AGENDA: DAY II
WEDNESDAY, MARCH 28, 2018
7:00 am
Registration Open; Networking Breakfast
MORNING PLENARY SESSION — HIPAA SECURITY
8:00 am
Welcome and Introductions
John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Co-Chair)
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Co-Chair)
John Parmigiani is President of John C Parmigiani & Associates, LLC. His current primary interest is on helping healthcare organizations become compliant with healthcare regulations, in particular HIPAA and HITECH revisions, and move toward e-health. He has worked with wide range of healthcare organizations and clients, including hospitals, physicians, suppliers, academic medical centers, health plans, labs, retail pharmacies, business associates, software developers, practice management system developers, billing companies, and transcription service companies providing risk and compliance assessments, program design, training, expert witness services, etc. He has over 40 years experience in information systems in both the private and public sectors in various executive and management positions. More information regarding his extensive list of presentations, publications, and affiliations as well as his credentials is available at www.johnparmigiani.com.
8:15 am
Health Privacy and Security: Challenges Behind Us and Challenges Ahead
Richard Campanelli, JD
Lecturer, Batten School of Leadership & Public Policy, University of Virginia, Former Counselor to the Secretary, Science & Public Health, HHS, Former Director, Office for Civil Rights, HHS, Washington, DC
Lecturer, Batten School of Leadership & Public Policy, University of Virginia, Former Counselor to the Secretary, Science & Public Health, HHS, Former Director, Office for Civil Rights, HHS, Washington, DC
Richard (“Rick”) Campanelli teaches Ethics & Public Policy at the University of Virginia’s Frank S. Batten School of Leadership & Public Policy, and consults on ethical issues arising from disruptive advances in genetic research. Previously, he was a trial attorney for the US Department of Justice (DOJ) Civil Rights Division, served as US State Department Legal Counsel to the South Africa Working Group, and as Senior Special Assistant to the Attorney General for the DOJ where he was responsible for final review and Attorney General approval of Foreign Intelligence Surveillance (FISA) applications. After leaving DOJ Rick entered private law practice, serving as general counsel to national and international not-for-profit organizations. Prior to this Rick was Director of the Office for Civil Rights (OCR) and Counselor to the Secretary at the US Department of Health & Human Services and Director for Health & Human Services at Lockheed Martin.
8:45 a.m.
Physician Awareness of and Preparedness for HIPAA Compliance and Cybersecurity
Laura G. Hoffman, JD
Assistant Director of Federal Affairs, American Medical Association, Washington, DC
Assistant Director of Federal Affairs, American Medical Association, Washington, DC
Laura G. Hoffman is the Assistant Director of Federal Affairs for the American Medical Association in Washington, D.C. In this capacity, she develops advocacy and policy strategy while engaging with federal agencies on health information technology matters, the Quality Payment Program, HIPAA privacy and security, and cybersecurity. Prior to her work with the AMA, Laura was an associate in the health care practice group of a Washington DC law firm, providing counsel to federal grantees such as federally qualified health centers, Title X programs, and community behavioral health organizations. Laura is also a member of the Practitioner Faculty at Loyola University Chicago’s School of Law, where she teaches a course on Health Care Regulation and Policy.
9:15 a.m.
Healthcare Chief Security Officers Best Practices Roundtable
Bob Chaput, CISSP, HCISPP, CRISC, CIPP/US
Chief Executive Officer, Clearwater Compliance; Former Vice President, Technology Operations, GE Information Services, Nashville, TN
Chief Executive Officer, Clearwater Compliance; Former Vice President, Technology Operations, GE Information Services, Nashville, TN
Bob Chaput is one of the healthcare cyber risk management industry’s most innovative leaders, accelerating cyber risk management best practices in a more reproducible and efficient way. Chaput’s risk management analyses and insights are frequently featured in the country’s top healthcare and cybersecurity publications, industry association journals and popular news sources. Chaput works with hospitals and health systems of all sizes, including over 40 of the top Integrated Delivery Networks in the country. Under Chaput’s direction, Clearwater helps healthcare organizations identify and understand their risks in an efficient, effective and granular manner. The results not only help defend against current cyber threats but also positions organizations to build capabilities for self-sufficiency to defend against future cyber threats. Most recently, under his leadership, Clearwater was designated as Best in KLAS for 2018 for Cybersecurity Advisory Services for their SaaS-based software, OCR-quality solutions and professional services.
David W. Loewy, PhD
Information Security Officer, SUNY Downstate Medical Center; Former HIPAA Privacy and Security SME and Program Manager, CNA Insurance, Brooklyn, NY
Information Security Officer, SUNY Downstate Medical Center; Former HIPAA Privacy and Security SME and Program Manager, CNA Insurance, Brooklyn, NY
David Loewy is the Chief Information Security Officer at SUNY Downstate Medical Center with experience Regulatory, IT Risk Management and IT Security Policies. Previously, he was HIPAA Privacy & Security SME & Program Manager at Cleardata and MedCPU and CNA Insurance and ICD-10 Program Director at Hartford HealthCare. He was also ICD-10 Program Director for Hartford HealthCare.
