Skip to main content
Image coming soon

SEC0723 Building a Scalable Security Program for Regulated Healthcare

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Building a Scalable Security Program for Regulated Healthcare

A step-by-step guide to designing, justifying, and defending a security program that scales under regulatory scrutiny

$199 one-time
30-day money-back guarantee Verified against latest insights, updated access provided within 24h

Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.

12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Spending cycles rebuilding audit narratives because control justifications lack depth or consistency

The situation this course is for

Security leaders with strong technical grounding still face rework when their control mappings don’t reflect auditable, principle-backed reasoning. The gap isn’t effort, it’s structured defensibility. Without a consistent framework for explaining *why* a control is designed a certain way, teams waste time retrofitting narratives under deadline pressure.

Who this is for

Senior security practitioners in regulated healthcare who hold or reference CISSP, leading security program design and audit response

Who this is not for

Entry-level compliance staff, non-technical policy writers, or consultants without healthcare context

What you walk away with

  • Build a security control narrative that withstands auditor and legal scrutiny
  • Reduce rework in audit preparation by aligning controls to CISSP domains from the start
  • Use your CISSP knowledge as a working tool, not just a credential
  • Document decisions with source-backed reasoning that reflects NIST and HIPAA alignment
  • Create repeatable templates for control justification that scale across teams

The 12 modules (with all 144 chapters)

