Skip to main content

Why She in ISO 27799

$349.00
Who trusts this:
Trusted by professionals in 160+ countries
Toolkit Included:
Includes a practical, ready-to-use toolkit containing implementation templates, worksheets, checklists, and decision-support materials used to accelerate real-world application and reduce setup time.
Your guarantee:
30-day money-back guarantee — no questions asked
When you get access:
Course access is prepared after purchase and delivered via email
How you learn:
Self-paced • Lifetime updates
Adding to cart… The item has been added

This curriculum spans the equivalent depth and breadth of a multi-workshop governance program, addressing the full lifecycle of health information security from policy formation and risk assessment to incident response and cultural sustainment, as typically managed in complex healthcare organizations with hybrid IT environments and interconnected clinical ecosystems.

Module 1: Establishing the Governance Framework for Health Information Security

  • Define the scope of health information assets subject to ISO 27799 controls based on jurisdictional data classifications and organizational data flows.
  • Select governance roles (e.g., Data Steward, Security Officer, Clinical Information Custodian) with clear RACI assignments for health data protection.
  • Map existing regulatory obligations (e.g., HIPAA, GDPR, PIPEDA) to ISO 27799 control objectives to avoid duplication and identify coverage gaps.
  • Determine the escalation path for data breaches involving protected health information (PHI), including mandatory reporting timelines and stakeholder notifications.
  • Integrate clinical leadership into governance committees to ensure security decisions reflect care delivery workflows and patient safety implications.
  • Decide whether to adopt ISO 27799 as a standalone framework or align it with an existing ISMS based on ISO 27001.
  • Evaluate the feasibility of applying ISO 27799 to third-party cloud providers hosting electronic health records (EHRs) under shared responsibility models.
  • Establish a formal process for reviewing and updating governance policies in response to changes in clinical technology or regulatory enforcement.

Module 2: Risk Assessment Specific to Health Data Environments

  • Conduct threat modeling for high-risk clinical systems such as radiology PACS, ICU monitoring devices, and telehealth platforms.
  • Assess insider threat risks related to privileged access by clinicians, administrative staff, and IT support personnel.
  • Identify vulnerabilities in legacy medical devices that cannot support modern encryption or patching requirements.
  • Quantify the impact of unauthorized access to genetic or mental health data using harm-based risk scoring models.
  • Perform data flow mapping across referral networks, laboratories, and public health agencies to locate unsecured data transit points.
  • Document residual risks accepted due to clinical necessity, such as unencrypted data transfer in emergency care settings.
  • Validate risk assessment findings with clinical department heads to ensure operational realism and avoid control overreach.
  • Integrate risk treatment plans into capital budget cycles for medical equipment upgrades with security requirements.

Module 3: Designing Access Control Policies for Clinical Workflows

  • Implement role-based access control (RBAC) models aligned with clinical job functions (e.g., nurse, radiologist, billing coder) and care settings.
  • Define just-in-time and just-enough access protocols for temporary staff and locum physicians during peak demand periods.
  • Configure emergency override access mechanisms with mandatory audit logging and post-event review requirements.
  • Negotiate access delegation rules for on-call physicians covering multiple departments or facilities.
  • Enforce multi-factor authentication for remote access to EHR systems while minimizing disruption to time-sensitive clinical tasks.
  • Restrict bulk data export capabilities based on user role and purpose, with automated alerts for anomalous download patterns.
  • Integrate access revocation workflows with HR offboarding systems to eliminate orphaned accounts for departed staff.
  • Test access control policies during clinical simulations to evaluate usability under time pressure and high workload.

Module 4: Securing Health Data Across Hybrid IT Environments

  • Apply encryption standards (e.g., AES-256) to PHI at rest in databases, backups, and test environments with key management oversight.
  • Configure secure data exchange protocols (e.g., TLS 1.3, AS2) for interoperability between EHRs, HIEs, and public health registries.
  • Isolate medical IoT devices on segmented networks with firewall rules restricting lateral movement and external connectivity.
  • Implement data loss prevention (DLP) rules tuned to detect and block unauthorized transmission of diagnosis codes or patient identifiers.
  • Enforce secure configuration baselines for mobile devices used by home health nurses and visiting clinicians.
  • Validate cloud service provider configurations against ISO 27799 control 7.4 for data storage location and jurisdictional compliance.
  • Conduct penetration testing on patient portals with explicit scope limitations to avoid disruption to live clinical systems.
  • Manage patching schedules for clinical systems to balance security updates with availability requirements for critical care services.