Dr. Loewy is on the Board of Directors for Cape Fear Group Homes. He has earned PhDs in Computer Science and International Business and is a Certified Project Director with over 15 years professional experience in the healthcare industry. Dr. Loewy is a subject matter expert on HIPAA, Meaningful Use and ICD-10 (US, EC & Asia)
Dr. Loewy is on the Board of Directors for Cape Fear Group Homes. He has earned PhDs in Computer Science and International Business and is a Certified Project Director with over 15 years professional experience in the healthcare industry. Dr. Loewy is a subject matter expert on HIPAA, Meaningful Use and ICD-10 (US, EC & Asia)
Dave Summitt, MS
Chief Information Security Officer, Moffitt Cancer Center; Former CISO, UAB Health System; IT & Network Security and HIPAA Security Officer, Bayfront Health, Tampa, FL
Chief Information Security Officer, Moffitt Cancer Center; Former CISO, UAB Health System; IT & Network Security and HIPAA Security Officer, Bayfront Health, Tampa, FL
Dave is the Chief Information Security officer and Director of Cyber Security Operations at the H. Lee Moffitt Cancer Center and Research Institute in Tampa, Florida. With nearly 30 years of experience in information technology, his experience spans across federal and private sectors. Prior to Moffitt, Dave held the Chief Information Security Officer role with the University of Alabama at Birmingham Health System and Manager of Information Security at Bayfront Medical Center in St. Petersburg. Before entering the healthcare sector, he had a 21 year career with the DoD holding roles that included a Technical Representative for a major missile defense program, security data custodian and Information Systems Security Officer.
John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Moderator)
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Moderator)
John Parmigiani is President of John C Parmigiani & Associates, LLC. His current primary interest is on helping healthcare organizations become compliant with healthcare regulations, in particular HIPAA and HITECH revisions, and move toward e-health. He has worked with wide range of healthcare organizations and clients, including hospitals, physicians, suppliers, academic medical centers, health plans, labs, retail pharmacies, business associates, software developers, practice management system developers, billing companies, and transcription service companies providing risk and compliance assessments, program design, training, expert witness services, etc. He has over 40 years experience in information systems in both the private and public sectors in various executive and management positions. More information regarding his extensive list of presentations, publications, and affiliations as well as his credentials is available at www.johnparmigiani.com.
10:45 a.m.
Break
MINI SUMMIT GROUP I: 11:15 am – 12:15 pm
Mini Summit I: Code Blue Clear: How One Hospital Survived the Largest Ransomware Attack in History & The Social Determinants of Health: The Next HIPAA Frontier
11:15 am
Code Blue Clear: How One Hospital Survived the Largest Ransomware Attack in History
Reg Harnish, CISA, CISM, CISSP
Chief Executive Officer, GreyCastle Security, New York, NY
Chief Executive Officer, GreyCastle Security, New York, NY
Reg Harnish is the CEO of GreyCastle Security, a leading cybersecurity risk assessment, advisory and mitigation firm headquartered in Troy, New York.
As CEO of GreyCastle, Reg is responsible for defining and executing the company’s vision. Under his leadership, the company has experienced six consecutive years of triple-digit growth and countless industry accolades. Today, GreyCastle Security is working with organizations in nearly every state in the U.S.
Reg is a nationally-recognized speaker and has presented at countless industry events. He was recently recognized as the 2017 Cybersecurity Consultant of the Year by the Cybersecurity Excellence Awards and he has been featured in Time, Forbes, CBS Nightly News, The Washington Post, Dark Reading and others.
Reg is a member of the Forbes Technology Council and a fellow of the National Cybersecurity Institute in Washington, DC.
As CEO of GreyCastle, Reg is responsible for defining and executing the company’s vision. Under his leadership, the company has experienced six consecutive years of triple-digit growth and countless industry accolades. Today, GreyCastle Security is working with organizations in nearly every state in the U.S.
Reg is a nationally-recognized speaker and has presented at countless industry events. He was recently recognized as the 2017 Cybersecurity Consultant of the Year by the Cybersecurity Excellence Awards and he has been featured in Time, Forbes, CBS Nightly News, The Washington Post, Dark Reading and others.
Reg is a member of the Forbes Technology Council and a fellow of the National Cybersecurity Institute in Washington, DC.
