Project Description
For this project I plan to research and develop best practices in information security for hospitals. Hospitals are a specialized type of organization and patient confidentiality and protection of information resources is important. Integrity of data is imperative as well as an error in dosage of medication could cause serious injury or death. The key to maintaining good security is developing a good security policy and implementing it in an effective and efficient manner.
I currently am working for a hospital as an IT consultant in their data center. I want to broaden my knowledge and experience in the IT security field and I believe this is an excellent opportunity to do so. Since I have experience dealing with hospitals, I understand many of the issues that hospitals deal with and I believe that it will play an invaluable role when developing my project. I do not want to use my client as a reference for organizational structure or for network architecture, but will instead be using a generic hospital example to illustrate my points.
The output of this project will be a document detailing the security policy and network architecture of a hospital along with recommended procedures and explanations for securing the network. The overall goal of this project is to provide insight as to the common vulnerabilities prevalent in medical hospitals and to provide technology solutions to mitigate unauthorized access of data and other security threats.
Ethical and Legal Assumptions
There are many ethical and legal considerations when dealing with information security in health care organizations. Health care providers and organizations entrusted with personal health information are responsible to protect it against deliberate or inadvertent misuse or disclosure. HIPAA is at the forefront of legislation that requires organizations to protect patient privacy. There are two parts to the HIPAA regulations that outline security standards and implementation specifications: 45 CFR 160, the general administrative requirement and 45 CFR 164 Subpart E Privacy of the Individually Identifiable Health Information. Specific noncompliance with HIPAA can lead to a maximum fine of $250,000.00 and up to ten years imprisonment if an individual obtains health information with the intent to sell, transfer, or use the information for commercial advantage, personal gain or malicious harm. Health organizations face exposure to lawsuits for breach of confidentiality, loss of accreditation, audits by the Centers for Medicare and Medicaid Services (CMS), loss of reputation, and loss of patients or members. Because of these consequences it is in a hospitalbest interests to comply with regulations and take the necessary precautions to safeguard patient data. Along with HIPAA there are other regulations dealing with financial data such as SOX, GLB, and FACTA. Each of these regulations must also be adhered to and add to the case that a comprehensive information security policy is a requirement.
Implementation Strategy
Project Plan
My project plan will involve research in text and articles found on the Web. I am currently working as a consultant for a hospital so my experiences there will help me understand how information security applies in that type of environment. I have family members that are involved in the health care industry and I believe interviewing them may provide insight into the healthcare industry. My father is a physician, my stepmother is a nurse, and my aunt is a health care administrator. Of all these resources I believe my aunt can give me some useful insight as to how regulations are applied.
Tasks and Schedule

Task will be broken down into the following schedule:
Gather resources and interview sources.  Week of July 13, 2008
Review regulation and compliance standards.  Week of July 20, 2008
Research Intrusion methods and consequences (risk management). Week of July 27, 2008
Research security countermeasures: firewalls, intrusion detection systems, and VPN strategies.  Week of August 3, 2008
Research identity management, network access control solutions, methods for securing network devices and complete Security policy.  Week of August 10, 2008
Research Patch and Vulnerability Management Solutions and submit Project Draft  Week of August 31, 2008
Submit Final Paper September 7, 2008
Since I will be conducting this project on my own without using specific security information of my current client my list of stakeholders is limited. I am a stakeholder since I am responsible for producing the report. Professor Gagnon is the approving authority on my project as well as the grader so she may be considered a stakeholder. My father will be providing input to the completion of my project so he may be considered a stakeholder as well. The list is as follows:
Jason Benin – Researcher
Luisito Benin Doctor/ research source
Sharon Gagnon Approving Authority
Risk Management
The risks associated with the completion of the project include maintaining schedule, keeping within the scope of the project, and finding the necessary materials for research. I must ensure that each schedule task receives the necessary time and attention for thorough research and must maintain constant track of my progress to ensure I do not fall behind schedule. I must also stay within the bounds of information security as it is related to hospitals. This is important because the topic of security has a very broad range and I must maintain focus so that the paper does not go off onto tangents that are unrelated to the subject material. Lack of appropriate research materials may be a concern but I should make use of the resources provided by the Capella online library, my local library, my own personal book collection, research materials on the Web to guarantee that each topic is properly researched and cited. All three of these risk factors can be mitigated by my actions and it is up to me to ensure that I take the appropriate steps to complete this project to the best of my ability and on time.
Stallings, W., Brown, L. (2008) Computer Security: Principles and Practice. Upper Saddle River, NJ: Prentice Hall.
Vasant, R., Fichadia, A. (2007) Risks, Controls, and Security: Concepts and Applications. Hoboken, NJ: John Wiley and Sons.
Miller, S., Melczer, A. (2003). HIPAA Security White Papers. Retrieved July 15, from:

