AGENDA: DAY II
TUESDAY, MARCH 5, 2019
7:00 am
Registration Open; Networking Breakfast
MORNING PLENARY SESSION — HIPAA SECURITY
8:00 am
Welcome, Introduction and Annual Health Care Security Update
John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Co-Chair)
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD (Co-Chair)
John Parmigiani is President of John C Parmigiani & Associates, LLC. His current primary focus is on helping healthcare organizations become compliant with healthcare regulations, in particular, HIPAA and the HITECH revisions, and move toward e-health. His work in these areas has ranged from performing compliance and risk assessments to designing systems and serving as an expert witness in Privacy violation cases. He has over 40 years’ experience in information systems management in both the public and private sectors. He chaired a government-wide team that developed the Security Rule and the electronic signature standard and served as a member of the federal committee that oversaw the development of the Privacy Rule and a number of HIPAA transactions and code sets. After his retirement from federal service, he was an executive in a number of consultancies that worked with national clients on the adoption and implementation of HIPAA-compliant requirements, before starting his own consultancy.
8:30 am
Trends and Characteristics of Reportable Health Data Breaches, 2010-2017
Thomas H. McCoy, MD
Director of Research, Center for Quantitative Health, Massachusetts General Hospital, Boston, MA
Director of Research, Center for Quantitative Health, Massachusetts General Hospital, Boston, MA
Dr. McCoy is the Director of Research at the Massachusetts General Hospital Center for Quantitative Health. His work focuses on development of algorithms to distil data generated through routine clinical care into tools for clinical risk stratification and life sciences discovery. His recent work has focused on natural language processing and topic modeling to build cross-diagnostic phenotypic maps of the electronic health record. His current areas of interest are multidimensional psychiatric phenotypes and biologically informed models of medication effects for repositioning and adverse event prediction. He has a history of successfully commercializing his research as physician facing software. He is a practicing psychiatrist and medical ethicist. He serves as co-director of the hospital’s clinical ethics consultation service.
9:00 a.m.
FBI Keynote
Tonya Ugoretz
Deputy Assistant Director, Cyber Division, FBI, Adjunct Associate Professor, Center for Security Studies, Georgetown University, Adjunct Faculty, Center for Intelligence Training, FBI Academy, Washington, DC
Deputy Assistant Director, Cyber Division, FBI, Adjunct Associate Professor, Center for Security Studies, Georgetown University, Adjunct Faculty, Center for Intelligence Training, FBI Academy, Washington, DC
Tonya Ugoretz is a career FBI Intelligence Analyst currently assigned to the Office of the Director of National Intelligence (ODNI) as Director of the Cyber Threat Intelligence Integration Center (CTIIC). Her government career began as a Presidential Management Fellow and all-source analyst with the FBI’s Counterterrorism program. Her service with the FBI includes roles as Unit Chief, Section Chief in the Senior Executive Service where she oversaw intelligence briefings for the FBI Director and the Attorney General, as well as FBI analysts’ contributions to the President’s Daily Brief. As the FBI’s Chief Intelligence Officer she also led the Bureau’s cadre of Senior National Intelligence Officers and the creation of a 24/7 Intelligence Watch. Ms. Ugoretz has also served in joint-duty positions with the Central Intelligence Agency, U.S. Customs and Border Protection, and the National Intelligence Council. She is an Adjunct Associate Professor with Georgetown University’s Center for Security Studies.
9:30 a.m.
DHS Keynote
Jeanette Manfra, MA
Assistant Director for Cybersecurity, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security, Former Director for Critical Infrastructure Cybersecurity, National Security Council, the White House, Washington, DC
Assistant Director for Cybersecurity, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security, Former Director for Critical Infrastructure Cybersecurity, National Security Council, the White House, Washington, DC
Jeanette Manfra serves as the Assistant Director for Cybersecurity for the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). Previously, Ms. Manfra served as Assistant Secretary for the Office of Cybersecurity and Communications (CS&C) for the National Protection and Programs Directorate (NPPD) before the agency became CISA. Prior to this position, Ms. Manfra served as Acting Deputy Under Secretary for Cybersecurity and Director for Strategy, Policy, and Plans for NPPD.
Ms. Manfra also served as Senior Counselor for Cybersecurity to the Secretary of Homeland Security and Director for Critical Infrastructure Cybersecurity on the National Security Council staff at the White House. At DHS, she held multiple positions in the Cybersecurity Division, including advisor for the Assistant Secretary for Cybersecurity and Communications and Deputy Director, Office of Emergency Communications.
Before joining DHS, Jeanette served in the U.S. Army as a communications specialist and a Military Intelligence Officer.
Ms. Manfra also served as Senior Counselor for Cybersecurity to the Secretary of Homeland Security and Director for Critical Infrastructure Cybersecurity on the National Security Council staff at the White House. At DHS, she held multiple positions in the Cybersecurity Division, including advisor for the Assistant Secretary for Cybersecurity and Communications and Deputy Director, Office of Emergency Communications.
Before joining DHS, Jeanette served in the U.S. Army as a communications specialist and a Military Intelligence Officer.
10:00 a.m.
