AGENDA: PRECONFERENCE
TUESDAY, MARCH 3, 2020
(Separate registration required; Choose one)
7:00 a.m.
Registration Open
PRECONFERENCE I: BASIC TRAINING FOR HEALTH CARE PRIVACY & SECURITY PROFESSIONALS
8:00 a.m.
HIPAA Privacy Basics
Adam Greene, JD, MPH
Partner and Co-chair, Health Information and HIPAA Practice, Davis Wright Tremaine LLP; HIPAA Summit Distinguished Service Award Winner; Former Senior Health Information, Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Partner and Co-chair, Health Information and HIPAA Practice, Davis Wright Tremaine LLP; HIPAA Summit Distinguished Service Award Winner; Former Senior Health Information, Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Adam Greene is a partner in the Washington, D.C. office of Davis Wright Tremaine and co-chair of its Health Information Group. Adam primarily counsels health care providers, technology companies, and financial institutions on compliance with health information privacy, security, and breach notification rules. Previously, Adam was a regulator at the U.S. Department of Health and Human Services, where he played a fundamental role in administering and enforcing the HIPAA rules. At HHS, Adam was responsible for determining how HIPAA rules apply to new and emerging health information technologies and was instrumental in the development of the current HIPAA enforcement process. Adam has been recognized as one of the top ten influencers in health information security, one of the top 50 healthcare IT experts, and is a frequent speaker and author on health information privacy and security issues.
9:00 a.m.
HIPAA Breach Notification Rule and HIPAA Enforcement Rule
Iliana Peters, JD, LLM
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Iliana L. Peters is a shareholder for Polsinelli, PC. For more than twelve years, she both developed health information privacy and security policy, including on emerging technologies and cyber threats, for the Department of Health and Human Services, and enforced HIPAA regulations, as both the Senior Advisor for HIPAA Enforcement for over six years, and as Acting Deputy Director for HIPAA. As a CISSP, Iliana works hard to bridge the gap between legal requirements for the security of health data and security industry best practices, so that clients can better understand data security issues and jargon. She is excited to bring her extensive experience drafting, implementing, and enforcing health privacy and security regulations and guidance to a practice that focuses on helping clients develop and implement good data privacy and security practices to avoid risk, and helping clients prepare for and recover from emerging cyber threats.
10:00 a.m.
Transition Break
10:15 a.m.
HIPAA Security Basics
John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; HIPAA Summit Distinguished Service Award Winner; Former Director of Enterprise Standards, HCFA (now CMS), Ellicott City, MD
President, John C. Parmigiani and Associates, LLC; HIPAA Summit Distinguished Service Award Winner; Former Director of Enterprise Standards, HCFA (now CMS), Ellicott City, MD
John Parmigiani is President of John C Parmigiani & Associates, LLC. His primary focus is on helping healthcare organizations become and maintain compliance with healthcare regulations, in particular HIPAA and the HITECH provisions and move toward electronic healthcare. He has over 40 years’ experience in information management systems in both the public and private sectors. His HIPAA/HITECH work has ranged from performing compliance and risk assessments and design activities to serving as an expert witness in privacy violation cases.
11:15 a.m.
Faculty Discussion and Q&A
12:00 p.m.
Adjournment; Lunch on Your Own
PRECONFERENCE II: PROFESSIONAL CERTIFICATION PRECONFERENCE: CERTIFIED CYBER SECURITY ARCHITECTSM (CCSASM) TRAINING
Learning Objectives:
- Examine how to establish an enterprise cybersecurity program based on the NIST Cybersecurity Framework.
- Identify policies that reflect an organization’s priority for cyber security in the areas of risk assessment, mobile devices, cloud computing, supply chain (business associates), and more.
- Leverage NIST standards for incident response management, encryption and other key areas for a credible, audit-ready, HIPAA compliance program.
- Understand how to align your HIPAA compliance program with the NIST Cybersecurity Framework.
8:00 a.m.
