4 ms·
You could just have hospitals be required to meet FedRAMP compliance. It is kind of crazy that hipaa compliance isn’t encompassing enough
by baskire 6y ago
You could just have hospitals be required to meet FedRAMP compliance.
It is kind of crazy that hipaa compliance isn’t encompassing enough
- 1MachineElf 6y agoLikewise, I love FISMA, but I don't think hospitals would cease operations just because their systems couldn't get an ATO. What kind of accountability would motivate them to complete POAMs with any urgency? I don't think there is an effective way to incentivize a proactive approach - financial penalties would simply be indirectly paid for by customers.
- stjohnswarts 6y agoI this case I think they could just have the proper regulations and use the "stick" portion of "carrot and stick" with fines.