Chief Security Officers Best Practices Roundtable
Julie A. Chua, CAP, CISSP, PMP
Risk Management Branch Chief, Office of Information Security (OIS), Department of Health and Human Services, Baltimore, MD
Risk Management Branch Chief, Office of Information Security (OIS), Department of Health and Human Services, Baltimore, MD
Julie Chua serves as the Branch Chief of the Risk Management Program within the HHS Office of Information Security (OIS). She is responsible for establishing a Department-wide enterprise risk management program and overseeing high visibility/high priority initiatives including identification and protection of HHS’ most critical high value assets and the HHS FedRAMP and Cloud Security Program. Julie also has a lead role in Healthcare and Public Health Sector public-private partnerships on many HHS cybersecurity initiatives to help push forward security and resiliency across the sector. Prior to joining OIS, Julie was the Cybersecurity Team Lead within the HHS Office of the National Coordinator for Health IT (ONC) leading Critical Infrastructure cybersecurity efforts.
Josh DeFrain, MS
Chief Information Security Officer, Flatiron Health; Former Global Cyber Security Operations Director, Capital One, Washington, DC
Chief Information Security Officer, Flatiron Health; Former Global Cyber Security Operations Director, Capital One, Washington, DC
Josh DeFrain is an engineer, director & CISO in the U.S. Intelligence Community, financial sector & health care industry. As CISO of Flatiron Josh is responsible for the information security of 2 million patient records and 500+ employees. In April of 2018 Flatiron was acquired by Roche for $2 billion.
As the Global Cyber Security Operations Director at Capital One Josh built 4 teams of 50+ analysts, engineers and developers who are responsible for 24×7 security monitoring, 24×7 incident response, SIEM, and DevOps.
As a SIEM engineer in US Intelligence Community he built big data platforms to identify targeted cyber-attack campaigns from nation state actors. During this time, he directly supported the SOC, Incident Response, Cyber Threat Intelligence and Insider Threat teams.
As the Global Cyber Security Operations Director at Capital One Josh built 4 teams of 50+ analysts, engineers and developers who are responsible for 24×7 security monitoring, 24×7 incident response, SIEM, and DevOps.
As a SIEM engineer in US Intelligence Community he built big data platforms to identify targeted cyber-attack campaigns from nation state actors. During this time, he directly supported the SOC, Incident Response, Cyber Threat Intelligence and Insider Threat teams.
John C. Parmigiani
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD
President, John C. Parmigiani and Associates, LLC; Former Director of Enterprise Standards, HCFA, Ellicott City, MD
John Parmigiani is President of John C Parmigiani & Associates, LLC. His current primary focus is on helping healthcare organizations become compliant with healthcare regulations, in particular, HIPAA and the HITECH revisions, and move toward e-health. His work in these areas has ranged from performing compliance and risk assessments to designing systems and serving as an expert witness in Privacy violation cases. He has over 40 years’ experience in information systems management in both the public and private sectors. He chaired a government-wide team that developed the Security Rule and the electronic signature standard and served as a member of the federal committee that oversaw the development of the Privacy Rule and a number of HIPAA transactions and code sets. After his retirement from federal service, he was an executive in a number of consultancies that worked with national clients on the adoption and implementation of HIPAA-compliant requirements, before starting his own consultancy.
Jon Moore, MS, JD, HCISPP
Chief Risk Officer, Clearwater Compliance, New York, NY (Moderator)
Chief Risk Officer, Clearwater Compliance, New York, NY (Moderator)
Jon Moore, Chief Risk Officer and Senior Vice President of Professional Services at Clearwater, works with healthcare leaders to safeguard their patients’ health, health information, corporate capital and earnings through the creation and development of strong proactive privacy and information/cyber risk management programs. He is a member of the AHLA, ISC2 and ISACA, an HCISPP and holds an ITIL Foundation Certification
11:00 am
Transition Break
MINI SUMMIT GROUP I: 11:15 am – 12:15 pm
Mini-Summit I: Update on OCR HIPAA Policy
11:15 am
Welcome, Introductions, Presentations and Q&A
Marissa Gordon-Nguyen, MPH, JD
Senior Advisor for HIPAA Policy, Office for Civil Rights, US Department of Health and Human Services, Washington DC
Senior Advisor for HIPAA Policy, Office for Civil Rights, US Department of Health and Human Services, Washington DC
Marissa Gordon-Nguyen is the Senior Advisor for HIPAA Policy in the Office for Civil Rights (OCR), U.S. Department of Health and Human Services (HHS). In this role, she leads the implementation of HIPAA privacy and security policies through rulemaking initiatives and the development of sub-regulatory guidance. She also advises federal agencies, advisory committees, and Congressional offices on aspects of the HIPAA Rules and their underlying privacy principles, among other responsibilities. Marissa joined OCR in 2009 to work on health information privacy policy.
Timothy Noonan, JD
Acting Deputy Director for Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Acting Deputy Director for Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC
Timothy Noonan is the Acting Deputy Director for Health Information Privacy, at the Office for Civil Rights (OCR), United States Department of Health and Human Services. The Health Information Privacy Division enforces the HIPAA Rules through investigations, rule-making and guidance, and outreach to the regulated community and to the public. Tim joined OCR as the Southeast Regional Manager in November 2013. Previously, Tim also served in OCR headquarters for approximately 1 ½ years as the Acting Associate Deputy Director for Operations and the Acting Director of OCR’s Centralized Case Management Operations. Prior to joining OCR, Tim was a Supervisory General Attorney for the U.S. Department of Education, Office for Civil Rights, and a shareholder in a Michigan law firm.
