Depending on the industry the company is in, and the geographies in which it does business, there are a variety of regulations a business must follow and be compliant with and most, if not all, have a technology component or impact. Typically, the Legal Department or legal representatives for the organization will determine which laws and regulations are applicable. From my perspective, it is important for IT leaders to work closely with the organization's legal representatives to determine which laws and regulations apply. Oftentimes, the organization's Board of Directors will require the use of 3rd party, or outside auditors, to determine what the organization needs to do to be compliant. I have hands-on experiencing in keeping organizations compliant with the regulations outlined below.
IT departments that handle electronic Protected Health Information (ePHI) must comply with several key requirements under the Health Insurance Portability and Accountability Act (HIPAA). These requirements are primarily outlined in the HIPAA Security Rule, which sets national standards for protecting ePHI.
By adhering to these requirements, IT departments can ensure the confidentiality, integrity, and availability of ePHI, thereby complying with HIPAA regulations.
As the Director of Technical Services for Longmont United Hospital, and then Vice President of Technical Operations for IMA Financial Group, I was responsible for ensuring their systems were HIPAA compliant and ePHI was secure.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that was adopted by the European Union (EU) became enforceable in 2018. The GDPR aims to enhance the protection of personal data and give individuals more control over how their data is collected, processed, and used. It applies to all organizations that process the personal data of EU residents, regardless of where the organization is located.
Key Principles of GDPR
In addition to keeping data secure and confidential, it's important to audit all of an organizations systems and databases to ensure compliance.
NYDFS Cybersecurity Regulation, also known as 23 NYCRR 500, establishes cybersecurity requirements for financial services companies operating in the state of New York. The regulation aims to protect customer information and the IT systems of regulated entities from cyber threats.
Key Requirements:
As IMA Financial Group was doing business in New York at the time the law went into effect, I was tasks with ensuring the company was compliant.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.