HIPAA and ISO 27001 Compliance for a Mental Health Organization

HIPAA and ISO 27001 Compliance for a Mental Health Organization

Industry
Healthcare, Education, Nonprofit
Service
Security & Compliance Consulting

Summary

A US nonprofit association for mental health and addiction treatment organizations had security policies in place and in progress but lacked the in-house expertise to be sure they met HIPAA and ISO 27001. INNERLUXES assessed the policies, found the gaps — chiefly in IT security risk assessment and management — and, within four weeks, drafted the missing documents and trained the security team, leaving the organization with a complete view of its IT assets and robust, standards-aligned risk management.

About the Client

The Client is a nonprofit membership association for mental health and addiction treatment organizations across the US. For over 50 years it has advocated for lifesaving legislation and provided state-of-the-science training on mental health and substance use challenges.

Compliance Concerns Without In-House Expertise

The Client had security policies in use and under development but lacked in-house compliance competencies to ensure adherence to HIPAA and ISO 27001. To close that knowledge gap, it sought a cybersecurity consulting provider with hands-on experience in healthcare compliance and approached INNERLUXES to review and improve its security policies.

Assessing Policies and Drafting What Was Missing

An INNERLUXES auditor assessed the compliance of the Client's IT security policies with HIPAA and ISO 27001 requirements, and found the organization lacked the policies and supporting documents for IT security risk assessment and management that both standards require. INNERLUXES then drafted the missing documents:

  • An asset inventory of asset passports with unique identifiers, assignment data (owner and custodian, use, storage), and security details (confidentiality, integrity, and availability ratings, and security class).
  • A data classification policy based on the sensitivity, value, and criticality of data to operations and business continuity — fundamental to asset management, and a basis for identifying risks per data type and choosing appropriate controls.
  • A risk management policy defining how to identify, assess, prioritize, manage, and mitigate information security risks under ISO 27001 and HIPAA, with a framework of templates and practices for performing, documenting, and monitoring risk management.

With the documents in place, INNERLUXES trained the Client's IT security team on the new policies and procedures, covering the threats to the organization's IT assets and how to perform cybersecurity risk assessments and asset management.

Compliant Policies in Four Weeks

  • In just four weeks, INNERLUXES assessed and enhanced the Client's IT security policies' compliance with HIPAA and ISO 27001.
  • The Client gained a complete picture of its IT assets, practical knowledge of cybersecurity risk-assessment best practices, and robust risk management procedures.
  • The Client was fully satisfied and plans to engage INNERLUXES again for penetration testing.

Cybersecurity Frameworks Used

  • FIPS 199 — Standards for Security Categorization of Federal Information and Information Systems.
  • NIST SP 800-30 — Guide for Conducting Risk Assessments.
  • NIST SP 800-39 — Managing Information Security Risk.
  • ISO/IEC 27005:2018 — Information security risk management.