Dayna Nicholson, JD, MPH
Counsel, Davis Wright Tremaine LLP, Los Angeles, CA (Moderator)
Counsel, Davis Wright Tremaine LLP, Los Angeles, CA (Moderator)
As Counsel at Davis Wright Tremaine, Dayna Nicholson focuses her practice on health care-related matters, such as licensing and other regulatory compliance, peer review and credentialing, and corporate and medical staff governance. Her clients include hospitals, medical staffs, managed care organizations, medical groups, medical device retailers, and other health care providers. Dayna also has experience in patient information privacy issues, appeals of state-issued administrative penalties, Medicare and Medi-Cal certification, emergency care requirements, and litigation arising out of peer review matters.
Dayna has significant experience counseling health care organizations regarding operational issues and regulatory and litigation matters. She has reviewed or drafted numerous policies, rules and regulations, bylaws, and other procedural documents, and regularly assists clients in interpreting and following such guidance. In the area of credentialing and peer-review, she is well-versed in state, federal and accreditation requirements, as well as the roles, responsibilities, and concerns of an organization’s leadership.
Dayna has significant experience counseling health care organizations regarding operational issues and regulatory and litigation matters. She has reviewed or drafted numerous policies, rules and regulations, bylaws, and other procedural documents, and regularly assists clients in interpreting and following such guidance. In the area of credentialing and peer-review, she is well-versed in state, federal and accreditation requirements, as well as the roles, responsibilities, and concerns of an organization’s leadership.
Mini-Summit II: The Role of Blockchain Technology in Healthcare Privacy, Data Security and HIPAA Compliance
11:15 am
Welcome, Introductions, Presentations and Q&A
Tatyana Kanzaveli
Founder and Chief Executive Officer, Open Health Network; Resident Mentor, 500 Startups; Chief Executive Officer, TEDxBayArea; Former USSR Chess Champion, San Francisco, CA
Founder and Chief Executive Officer, Open Health Network; Resident Mentor, 500 Startups; Chief Executive Officer, TEDxBayArea; Former USSR Chess Champion, San Francisco, CA
Tatyana Kanzaveli has gone from a programmer to senior executive to founder and CEO of a startup company along her 20 year career. She is recognized as a thought leader and mentor for her ability to guide Fortune 500 and startup companies through business challenges. She’s worked for major companies like PricewaterhouseCoopers and Fujitsu and startups in the early days of the Web. Today she is the founder and CEO of Open Health Network, the startup in a Big Data/Artificial Intelligence Healthcare space. She is a mentor at 500Startups and Richard Branson Entrepreneurs Centre and serves on the board for private companies. Tatyana has been featured in the White House blog, spoken at the United Nations, and presented at the first White House Demo Day hosted by President Obama.
John Mattison, MD
Chief Medical Information Officer, Kaiser Permanente; Faculty, Singularity University, Pasadena, CA
Chief Medical Information Officer, Kaiser Permanente; Faculty, Singularity University, Pasadena, CA
John Mattison began his medical career at the UCSD and Scripps Clinic, where he practiced in many clinical settings including emergency services, primary care, critical care, preventive medicine, hyperbaric medicine, trauma and helicopter medicine.
He joined the SCAL region of Kaiser-Permanente in 1989, and was appointed as Assistant Medical Director and Chief Medical Information Officer (CMIO). He directed the largest and first deployment of KP HealthConnect, Kaiser-Permanente’s revolutionary program to improve the quality and safety of healthcare through the use of information technology. He is now the Chief Medical Information Officer and is on the faculty of Singularity University.
John is an active spokesman and proponent for international health data standards and was the founding visionary for the international XML standards for health record exchange resulting in the Clinical Document Architecture (CDA) and the Continuity of Care Document (CCD).
He joined the SCAL region of Kaiser-Permanente in 1989, and was appointed as Assistant Medical Director and Chief Medical Information Officer (CMIO). He directed the largest and first deployment of KP HealthConnect, Kaiser-Permanente’s revolutionary program to improve the quality and safety of healthcare through the use of information technology. He is now the Chief Medical Information Officer and is on the faculty of Singularity University.
John is an active spokesman and proponent for international health data standards and was the founding visionary for the international XML standards for health record exchange resulting in the Clinical Document Architecture (CDA) and the Continuity of Care Document (CCD).
Iliana Peters, JD, LLM
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
liana L. Peters is a shareholder for Polsinelli, PC. For more than twelve years, she both developed health information privacy and security policy, including on emerging technologies and cyber threats, for the Department of Health and Human Services, and enforced HIPAA regulations, as both the Senior Advisor for HIPAA Enforcement for over six years, and as Acting Deputy Director for HIPAA. As a CISSP, Iliana works hard to bridge the gap between legal requirements for the security of health data and security industry best practices, so that clients can better understand data security issues and jargon. She is excited to bring her extensive experience drafting, implementing, and enforcing health privacy and security regulations and guidance to a practice that focuses on helping clients develop and implement good data privacy and security practices to avoid risk, and helping clients prepare for and recover from emerging cyber threats.
Mini-Summit III: Performing Effective HIPAA Risk Assessments; Dos and Don’ts & Security Risk Analysis — By the Book
11:15 am
Performing Effective HIPAA Risk Assessments; Dos and Don’ts
Matthew Farry
Senior Security Specialist, GreyCastle Security, Troy, NY
Senior Security Specialist, GreyCastle Security, Troy, NY
Matt Farry is a Security Specialist at GreyCastle Security with over 10 years of experience in information protection assessments and controls implementation. At GreyCastle, Matt specializes in organizational risk assessments and remediation guidance based on industry standards and regulations including NIST SP800-53, ISO 27002, HIPAA, FERPA, PCI, and others.