11:45 am
The Social Determinants of Health: The Next HIPAA Frontier
Jana Aagaard, MA, JD
Senior Counsel, Privacy/Health Information Technology, Dignity Health; Former Counsel, Sharp HealthCare, Sacramento, CA
Senior Counsel, Privacy/Health Information Technology, Dignity Health; Former Counsel, Sharp HealthCare, Sacramento, CA
Jana Aagaard is specializes in health care law, with emphases in health information privacy and technology and clinical research. Since 2002, she has worked for Dignity Health (formerly named Catholic Healthcare West) both as in-house counsel and of counsel. Dignity Health is the largest nonprofit health system in the western United States, with 39 hospitals in California, Arizona and Nevada. Ms. Aagaard is currently the lead attorney at Dignity Health for all health privacy issues; she advises Dignity Health on all aspects of state and federal health information privacy compliance requirements, health information exchange, the federal Electronic Health Record Incentive Program (“Meaningful Use”) and emerging health technologies.
Ms. Aagaard was an associate at Luce, Forward, Hamilton & Scripps in San Diego, CA before becoming in-house counsel at Sharp Healthcare (San Diego) in 1999.
Ms. Aagaard was an associate at Luce, Forward, Hamilton & Scripps in San Diego, CA before becoming in-house counsel at Sharp Healthcare (San Diego) in 1999.
Gayland Hethcoat, II, JD, LLM
Corporate Counsel, Dignity Health, Sacramento, CA
Corporate Counsel, Dignity Health, Sacramento, CA
Gayland Hethcoat is the Corporate Counsel – Operations at Dignity Health. Prior to joining Dignity Health, he was a Healthcare Associate with Barnes & Thornburg LLP. His past experience also includes an externship with McDermott Will & Emery and a judicial internship for the Honorable Leslie B. Rothenberg on the Florida Third District Court of Appeal.
Mini Summit II: Securing Medical Devices and the IoT in Healthcare
11:15 am
Welcome, Introductions, Presentations and Q&A
Aftin Ross, PhD
Senior Health Advisor/Senior Project Manager, Staff Fellow, Food and Drug Administration, Washington, DC
Senior Health Advisor/Senior Project Manager, Staff Fellow, Food and Drug Administration, Washington, DC
Aftin Ross is a senior science health advisor/senior project manager in the Emergency Preparedness/Operations and Medical Countermeasures program at the FDA’s Center for Devices and Radiological Health (CDRH). In this role, she leads cross-disciplinary projects related to preparedness including medical device cybersecurity, respiratory protective devices, personal protective equipment, and incident response. Specifically, she has been a lead in CDRH’s medical device cybersecurity efforts spearheading the execution of two FDA public workshops, serving on various interagency cybersecurity work groups, managing CDRH’s MITRE cybersecurity contract, and engaging in policy development as a member of the CDRH cybersecurity workgroup. In June 2016, she completed the National Preparedness Leadership Initiative, an executive education program in the Harvard School of Public Health and Kennedy School of Government.
Dana-Megan Rossi
Senior Manager, Product Security Policy & Strategy, Becton Dickinson, Former Senior Staff Product Security Leader, Product Security Incident Response Team (PSIRT), General Electric, Washington, DC
Senior Manager, Product Security Policy & Strategy, Becton Dickinson, Former Senior Staff Product Security Leader, Product Security Incident Response Team (PSIRT), General Electric, Washington, DC
Dana-Megan Rossi leads the Product Security Policy & Strategy program at Becton Dickinson. Her work focuses on strategic cyber initiatives, partnerships and intelligence to enhance the security of product to customers by design, in use and through partnership. Ms. Rossi previously served as the Product Security Officer for Technology Solutions and Digital Health at BD. Before joining BD, Ms. Rossi managed the product cybersecurity incident response program at GE. In this role, Ms. Rossi led incident response coordination and preparedness, including PSIRT and crisis-level cybersecurity response plans and processes, drafted and led tabletop exercises, and coordinated multi-stakeholder security responses. Prior to GE, Ms. Rossi created and led a cybersecurity law & policy forum for in-house counsel, bridging the gap between legal counsel and IT professionals in security preparedness. Ms. Rossi currently serves as the Health Care and Public Health Sector Chief for InfraGard’s National Capital Region and is a member of the national Cyber Health Working Group.
Sheetal Sood, CHC, CIPP, CISSP, CISA, CRISC, GSEC, MCSE
Senior Executive Compliance Officer, Information Governance, NYC Health + Hospitals, Former Chief Privacy Officer and IT Audit Manager, New York City Housing Authority, New York, NY
Senior Executive Compliance Officer, Information Governance, NYC Health + Hospitals, Former Chief Privacy Officer and IT Audit Manager, New York City Housing Authority, New York, NY
Sheetal is an information security leader with expertise in information security management, IT risk governance and management, cyber-security tools and techniques, audit and investigation of physical and information systems and networks, business continuity, security awareness education and metrics, data privacy and compliance.
Certified in Information Privacy, Information Systems Audit, Security and Risk Management and Healthcare Compliance (CIPP/US, CISA, CISSP, CRISC, GIAC GSEC and CHC), Sheetal also has numerous product-specific certifications. including expertise in NIST risk management, COBiT information assurance and HITRUST frameworks.
