AGENDA: CERTIFICATION PRECONFERENCE
MONDAY, MARCH 22, 2021
(Separate registration required. Registration includes preparatory course, practice exam and certification exam.)
CERTIFIED CYBER SECURITY ARCHITECTSM (CCSASM) TRAINING
Learning Objectives:
- Examine how to establish a compliance and cybersecurity program based on the NIST Cybersecurity Framework.
- Step through the new DoD cybersecurity mandate, CMMC, a standard for securing the cyber supply chain.
- Leverage NIST standards for incident response, encryption and other key areas for a credible, audit-ready, HIPAA compliance program.
- Understand how to align your HIPAA compliance program with the NIST Cybersecurity Framework.
10:00 am EDT
Welcome, Introduction and CCSA Course Content
Uday O. Ali Pabrai, MSEE, CMMC RP, CISSP, HITRUST (CCSFP)
Chief Executive and Co-founder, ecfirst (A HITRUST Authorized External Assessor & CMMC RPO), Waukee, IL
Chief Executive and Co-founder, ecfirst (A HITRUST Authorized External Assessor & CMMC RPO), Waukee, IL
Ali Pabrai is the CEO of ecfirst. A highly sought after information security and regulatory compliance expert, he has successfully delivered solutions on compliance and information security to organizations worldwide. Mr. Pabrai has presented opening keynote and other sessions at several conferences, including ISACA, ISSA, FBI InfraGard, HIMSS, HCFA, HIPAA Summit, Microsoft Tech Forum, NASEBA Healthcare Congress (Middle East), Kingdom Healthcare (Saudia Arabia), Internet World, DCI Expo, Comdex, Net Secure, Nurse Practitioners Conference, National Council for Prescription Drug Programs (NCPDP), National Council for State Board of Nursing IT Conference, and many others.
12:30 pm EDT
Adjournment/Visit Exhibit Hall
OPENING PLENARY SESSION: PRIVACY
1:05 pm EDT
Welcome, Introductions and Summit Overview
Adam Greene, JD, MPH
Partner and Co-chair, Health Information, & HIPAA Practice, Davis Wright Tremaine LLP, HIPAA Summit Distinguished Service Award Winner, Former Senior Health Information Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Co-chair)
Partner and Co-chair, Health Information, & HIPAA Practice, Davis Wright Tremaine LLP, HIPAA Summit Distinguished Service Award Winner, Former Senior Health Information Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Co-chair)
Adam Greene is a partner in the Washington, D.C. office of Davis Wright Tremaine and co-chair of its Health Information Group. Adam primarily counsels health care providers, technology companies, and financial institutions on compliance with health information privacy, security, and breach notification rules. Previously, Adam was a regulator at the U.S. Department of Health and Human Services, where he played a fundamental role in administering and enforcing the HIPAA rules. At HHS, Adam was responsible for determining how HIPAA rules apply to new and emerging health information technologies and was instrumental in the development of the current HIPAA enforcement process. Adam has been recognized as one of the top ten influencers in health information security, one of the top 50 healthcare IT experts, and is a frequent speaker and author on health information privacy and security issues.
1:30 pm EDT
Update from the HHS Office for Civil Rights
Timothy Noonan, JD
Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
2:00 pm EDT
OCR Update on HIPAA Compliance and Enforcement
Serena Mosley-Day, JD, MPM, LLM
Senior Advisor for HIPAA Compliance and Enforcement, Office for Civil Rights, US Department of Health and Human Services, Former Assistant Regional Counsel, Social Security Administration, Washington, DC
Senior Advisor for HIPAA Compliance and Enforcement, Office for Civil Rights, US Department of Health and Human Services, Former Assistant Regional Counsel, Social Security Administration, Washington, DC
Serena Mosley-Day is the Senior Advisor for HIPAA Compliance and Enforcement, Office for Civil Rights (OCR), the U.S. Department of Health and Human Services (HHS). Serena has been with HHS OCR since December 2013. Prior to serving as Senior Advisor, Serena was the Deputy Regional Manager, Southeast Region of HHS/OCR. Before joining HHS/OCR, Serena was an attorney at the Social Security Administration and a supervisory attorney for the U.S. Department of Education, Office for Civil Rights.
2:30 pm EDT
OCR Update on HIPAA Policy
Marissa Gordon-Nguyen, MPH, JD
Senior Advisor for HIPAA Policy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Senior Advisor for HIPAA Policy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Marissa Gordon-Nguyen is the Senior Advisor for Health Information Privacy Policy in the Office for Civil Rights (OCR), U.S. Department of Health and Human Services (HHS). In this role, she leads OCR’s administration of the HIPAA Rules through rulemaking initiatives and the development of sub-regulatory guidance. She also advises federal agencies, advisory committees, and Congressional offices on aspects of the HIPAA Rules and their underlying privacy and security principles, among other responsibilities. Marissa joined OCR’s Health Information Privacy Division in 2009.
2:45 pm EDT
OCR Faculty Q&A
3:30 pm EDT
Break/Visit Exhibit Hall
3:45 pm EDT
FTC Update
Elisa K. Jillson, JD
Attorney, Division of Privacy and Identity Protection, Bureau of Consumer Protection, US Federal Trade Commission, Washington, DC
Attorney, Division of Privacy and Identity Protection, Bureau of Consumer Protection, US Federal Trade Commission, Washington, DC
Elisa Jillson is an attorney in the FTC’s Division of Privacy and Identity Protection in the Bureau of Consumer Protection, where she works on policy matters, investigations, and litigation related to privacy and data security. Elisa was previously an attorney in the FTC’s Division of Enforcement, in the Bureau of Consumer Protection, where she worked primarily on order enforcement and litigation related to advertising and data security. She has lectured on privacy as part of a consumer protection course at George Mason University’s Scalia Law School. Before joining the FTC, Elisa was an associate at Sidley Austin LLP in Washington, DC and a project manager for an electronic health record vendor.