11:45 am
Security Risk Analysis — By the Book
Steve Cagle, MBA
Chief Executive Officer, Clearwater Compliance, Executive Chairman, CMP Pharma, New York, NY
Chief Executive Officer, Clearwater Compliance, Executive Chairman, CMP Pharma, New York, NY
Steve Cagle is the CEO and a board member of Clearwater, a leading provider of healthcare cyber risk management and HIPAA compliance solutions. Mr. Cagle is responsible for leading Clearwater’s strategic growth plan and for management of the company’s overall operations. He has extensive experience leading, innovating, and scaling healthcare and technology businesses, including having guided a number of companies through critical transformation periods. Formerly, Mr. Cagle was president and CEO of Moberg Pharma North America. Prior to its acquisition by Moberg AB, Mr. Cagle was president and CEO of Alterna LLC. Previously, Mr. Cagle was a principal and executive team member of Sparta Systems, Inc. Mr. Cagle serves as the executive chairman of CMP Pharma where he has guided its transformation to an institutionally owned specialty pharmaceutical company.
Mini-Summit IV: GDPR and New California Privacy Law Update
11:15 am
GDPR and New California Privacy Law Update
Andrew Clearwater, CIPP/US, LLM
Director of Privacy, OneTrust, Portland, ME
Director of Privacy, OneTrust, Portland, ME
Andrew Clearwater serves as Director of Privacy at OneTrust. Mr. Clearwater is a Certified Information Privacy Professional (CIPP/US), holds an LLM in Global Law and Technology and is a licensed attorney. In his role as Director of Privacy, Clearwater provides counsel, leadership, and guidance on data protection. He is also responsible for providing public policy analysis in the areas of privacy, data security, information policy, and technology transactions.
Before joining OneTrust, Mr. Clearwater was the Privacy Officer for RxAnte. Clearwater also held privacy roles at the Future of Privacy Forum, as well as the Network Advertising Initiative. In addition, he made contributions to the NTIA mobile application transparency discussion, helped launch a privacy seal program for companies that use consumer energy data, participated as a member of the W3C Tracking Protection Working Group, and taught as an adjunct professor of privacy and technology law at the University of Maine.
Before joining OneTrust, Mr. Clearwater was the Privacy Officer for RxAnte. Clearwater also held privacy roles at the Future of Privacy Forum, as well as the Network Advertising Initiative. In addition, he made contributions to the NTIA mobile application transparency discussion, helped launch a privacy seal program for companies that use consumer energy data, participated as a member of the W3C Tracking Protection Working Group, and taught as an adjunct professor of privacy and technology law at the University of Maine.
Daniel F. Gottlieb, JD
Partner and Co-leader, Global Privacy and Cybersecurity Practice, McDermott Will & Emery, Chicago, IL
Partner and Co-leader, Global Privacy and Cybersecurity Practice, McDermott Will & Emery, Chicago, IL
Daniel Gottlieb is a Partner and Co-leader in the Global Privacy and Cybersecurity Practice at McDermott Will & Emery. He counsels a wide range of health care industry clients. Daniel advises health care industry clients in all aspects of software licenses and other agreements for the acquisition electronic health record (EHR) systems, enterprise resource planning systems, enterprise data warehouses and other mission critical health IT. Daniel also counsels health care clients regarding compliance with (HIPAA) and other federal and state privacy, security and breach notification laws as well as compliance with Medicare and Medicaid reimbursement, fraud and abuse laws, PhRMA’s Code on Interactions with Health Care Professionals and AdvaMed’s Code of Ethics on Interactions with Health Care Professionals.
Kate Heinzelman, JD
Counsel, Sidley Austin LLP; Former Deputy General Counsel, US Department of Health and Human Services; Former Special Assistant and Associate Counsel to President Barack Obama, Washington, DC
Counsel, Sidley Austin LLP; Former Deputy General Counsel, US Department of Health and Human Services; Former Special Assistant and Associate Counsel to President Barack Obama, Washington, DC
Kate Heinzelman is a member of the Privacy and Cybersecurity, Healthcare, and Commercial Litigation groups at Sidley Austin. Her practice focuses on compliance counseling, incident-response, investigations, and regulatory matters in privacy/cybersecurity and healthcare. Before joining Sidley, Kate was Deputy General Counsel at the Department of Health & Human Services. Before joining the Department of Health & Human Services, Kate worked in the White House Counsel’s Office as Special Assistant and Associate Counsel to President Barack Obama. In this role, she advised the President and his Administration on national security, privacy and technology, energy, and environmental matters. Kate also served as Counsel to the Assistant Attorney General for National Security at the Department of Justice. Kate served as a law clerk to Chief Justice John G. Roberts, Jr. on the U.S. Supreme Court and Judge Merrick Garland on the U.S. Court of Appeals for the D.C. Circuit.