Certified in Information Privacy, Information Systems Audit, Security and Risk Management and Healthcare Compliance (CIPP/US, CISA, CISSP, CRISC, GIAC GSEC and CHC), Sheetal also has numerous product-specific certifications. including expertise in NIST risk management, COBiT information assurance and HITRUST frameworks.
Sue Wang, MS
Technical Lead of the Healthcare Sector Team, National Cybersecurity FFRDC (MITRE), National Cybersecurity Center of Excellence (NCCoE) at NIST, Rockville, MD
Technical Lead of the Healthcare Sector Team, National Cybersecurity FFRDC (MITRE), National Cybersecurity Center of Excellence (NCCoE) at NIST, Rockville, MD
Sue Wang is a Technical Lead of the Healthcare Sector Team in the National Cybersecurity FFRDC, National Cybersecurity Center of Excellence (NCCoE) at NIST. She has more than 25 years of experience in System Development Life Cycle (SDLC) and project management including architecture design, development, implementation, quality control, and web application systems. She is a subject matter expert in information system interoperability, software assurance, secure programming, static analysis, and software weaknesses and vulnerability research.
At the NCCoE, she supports the healthcare sector lead in the overall technical direction of healthcare-related projects, designing and building reference solutions including securing wireless infusion pumps and electronic health records on mobile devices. She is also instrumental in defining future projects.
At the NCCoE, she supports the healthcare sector lead in the overall technical direction of healthcare-related projects, designing and building reference solutions including securing wireless infusion pumps and electronic health records on mobile devices. She is also instrumental in defining future projects.
Bob Chaput, CISSP, HCISPP, CRISC, CIPP/US
Chief Executive Officer, Clearwater Compliance, Former Vice President, Technology Operations, GE Information Services, Nashville, TN (Moderator)
Chief Executive Officer, Clearwater Compliance, Former Vice President, Technology Operations, GE Information Services, Nashville, TN (Moderator)
Bob Chaput is one of the healthcare cyber risk management industry’s most innovative leaders, accelerating cyber risk management best practices in a more reproducible and efficient way. Chaput’s risk management analyses and insights are frequently featured in the country’s top healthcare and cybersecurity publications, industry association journals and popular news sources. Chaput works with hospitals and health systems of all sizes, including over 40 of the top Integrated Delivery Networks in the country. Under Chaput’s direction, Clearwater helps healthcare organizations identify and understand their risks in an efficient, effective and granular manner. The results not only help defend against current cyber threats but also positions organizations to build capabilities for self-sufficiency to defend against future cyber threats. Most recently, under his leadership, Clearwater was designated as Best in KLAS for 2018 for Cybersecurity Advisory Services for their SaaS-based software, OCR-quality solutions and professional services.
12:15 pm
Networking Luncheon and Presentations
MINI SUMMITS GROUP II: 12:30 pm – 1:30 pm
Mini Summit III: Why a HIPAA Security Analysis Is Not Enough & Asymmetric Attacks Mandate Credible Cybersecurity Program: A Blueprint
12:30 pm
Why a HIPAA Security Analysis Is Not Enough
David W. Loewy, PhD
Information Security Officer, SUNY Downstate Medical Center; Former HIPAA Privacy, Security SME and Program Manager, CNA, Brooklyn, NY
Information Security Officer, SUNY Downstate Medical Center; Former HIPAA Privacy, Security SME and Program Manager, CNA, Brooklyn, NY
David Loewy is the Chief Information Security Officer at SUNY Downstate Medical Center with experience Regulatory, IT Risk Management and IT Security Policies. Previously, he was HIPAA Privacy & Security SME & Program Manager at Cleardata and MedCPU and CNA Insurance and ICD-10 Program Director at Hartford HealthCare. He was also ICD-10 Program Director for Hartford HealthCare.
Dr. Loewy is on the Board of Directors for Cape Fear Group Homes. He has earned PhDs in Computer Science and International Business and is a Certified Project Director with over 15 years professional experience in the healthcare industry. Dr. Loewy is a subject matter expert on HIPAA, Meaningful Use and ICD-10 (US, EC & Asia)
Dr. Loewy is on the Board of Directors for Cape Fear Group Homes. He has earned PhDs in Computer Science and International Business and is a Certified Project Director with over 15 years professional experience in the healthcare industry. Dr. Loewy is a subject matter expert on HIPAA, Meaningful Use and ICD-10 (US, EC & Asia)
1:00 pm
Asymmetric Attacks Mandate Credible Cybersecurity Program: A Blueprint
Uday O. Ali Pabrai, MSEE, CISSP
Chief Executive and Co-Founder, ecfirst (Home of HIPAA Academy), Irvine, CA
Chief Executive and Co-Founder, ecfirst (Home of HIPAA Academy), Irvine, CA
Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP), Security +, CCSFP, is the CEO of ecfirst. A highly sought after information security and regulatory compliance expert, he has successfully delivered solutions on compliance and information security to organizations worldwide. Mr. Pabrai has presented opening keynote and other sessions at several conferences, including ISACA, ISSA, FBI InfraGard, HIMSS, HCFA, HIPAA Summit, Microsoft Tech Forum, NASEBA Healthcare Congress (Middle East), Kingdom Healthcare (Saudia Arabia), Internet World, DCI Expo, Comdex, Net Secure, Nurse Practitioners Conference, National Council for Prescription Drug Programs (NCPDP), National Council for State Board of Nursing IT Conference, and many others.
