HIPAA regulation Summit
HIPAA regulation Summit
HIPAA regulation Summit
HIPAA regulation Summit
HIPAA regulation Summit
HIPAA regulation Summit



Overview | Agenda | Certifications | CE Credits | Promotional Opportunities | Grantors & Exhibitors
Admin | Speaking Proposals | HIPAA Award Winners | Webcast Login | Past Summits | Contact Us | Home




Go to Agenda:
Preconferences / Day 1 | Day 3

TWENTY-FOURTH NATIONAL HIPAA SUMMIT
AGENDA: DAY II

Tuesday, March 22, 2016

7:00 a.m. Registration Open; Networking Breakfast

MORNING PLENARY SESSION - HIPAA SECURITY
8:00 a.m.

Welcome and Introduction

John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Co-Chair)

    Speaker Bio

    John Parmigiani is the President of John C. Parmigiani & Associates, LLC. His current primary focus is on helping healthcare organizations become compliant with healthcare regulations, in particular HIPAA and the HITECH revisions, and move toward e-health. He has worked with a wide range of healthcare organizations and clients.

    Mr. Parmigiani has over 40 years experience in information systems management in both the public and private sectors. The former Director of Enterprise Standards for the Health Care Financing Administration (HCFA), now the Centers for Medicare & Medicaid Services (CMS), he was the chairman of the government-wide HIPAA Administrative Simplification Security and Electronic Signature Standards Implementation Team that created the Security Rule and was a member of the federal committee that oversaw the development and implementation of the HIPAA Transactions and Code Sets and the Privacy Rule. His post-government experience includes serving as the Senior Vice President for Consulting Services for QuickCompliance, Inc.; the National Practice Director, Regulatory and Compliance Services for CTG HealthCare Solutions, Inc.; and the Practice Director, Compliance Programs for Healthcare Computing Strategies, Inc.

    More information regarding his extensive list of presentations, publications, and affiliations as well as his credentials is available at www.johnparmigiani.com.
    Presentation Material (Acrobat)
8:15 a.m.

Healthcare Cyber Risk = Business Risk

Uday O. Ali Pabrai, MSEE, CISSP
Chief Executive Officer and Co-founder, ecfirst, (Home of HIPAA Academy), Irvine, CA

    Speaker Bio

    Ali Pabrai, MSEE, CISSP (ISSAP, ISSMP), Security+, a cyber security & compliance expert, is the CEO of ecfirst. A highly sought after professional, he has successfully delivered solutions to U.S. government agencies, IT firms, healthcare systems, legal and other organizations worldwide. Mr. Pabrai serves as an Interim CISO for a health system with 30+ locations in USA. Mr. Pabrai has led numerous engagements worldwide for ISO 27000, PCI DSS, NIST and HIPAA/HITECH security assessments. Mr. Pabrai has presented keynote and featured briefs on cyber security and compliance subjects at leading conferences globally, including the USA, Canada, India, UAE, Saudi Arabia, Philippines, Japan and other countries.

    Mr. Pabrai is a proud member of the InfraGard (FBI).
    Presentation Material (Acrobat)
8:45 a.m.

How to Determine if an Incident is a HIPAA Data Breach to Ensure Legal Compliance

Rick Kam, CIPP
President and Co-founder, ID Experts, Portland, OR

    Speaker Bio

    Rick Kam is president and co-founder of ID Experts. ID Experts serves consumers with identity protection, and enterprises with data breach software and services to simplify the complexities of managing privacy and security incidents. Rick has extensive experience leading organizations in the development of policies and solutions to protect protected health information (PHI) and personally identifiable information (PII), and remediating privacy and security incidents, identity theft, and medical identity theft. Rick leads and participates in several cross-industry groups including chair of PHI Protection Network (PPN) and founding member of the Medical Identity Fraud Alliance.
    Presentation Material (Acrobat)
9:15 a.m.

Recovering from a Breach: Strategies for Reporting and Responding to OCR

David Holtzman, JD, CIPP
Vice President, Compliance, Cynergistek, Inc.; Former Senior Adviser for HIT and the HIPAA Security Rule, Office for Civil Rights, HHS, Austin, TX

    Speaker Bio

    David Holtzman is vice president of compliance for CynergisTek. He is considered a subject matter expert in health information privacy and compliance issues. David was named by Health Data Management as one of the top 50 Healthcare IT experts of 2015. Prior to CynergisTek, Holtzman served as a senior advisor for health information technology and the HIPAA Security Rule at the Department of Health & Human Services, Office for Civil Rights (OCR/HHS). Prior to joining HHS, David was the privacy & security officer for Kaiser Permanente's Mid-Atlantic Region.
    Presentation Material (Acrobat)
9:45 a.m.