12:15 pm
Networking Luncheon and Presentations
MINI SUMMITS: GROUP II 12:30 pm – 1:30 pm
Mini-Summit V: The Privacy Threat Spectrum
12:30 pm
Welcome, Introductions, Presentations and Q&A
Nick Culbertson
Co-founder and Chief Executive Officer, Protenus, Baltimore, MD
Co-founder and Chief Executive Officer, Protenus, Baltimore, MD
Nick Culbertson is the Co-Founder and CEO of Protenus, a leading healthcare compliance analytics platform. Nick is an eight-year U.S. Army veteran and completed his service as a highly decorated U.S. Special Forces operator (Green Beret). He was awarded two Bronze Star medals during his service, one for extraordinary valor. While serving in the U.S. Army, Nick specialized in human intelligence network gathering and analysis. He used this expertise in building behavioral profiles to co-found Protenus, which protects the data of patients at top health systems in the country from insider threats. In 2018, Protenus was named one of The Best Places to Work in Healthcare by Modern Healthcare Magazine, and one of the Best Places to Work in Baltimore by the Baltimore Business Journal. Nick speaks about leadership, entrepreneurship, and health data privacy at leading healthcare and investment conferences.
Mini-Summit VI: How to Respond to a Ramsomware Attack
12:30 pm
Welcome, Introductions, Presentations and Q&A
John Boles
Principal, PricewaterhouseCoopers Advisory Services, LLC, Atlanta, GA
Principal, PricewaterhouseCoopers Advisory Services, LLC, Atlanta, GA
John Boles is a Principal in PriceWaterhouseCoopers’ Incident and Threat Management practice. His experience from over 27 years in federal law enforcement, national security, and cyber operations has given him a unique perspective on cyber security and risk.
John served in the FBI for over 20 years, conducting and leading investigations around the world, including cyber, fraud, terrorism, and violent crimes. As Deputy Assistant Director, in charge of FBI Cyber Operations, he oversaw the federal response to many of the more notorious cyber attacks in recent memory. He advised the White House and National Security Council on cyber-related issues and policies and has testified before Congress on cyber-crime issues. John also led the National Cyber Investigative Joint Task Force, a 19-agency team of US and allied intelligence agencies dedicated to national security investigations and response. He finished his career as Assistant Director. Prior to joining PwC, John led Navigant/Ankura’s global incident response.
John served in the FBI for over 20 years, conducting and leading investigations around the world, including cyber, fraud, terrorism, and violent crimes. As Deputy Assistant Director, in charge of FBI Cyber Operations, he oversaw the federal response to many of the more notorious cyber attacks in recent memory. He advised the White House and National Security Council on cyber-related issues and policies and has testified before Congress on cyber-crime issues. John also led the National Cyber Investigative Joint Task Force, a 19-agency team of US and allied intelligence agencies dedicated to national security investigations and response. He finished his career as Assistant Director. Prior to joining PwC, John led Navigant/Ankura’s global incident response.
Nicholas Heesters, JD, CIPP
Health Information Privacy and Security Specialist, Office for Civil Rights, US Department of Health and Human Services; Former MIS Director, Delaware River and Bay Authority; Former Vice President, Technology Infrastructure, JP Morgan Chase, Washington, DC
Health Information Privacy and Security Specialist, Office for Civil Rights, US Department of Health and Human Services; Former MIS Director, Delaware River and Bay Authority; Former Vice President, Technology Infrastructure, JP Morgan Chase, Washington, DC
Nicholas Heesters is Health Information Privacy Security Specialist, HIP Division in the Office for Civil Rights (OCR), U.S. Department of Health and Human Services (HHS). He is a certified information privacy professional with over 25 years of experience supporting technology and information security efforts in many diverse industries including financial services, government, defense, education and healthcare. Currently, Mr. Heesters works for the U.S. Department of Health and Human Services Office for Civil Rights supporting HIPAA compliance and enforcement activities.
Adam Greene, JD, MPH
Partner and Co-chair, Health Information and HIPAA Practice, Davis Wright Tremaine LLP; HIPAA Summit Distinguished Service Award Winner; Former Senior Health Information, Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Partner and Co-chair, Health Information and HIPAA Practice, Davis Wright Tremaine LLP; HIPAA Summit Distinguished Service Award Winner; Former Senior Health Information, Technology and Privacy Specialist, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Adam Greene is a partner in the Washington, D.C. office of Davis Wright Tremaine and co-chair of its Health Information Group. Adam primarily counsels health care providers, technology companies, and financial institutions on compliance with health information privacy, security, and breach notification rules. Previously, Adam was a regulator at the U.S. Department of Health and Human Services, where he played a fundamental role in administering and enforcing the HIPAA rules. At HHS, Adam was responsible for determining how HIPAA rules apply to new and emerging health information technologies and was instrumental in the development of the current HIPAA enforcement process. Adam has been recognized as one of the top ten influencers in health information security, one of the top 50 healthcare IT experts, and is a frequent speaker and author on health information privacy and security issues.
Mini-Summit VII: HIPAA and Artificial Intelligence (AI) in Healthcare & Practical Cybersecurity for Medical Device Applications
12:30 pm
HIPAA and Artificial Intelligence (AI) in Healthcare
Rebecca L. Williams, RN, JD
Partner and Chair, Health Information Practice, Davis Wright Tremaine LLP, Seattle, WA
Partner and Chair, Health Information Practice, Davis Wright Tremaine LLP, Seattle, WA
Rebecca Williams is a nationally recognized authority on HIPAA, health information privacy, and data breach response. As a registered nurse with hands-on experience in hospital and other health care environments, she brings a practical perspective to her practice. From initial development of HIPAA compliance programs to one-off questions to government investigations, Becky works with HIPAA covered entities and business associates to safeguard health information while keeping their businesses running efficiently. Becky’s clients include: health care providers; financial institutions and payment processors; cloud service providers; business associates; AI and technology developers; and health plans and plan sponsors. Becky is a frequent national speaker, is an author of numerous publications, including a contributing author of the HIPAA Portability, Privacy & Security Manual, published by the Employee Benefits Institute of America (a Thomson Reuters imprint), and regularly is quoted in the media.
