<?xml version="1.0" standalone="no" ?>

<!--  AIT_HIPAA_Security.xml Course Outline in XML format
 *
 * Copyright 2012 Affinity IT Training, LLC. All Rights Reserved.
 *
 -->

<!DOCTYPE FAI:CourseOutline SYSTEM "FAI_CourseOutline.dtd">

<?xml-stylesheet type="text/xsl" href="FAI_CourseOutline.xsl" ?>	

<FAI:CourseOutline FAI:link="AIT_HIPAA_Security.xml"
     xmlns:FAI="http://www.fisher-assoc.com/DTDs/FAI_CourseOutline.dtd" >

  <FAI:CourseTitle FAI:level="Introduction"  FAI:code="HIPAA">
	Understanding HIPAA Security Compliance
  </FAI:CourseTitle>  
  
  <FAI:CourseCategory>CyberSec</FAI:CourseCategory>
     
  <FAI:SummaryInfo>

    <FAI:CourseDesc FAI:version="Jul10">
    	The Health Information Portability and Accountability Act (HIPAA) defined rules that must be 
    	observed in the curation of health care information.
    	It defines required requirements for organizations that store, process, or transmit health care information
    	or related sensitive data.
    	This course explains the HIPAA Security Rule in the context of the larger framework of IT Security, 
    	and will help organizations understand the motivation for each requirement.
    	Strategies for the successful implementation of each requirement will be examined.    	
   </FAI:CourseDesc>

    <FAI:CourseDuration>
	1 Day
    </FAI:CourseDuration>

    <FAI:CourseAudience>
	Managers and staff of entities that must be HIPAA Security compliant.
    </FAI:CourseAudience>

    <FAI:CourseObjectives>

      <FAI:Objective FAI:desc="Understand the purpose and motivation for the HIPAA Security Rule" />
      <FAI:Objective FAI:desc="Clearly understand who must comply with HIPAA Security Rule" />
      <FAI:Objective FAI:desc="Be familiar with HIPAA terms and vocabulary" />
      <FAI:Objective FAI:desc="Be familiar with all HIPAA Security Requirements" />
      <FAI:Objective FAI:desc="Understand how to interpret HIPAA Requirements in the broader context of IT Security" />
      
    </FAI:CourseObjectives>

    <FAI:CourseSetupList>
    </FAI:CourseSetupList>    

    <FAI:CourseTextList>
      <FAI:Text FAI:title="Course Workbook" />
    </FAI:CourseTextList>    

    <FAI:CoursePrerequisiteList>
    </FAI:CoursePrerequisiteList>    

  </FAI:SummaryInfo>  

  <FAI:TopicList>                                  

    <FAI:SuperTopic FAI:title="Introduction">
	<FAI:Topic FAI:title="Welcome"/>
	<FAI:Topic FAI:title="Motivation"/>
	<FAI:Topic FAI:title="Objectives"/>
	<FAI:Topic FAI:title="Terms and Concepts"/>
	<FAI:Topic FAI:title="HIPAA Applicability"/>
	<FAI:Topic FAI:title="HIPAA Compliance"/>
	<FAI:Topic FAI:title="Course Overview"/>
	<FAI:Topic FAI:title="HIPAA Requirements Overview"/>
	<FAI:Topic FAI:title="Required vs. Addressable Specifications"/>
    </FAI:SuperTopic>
    
    <FAI:SuperTopic FAI:title="IT Security Concepts and Terms" >
      <FAI:Topic FAI:title="Malware" />
      <FAI:Topic FAI:title="Vulnerabilities, Threats, and Attacks" />
      <FAI:Topic FAI:title="Vulnerabilities and Threats" />
      <FAI:Topic FAI:title="Countermeasures" />
      <FAI:Topic FAI:title="Policies and Procedures" />
      <FAI:Topic FAI:title="Risks and Risk Management" />
      <FAI:Topic FAI:title="Risk Analysis and Mitigation" />
      <FAI:Topic FAI:title="Defense in Depth" />
      <FAI:Topic FAI:title="Security Domains" />
      <FAI:Topic FAI:title="Security vs. Convenience" />
      <FAI:Topic FAI:title="Security Goals" />
      <FAI:Topic FAI:title="Security Resources" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Understanding IT Security Risk" >
      <FAI:Topic FAI:title="Risk and Risk Management" />
      <FAI:Topic FAI:title="Threats and Attacker Motivation" />
      <FAI:Topic FAI:title="Internal Threats" />
      <FAI:Topic FAI:title="Examples of IT Security Risk" />
      <FAI:Topic FAI:title="Risk Valuation" />
      <FAI:Topic FAI:title="Risk Analysis and Mitigation" />
      <FAI:Topic FAI:title="HIPAA: Risk Analysis and Management" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

  <FAI:SuperTopic FAI:title="HIPAA Security: General Rules" >
      <FAI:Topic FAI:title="Confidentiality, Integrity, and Availability" />
      <FAI:Topic FAI:title="Threat Management" />
      <FAI:Topic FAI:title="Governance" />
      <FAI:Topic FAI:title="Flexibility of Approach" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

  <FAI:SuperTopic FAI:title="HIPAA Security: Administrative Safeguards" >
      <FAI:SuperTopic FAI:title="Standard: Security Management Process" >
	      <FAI:SuperTopic FAI:title="Implementation Specifications" >
		      <FAI:Topic FAI:title="Risk Analysis" />
		      <FAI:Topic FAI:title="Risk Management" />
		      <FAI:Topic FAI:title="Sanction Policy" />
		      <FAI:Topic FAI:title="Information System Activity Review" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Standard: Assigned Security Responsibility" />
      <FAI:SuperTopic FAI:title="Standard: Workforce Security" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
 		<FAI:Topic FAI:title="Addressable Specifications" />
	</FAI:SuperTopic>
      </FAI:SuperTopic>
      	
      <FAI:SuperTopic FAI:title="Standard: Information Access Management" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Isolating Healthcare Clearinghouse Functions" />
      		<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Standard: Security Awareness and Training" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
            	<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Standard: Security Incident Procedures" >
	      <FAI:SuperTopic FAI:title="Implementation Specifications" >
		<FAI:Topic FAI:title="Incident Response and Reporting" />
	      </FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:SuperTopic FAI:title="Standard: Contingency Planning">
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Data Backup" />
		<FAI:Topic FAI:title="Disaster Recovery" />
		<FAI:Topic FAI:title="Emergency Mode Operation" />
      		<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Standard: Evaluation" />
      <FAI:SuperTopic FAI:title="Standard: Business Associate Contracts and Other Arrangements" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Written Contract or Other Arrangements" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

  <FAI:SuperTopic FAI:title="HIPAA Security: Physical Safeguards" >
      <FAI:Topic FAI:title="Standard: Facilities Access Controls" />
      <FAI:SuperTopic FAI:title="Implementation Specifications" >
      	<FAI:Topic FAI:title="Addressable Specifications" />
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Standard: Workstation Use" />
      <FAI:Topic FAI:title="Standard: Workstation Security" />
      <FAI:SuperTopic FAI:title="Standard: Device and Media Controls" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="(Electronic Media) Disposal" />
      		<FAI:Topic FAI:title="(Electronic Media) Reuse" />
      		<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

  <FAI:SuperTopic FAI:title="HIPAA Security: Technical Safeguards" >
      <FAI:SuperTopic FAI:title="Standard: Access Control" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Unique User Id" />
      		<FAI:Topic FAI:title="Emergency Access Procedure" />
      		<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Standard: Audit Controls" />
      <FAI:SuperTopic FAI:title="Standard: Integrity" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Standard: Person or Entity Authentication" />
      <FAI:SuperTopic FAI:title="Standard: Transmission Security" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Addressable Specifications" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

  <FAI:SuperTopic FAI:title="HIPAA Security: Organizational Requirements" >
      <FAI:Topic FAI:title="Standard: Business Associate Contracts or Other Arrangements" />
      <FAI:Topic FAI:title="Quiz" />
  </FAI:SuperTopic>

  <FAI:SuperTopic FAI:title="HIPAA Security: Policies and Procedures" >
      <FAI:Topic FAI:title="Standard: Policies and Procedures" />
      <FAI:SuperTopic FAI:title="Standard: Documentation" >
      	<FAI:SuperTopic FAI:title="Implementation Specifications" >
      		<FAI:Topic FAI:title="Time Limit" />
      		<FAI:Topic FAI:title="Availability" />
      		<FAI:Topic FAI:title="Updates" />
      	</FAI:SuperTopic>
      </FAI:SuperTopic>
      <FAI:Topic FAI:title="Quiz" />
  </FAI:SuperTopic>

  </FAI:TopicList>

  <FAI:Appendix FAI:title="Quiz Answers" />
  <FAI:Appendix FAI:title="Additional Resources" />
    
</FAI:CourseOutline>

 
