoT)
dc.subjectProtected Health Information (PHI)
dc.subjectRisk Analysis
dc.subjectRisk Factor
dc.subjectRisk Management
dc.subjectSmall and Midsize Business (SMB)
dc.subjectSMBE&A
dc.subject.lcshComputer security
dc.subject.lcshCloud computing
dc.subject.lcshRisk assessment
dc.subject.lcshSmall business--Information technology
dc.titleA Framework for Evaluation of Risk Management Models for HIPAA Compliance for Electronic Personal Health Information used by Small and Medium Businesses using Cloud Technologies
dc.typeMaster's Thesis
dc.type.materialtext

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
LUNA-MASTERSTHESIS-2018.pdf
Size:
4.51 MB
Format:
Adobe Portable Document Format