Introduction and Overview
Uday O. Ali Pabrai, MSEE, CISSP, HITRUST (CCSFP)
Chief Executive and Co-founder, ecfirst (A HITRUST Authorized External Assessor), Irvine, CA
Chief Executive and Co-founder, ecfirst (A HITRUST Authorized External Assessor), Irvine, CA
Ali Pabrai is the chief executive officer of ecfirst, an Inc 500 business in its first year of eligibility. A highly sought-after information security and regulatory compliance expert, he has successfully delivered solutions on compliance and information security to organizations worldwide. He is a keynote and featured speaker at conferences worldwide! He has consulted and advised 1000s of clients globally! He was appointed and services as a member of the select HITRUST SCF Assessor Council and is a proud member of InfraGard (FBI).
12:00 p.m.
Adjournment; Lunch on Your Own
OPENING PLENARY SESSION — HIPAA PRIVACY
1:00 p.m.
Introduction and Overview
Adam Greene, JD, MPH
Partner, Davis Wright Tremaine; Former Senior Health Information Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Co chair)
Partner, Davis Wright Tremaine; Former Senior Health Information Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Co chair)
Adam Greene is a partner in the Washington, D.C. office of Davis Wright Tremaine and co-chair of its Health Information Group. Adam primarily counsels health care providers, technology companies, and financial institutions on compliance with health information privacy, security, and breach notification rules. Previously, Adam was a regulator at the U.S. Department of Health and Human Services, where he played a fundamental role in administering and enforcing the HIPAA rules. At HHS, Adam was responsible for determining how HIPAA rules apply to new and emerging health information technologies and was instrumental in the development of the current HIPAA enforcement process. Adam has been recognized as one of the top ten influencers in health information security, one of the top 50 healthcare IT experts, and is a frequent speaker and author on health information privacy and security issues.
1:15 p.m.
OCR Keynote Address
Timothy Noonan, JD
Deputy Director, Health Information Privacy, US Department of Health and Human Services; Former Supervisory General Attorney, US Department of Education, Washington, DC
Deputy Director, Health Information Privacy, US Department of Health and Human Services; Former Supervisory General Attorney, US Department of Education, Washington, DC
Timothy Noonan is the Deputy Director for Health Information Privacy, at the Office for Civil Rights (OCR), United States Department of Health and Human Services. The Health Information Privacy Division enforces the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security and Breach Notification Rules and the Patient Safety and Quality Improvement Act and Rule through investigations, rule-making and guidance, and outreach. Previously, Tim served in OCR headquarters for approximately 1 ½ years as the Acting Associate Deputy Director for Operations and the Acting Director of OCR’s Centralized Case Management Operations. Tim joined OCR as the Southeast Regional Manager in November 2013. Prior to joining OCR, Tim was a Supervisory General Attorney for the U.S. Department of Education, Office for Civil Rights, and a shareholder in a Michigan law firm.
1:45 p.m.
OCR Policy and Implementation Update
Serena Mosley-Day, JD
Senior Advisor for HIPAA Compliance and Enforcement, Office for Civil Rights, US Department of Health and Human Services, Former Assistant Regional Counsel, Social Security Administration, Washington, DC
Senior Advisor for HIPAA Compliance and Enforcement, Office for Civil Rights, US Department of Health and Human Services, Former Assistant Regional Counsel, Social Security Administration, Washington, DC
Serena Mosley-Day is the Senior Advisor for HIPAA Compliance and Enforcement, Office for Civil Rights (OCR), U.S. Department of Health and Human Services (HHS). In this role Serena is the national lead for OCR enforcement of the HIPAA Rules, and works closely with OCR’s regional offices to promote compliance with and enforcement of the HIPAA Rules, including through negotiated resolution agreements. Serena has been with HHS OCR since December 2013. Prior to serving as Senior Advisor, Serena was the Deputy Regional Manager, Southeast Region of HHS OCR. Before joining HHS OCR, Serena was an attorney at the Social Security Administration and a supervisory attorney for the U.S. Department of Education, Office for Civil Rights.
2:30 p.m.