1:00 pm
Practical Cybersecurity for Medical Device Applications
Rob Theriot, MBA, CISA, CRISC, GISP
Director of Security Services, TraceSecurity, Baton Rouge, LA
Director of Security Services, TraceSecurity, Baton Rouge, LA
Rob Theriot is the Director of Security Services at TraceSecurity, and feels the practices of making users more safe and secure with their personal data and transactions is extremely important in business. He has spent much of his career in the Financial Services industry, working with both large and small financial institutions across the country. His passion lies in the optimization of processes to ensure the security of an organization, and to optimize the way they comply with regulations. At TraceSecurity Rob oversees a team of computer security specialists dedicated to providing analysis of their customers infrastructure, which allows them to provide a more safe and secure environment for their customers. Their work centers around the NIST frameworks, with implications in Healthcare, Finance, and other industries.
Mini-Summit VIII: Data is Worth More Than Gold & NIST CsF = Standard for HIPAA Compliance + Cybersecurity
12:30 pm
Data is Worth More Than Gold: Why Focusing on HIPAA May Be Your Biggest Mistake
Mike Semel, CHSP, CBCP, CHA, CSCS
President and Chief Security Officer, Semel Consulting, LLC; Former Vice President, Business Continuity and Compliance, Connecting Point of Las Vegas; Former Chief Information Officer, Schuyler Hospital, Las Vegas, NV
President and Chief Security Officer, Semel Consulting, LLC; Former Vice President, Business Continuity and Compliance, Connecting Point of Las Vegas; Former Chief Information Officer, Schuyler Hospital, Las Vegas, NV
Mike Semel is a noted thought leader, speaker, blogger, and the best-selling author of How to Avoid HIPAA Headaches. Mike has spoken to many audiences including the medical team at the Kennedy Space Center and the New York State Cyber Security conference. He is the President and Chief Security Officer of Semel Consulting, focused on HIPAA and other regulations; cyber security; and Business Continuity planning. Mike is a Certified Business Continuity Professional through the Disaster Recovery Institute, a Certified HIPAA Professional, Certified Security Compliance Specialist, and Certified Health IT Specialist. He has owned or managed technology companies for over 30 years; served as Chief Information Officer (CIO) for a hospital and a K-12 school district; and managed operations at an online backup company.
1:00 pm
NIST CsF = Standard for HIPAA Compliance + Cybersecurity
Uday O. Ali Pabrai, MSEE, CISSP
Chief Executive and Co-founder, ecfirst (Home of HIPAA Academy), Irvine, CA
Chief Executive and Co-founder, ecfirst (Home of HIPAA Academy), Irvine, CA
Ali Pabrai is the CEO of ecfirst. A highly sought after information security and regulatory compliance expert, he has successfully delivered solutions on compliance and information security to organizations worldwide. Mr. Pabrai has presented opening keynote and other sessions at several conferences, including ISACA, ISSA, FBI InfraGard, HIMSS, HCFA, HIPAA Summit, Microsoft Tech Forum, NASEBA Healthcare Congress (Middle East), Kingdom Healthcare (Saudia Arabia), Internet World, DCI Expo, Comdex, Net Secure, Nurse Practitioners Conference, National Council for Prescription Drug Programs (NCPDP), National Council for State Board of Nursing IT Conference, and many others.
1:30 p.m.
Transition Break
MINI SUMMITS: GROUP III: 1:45 pm – 2:45 pm
Mini Summit IX: Personal Health Information Beyond HIPAA Protection: Who Is Regulating Its Privacy? Who Should, and How?
1:45 pm
Welcome, Introductions, Presentations and Q&A
Tina Grande, MHS
Senior Vice President, Policy and Chair, Confidentiality Coalition, Healthcare Leadership Counsel, Washington, DC
Senior Vice President, Policy and Chair, Confidentiality Coalition, Healthcare Leadership Counsel, Washington, DC
Tina Grande is Senior Vice President for Policy for the Healthcare Leadership Council (HLC). Ms. Grande oversees all policy-related matters pertaining to delivery systems, payment reform, health information technology, patient safety, and healthcare quality. She is also the Chair of the Confidentiality Coalition. Ms. Grande was a Policy Director at HLC in the late 1990s. She also served as Vice Chair of the Health Data Consortium’s Policy Committee. Prior to leading HLC’s policy efforts, Ms. Grande was Health Policy Director for Arnold & Porter LLP. Early in her career, Grande launched the Medicare Advisory Group, Inc. Ms. Grande launched her career in health policy working in the U.S. Senate for Senator David Durenberger (R-MN). From there she went on to work as a researcher for the Health Care Advisory Board, health policy analyst for Patton Boggs LLP, and research director at the Institute for the Future in California
Nancy L. Perkins, MPP, JD
Counsel, Arnold & Porter, Washington, DC
Counsel, Arnold & Porter, Washington, DC
Nancy Perkins, of Arnold & Porter LLP, advises clients on federal, state, and global data privacy law, particularly HIPAA and the HITECH Act. Nancy also assists clients on data security issues raised by mobile applications and other emerging technologies, and in responding to data security breaches. Ms. Perkins is the author of numerous articles on data privacy and security, is an Adviser on the American Law Institute’s forthcoming Principles of the Law, Data Privacy, and has been ranked for Privacy & Data Security by Chambers USA since 2009.