Module 1. Aligning CISSP Domains to Healthcare Security Needs
Map each CISSP domain to real-world healthcare security decisions, from access control in EHR systems to risk assessment in telehealth platforms.
12 chapters in this module
  1. Introduction to CISSP as a decision-making framework in healthcare
  2. Matching CISSP Domain 1 to HIPAA Security Rule requirements
  3. Applying security governance principles to medical device oversight
  4. How risk management (Domain 2) shapes third-party vendor assessments
  5. Linking asset classification to patient data handling policies
  6. Using CISSP’s security model to justify firewall segmentation in clinics
  7. Integrating regulatory requirements into security program objectives
  8. Case study: CISSP alignment in a recent OCR audit
  9. Common gaps between CISSP knowledge and healthcare implementation
  10. Building a crosswalk between NIST CSF and CISSP domains
  11. Documenting decisions using CISSP-aligned rationale
  12. Module 1 action plan: Draft your domain-to-function mapping
Module 2. Designing Defensible Access Control Systems
Create access control models that pass auditor review by grounding them in least privilege, role-based design, and clinical workflow realities.
12 chapters in this module
  1. Access control in healthcare: Beyond username and password
  2. Applying MAC, DAC, and RBAC to EHR and scheduling systems
  3. Designing role matrices for clinical vs. administrative staff
  4. Justifying segregation of duties in pharmacy and billing systems
  5. Documenting access reviews with audit-ready evidence
  6. Handling emergency access without compromising compliance
  7. Mapping access controls to HIPAA technical safeguards
  8. Using logging and monitoring to support access accountability
  9. Case study: How a hospital reduced access exceptions by 60%
  10. Common auditor findings in access control reviews
  11. Template: Access control policy with defensible rationale
  12. Module 2 action plan: Audit one role in your system
Module 3. Risk Assessments That Stand Up to Scrutiny
Conduct risk assessments that are repeatable, evidence-based, and aligned with both NIST and CISSP standards.
12 chapters in this module
  1. The anatomy of a defensible risk assessment in healthcare
  2. Using NIST SP 800-30 as a foundation for risk analysis
  3. Documenting threat sources with real-world examples
  4. Calculating impact using clinical, financial, and reputational factors
  5. Linking vulnerabilities to actual system configurations
  6. Creating risk treatment plans with prioritized remediation
  7. Justifying residual risk decisions with executive input
  8. Case study: Risk assessment that survived HHS review
  9. Common mistakes in risk documentation and how to avoid them
  10. Template: Risk register with CISSP-aligned rationale
  11. Integrating risk findings into capital planning
  12. Module 3 action plan: Draft one risk scenario with full justification
Module 4. Building Audit-Ready Policy Frameworks
Develop policies that are not just compliant but defensible, with clear lineage from regulation to implementation.
12 chapters in this module
  1. From regulation to policy: Creating a defensible chain of custody
  2. Structuring policies to reflect HIPAA, HITECH, and state laws
  3. Writing policy statements that support auditor questioning
  4. Linking policy to standards, procedures, and controls
  5. Documenting policy exceptions with risk-based justification
  6. Using version control to show policy evolution over time
  7. Case study: Policy framework that reduced audit findings by 40%
  8. Aligning security policies with organizational culture
  9. Template: Policy with embedded regulatory citations
  10. Training staff on policy using real-world scenarios
  11. Handling policy updates during M&A or system migration
  12. Module 4 action plan: Revise one policy with full rationale
Module 5. Secure Software Development for Clinical Systems
Integrate security into the software lifecycle of EHRs, patient portals, and medical devices.
12 chapters in this module
  1. Applying CISSP Domain 8 to healthcare application security
  2. Integrating security requirements into vendor contracts
  3. Conducting code reviews with clinical safety in mind
  4. Using threat modeling for patient-facing applications
  5. Managing third-party libraries in medical software
  6. Documenting secure development practices for auditors
  7. Case study: Secure rollout of a telehealth platform
  8. Aligning SDLC with HITRUST requirements
  9. Handling patching in 24/7 clinical environments
  10. Template: Secure development checklist with justifications
  11. Training developers on healthcare-specific threats
  12. Module 5 action plan: Assess one application in your environment
Module 6. Third-Party Risk Management with Defensible Rigor
Evaluate vendors with a framework that ensures accountability and reduces downstream liability.
12 chapters in this module
  1. Why third-party risk is a top audit finding in healthcare
  2. Using SIG and CAIQ questionnaires with purpose
  3. Conducting site visits with a CISSP-aligned checklist
  4. Assessing cloud providers under HIPAA BAAs
  5. Documenting vendor risk ratings with clear criteria
  6. Managing subcontractor oversight in SaaS environments
  7. Case study: Vendor incident that didn’t become a breach
  8. Aligning vendor reviews with NIST 800-161
  9. Template: Vendor risk assessment with rationale
  10. Handling vendor non-compliance without contract termination
  11. Integrating vendor data into enterprise risk reporting
  12. Module 6 action plan: Complete one vendor assessment
Module 7. Incident Response That Withstands Review
Design and document an incident response plan that proves readiness and minimizes liability.
12 chapters in this module
  1. Building an IR plan that aligns with HIPAA Breach Notification Rule
  2. Defining roles using CISSP’s incident management framework
  3. Documenting decision logs during active incidents
  4. Conducting tabletop exercises with executive participation
  5. Using playbooks that reflect real healthcare scenarios