4:15 pm EDT
Update on 42 CFR Part 2, the Privacy Rule that Governs Substance Use Disorder Treatment Records
Neeraj Gandotra, MD
Chief Medical Officer, Substance Abuse, and Mental Health Services Administration (SAMHSA); Instructor, Department of Psychiatry, Johns Hopkins University School of Medicine, Rockville, MD
Chief Medical Officer, Substance Abuse, and Mental Health Services Administration (SAMHSA); Instructor, Department of Psychiatry, Johns Hopkins University School of Medicine, Rockville, MD
Dr. Gandotraserves as the Chief Medical Officer for SAMHSA. He previously served as the Chief Medical Officer for a nationwide addiction treatment network where he developed national strategies aimed at reducing risk and improving outcomes. He is familiar with the development and utilization of medical services budgets, nuances of regulations, and code across various states. He supervised providers across facilities and provided expertise to elected and appointed officials in local markets.As Medical Director of Addiction Treatment Services at Johns Hopkins,Dr. Gandotridirected patient care through implementation of department initiatives and medical center resources, andwas responsible for developing program policy and procedures.In addition to his clinical work, Dr. Gandotra is a member of the American Society of Addiction Medicine and American Academy of Addiction Psychiatry. Dr. Gandotra has also worked with the Maryland State Attorney General, and the NFL player’s assistance program for substance use disorders.
4:35 pm EDT
EEOC Guidance for Managing Employee Medical Information
Joyce Walker-Jones, JD
Senior Attorney Advisor, Americans with Disabilities Act (ADA) and Genetic Information Nondiscrimination Act (GINA) Policy Division, Office of Legal Counsel, US Equal, Employment Opportunity Commission (EEOC), Washington, DC
Senior Attorney Advisor, Americans with Disabilities Act (ADA) and Genetic Information Nondiscrimination Act (GINA) Policy Division, Office of Legal Counsel, US Equal, Employment Opportunity Commission (EEOC), Washington, DC
Joyce Walker-Jones a Senior Attorney Advisor at the U.S. Equal Employment Opportunity Commission in Washington, DC, advises the Commission on the interpretation and application of Title I of the Americans with Disabilities Act (ADA), the Genetic Information Nondiscrimination Act, Title VII, and the Age Discrimination in Employment Act. She assisted in drafting amendments to the Commission’s ADA regulations and has written several agency guidances. Ms. Walker-Jones has served as a government fellow on the American Bar Association’s Section of Labor and Employment Law, and has been an attorney at the EEOC since 1987.
5:05 pm EDT
Lessons Learned from Emerging Privacy Data Threats during a Pandemic
Russ Branzell, MS
President & CEO, CHIME, Ann Arbor, Michigan
President & CEO, CHIME, Ann Arbor, Michigan
Russ Branzell is CEO and president of the College of Healthcare Information Management Executives (CHIME). In addition to his position at CHIME, he serves on the faculty at Columbia University where he teaches executive HIT classes. Russ is a member of the Baldrige Foundation Board and former member of the Board of Overseers of the Malcolm Baldrige National Quality Award, a position that was appointed by the Secretary of Commerce. Prior to joining CHIME, Mr. Branzell served in numerous administration positions for several healthcare organizations, including the Air Mobility Command Surgeon General’s Office while serving in the US Air Force.
Darren Dworkin
Senior Vice President of Enterprise Information Systems and Chief Information Officer, Cedars-Sinai Health System, Former Chief Technology Officer, Boston Medical Center, Los Angeles, CA
Senior Vice President of Enterprise Information Systems and Chief Information Officer, Cedars-Sinai Health System, Former Chief Technology Officer, Boston Medical Center, Los Angeles, CA
Gary Goodin, MBA, ZTSX-I
Chief Technology and Security Officer, Seattle Children’s Hospital, Seattle, WA
Chief Technology and Security Officer, Seattle Children’s Hospital, Seattle, WA
Gary Goodin is currently the Chief Technology and Security Officer (CTSO) for Seattle Children’s (Hospital, Research, Foundation). Prior to the CTSO role, Gary was driving the IT Security Strategy for the organization (people, process and technology). He and his team were executing against a roadmap that was created in an effort to modernize the Information security footprint within the hospital, research and foundation environment both from a technology and governance perspective (inclusive of the technology for physical security). In his current role as CTSO he is now creating an aligned strategy for core infrastructure and security. Gary previously held a similar role at Children’s Hospital Los Angeles. Prior to joining Seattle Children’s, Gary spent the last 26yrs at Children’s Hospital Los Angeles, Amgen, Mattel and The Walt Disney Company in several IT executive leadership roles within Information Systems Infrastructure and Application Development and delivery.
Jacki Monson, JD, CHC, CHPC
Vice President, Chief Privacy and Information Security Officer, Sutter Health, Former Chief Privacy Officer, Mayo Clinic, Sacramento, CA
Vice President, Chief Privacy and Information Security Officer, Sutter Health, Former Chief Privacy Officer, Mayo Clinic, Sacramento, CA
Nick Culbertson, MD
Cofounder and Chief Executive Officer, Protenus, Former Green Beret and 2 Bronze Star Recipient, Baltimore, MD (Moderator)
Cofounder and Chief Executive Officer, Protenus, Former Green Beret and 2 Bronze Star Recipient, Baltimore, MD (Moderator)
Nick Culbertson is the Co-Founder and CEO of Protenus, a leading healthcare compliance analytics platform.