Module 5: Managing Third-Party Risk in Healthcare Ecosystems

  • Conduct security assessments of business associates (e.g., transcription services, billing vendors) using ISO 27799-aligned questionnaires.
  • Negotiate data processing agreements that specify security responsibilities for PHI handled by SaaS providers.
  • Monitor third-party access to health data through centralized logging and periodic access reviews.
  • Require evidence of independent audits (e.g., SOC 2, HITRUST) from cloud vendors hosting sensitive clinical workloads.
  • Establish incident response coordination procedures with external partners for joint breach investigations.
  • Enforce data minimization in vendor contracts by limiting the types and volume of PHI shared for operational purposes.
  • Terminate contracts with vendors that fail to remediate critical security findings within agreed timeframes.
  • Implement vendor offboarding procedures to ensure complete data deletion or return upon contract expiration.

Module 6: Audit and Monitoring for Compliance and Accountability

  • Define audit log content requirements for EHR systems to capture user identity, timestamp, data element accessed, and action performed.
  • Retain audit logs for minimum periods required by law (e.g., 6 years under HIPAA) with integrity protection mechanisms.
  • Configure automated alerts for suspicious activities such as off-hours access, repeated failed logins, or access to VIP patient records.
  • Conduct regular log reviews using clinical input to distinguish legitimate care activities from potential misuse.
  • Respond to audit findings by updating access policies, retraining staff, or initiating disciplinary actions as warranted.
  • Prepare for regulatory audits by organizing evidence of control implementation in a retrievable, time-stamped format.
  • Use audit data to support forensic investigations following suspected data breaches or insider threats.
  • Balance monitoring scope with privacy expectations of clinicians by defining acceptable surveillance boundaries.

Module 7: Incident Response and Breach Management in Clinical Settings

  • Classify incidents involving health data using severity criteria based on data sensitivity, number of records, and potential harm.
  • Activate incident response teams with defined roles for IT, legal, communications, and clinical leadership.
  • Preserve evidence from clinical systems while minimizing disruption to ongoing patient care operations.
  • Assess breach notification obligations under applicable laws, including timelines and required content for patient notices.
  • Coordinate with law enforcement when criminal activity (e.g., ransomware, data theft) is suspected.
  • Conduct post-incident reviews to identify root causes and update controls to prevent recurrence.
  • Manage public communications with approved messaging to maintain organizational reputation and patient trust.
  • Report breaches to regulatory bodies using mandated forms and supporting documentation within legal deadlines.

Module 8: Privacy by Design and Data Lifecycle Management

  • Embed privacy controls into the design of new clinical applications, including data minimization and purpose limitation.
  • Define retention periods for different categories of health records based on legal, regulatory, and clinical requirements.
  • Implement secure data destruction methods (e.g., cryptographic erasure, physical destruction) for decommissioned storage media.
  • Establish data anonymization procedures for research and analytics use cases while preserving data utility.
  • Control the creation of unauthorized data copies (e.g., spreadsheets, USB drives) through technical and policy enforcement.
  • Classify data based on sensitivity (e.g., HIV status, substance abuse history) to apply enhanced protection measures.
  • Integrate data lifecycle policies into EHR configuration to automate record archiving and deletion.
  • Train clinical staff on proper handling of paper records and verbal disclosures in shared environments.

Module 9: Governance of Emerging Technologies in Healthcare

  • Assess security and privacy implications of AI-driven diagnostic tools using ISO 27799 control 12.7 on system acquisition.
  • Establish governance protocols for wearable health devices that transmit patient data to clinical systems.
  • Regulate the use of consumer messaging apps (e.g., WhatsApp, SMS) for care coordination through policy and technical controls.
  • Oversee pilot programs for blockchain-based health data exchange with clear evaluation criteria and exit strategies.
  • Define data ownership and access rights for patient-generated health data uploaded to EHRs.
  • Implement security controls for voice-enabled clinical documentation tools to prevent eavesdropping and unauthorized access.
  • Review ethical implications of predictive analytics models that use sensitive health data for risk stratification.
  • Update governance frameworks to address cybersecurity risks associated with remote patient monitoring at home.

Module 10: Sustaining Governance Through Performance and Culture

  • Define key performance indicators (KPIs) for security controls, such as patch compliance rates and incident response times.
  • Conduct annual governance maturity assessments using ISO 27799 as a benchmarking tool.
  • Deliver role-specific security training for clinicians, administrators, and IT staff with realistic clinical scenarios.
  • Integrate security performance into clinical quality review meetings to reinforce accountability.
  • Address cultural resistance to security controls by involving clinical champions in policy development.
  • Report governance metrics to executive leadership and boards using dashboards focused on risk exposure and mitigation.
  • Revise policies based on feedback from frontline staff to improve adherence and operational feasibility.
  • Conduct tabletop exercises simulating health data incidents to test coordination and decision-making under pressure.