Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

A risk assessment will be performed every two years year with coordination of the NCSA Security Office and the NCSA HIPAA liaisonLiaison. Exceptions to this include (i) substantial infrastructure/environment changes that would require a new impact analysis and (ii) a security incident that warrants reevaluation of risks.

...

  1. A risk assessment performed.
  2. Findings are submitted to the NCSA Security Office within 30 days, and the Security Office forwards it to the HIPAA liaisonLiaison.
  3. The NCSA Security Office works with the project(s) to remediate vulnerabilities and mitigate risks within 90 days of finishing the assessment. If this is not possible for all risks, an exemption must be requested in writing to the Security Office and HIPAA liaisonLiaison.
  4. Remediation activities are documented in a remediation plan.
  5. The remediation plan is sent to the Security Office, who sends it to the HIPAA liaisonLiaison.

Privacy

All data from the risk assessment is kept confidential and not shared without written approval from the NCSA Security Office and HIPAA liaisonLiaison.

Consequences

Violations can result in disciplinary action as described in the University of Illinois HIPAA policies.