As is the case with SOC2, the "vulnerability scan" requirement here is likely to be meaningless; any automated process that can plausibly be described as instrumental in finding some kind of vulnerability is a "vulnerability scan", so all you have to do is run nmap.
dgellow•16m ago
If it is like SOC2 I would expect respected auditors to reject that
morpheuskafka•6m ago
But there are no auditors required for HIPAA. Only the government (HHS OCR) itself can enforce the standards.
time0ut•6m ago
Interesting. I haven’t fully read through the rule change, but seems like HHS is directing adopting the controls required by HITRUST? I have been out of the industry for a while. Always interesting how the industry shapes regulation and vice versa.
tptacek•24m ago
dgellow•16m ago
morpheuskafka•6m ago