Mini Summit IV: Vendor Management — a HIPAA Perspective & Taming the Wild West: Application Risk Assessments
12:30 pm
Vendor Management — a HIPAA Perspective
Thomas Miller, MA, LPC, ALPS, ADC
Privacy and Security Officer, West Virginia Department of Administration, Charleston, WV
Privacy and Security Officer, West Virginia Department of Administration, Charleston, WV
Tom Miller has over 20 years of experience in compliance program design, implementation and management. He has served as the Privacy and/or Security Officer for several public and private organizations. Tom has performed risk, threat, and vulnerability assessments and consultation for government and private entities across the nation and has developed response and mitigation plans to mitigate identified issues. He has served as the Privacy & Security Officer for the WV Department of Administration since early 2011 and has responsibilities over the regulatory compliance of the fifteen agencies within the Department including, but not limited to: the West Virginia Public Employees Insurance Agency, the WV Division of Personnel, the WV Consolidated Public Retirement Board, the WV Office of Technology, the WV Division of Finance, and the WV Public Employees Grievance Board. Tom has presented at numerous conferences and has taught on the undergraduate and graduate levels.
1:00 pm
Data Security: Taming the Wild West: Application Risk Assessments
Cliff Baker
Chief Executive Officer, CORL Technologies, Managing Partner, Meditology Services, Chamblee, GA
Chief Executive Officer, CORL Technologies, Managing Partner, Meditology Services, Chamblee, GA
Cliff Baker is an industry leader in healthcare information technology, privacy and security, and has over 20 years of industry experience. In his dedication to the industry and passion to tackle many of its most challenging risks, Cliff has created solutions that are leveraged and used by organizations across the nation. He is the founder and CEO of two successful companies that provide information protection services to healthcare organizations including many of the nation’s leading provider, payer and business associate organizations. Cliff also led the creation the HITRUST framework, which is the most broadly adopted healthcare security and privacy framework in the industry. Cliff started his career with PricewaterhouseCoopers where he established and lead the firm’s first dedicated healthcare care security practice.
Tracy J. Griffin
Director, Information Security Risk and Compliance Manager, Bon Secours Health Systems, Richmond, VA
Director, Information Security Risk and Compliance Manager, Bon Secours Health Systems, Richmond, VA
Tracy J. Griffin is a subject matter expert in healthcare compliance; specializing in privacy, security and information security risk management. Tracy has spent over 15 years working for multi facility healthcare systems. During her career, she has had the opportunity to serve in various leadership positions, be a founding leader of a new hospital and served as a subject matter expert in HIPAA compliance. Over the course of the past 7 years, serving as the Enterprise Director of Information Security Risk Management, Tracy has designed and implemented HIPAA auditing and Information Risk Management programs. She has a passion for ensuring that all emerging technologies that serve the organization’s patients are secure and compliant.
AFTERNOON MINI SUMMITS: GROUP III 1:30 pm – 2:30 pm
Mini Summit V: Closing the Deal: Addressing HIPAA Issues from Both Sides of the Transaction & HIPAA and the Telephone Consumer Protection Act
1:30 pm
Closing the Deal: Addressing HIPAA Issues from Both Sides of the Transaction
Alessandra V. Swanson, JD
Associate, Winston & Strawn LLP; Former SEOS/Team Leader, Office for Civil Rights, US Department of Health and Human Services, Chicago, IL
Associate, Winston & Strawn LLP; Former SEOS/Team Leader, Office for Civil Rights, US Department of Health and Human Services, Chicago, IL
Alessandra Swanson is an Associate in Winston & Strawn LLP’s Chicago office. Ms. Swanson regularly counsels clients on all aspects of HIPAA compliance. She offers practical, business-focused advice for covered entities and business associates in a broad spectrum of industries to help them understand and meet their obligations under HIPAA. Prior to joining Winston, Alessandra spent five years with the U.S. Department of Health and Human Services–Office for Civil Rights (HHS-OCR). During her tenure with HHS-OCR, she was involved with a number of high-profile investigations and settlements.