  6. Case study: Ransomware response that avoided OCR fines
  7. Maintaining evidence integrity for legal proceedings
  8. Reporting to boards without over-simplifying technical details
  9. Template: Incident response playbook with justification
  10. Integrating IR with cyber insurance requirements
  11. Post-incident review that drives real improvement
  12. Module 7 action plan: Run a mini tabletop exercise
Module 8. Disaster Recovery and Business Continuity in Clinical Settings
Ensure continuity of care while meeting regulatory requirements for resiliency.
12 chapters in this module
  1. Why business continuity is a patient safety issue
  2. Aligning BCP with The Joint Commission standards
  3. Documenting RTOs and RPOs with clinical impact analysis
  4. Testing failover in EHR and pharmacy systems
  5. Case study: Data center outage with zero clinical impact
  6. Using cloud for redundancy without violating BAAs
  7. Template: BCP with role-specific recovery steps
  8. Coordinating with emergency management teams
  9. Handling long-term outages in rural clinics
  10. Integrating BCP into capital planning
  11. Reporting recovery metrics to leadership
  12. Module 8 action plan: Validate one recovery time objective
Module 9. Physical and Environmental Security for Healthcare Facilities
Secure data centers, clinics, and mobile devices with auditable controls.
12 chapters in this module
  1. Applying physical security controls to server rooms and clinics
  2. Using badge systems to enforce least privilege access
  3. Securing mobile devices used by clinical staff
  4. Documenting visitor management for compliance
  5. Case study: Preventing data theft from a stolen laptop
  6. Aligning with NFPA and building codes
  7. Template: Physical security checklist with rationale
  8. Handling security in leased or shared spaces
  9. Integrating CCTV with privacy policies
  10. Training staff on tailgating and social engineering
  11. Auditing physical controls without disrupting operations
  12. Module 9 action plan: Assess one physical location
Module 10. Security Awareness That Changes Behavior
Design training programs that reduce phishing success and improve compliance.
12 chapters in this module
  1. Why most security awareness programs fail in healthcare
  2. Using real phishing data to tailor training content
  3. Designing role-based training for clinical and admin staff
  4. Measuring behavior change, not just completion rates
  5. Case study: 70% reduction in click rates after redesign
  6. Integrating training with credentialing and onboarding
  7. Template: Annual training plan with defensible metrics
  8. Using posters, huddles, and simulations effectively
  9. Handling repeat offenders with coaching, not punishment
  10. Aligning with OSHA and HR policies
  11. Reporting awareness outcomes to leadership
  12. Module 10 action plan: Launch a micro-training campaign
Module 11. Encryption and Data Protection Across the Enterprise
Implement encryption that protects data at rest, in transit, and in use, without disrupting clinical workflows.
12 chapters in this module
  1. When to use AES, TLS, and end-to-end encryption in healthcare
  2. Key management best practices for compliance
  3. Encrypting data in cloud and hybrid environments
  4. Case study: Encryption rollout without EHR downtime
  5. Handling legacy systems that can’t support modern crypto
  6. Documenting data flow diagrams for auditors
  7. Template: Data protection policy with technical rationale
  8. Using tokenization and masking for analytics
  9. Aligning with NIST 800-53 encryption controls
  10. Training staff on encrypted email and file sharing
  11. Auditing encryption coverage across the organization
  12. Module 11 action plan: Map one data flow with protection controls
Module 12. Putting It All Together: The Defensible Security Program
Integrate all components into a cohesive, scalable, and defensible security program.
12 chapters in this module
  1. How the 11 prior modules form a unified program
  2. Creating a single source of truth for all controls
  3. Using dashboards to show program maturity to leadership
  4. Case study: Complete program that passed unannounced audit
  5. Maintaining defensibility during leadership changes
  6. Updating the program as regulations evolve
  7. Template: Security program playbook with rationale
  8. Onboarding new team members using the playbook
  9. Scaling the program to new facilities or acquisitions
  10. Handling regulator questions with confidence
  11. Continuous improvement using feedback loops
  12. Module 12 action plan: Publish your first version of the playbook

How this maps to your situation

  • Audit preparation
  • Regulatory compliance
  • Executive accountability
  • Team scalability

Before vs. after

Before
Spending cycles rebuilding audit narratives, justifying controls post-hoc, and managing rework under deadline pressure.
After
Walking into every compliance conversation with pre-built, source-backed rationales for every control, reducing rework and increasing trust.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per module, recommended over six weeks with team application.

If nothing changes
Without a defensible framework, security decisions remain vulnerable to challenge, requiring last-minute rework and exposing leadership to scrutiny during audits or incidents.

How this compares to the alternatives

Unlike generic CISSP prep courses, this program focuses on applying CISSP knowledge to real healthcare security program challenges, with templates and examples you can use immediately.

Frequently asked

Is this course technical or strategic?
It’s implementation-grade, focused on the tangible artefacts security leaders produce, like control mappings, risk assessments, and policy documents, with CISSP reasoning embedded throughout.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Can I use this with my team?
Yes, each module includes team application exercises and templates designed for group use.
$199 one-time. Approximately 90 minutes per module, recommended over six weeks with team application..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours