A tailored course, built for your situation
Mastering ISO 27799 for Chief Compliance Officers in Healthcare
Become the recognized authority on health information security and compliance in your organization
Who this is for
Senior compliance and privacy leaders in healthcare organizations who are expected to align ISO standards with HIPAA, internal risk frameworks, and executive decision-making
Who this is not for
Individuals new to compliance or those without responsibility for information security frameworks or cross-functional coordination
What you walk away with
- Lead ISO 27799 implementation with confidence and organization-wide credibility
- Position yourself as the internal reference on health information security controls
- Align ISO 27799 controls with HIPAA requirements and audit expectations
- Deliver clear, authoritative responses during executive reviews and regulator-facing discussions
- Build repeatable templates and playbooks that reinforce your status as the subject matter expert
The 12 modules (with all 144 chapters)
- Origins of ISO 27799
- Healthcare context for security
- Linking to HIPAA Privacy Rule
- Linking to HIPAA Security Rule
- Scope of protected health information
- Roles in health information handling
- Baseline control mapping
- Risk assessment alignment
- Regulatory overlap awareness
- Executive reporting expectations
- Audit preparedness fundamentals
- Control ownership models
- Role-based access principles
- User provisioning workflows
- Privileged access oversight
- Session timeout enforcement
- Multi-factor authentication use
- Emergency access design
- Access review cycles
- Delegation controls
- Service account governance
- Access logging standards
- Incident linkage procedures
- Audit trail retention
- Data classification schema
- PHI labeling standards
- Data lifecycle stages
- Storage location inventory
- Cloud asset tracking
- Mobile device handling
- Third-party data flows
- Asset ownership rules
- Decommissioning procedures
- Data retention alignment
- Legal hold requirements
- Audit-ready asset logs
- Privacy impact assessments
- Vendor onboarding checks
- Data minimization tactics
- Consent management models
- Notice distribution methods
- Opt-out mechanism design
- Data anonymization standards
- Re-identification risk control
- Processing agreement terms
- Breach notification triggers
- Patient data rights workflows
- Internal privacy monitoring
- Incident definition criteria
- Detection mechanisms
- Escalation pathways
- Response team roles
- Containment protocols
- Forensic readiness
- Legal counsel notification
- Regulator reporting timelines
- Patient notification rules
- Post-event review process
- Corrective action tracking
- Documentation retention
- Critical system identification
- Recovery time objectives
- Failover testing schedules
- Data backup verification
- Alternate site readiness
- Staff communication plans
- Vendor dependency review
- Insurance alignment
- Regulatory reporting continuity
- Patient access assurance
- Audit documentation
- Plan maintenance cycle
- Vendor risk classification
- Pre-contract review steps
- Due diligence checklists
- BAAs and data clauses
- Audit right negotiations
- Ongoing monitoring frequency
- Performance issue handling
- Subcontractor oversight
- Exit process controls
- Penetration test sharing
- Compliance reporting demands
- Termination safeguards
- Control mapping methodology
- Evidence collection workflow
- Control testing procedures
- Gap identification process
- Remediation tracking
- Management sign-off steps
- Audit committee reporting
- Internal auditor coordination
- External auditor liaison
- Corrective action timelines
- Follow-up audit preparation
- Continuous monitoring setup
- Role-based curriculum design
- Onboarding integration
- Phishing simulation use
- Annual training delivery
- Manager accountability
- Content refresh cycle
- Policy attestation methods
- Compliance quiz design
- Reporting awareness metrics
- Incident reporting culture
- Leadership messaging
- External benchmarking
- Policy hierarchy structure
- Stakeholder review process
- Approval workflows
- Version control system
- Distribution methods
- Acknowledgment tracking
- Enforcement standards
- Exception handling
- Legal alignment checks
- Industry update integration
- Review cycle schedule
- Retirement procedures
- Risk dashboard design
- Executive summary writing
- KPIs for compliance
- Incident escalation levels
- Budget justification
- Strategic initiative alignment
- Board-level summary prep
- Metrics interpretation
- Trend reporting
- Outsider explanation skills
- Timeline clarity
- Action recommendation framing
- Continuous monitoring tools
- Automated control checks
- Internal audit integration
- Feedback loop design
- Benchmarking against peers
- Regulatory change tracking
- Team knowledge sharing
- Mentorship development
- Innovation encouragement
- Lessons learned capture
- Annual improvement plan
- Succession planning
How this maps to your situation
- New regulatory scrutiny on health data
- Increasing third-party vendor complexity
- Executive demand for compliance clarity
- Need for audit-ready posture
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 2.5 hours per module, designed for completion in 2-3 weeks with consistent pacing.
How this compares to the alternatives
Unlike generic compliance courses, this program is tailored to healthcare Chief Compliance Officers and centers on ISO 27799 as the benchmark for health information security , combining structured learning with actionable frameworks you can deploy immediately.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.