Alessandra also dedicates a significant portion of her practice to providing advice on a range of other privacy, marketing, advertising, and intellectual property issues, with an emphasis on matters that implicate the collection, use, protection, and cross-border transfer of consumer information. Alessandra’s experience further extends to providing advice on software and mobile application development matters, end-user licenses, application service provider agreements, and software licensing matters.
Alessandra also dedicates a significant portion of her practice to providing advice on a range of other privacy, marketing, advertising, and intellectual property issues, with an emphasis on matters that implicate the collection, use, protection, and cross-border transfer of consumer information. Alessandra’s experience further extends to providing advice on software and mobile application development matters, end-user licenses, application service provider agreements, and software licensing matters.
2:00 pm
HIPAA and the Telephone Consumer Protection Act: What Risks Loom in Contacting Patients by Phone and Text Messages?
Tina Grande, MHS
Senior Vice President, Policy and Chair, Confidentiality Coalition, Healthcare Leadership Counsel, Washington, DC
Senior Vice President, Policy and Chair, Confidentiality Coalition, Healthcare Leadership Counsel, Washington, DC
Tina Olson Grande is Senior Vice President for Policy for the Healthcare Leadership Council (HLC), a coalition of chief executives of the nation’s leading healthcare companies and organizations. HLC advocates for consumer-centered health reform, emphasizing the value of private sector innovation. She is also Chair of the Confidentiality Coalition. Ms. Grande was asked back to HLC after a previous time at HLC as Policy Director in the late 1990s.
Prior to leading HLC’s policy efforts, Ms. Grande was Health Policy Director for Arnold & Porter LLP. Ms. Grande was founder of the Medicare Advisory Group, Inc.
Ms. Grande launched her career in health policy working in the U.S. Senate for Senator David Durenberger (R-MN). She was also a researcher for the Health Care Advisory Board, health policy analyst for Patton Boggs LLP, and research director at the Institute for the Future in California.
Prior to leading HLC’s policy efforts, Ms. Grande was Health Policy Director for Arnold & Porter LLP. Ms. Grande was founder of the Medicare Advisory Group, Inc.
Ms. Grande launched her career in health policy working in the U.S. Senate for Senator David Durenberger (R-MN). She was also a researcher for the Health Care Advisory Board, health policy analyst for Patton Boggs LLP, and research director at the Institute for the Future in California.
Nancy L. Perkins, MPP, JD
Counsel, Arnold & Porter Kaye Scholer LLP, Washington, DC
Counsel, Arnold & Porter Kaye Scholer LLP, Washington, DC
Nancy Perkins, of Arnold & Porter LLP, advises clients on federal, state, and global data privacy law, particularly HIPAA and the HITECH Act. Nancy also assists clients on data security issues raised by mobile applications and other emerging technologies, and in responding to data security breaches. A graduate of Harvard Law School and Harvard’s Kennedy School of Government, Ms. Perkins is the author of numerous articles on data privacy and security, is an Adviser on the American Law Institute’s forthcoming Principles of the Law, Data Privacy, and has been ranked for Privacy & Data Security by Chambers USA since 2009.
Mini Summit VI: Record Retention — A Security Issue that is NOT Being Addressed & The Rise of Ransomware: Best Practices for Preventing Ransomware
1:30 pm
Record Retention — A Security Issue that is NOT Being Addressed
Katherine E. Downing, MA, RHIA, CHPS, PMP
Vice President, Information Governance, Informatics Standards, AHIMA, Richmond, TX
Vice President, Information Governance, Informatics Standards, AHIMA, Richmond, TX
Katherine Downing is AHIMA’s Vice President Information Governance, Informatics and Standards. She has over 20 years of healthcare experience as a consultant, Director, Privacy Officer, Project Manager, and IT System Analyst. As a Director of Patient Health Information Protection at a hospital systems’ corporate office she led the creation of the Privacy Program for over 300 hospitals, surgery centers, and physician practices including training over 1000 privacy officers. She has expertise in Electronic Health Records and has worked with numerous sites during implementations and is a certified Project Management Professional (PMP).
Ms. Downing is an established speaker on diverse healthcare topics and an active author on information governance, security, privacy and legal health records. She is also an adjunct faculty member for the University of Cincinnati.
Ms. Downing is an established speaker on diverse healthcare topics and an active author on information governance, security, privacy and legal health records. She is also an adjunct faculty member for the University of Cincinnati.
2:00 pm
The Rise of Ransomware: Best Practices for Preventing Ransomware
Joseph Kirkpatrick, CISSP, CISA, CGEIT, and CRISC
Managing Partner, KirkpatrickPrice, Tampa, FL
Managing Partner, KirkpatrickPrice, Tampa, FL
Joseph Kirkpatrick is the Managing Partner at KirkpatrickPrice and holds the CISSP, CISA, CGEIT, CRISC, and QSA certifications, specializing in data security, IT governance, and regulatory compliance. He enjoys helping clients and stakeholders by navigating them through the complex maze of compliance and regulatory requirements.