Update on 42 CFR Part 2, the Privacy Rule that Governs Substance Use Disorder Treatment Records
Michael D. Greenberg, JD, PhD
Principal Life Scientist and Project Lead, MITRE Corporation, Department of Health Policy, Pittsburgh, PA
Principal Life Scientist and Project Lead, MITRE Corporation, Department of Health Policy, Pittsburgh, PA
Michael Greenberg is a Principal Life Scientist with the MITRE Corporation. Dr. Greenberg is a lawyer and a clinical psychologist by training. His areas of expertise include organizational behavior, corporate governance and compliance, and healthcare policy and regulation. His work at MITRE is focused on the areas of federal health policy, regulation, and administration.
Previously, he served as a senior research analyst and executive at the RAND Corporation, as RAND’s Director for Intellectual Property Strategy and Management, and as a Professor at the RAND-Pardee Graduate School.
Outside of his work at MITRE and at RAND, Greenberg has served as an adjunct faculty member at the University of Pittsburgh School of Law; the University of Pittsburgh School of Medicine; and the Heinz College of Public Policy at Carnegie Mellon University. Dr. Greenberg serves on the Board of Directors of No Crayon Left Behind.
Previously, he served as a senior research analyst and executive at the RAND Corporation, as RAND’s Director for Intellectual Property Strategy and Management, and as a Professor at the RAND-Pardee Graduate School.
Outside of his work at MITRE and at RAND, Greenberg has served as an adjunct faculty member at the University of Pittsburgh School of Law; the University of Pittsburgh School of Medicine; and the Heinz College of Public Policy at Carnegie Mellon University. Dr. Greenberg serves on the Board of Directors of No Crayon Left Behind.
3:00 p.m.
Break
3:30 p.m.
Privacy Policy Keynote
Daniel J. Solove, JD
John Marshall Harlan Research Professor of Law, George Washington University Law School; Founder, TeachPrivacy; Author, Understanding Privacy; Information Privacy Law; The Future of Reputation: Gossip, Rumor, and Privacy on the Internet; and The Digital Person: Technology and Privacy in the Information Age, Washington, DC
John Marshall Harlan Research Professor of Law, George Washington University Law School; Founder, TeachPrivacy; Author, Understanding Privacy; Information Privacy Law; The Future of Reputation: Gossip, Rumor, and Privacy on the Internet; and The Digital Person: Technology and Privacy in the Information Age, Washington, DC
Daniel J. Solove is the John Marshall Harlan Research Professor of Law at the George Washington University Law School. He is also the founder of TeachPrivacy, a company that provides privacy and data security training programs to businesses, law firms, healthcare institutions, schools, and other organizations. One of the world’s leading experts in privacy law, Solove is the author of 10+ books and textbooks and 50+ articles. His articles have appeared in the Harvard Law Review, Yale Law Journal, Stanford Law Review, and Columbia Law Review, among others. Professor Solove blogs at LinkedIn at Privacy+Security Blog.
4:00 p.m.
The Role of the Health Care Chief Compliance Officer in HIPAA and Privacy and Security Compliance
Gerry Zack, MBA, CPA, CFE, CIA, CRMA
Chief Executive Officer, Health Care Compliance Association (HCCA), and Society of Corporate Compliance and Ethics (SCCE); Former Chair, Association of Certified Fraud Examiners (ACFE) Minneapolis, MN
Chief Executive Officer, Health Care Compliance Association (HCCA), and Society of Corporate Compliance and Ethics (SCCE); Former Chair, Association of Certified Fraud Examiners (ACFE) Minneapolis, MN
Gerry Zack is a compliance and antifraud expert and author, with more than 30 years’ experience in the prevention, detection and investigation of fraud, noncompliance, and corruption. Effective November 1, 2018 Gerry became the CEO of SCCE & HCCA, following a 12-month transition during which he worked closely with former CEO and founder Roy Snell.
Prior to joining SCCE & HCCA last year, Zack spent more than 30 years providing services for the prevention, detection, investigation, and remediation of fraud, corruption and noncompliance. He served as a Managing Director in the Global Forensics practice at BDO and ran his own advisory and investigative practice. He also served as Chief Operating and Compliance Officer, and Deputy Executive Director, of the Optical Society from 2010 to 2012.
He served on the Faculty at the Association of Certified Fraud Examiners for 11 years and is a former chair of its Board of Regents.
