Milliman Security Management System MS2 Home | Contact | Site Map | Milliman    
Milliman Security Management System
Overview
MS2
MS2:VM
 

Compliance FAQs

 

What features in MS2 help organizations achieve HIPAA Security compliance?

 

HIPAA Security compliance requires covered entities to establish a security program for electronic protected health information and to conduct routine risk assessments that evaluate a covered entity’s security needs. The risk assessment should, at a minimum, consider how the entity’s security safeguards address 42 specifications found in HIPAA’s security rule.

 

MS2, based on simple, comprehensive question-and-response logic, can provide the basis for HIPAA’s required security program and risk assessment. It automatically:

  • Documents security policy and procedures
  • Performs security risk assessments in relation to HIPAA’s 42 specifications as well as other security needs
  • Prepares a security gap assessment
  • Develops a solution set to address gaps for required HIPAA standards and specifications
  • Develops rationales, as required by the rule, for specifications not addressed
  • Contains a Compliance Tracking Center that identifies Action Plan Status of planned and updated security controls
  • Contains a reporting and archiving center
    • Security policies and procedures
    • Risks assessments
  • Provides for future assessments and updates
  • Provides tools for tracking business associate compliance
  • Contains a Best Practice and Solution Resource Center

 

 

 

 

 

 

 

 

 

 

Compliance FAQs

How does MS2 help implement and maintain an effective security compliance program?


How does MS2 help ensure that the proper security safeguards are in place?


How does MS2 help your organization comply with Sarbanes-Oxley?


How does MS2 help with Gramm-Leach-Bliley Act (GLBA) compliance?


Are all the elements of the GLBA Safeguard Rule included in MS2?


What kind of security risk assessment methodology does MS2 use and does it conform to NIST (National Institute of Standards) protocols?


Why does MS2 map controls to standards such as NIST and ISO?


What is the ISO 17799 standard, and why is it so important?


Does MS2 calculate a Return of Investment (ROI) for the security gaps identified during the risk and gap assessment?


How does MS2 help achieve HIPAA compliance?


Which features in MS2 help organizations achieve HIPAA Security compliance?


What is the definition of common control?

 

If my vendor says that the system we are using is HIPAA Security compliant, does that mean we are also HIPAA Security compliant?