2:30 p.m.
Break
AFTERNOON PLENARY SESSION — HIPAA, HITECH AND HEALTH REFORM
3:00 p.m.
Introductions and The Path Towards a New and Complete Consumer Health Privacy and Security Regulatory Structure
Kirk J. Nahra, JD
Partner, Wiley Rein LLP; Editor, The Privacy Advisor, International Association of Privacy Professionals; Editorial Board, BNA Privacy & Security Law Report, Washington, DC (Co-Chair)
Partner, Wiley Rein LLP; Editor, The Privacy Advisor, International Association of Privacy Professionals; Editorial Board, BNA Privacy & Security Law Report, Washington, DC (Co-Chair)
Kirk J. Nahra is a partner with Wiley Rein LLP in Washington, D.C., where he represents companies in a broad range of industries in connection with privacy and data security laws and regulations across the United States and globally. He is chair of the firm’s Privacy Practice and co-chair of its Health Care Practice.
He is a nationally recognized expert on privacy and data security laws related to the health care and insurance industries. He assists companies in a wide range of industries in analyzing and implementing the requirements of privacy and security laws across the country and internationally.
He serves on the Board of Directors of the International Association of Privacy Professionals and as the editor of Privacy Advisor. He is a Certified Information Privacy Professional and serves on the Advisory Board for the Health Law Reporter, the Privacy and Security Law Report and the Health Care Fraud Report.
He is a nationally recognized expert on privacy and data security laws related to the health care and insurance industries. He assists companies in a wide range of industries in analyzing and implementing the requirements of privacy and security laws across the country and internationally.
He serves on the Board of Directors of the International Association of Privacy Professionals and as the editor of Privacy Advisor. He is a Certified Information Privacy Professional and serves on the Advisory Board for the Health Law Reporter, the Privacy and Security Law Report and the Health Care Fraud Report.
3:30 p.m.
ONC Privacy and Security Policy Update
Donald Rucker, MD, MBA
National Coordinator for Health Information Technology, US Department of Health and Human Services, Washington, DC
National Coordinator for Health Information Technology, US Department of Health and Human Services, Washington, DC
Dr. Don Rucker is the National Coordinator for Health Information Technology at the U.S. Department of Health and Human Services, where he leads is the formulation of the federal health IT strategy and coordinates federal health IT policies, standards, programs, and investments.
Dr. Rucker has three decades of clinical and informatics experience. He started his informatics career at Datamedic Corporation, where he co-developed the world’s first Microsoft Windows-based electronic medical record. He then spent over a decade serving as Chief Medical Officer at Siemens Healthcare USA.
Dr. Rucker has also practiced emergency medicine for a variety of organizations including at Kaiser in California; at Beth Israel Deaconess Medical Center; at the University of Pennsylvania’s Penn Presbyterian and Pennsylvania Hospitals; and, most recently, at Ohio State University’s Wexner Medical Center.
Dr. Rucker has three decades of clinical and informatics experience. He started his informatics career at Datamedic Corporation, where he co-developed the world’s first Microsoft Windows-based electronic medical record. He then spent over a decade serving as Chief Medical Officer at Siemens Healthcare USA.
Dr. Rucker has also practiced emergency medicine for a variety of organizations including at Kaiser in California; at Beth Israel Deaconess Medical Center; at the University of Pennsylvania’s Penn Presbyterian and Pennsylvania Hospitals; and, most recently, at Ohio State University’s Wexner Medical Center.
4:00 p.m.
Lessons Learned from OCR HIPAA Audits Undertaken to Date
Zinethia Clemmons, RHIA, MBA, MHA, PMP, COR
HIPAA Compliance Audit Program Director, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
HIPAA Compliance Audit Program Director, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Zinethia Clemmons serves as the HIPAA Compliance Audit Program Director in the Office for Civil Rights at the Department of Health and Human Services in Washington, DC. Ms. Clemmons is responsible for managing the development and execution of OCR’s HIPAA Compliance Audits where she leads complex, critical, and urgent tasks and teams promoting voluntary compliance with the HIPAA Rules and HITECH Act. Prior to joining HHS, her past health care consulting experience extended throughout many verticals of the health care industry including long term care, acute care, managed care and the private sector in Georgia, California, the U.S. Virgin Islands and Washington, DC. Ms. Clemmons is an Adjunct Professor in the Health Informatics Administration Division at the University of Maryland University College. She is also a Board of Director Alumni for the American Health Information Management Association (AHIMA) and a mayoral-appointed Commissioner for the Statewide Health Coordinating Council for the District of Columbia.