Business Associate Breaches -- What You Don't Know May Cost You!

Cliff Baker
Managing Partner, Meditology, Atlanta, GA

    Speaker Bio

    Cliff is an industry leader in healthcare information technology, privacy and security, and has over 17 years of industry experience. He has worked with the nation's leading healthcare organizations across all sectors of the industry and has served as an executive advisor for key industry affiliations and companies. He is a sought after contributor and speaker for various health IT and information risk management forums, the lead author of the HITRUST Common Security Framework, and author of various IT Risk Management publications. Prior to forming Meditology, Cliff was the Chief Strategy Officer for HITRUST and also led PricewaterhouseCoopers' healthcare security practice.
Janelle Burns, Esq.
Corporate Privacy and Security Officer, Baptist Memorial Healthcare Corporation, Memphis, TN

    Speaker Bio

    Janelle Burns is the Corporate Privacy & Security Officer for Baptist Memorial Health Care Corporation in Memphis, Tennessee, where she oversees compliance with patient privacy laws for fourteen hospitals and approximately 150 physician practices located in Tennessee, Mississippi, and Arkansas. Ms. Burns began her career with Baptist in January 2002. Ms. Burns received her Doctor of Jurisprudence and a Certificate in Health Law from the University of Tulsa College of Law in 1999.
    Presentation Material (Acrobat)
10:15 a.m. Break
10:45 a.m.

Stolen Healthcare Records: Report from the "Dark Web"

Ben Goodman, CRISC
President, 4A Security & Compliance, New York, NY

    Speaker Bio

    Ben Goodman is a cyber risk management and data security expert dedicated to strengthening the cyber defenses and compliance posture of organizations and critical infrastructure. As President of 4A Security and Compliance, Mr. Goodman and his team provide information security assurance, risk analysis, guidance on HIPAA and other regulatory compliance, incident response planning, training, vendor due diligence, data breach forensics, IT audit and security architecture services. In addition, Ben is the Cybersecurity Advisor to the Steering Committee of the Greater Philadelphia Healthcare Innovation Taskforce and a faculty member at Drexel University, Lebow College of Business.
    Presentation Material (Acrobat)
11:15 a.m.

Healthcare Security Officer Best Practices Roundtable

Janelle Burns, Esq.
Corporate Privacy and Security Officer, Baptist Memorial Healthcare Corporation, Memphis, TN

    Speaker Bio

    Janelle Burns is the Corporate Privacy & Security Officer for Baptist Memorial Health Care Corporation in Memphis, Tennessee, where she oversees compliance with patient privacy laws for fourteen hospitals and approximately 150 physician practices located in Tennessee, Mississippi, and Arkansas. Ms. Burns began her career with Baptist in January 2002. Ms. Burns received her Doctor of Jurisprudence and a Certificate in Health Law from the University of Tulsa College of Law in 1999.
Dr. Angela Duncan Diop, ND, CHCIO
Vice President of Information Systems, Unity Health Care, Inc., Washington, DC

    Speaker Bio

    Dr. Angela Duncan Diop is Vice President of Information Systems at Unity Health Care Inc. (Unity), a Federally Qualified Health Center providing medical homes to over 105,000 residents in Washington, DC. Dr. Diop has led adoption and expansion of health information technology throughout Unity's more than 25 sites. Under her leadership, Unity achieved the Health Information Systems Society (HIMSS) Davies award. Dr. Diop is a member of the District of Columbia Health Information Exchange Policy Board and the HIMSS Davies Ambulatory Committee. Dr. Diop is excited about the opportunity to utilize information technology to engage and improve the health in communities.
Clyde Hewitt, MS
Vice President and Chief Security Officer, Allscripts; Immediate Past President, North Carolina Healthcare Information and Communication Alliance (NCHICA), Raleigh, NC

    Speaker Bio

    Clyde Hewitt is the Vice President and Chief Security Officer for Allscripts Healthcare. In this role, he is responsible for managing a global Information Security Management System (ISMS) supporting clients on four continents. He is accountable for all aspects of Security Operations and Administration, Compliance and IT Audit, and Vendor Compliance Management. He is also the immediate Past President of the North Carolina Healthcare Information and Communications Alliance, a 330+ member organization whose mission is accelerating the transformation of the U.S. healthcare system through the effective use of information technology, informatics and analytics. Mr. Hewitt’s credentials include CISSP, ISO 27001 Lead Auditor, CHS, and Level III Program Manager. He is also a prolific public speaker and author.
David Holtzman, JD, CIPP
Vice President, Compliance, CynergisTek, Inc.; Former Senior Adviser for HIT and the HIPAA Security Rule, Office for Civil Rights, HHS, Austin, TX

