Question
A large hospital has an existing contract with a vendor in another country to provide software support and maintenance of the hospitals patient records Information
A large hospital has an existing contract with a vendor in another country to provide software support and maintenance of the hospitals patient records Information system. From the hospital management perspective, which of the following controls would be most effective to address privacy risks related to this outsourcing arrangement? a) Conduct periodic reviews of the privacy policy to ensure that the existing policy meets current legislation requirements in both regions. b) Include a wright to audit clause in the contract and impose detailed security obligations on the outsourced vendor. c) Implement mandatory privacy training for management to help with identifying privacy risks when outsourcing services. d) Develop an incident monitoring and response plan to track breaches from internal and external sources.
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started