Adam Greene, JD, MPH
Partner, Davis Wright Tremaine; Former Senior Health Information Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Partner, Davis Wright Tremaine; Former Senior Health Information Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Adam Greene is a partner in the Washington, D.C. office of Davis Wright Tremaine and co-chair of its Health Information Group. Adam primarily counsels health care providers, technology companies, and financial institutions on compliance with health information privacy, security, and breach notification rules. Previously, Adam was a regulator at the U.S. Department of Health and Human Services, where he played a fundamental role in administering and enforcing the HIPAA rules. At HHS, Adam was responsible for determining how HIPAA rules apply to new and emerging health information technologies and was instrumental in the development of the current HIPAA enforcement process.
Adam has been recognized as one of the top ten influencers in health information security, one of the top 50 healthcare IT experts, and is a frequent speaker and author on health information privacy and security issues.
Adam has been recognized as one of the top ten influencers in health information security, one of the top 50 healthcare IT experts, and is a frequent speaker and author on health information privacy and security issues.
4:45 p.m.
Employer Health Plans and HIPAA
Rebecca L. Williams, RN, JD
Partner and Chair, Health Information Practice, Davis Wright Tremaine LLP, Seattle, WA
Partner and Chair, Health Information Practice, Davis Wright Tremaine LLP, Seattle, WA
Becky Williams is a partner in the law firm of Davis Wright Tremaine, LLP where she is Co-Chair of the Health Information Practice. Ms. Williams has been named one of the “Best Lawyers in America” in health law by Woodward/White and a Best Lawyer in Seattle. As a registered nurse with hands-on experience in hospital and other health care environments, she brings a practical perspective to her practice. Ms. Williams is a Contributing Author of the HIPAA Portability, Privacy & Security Manual, published by the Employee Benefits Institute of America, a Thomson Reuters imprint, and serves on the Legal Task Force for the Health Information Management Systems Society (HIMSS). She also is a former Co-Chair of the Enforcement Subworkgroup and Chair of the Preemption Subworkgroup for the Workgroup for Electronic Data Interchange (WEDI), and Vice-Chair of the Health Information and Technology Practice Group of the American Health Lawyers Association (AHLA).
5:15 p.m.
How Privacy Monitoring Technologies Change the Ethical Standard
Nick Culbertson
Co-founder and Chief Executive Officer, Protenus, Baltimore, MD
Co-founder and Chief Executive Officer, Protenus, Baltimore, MD
Nick Culbertson is Co-founder and CEO of Protenus, a platform that protects patient data in electronic health record (EHR) systems for some of the nation’s top-ranked hospitals. In 2014, Nick and his co-founder Robert Lord developed the initial prototype and algorithms that launched Protenus, fulfilling a critical need to advance health data security and better protect patient data.
Nick served eight years in the U.S. Army and completed his service as a highly decorated Special Forces operator (Green Beret). He was awarded two bronze stars during his service, one for extraordinary valor. While serving in the military, Nick specialized in Human Intelligence network gathering and analysis. After his service, Nick spent four years as a biomedical researcher at Johns Hopkins University, where he participated in a variety of studies including synthetic biology, cellular engineering, and clinical outcomes. Nick helps run The 6th Branch, a veteran-led community service organization in East Baltimore.
Nick served eight years in the U.S. Army and completed his service as a highly decorated Special Forces operator (Green Beret). He was awarded two bronze stars during his service, one for extraordinary valor. While serving in the military, Nick specialized in Human Intelligence network gathering and analysis. After his service, Nick spent four years as a biomedical researcher at Johns Hopkins University, where he participated in a variety of studies including synthetic biology, cellular engineering, and clinical outcomes. Nick helps run The 6th Branch, a veteran-led community service organization in East Baltimore.
Matthew Olsen, MA
Chief Privacy Officer, Sidley Austin LLP; Former Chief Privacy and Data Sharing Officer, US Department of Health and Human Services; Former Privacy, FOIA, and Records Officer, Peace Corps; Former Deputy FOIA Officer, The National Archives, Washington, DC
Chief Privacy Officer, Sidley Austin LLP; Former Chief Privacy and Data Sharing Officer, US Department of Health and Human Services; Former Privacy, FOIA, and Records Officer, Peace Corps; Former Deputy FOIA Officer, The National Archives, Washington, DC
Matthew Olsen is currently the Chief Privacy Officer at Sidley Austin LLP in Chicago, IL. He was previously the Chief Privacy & Data Sharing Director for the U.S. Department of Health and Human Services, where he focused on internal privacy compliance and risk management activity.
He has also held positions at the Social Security Administration (SSA), White House Office of Management and Budget, Peace Corps, and the National Archives and Records Administration with responsibilities across the information management spectrum within the federal government over the last 16 years, including privacy, the Freedom of Information Act (FOIA), records management, and data breach response.
He has also held positions at the Social Security Administration (SSA), White House Office of Management and Budget, Peace Corps, and the National Archives and Records Administration with responsibilities across the information management spectrum within the federal government over the last 16 years, including privacy, the Freedom of Information Act (FOIA), records management, and data breach response.