    Speaker Bio

    David Holtzman is vice president of compliance for CynergisTek. He is considered a subject matter expert in health information privacy and compliance issues. David was named by Health Data Management as one of the top 50 Healthcare IT experts of 2015. Prior to CynergisTek, Holtzman served as a senior advisor for health information technology and the HIPAA Security Rule at the Department of Health & Human Services, Office for Civil Rights (OCR/HHS). Prior to joining HHS, David was the privacy & security officer for Kaiser Permanente's Mid-Atlantic Region.
John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Moderator)

    Speaker Bio

    John Parmigiani is the President of John C. Parmigiani & Associates, LLC. His current primary focus is on helping healthcare organizations become compliant with healthcare regulations, in particular HIPAA and the HITECH revisions, and move toward e-health. He has worked with a wide range of healthcare organizations and clients.

    Mr. Parmigiani has over 40 years experience in information systems management in both the public and private sectors. The former Director of Enterprise Standards for the Health Care Financing Administration (HCFA), now the Centers for Medicare & Medicaid Services (CMS), he was the chairman of the government-wide HIPAA Administrative Simplification Security and Electronic Signature Standards Implementation Team that created the Security Rule and was a member of the federal committee that oversaw the development and implementation of the HIPAA Transactions and Code Sets and the Privacy Rule. His post-government experience includes serving as the Senior Vice President for Consulting Services for QuickCompliance, Inc.; the National Practice Director, Regulatory and Compliance Services for CTG HealthCare Solutions, Inc.; and the Practice Director, Compliance Programs for Healthcare Computing Strategies, Inc.

    More information regarding his extensive list of presentations, publications, and affiliations as well as his credentials is available at www.johnparmigiani.com.
    Presentation Material (Acrobat)
Noon Networking Luncheon
Luncheon Keynote Address

Charles Ornstein
Senior Reporter, ProPublica, Awardee, Pulitzer Prize for Public Service, Past President, Association of Health Care Journalists, New York, NY

    Speaker Bio

    Charles Ornstein is a senior reporter at ProPublica. In 2004, while at the Los Angeles Times, he co-wrote a series about a troubled hospital that won the 2005 Pulitzer Prize for Public Service. He also co-wrote a series about failures in oversight by the California Board of Registered Nursing, which was a finalist for the 2010 Pulitzer Prize for Public Service. Ornstein is past president of the Association of Health Care Journalists and an adjunct professor at Columbia University's Graduate School of Journalism. @charlesornstein.
    Presentation Material (Acrobat)

AFTERNOON PLENARY SESSION - HIPAA, HITECH AND HEALTH REFORM
1:15 p.m.

Welcome and Introductions

William R. Braithwaite, MD, PhD
"Doctor HIPAA", Braithwaite Consulting; HIPAA Summit Distinguished Service Award Winner; Former Senior Advisor on Health Information Policy, DHHS, Washington, DC (Co-Chair)

    Speaker Bio

    Dr. Bill Braithwaite has dedicated his career to improving the quality and efficiency of health care for patients and practitioners utilizing information technology. He is best known as the author of the Administrative Simplification Subtitle of HIPAA and as a major contributor to the subsequent federal regulations setting standards for transactions, code sets, identifiers, security, and privacy of personal health information. As an independent consultant, he now works with a few small clients on the policy, technology, and compliance issues of health information privacy and security.
    Presentation Material (Acrobat)
1:30 p.m.

ONC Privacy and Security Policy Update

Lucia Savage, Esq.
Chief Privacy Officer, Office of the National Coordinator for Health IT, US Department of Health and Human Services; Former Senior Associate General Counsel, UnitedHealthcare; Former General Counsel, Pacific Business Group on Health, Washington, DC

    Speaker Bio

    Lucia Savage joined the Office of the National Coordinator for Health Information Technology, Department of Health & Human Services in October 2014 as the Chief Privacy Officer. Lucia was the Senior Associate General Counsel at UnitedHealthcare, where she supervised a team that represents UnitedHealthcare in its work in large data transactions related to health information exchanges, healthcare transparency projects, and other data-driven health care innovation projects. She has served on the Governance Board of the Centers for Medicare & Medicaid Services' Multi-Payer Claims data base project (2011-2013), and collaborated with health information exchanges and state agencies in their planning with payers.

    Prior to joining UnitedHealthcare, Lucia was General Counsel at the non-profit Pacific Business Group on Health, where she oversaw the legal affairs and state policy initiatives for one of the nation's oldest employer healthcare purchasing coalitions and its small group health insurance exchange, PacAdvantage.
    Presentation Material (Acrobat)
2:00 p.m.