Prior to joining SCCE & HCCA last year, Zack spent more than 30 years providing services for the prevention, detection, investigation, and remediation of fraud, corruption and noncompliance. He served as a Managing Director in the Global Forensics practice at BDO and ran his own advisory and investigative practice. He also served as Chief Operating and Compliance Officer, and Deputy Executive Director, of the Optical Society from 2010 to 2012.
He served on the Faculty at the Association of Certified Fraud Examiners for 11 years and is a former chair of its Board of Regents.
4:30 p.m.
ONC Privacy and Security Policy Update
Donald Rucker, MD
National Coordinator for Health Information Technology; Former Chief Medical Officer, Siemens Healthcare, Washington, DC
National Coordinator for Health Information Technology; Former Chief Medical Officer, Siemens Healthcare, Washington, DC
Dr. Don Rucker is the National Coordinator for Health Information Technology at the U.S. Department of Health and Human Services, where he leads the formulation of the federal health IT strategy and coordinates federal health IT policies, standards, programs, and investments. Dr. Rucker has three decades of clinical and informatics experience. He started his informatics career at Datamedic Corporation, where he codeveloped the world’s first Microsoft Windows-based electronic medical record. He then spent over a decade serving as Chief Medical Officer at Siemens Healthcare USA. Dr. Rucker has also practiced emergency medicine for a variety of organizations including at Kaiser in California; at Beth Israel Deaconess Medical Center; at the University of Pennsylvania’s Penn Presbyterian and Pennsylvania Hospitals; and, most recently, at Ohio State University’s Wexner Medical Center.
5:00 p.m.
Chief Privacy Officers Best Practices Roundtable
Angela Alton, MPA, CHPC, CHC
Vice President and Privacy Officer, Ann & Robert H Lurie Children’s Hospital of Chicago; Former Deputy Chief Privacy Officer, Bay Area, Sutter Health, Chicago, IL
Vice President and Privacy Officer, Ann & Robert H Lurie Children’s Hospital of Chicago; Former Deputy Chief Privacy Officer, Bay Area, Sutter Health, Chicago, IL
Angela Alton has worked in healthcare for over twenty years. For the past fifteen years Angela has focused on the areas of information privacy, security and regulatory compliance. Currently, Angela is Vice President, Privacy Officer for Ann & Robert H. Lurie Children’s Hospital of Chicago where she provides direction and oversight for all facets of the privacy program. Prior to this, Angela served as the Deputy Chief Privacy Officer- Bay Area for Sutter Health in California.
Andrew Clearwater, CIPP/E, LLM
Director of Privacy, OneTrust, Atlanta, GA
Director of Privacy, OneTrust, Atlanta, GA
Andrew Clearwater serves as Director of Privacy at OneTrust. Mr. Clearwater is a Certified Information Privacy Professional (CIPP/US), holds an LLM in Global Law and Technology and is a licensed attorney. In his role as Director of Privacy, Clearwater provides counsel, leadership, and guidance on data protection. He is also responsible for providing public policy analysis in the areas of privacy, data security, information policy, and technology transactions.
Before joining OneTrust, Mr. Clearwater was the Privacy Officer for RxAnte. Clearwater also held privacy roles at the Future of Privacy Forum, as well as the Network Advertising Initiative. In addition, he made contributions to the NTIA mobile application transparency discussion, helped launch a privacy seal program for companies that use consumer energy data, participated as a member of the W3C Tracking Protection Working Group, and taught as an adjunct professor of privacy and technology law at the University of Maine.
Before joining OneTrust, Mr. Clearwater was the Privacy Officer for RxAnte. Clearwater also held privacy roles at the Future of Privacy Forum, as well as the Network Advertising Initiative. In addition, he made contributions to the NTIA mobile application transparency discussion, helped launch a privacy seal program for companies that use consumer energy data, participated as a member of the W3C Tracking Protection Working Group, and taught as an adjunct professor of privacy and technology law at the University of Maine.
