Milliman Security Management System MS2 Home | Contact | Site Map | Milliman    
Milliman Security Management System
Overview
MS2
MS2:VM
 

Compliance FAQs

 

If my vendor says that the system we are using is HIPAA Security compliant, does that mean we are also HIPAA Security compliant?

 

No, it does not.

 

A system in and of itself cannot be HIPAA compliant because the administrative controls and practices of the user must also be considered and evaluated.

 

Only a Covered Entity (CE) can be HIPAA Security compliant. (Note: This is explicitly stated in the regulation.) The HIPAA Security rule requires that the CE entity either implement or address the administrative, physical, and technical security standards and specifications described in the rule. For example, HIPAA requires that a security risk assessment be performed and that documented security policies and procedures for the CE organization be in place and maintained for six years.

 

While a system may support many or all of the required technical safeguards, a CE cannot be HIPAA Security compliant until it has documented and addressed all the administrative, physical, and technical standards and specifications that the rule requires.

Compliance FAQs

How does MS2 help implement and maintain an effective security compliance program?


How does MS2 help ensure that the proper security safeguards are in place?


How does MS2 help your organization comply with Sarbanes-Oxley?


How does MS2 help with Gramm-Leach-Bliley Act (GLBA) compliance?


Are all the elements of the GLBA Safeguard Rule included in MS2?


What kind of security risk assessment methodology does MS2 use and does it conform to NIST (National Institute of Standards) protocols?


Why does MS2 map controls to standards such as NIST and ISO?


What is the ISO 17799 standard, and why is it so important?


Does MS2 calculate a Return of Investment (ROI) for the security gaps identified during the risk and gap assessment?


How does MS2 help achieve HIPAA compliance?


Which features in MS2 help organizations achieve HIPAA Security compliance?


What is the definition of common control?

 

If my vendor says that the system we are using is HIPAA Security compliant, does that mean we are also HIPAA Security compliant?