Preparing for and Responding to an OCR HIPAA Audit

Margret Amatayakul, MBA, RHIA, CPEHR, CPHIT, CPHIE, CPORA, CHPS, FHIMSS
President, Margret\A Consulting, LLC; Adjunct Faculty in Health Informatics, College of St. Scholastica, Schaumburg, IL

    Speaker Bio

    Margret Amatayakul, MBA, RHIA, CPHIT, CPEHR, CHPS, FHIMSS, is president of Margret\A Consulting, LLC, a health information management and systems consulting firm based in Schaumburg, IL. The firm focuses on helping organizations navigate and achieve benefits from regulations such as HIPAA, HITECH, and ACA.

    Margret A's background includes extensive experience working with hospitals, physician practices, health information exchange organizations, accountable care organizations, vendors, and public policymakers. Previous positions have included adjunct professor in health informatics at the College of St. Scholastica, executive director of the Computer-based Patient Record Institute, associate executive director of AHIMA, associate professor at the University of Illinois at Chicago College of Applied Health Sciences, and director of the health information management department at the Illinois Eye and Ear Infirmary. She is also a partner in Health IT Certification, LLC. She has written several books on HIPAA, EHR, and process improvement. Additional information is available at www.margret-a.com.
Rebecca L. Williams, RN, JD
Partner and Chair, Health Information Practice, Davis Wright Tremaine LLP, Seattle, WA

    Speaker Bio

    Becky Williams is a nationally recognized authority on HIPAA. She is a partner in the Seattle office of the law firm Davis Wright Tremaine, LLP where she is Co-Chair of the Health Information Practice. Ms. Williams has been named one of the "Best Lawyers in America" in health law by Woodward/White. She also is a registered nurse with hands-on experience in hospital and other health care environments. She has served on various committees for the Workgroup for Electronic Data Interchange, the Healthcare Information and Management Systems Society, and the American Health Lawyers Association.
    Presentation Material (Acrobat)
2:45 p.m.

HIPAA Services and Solutions Innovation Showcase

William R. Braithwaite, MD, PhD
"Doctor HIPAA", Braithwaite Consulting; HIPAA Summit Distinguished Service Award Winner; Former Senior Advisor on Health Information Policy, DHHS, Washington, DC (Moderator)

    Speaker Bio

    Dr. Bill Braithwaite has dedicated his career to improving the quality and efficiency of health care for patients and practitioners utilizing information technology. He is best known as the author of the Administrative Simplification Subtitle of HIPAA and as a major contributor to the subsequent federal regulations setting standards for transactions, code sets, identifiers, security, and privacy of personal health information. As an independent consultant, he now works with a few small clients on the policy, technology, and compliance issues of health information privacy and security.
3:30 p.m. Break
4:00 p.m.

What's Next for Health Care Privacy and Security?

Kirk J. Nahra, Esq.
Partner, Wiley Rein LLP; Editor, The Privacy Advisor, International Association of Privacy Professionals, Washington, DC

    Speaker Bio

    Kirk J. Nahra is a partner with Wiley Rein LLP in Washington, D.C., where he specializes in privacy and information security litigation and counseling, along with a variety of health care and compliance issues. He is chair of the firm's Privacy Practice and co-chair of its Health Care Practice. He assists companies in a wide range of industries in analyzing and implementing the requirements of privacy and security laws across the country and internationally. He provides advice on data breaches, enforcement actions, contract negotiations, business strategy, research and de-identification issues and privacy, data security and cybersecurity compliance. He served as a long-time member of the IAPP Board of Directors and as the editor of Privacy Advisor. He teaches health care privacy and data security law at American University.
    Presentation Material (Acrobat)
4:30 p.m.

Information Governance -- the Next Evolution of Privacy and Security

Katherine E. Downing, MA, RHIA, PMP, CHP, HIM
Practice Excellence, AHIMA; Adjunct Faculty, HIM Bachelors' Degree Program, University of Cincinnati, Chicago, IL

    Speaker Bio

    Kathy Downing is the Senior Director IG Advisors at the American Health Information Management Association in Chicago focused on Information Governance, Privacy, Security and the Electronic Health Record. Kathy has over 15 years of experience in healthcare as a Privacy Officer, Project manager, HIM Director and IT analyst. As a Director of Patient Health Information Protection at a hospital systems' corporate office she led the creation of the Privacy Program for over 300 hospitals, surgery centers, and physician practices including training over 1000 privacy officers. She has expertise in Electronic Health Records and has worked with numerous sites during implementations.
    Presentation Material (Acrobat)
5:00 p.m. Adjournment

Go to Agenda:
Preconferences / Day 1 | Day 3





Overview | Agenda | Certifications | CE Credits | Promotional Opportunities | Grantors & Exhibitors
Admin | Speaking Proposals | HIPAA Award Winners | Webcast Login | Past Summits | Contact Us | Home




© Health Care Conference Administrators
Contact Webmaster