Mini-Summit X: Cutting through the Noise: Determining Whether your Vendor’s Security Incident is a Breach
1:45 pm
Welcome, Introductions, Presentations and Q&A
Mark Fox, CHC, CHPC, CHRC
Compliance and Privacy Officer, American College of Cardiology, Miami, FL
Compliance and Privacy Officer, American College of Cardiology, Miami, FL
Mark Fox currently serves as the Privacy and Research Compliance Officer of the American College of Cardiology. Mark is responsible for oversight of the College’s privacy infrastructure and all areas of research compliance. Mark has overseen the development of the privacy infrastructure for the National Cardiovascular Data Registry. Prior to ACC, Mark worked for MedCath as an Implementation Specialist overseeing the standardization of systems for Performance Improvement, and Risk Management for thirteen acute care hospitals. Mark has both clinical experience as a Emergency Medical Technician and data management experience. He currently holds certifications in Healthcare Compliance, Healthcare Privacy Compliance, and Healthcare Research Compliance.
David Holtzman, JD, CIPP
Executive Advisor, CynergisTek, Inc.; Former Senior Adviser for HIT and the HIPAA Security Rule, Office for Civil Rights, US Department of Health and Human Services, Austin, TX
Executive Advisor, CynergisTek, Inc.; Former Senior Adviser for HIT and the HIPAA Security Rule, Office for Civil Rights, US Department of Health and Human Services, Austin, TX
David Holtzman is an Executive Advisor for CynergisTek. He is considered a subject matter expert in health information privacy and compliance issues. David is a sought after public speaker, commentator and contributor regarding compliance and enforcement of health information privacy in the health care industry. Prior to CynergisTek, Holtzman served as a senior advisor for health information technology and the HIPAA Security Rule at the Department of Health & Human Services, Office for Civil Rights (OCR/HHS). Prior to joining HHS, David was the privacy & security officer for Kaiser Permanente’s Mid-Atlantic Region.
Thora A. Johnson, JD
Partner and Co-chair, Health Care Initiative, Venable, LLP, Baltimore, MD
Partner and Co-chair, Health Care Initiative, Venable, LLP, Baltimore, MD
Thora Johnson chairs Venable’s Healthcare Initiative. She provides counsel on regulatory, compliance, tax, and business matters impacting healthcare providers, hospitals, continuing care retirement communities, health insurers, group health plans, pharmaceutical and medical device companies, and digital health companies. She has a broad knowledge of traditional healthcare regulatory matters, including HIPAA privacy, security, and breach notification requirements; state health information privacy laws; Medicare/Medicaid compliance; and federal and state fraud and abuse rules. Thora has extensive experience in health and welfare plan compliance, including the regulatory requirements of ERISA, the Internal Revenue Code, federal and state healthcare coverage continuation laws, the Mental Health Parity and Addiction Equity Act, Genetic Information Nondiscrimination Act, the regulations under the Americans with Disabilities Act (ADA) applicable to employer wellness programs, and the ACA.
Mini-Summit XI: Research Data Governance & Vendor Management in the Era of Big Data and Machine Learning
1:45 pm
Research Data Governance: Best Practices and Case Study
William J. Roberts, JD
Partner, Shipman & Goodwin LLP, North American Privacy Lead, Interlaw, Hartford, CT
Partner, Shipman & Goodwin LLP, North American Privacy Lead, Interlaw, Hartford, CT
William Roberts is the Chair of Shipman & Goodwin LLP’s Privacy and Data Protection Practice. He focuses his practice at the intersection of privacy, technology and the law, with a particular emphasis on the health care and insurance sectors.
Tracey Scraba, MPH, JD
Vice President and Chief Privacy Officer, CVS Health, Former Vice President and Chief Privacy Officer, Aetna, Hartford, CT
Vice President and Chief Privacy Officer, CVS Health, Former Vice President and Chief Privacy Officer, Aetna, Hartford, CT
Tracey Scraba is the Vice President, Chief Privacy Officer at CVS Health. She has enterprise-wide responsibility for CVS Health’s privacy program including daily operations of the privacy office, development and implementation of privacy policies and procedures, monitoring privacy compliance, information governance, incident investigation and breach response and providing privacy and security legal support.
Prior to joining CVS Health, she was the Chief Privacy Officer at Aetna. She also served as Senior Privacy and Security Counsel, Behavioral Health Counsel and Counsel for National Accounts Retiree programs. Prior to her work at Aetna, Tracey worked at the law firm of Robinson & Cole in their health law practice.
Tracey is also a graduate of the Higher Ambition Leadership Institute (HALI), a year-long multi-session program that provides leaders the opportunity to develop their capabilities, as well as contribute to the advancement of their company’s mission and purpose.
Prior to joining CVS Health, she was the Chief Privacy Officer at Aetna. She also served as Senior Privacy and Security Counsel, Behavioral Health Counsel and Counsel for National Accounts Retiree programs. Prior to her work at Aetna, Tracey worked at the law firm of Robinson & Cole in their health law practice.
Tracey is also a graduate of the Higher Ambition Leadership Institute (HALI), a year-long multi-session program that provides leaders the opportunity to develop their capabilities, as well as contribute to the advancement of their company’s mission and purpose.
