Artwork

Контент предоставлен Makala Barsolona and Britton Burton | Sr Director of Product Strategy. Весь контент подкастов, включая эпизоды, графику и описания подкастов, загружается и предоставляется непосредственно компанией Makala Barsolona and Britton Burton | Sr Director of Product Strategy или ее партнером по платформе подкастов. Если вы считаете, что кто-то использует вашу работу, защищенную авторским правом, без вашего разрешения, вы можете выполнить процедуру, описанную здесь https://ru.player.fm/legal.
Player FM - приложение для подкастов
Работайте офлайн с приложением Player FM !

Horror Stories: Why Third-Party Vendor Risk Management is So Scary

44:39
 
Поделиться
 

Manage episode 344607250 series 3052259
Контент предоставлен Makala Barsolona and Britton Burton | Sr Director of Product Strategy. Весь контент подкастов, включая эпизоды, графику и описания подкастов, загружается и предоставляется непосредственно компанией Makala Barsolona and Britton Burton | Sr Director of Product Strategy или ее партнером по платформе подкастов. Если вы считаете, что кто-то использует вашу работу, защищенную авторским правом, без вашего разрешения, вы можете выполнить процедуру, описанную здесь https://ru.player.fm/legal.

The last few years third-party vendor risk management (TPRM) has transitioned from being a relatively minor part of security and compliance programs for healthcare entities into a massive undertaking with potentially dire consequences if not managed properly. This is one of those topics that seems to really have CISOs shaking in their boots.

What makes third party vendor risk so scary? Why are security leaders having nightmares?

Join us for this episode of the CyberPHIx podcast where we hear from James Ballou, Chief Information Security Officer for North American Partners of Anesthesia.

James shares insights from his extensive experience managing security teams and third-party risk management programs for leading healthcare organizations.

Topics covered in this session include:

  • What makes third-party vendor risk management so scary for healthcare cybersecurity and risk professionals?
  • Regulatory requirements related to third-party vendor risk management including HIPAA and state laws
  • OCR enforcement of third-party business associate compliance mandates
  • Third-party vendor risk governance best practices and models
  • The implications for vendors that acquire certifications including HITRUST, SOC 2, and ISO
  • The limitations of questionnaire-based vendor assessment models
  • Best practices for strategic and operational management of third-party vendor risk management programs in healthcare
  • The future of third-party vendor risk management
  continue reading

99 эпизодов

Artwork
iconПоделиться
 
Manage episode 344607250 series 3052259
Контент предоставлен Makala Barsolona and Britton Burton | Sr Director of Product Strategy. Весь контент подкастов, включая эпизоды, графику и описания подкастов, загружается и предоставляется непосредственно компанией Makala Barsolona and Britton Burton | Sr Director of Product Strategy или ее партнером по платформе подкастов. Если вы считаете, что кто-то использует вашу работу, защищенную авторским правом, без вашего разрешения, вы можете выполнить процедуру, описанную здесь https://ru.player.fm/legal.

The last few years third-party vendor risk management (TPRM) has transitioned from being a relatively minor part of security and compliance programs for healthcare entities into a massive undertaking with potentially dire consequences if not managed properly. This is one of those topics that seems to really have CISOs shaking in their boots.

What makes third party vendor risk so scary? Why are security leaders having nightmares?

Join us for this episode of the CyberPHIx podcast where we hear from James Ballou, Chief Information Security Officer for North American Partners of Anesthesia.

James shares insights from his extensive experience managing security teams and third-party risk management programs for leading healthcare organizations.

Topics covered in this session include:

  • What makes third-party vendor risk management so scary for healthcare cybersecurity and risk professionals?
  • Regulatory requirements related to third-party vendor risk management including HIPAA and state laws
  • OCR enforcement of third-party business associate compliance mandates
  • Third-party vendor risk governance best practices and models
  • The implications for vendors that acquire certifications including HITRUST, SOC 2, and ISO
  • The limitations of questionnaire-based vendor assessment models
  • Best practices for strategic and operational management of third-party vendor risk management programs in healthcare
  • The future of third-party vendor risk management
  continue reading

99 эпизодов

Усі епізоди

×
 
Loading …

Добро пожаловать в Player FM!

Player FM сканирует Интернет в поисках высококачественных подкастов, чтобы вы могли наслаждаться ими прямо сейчас. Это лучшее приложение для подкастов, которое работает на Android, iPhone и веб-странице. Зарегистрируйтесь, чтобы синхронизировать подписки на разных устройствах.

 

Краткое руководство