<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://connect.educause.edu" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>EDUCAUSE | EDUCAUSE CONNECT - EDUCAUSE Security Professionals Conference 2006.Summary: Implementing HIPAA Security Rule Training Program for Sys Admins at ECU - Comments</title>
 <link>http://connect.educause.edu/display/2279</link>
 <image>
    <title>EDUCAUSE CONNECT</title> 
    <link>http://connect.educause.edu/display/2279</link> 
    <url>http://connect.educause.edu/educause/images/e_rss.png</url> 
 </image>
 <description>Comments for &quot;EDUCAUSE Security Professionals Conference 2006.Summary: Implementing HIPAA Security Rule Training Program for Sys Admins at ECU&quot;</description>
 <language>en</language>

<item>
 <title>EDUCAUSE Security Professionals Conference 2006.Summary: Implementing HIPAA Security Rule Training Program for Sys Admins at ECU</title>
 <link>http://connect.educause.edu/display/2279</link>
 <description>&lt;span&gt;&lt;span&gt;&lt;div&gt;Implementing a HIPAA Security Rule Training Program for System Administrators at East Carolina University.&amp;nbsp;&amp;nbsp;&amp;nbsp; Carol Davis, DRP Coordinator, East Carolina University&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;This session walked us through the planning and implementation process that created a training program for systems administrators at ECU for the HIPAA Security Rule.&amp;nbsp; The program was added to a privacy program that already existed but was in need of revision.&amp;nbsp; A key resource was the SANS Press HIPAA Security Implementation book. &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Key questions for the planning process were&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;What is the training? &lt;/li&gt;&lt;li&gt;Who needs the training? &lt;/li&gt;&lt;li&gt;What are the overall project alternatives? &lt;/li&gt;&lt;li&gt;How will it be delivered? &lt;/li&gt;&lt;li&gt;What will the cost be? &lt;/li&gt;&lt;li&gt;What is the &amp;ldquo;completion&amp;rdquo; point? &lt;/li&gt;&lt;li&gt;How will effectiveness be measured? &lt;/li&gt;&lt;li&gt;How often must the training be taken? &lt;/li&gt;&lt;li&gt;Who will do the Public Relations on the project and what will be included? &lt;/li&gt;&lt;li&gt;Who will continue to update the training content and monitor? &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;The project was developed over three months using their HIPAA Committee as the key advisory group. &amp;nbsp;This committee developed the policies for the project.&amp;nbsp; &amp;nbsp;Time was spent on fully understanding the rule sets: the privacy rule, the transaction and code set rule, and the security rule.&amp;nbsp; Technical safeguards and related policies were to be included in the training. &amp;nbsp;Initial options considered included purchasing a full set of modules or customizing the training using Blackboard which was already an established resource.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Awareness training was to be included for all members of their health care workforce including management.&amp;nbsp; Visitors and students complete an abbreviated version of the training and students take a web-based quiz and take the results to their faculty.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The course objectives were:&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Familiarity with HIPAA and the security rule &lt;/li&gt;&lt;li&gt;Understanding rule sets &lt;/li&gt;&lt;li&gt;Understanding why both Privacy and Security rules are needed &lt;/li&gt;&lt;li&gt;Understanding how the rule applies to the trainee. &lt;/li&gt;&lt;li&gt;Understanding safeguards &lt;/li&gt;&lt;li&gt;Review of security policies &lt;/li&gt;&lt;li&gt;Understanding technical security awareness &lt;/li&gt;&lt;li&gt;Understanding individual responsibility for protecting health information &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The content was created in five sections:&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Overview and structure &lt;/li&gt;&lt;li&gt;Security rule principles &lt;/li&gt;&lt;li&gt;ITCS safeguards &lt;/li&gt;&lt;li&gt;Security awareness &lt;/li&gt;&lt;li&gt;Security incident notifications &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;A Blackboard course was populated &amp;amp; information on the program was distributed &lt;/div&gt;&lt;div&gt;Training guidelines were provided electronically and course deadlines were included&lt;/div&gt;&lt;div&gt;Management helped to ensure course completion.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Current knowledge was sampled by having administrators complete the quiz before the online training and again afterwards.&amp;nbsp; The specific training assessment is a quiz of 10 questions based on HIPAA privacy but concentrating on security specifics.&amp;nbsp; Instant feedback is provided for both correct and incorrect answers.&amp;nbsp; The training and quiz can be retaken to improve learning.&amp;nbsp; Certificates are awarded for 80% or better scores.&amp;nbsp; The certificates are popular and being hung on office walls and added to resumes.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Each person taking the training is asked to complete an evaluation survey that includes the question of the application of the training to their position and a blank field for additional comments.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The latest phase is to more fully utilize Blackboard with one training package that includes two modules and to incorporate student training into the system as well as reviewing role-based training opportunities.&amp;nbsp; HR is assisting in identifying new departments or individual positions that require compliancy or other special training.&amp;nbsp; And, of course, the training content is continually reviewed and revised when appropriate.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;HIPAA Security Rule Training &amp;ndash; &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS25/HIPAA%20Security%20Rule%20EDUCAUSE.ppt&quot;&gt;presentation slides&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;HIPAA System Admin Training Guidelines &amp;ndash; &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS25/Blackboard%20Guidelines%20-%20HIPAA%20System%20Admin%20Training.doc&quot;&gt;4 page document&lt;/a&gt; &amp;ndash; instructions for training program.&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;</description>
 <comments>http://connect.educause.edu/display/2279#comments</comments>
 <category domain="http://connect.educause.edu/tag/HIPAA/1678">HIPAA</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <category domain="http://connect.educause.edu/tag/Training/230">Training</category>
 <pubDate>Tue, 25 Apr 2006 14:31:00 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2279 at http://connect.educause.edu</guid>
</item>
</channel>
</rss>