Elizabeth Delahoussaye, RHIA, CHPS
Chief Privacy Officer, Ciox Health; Former Speaker of the House of Delegates, AHIMA, Alpharetta, GA
Chief Privacy Officer, Ciox Health; Former Speaker of the House of Delegates, AHIMA, Alpharetta, GA
Elizabeth Delahoussaye is the Chief Privacy Officer for Ciox Health, with corporate headquarters located in Alpharetta, GA. Elizabeth has served on AHIMA Board of Directors and was the Speaker of the House of Delegates in 2016. She has also served as a representative for THIMA on the AHIMA House of Delegates, as well as President-Elect and President for THIMA from 2008-2010. Elizabeth has served on various committees at the national level with AHIMA, including as co-chair on AHIMA ROI Tool Kit in 2013, the AHIMA Annual Program Committee in 2014-2015, and is currently serving on the AHIMA Privacy and Security Council. In 2013 she received the THIMA Distinguished Member Award for her many years of volunteering on both the state and national level.
Alta Whisnant, MS, RHIA, CHC
Vice President and Enterprise Privacy Official, Envision Healthcare Corporation, Nashville, TN
Vice President and Enterprise Privacy Official, Envision Healthcare Corporation, Nashville, TN
Alta Whisnant is the Privacy Officer for Envision Healthcare Corporation and is certified in Healthcare Compliance. She is a seasoned healthcare compliance/privacy professional whose experience spans more than 15 years in the compliance/privacy arena and has over 35 years of healthcare experience overall. Ms. Whisnant joined AmSurg Corp. in 2007 as Director of Compliance & Privacy and in 2015 she was named Vice President, Compliance/Privacy Official. AmSurg and Envision merged in 2017 and Ms. Whisnant became the Corporate Privacy Officer for Envision Healthcare Corporation. Prior to joining AmSurg, Ms. Whisnant served in positions of Health Information Management/Privacy Officer for several healthcare systems.
Anne Kimbol, JD, LLM
Assistant General Counsel and Chief Privacy Officer, HITRUST; Former General Counsel, Texas Health Services Authority, Frisco, TX
Assistant General Counsel and Chief Privacy Officer, HITRUST; Former General Counsel, Texas Health Services Authority, Frisco, TX
Anne Kimbol is the Assistant General Counsel and Chief Privacy Officer for HITRUST. In this role, she works on legal issues for the company and leads the company’s efforts in the areas of privacy and related policy. She holds the CIPP/US, CIPP/E, CIPM, and CHPC certifications. She has also been recognized as a Fellow in Information Privacy by the International Association of Privacy Professionals.
Erika Riethmiller, MS, CIPP/US, CISM, CPHRM
Chief Privacy Officer and Sr. Director of Privacy Strategy, University of Colorado Health; Former Director of Corporate Privacy, Anthem; Former Privacy Officer, State of Colorado, Department of Health Care Policy and Financing, Aurora, CO
Chief Privacy Officer and Sr. Director of Privacy Strategy, University of Colorado Health; Former Director of Corporate Privacy, Anthem; Former Privacy Officer, State of Colorado, Department of Health Care Policy and Financing, Aurora, CO
Erika Riethmiller is the Chief Privacy Officer & Senior Director of Privacy Strategy for University of Colorado Health. Previously, she was the Director of Corporate Privacy for Anthem, Inc. and the Privacy Officer for The State of Colorado, Department of Health Care Policy & Financing. She is a past president and board member of the Colorado Healthcare Associate Risk Managers.
Iliana Peters, JD, LLM
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Iliana L. Peters is a shareholder for Polsinelli, PC. For more than twelve years, she both developed health information privacy and security policy, including on emerging technologies and cyber threats, for the Department of Health and Human Services, and enforced HIPAA regulations, as both the Senior Advisor for HIPAA Enforcement for over six years, and as Acting Deputy Director for HIPAA. As a CISSP, Iliana works hard to bridge the gap between legal requirements for the security of health data and security industry best practices, so that clients can better understand data security issues and jargon. She is excited to bring her extensive experience drafting, implementing, and enforcing health privacy and security regulations and guidance to a practice that focuses on helping clients develop and implement good data privacy and security practices to avoid risk, and helping clients prepare for and recover from emerging cyber threats.