2:15 pm
Vendor Management in the Era of Big Data and Machine Learning
Daniel Fabbri, MS, PhD
Founder and Chief Executive Officer, Maize Analytics Inc.; Assistant Professor, Vanderbilt University, Nashville, TN
Founder and Chief Executive Officer, Maize Analytics Inc.; Assistant Professor, Vanderbilt University, Nashville, TN
Daniel Fabbri is an Assistant Professor of Biomedical Informatics and Computer Science at Vanderbilt University. His research focuses on machine learning applied to electronic medical records, clinical data and data privacy. Dr. Fabbri is also the Founder and CEO of Maize Analytics. Dr. Fabbri’s research has been sponsored by the National Science Foundation, National Institutes of Health and U.S. Department of Defense. He has been an invited speaker at the HHS Safeguarding Health Information Conference (2013), the National Academy of Medicine Digital Learning Collaborative (2017), and HHS “Data Min(d)ing: Privacy and Our Digital Identities” (2018). His research on machine learning in healthcare and data privacy has been published in JAMA Internal Medicine, the Journal of the American Medical Informatics Association, Journal of Pediatrics, International Journal of Medical Informatics, and multiple other computer science proceedings.
2:45 p.m.
Break
AFTERNOON PLENARY SESSION
3:15 p.m.
Welcome, Introductions and the Long and Winding Road towards Federal Privacy Legislation
Kirk J. Nahra, JD
Partner and Co-chair of the Privacy and Cybersecurity Practice, Wilmer Hale, Washington, DC (Co-Chair)
Partner and Co-chair of the Privacy and Cybersecurity Practice, Wilmer Hale, Washington, DC (Co-Chair)
Kirk J. Nahra is a partner with Wiley Rein LLP in Washington, D.C., where he represents companies in a broad range of industries in connection with privacy and data security laws and regulations across the United States and globally. He is chair of the firm’s Privacy Practice and co-chair of its Health Care Practice.
He is a nationally recognized expert on privacy and data security laws related to the health care and insurance industries. He assists companies in a wide range of industries in analyzing and implementing the requirements of privacy and security laws across the country and internationally.
He serves on the Board of Directors of the International Association of Privacy Professionals and as the editor of Privacy Advisor. He is a Certified Information Privacy Professional and serves on the Advisory Board for the Health Law Reporter, the Privacy and Security Law Report and the Health Care Fraud Report.
He is a nationally recognized expert on privacy and data security laws related to the health care and insurance industries. He assists companies in a wide range of industries in analyzing and implementing the requirements of privacy and security laws across the country and internationally.
He serves on the Board of Directors of the International Association of Privacy Professionals and as the editor of Privacy Advisor. He is a Certified Information Privacy Professional and serves on the Advisory Board for the Health Law Reporter, the Privacy and Security Law Report and the Health Care Fraud Report.
4:00 p.m.
ONC Privacy and Security Policy Update
Donald Rucker, MD
National Coordinator for Health Information Technology, US Department of Health and Human Services; Former Chief Medical Officer, Siemens Healthcare, Washington, DC
National Coordinator for Health Information Technology, US Department of Health and Human Services; Former Chief Medical Officer, Siemens Healthcare, Washington, DC
Dr. Don Rucker is the National Coordinator for Health Information Technology at the U.S. Department of Health and Human Services, where he leads is the formulation of the federal health IT strategy and coordinates federal health IT policies, standards, programs, and investments. Dr. Rucker has three decades of clinical and informatics experience. He started his informatics career at Datamedic Corporation, where he co-developed the world’s first Microsoft Windows-based electronic medical record. He then spent over a decade serving as Chief Medical Officer at Siemens Healthcare USA. Dr. Rucker has also practiced emergency medicine for a variety of organizations including at Kaiser in California; at Beth Israel Deaconess Medical Center; at the University of Pennsylvania’s Penn Presbyterian and Pennsylvania Hospitals; and, most recently, at Ohio State University’s Wexner Medical Center.
4:30 p.m.
Health Plans are Covered Entities Too! Best Practices for Compliance and Policy Integration
Kristen Erbes, CIPP/US
Chief Privacy Officer, Cambia Health Solutions, Portland, OR
Chief Privacy Officer, Cambia Health Solutions, Portland, OR
Kristen Erbes has over 12 years compliance experience in both the private and public sectors. For more than 6 years she has been the Chief Privacy Officer at Cambia Health Solutions which includes six health insurance plans that serve members throughout the Pacific Northwest as well as a number of direct health solutions companies.
Deidre Rodriguez, MS, CIPP/US
Staff Vice President, Privacy and Compliance, Anthem; Co-Chair, Privacy and Security Workgroup, WEDI, Denver, CO
Staff Vice President, Privacy and Compliance, Anthem; Co-Chair, Privacy and Security Workgroup, WEDI, Denver, CO
Deidre Rodriguez is the Staff VP of Privacy and Compliance for Anthem, Inc. (parent company of Anthem BCBS). Deidre has been with the company for 15 years. Deidre has over 30 years of healthcare experience, 25 years of compliance experience and 20+ years of privacy experience
Tabatha George, JD
Partner, The Benefits Group, LLC, New Orleans, LA (Moderator)
Partner, The Benefits Group, LLC, New Orleans, LA (Moderator)
Tabatha George is a partner at The Benefits Practice, LLC and a graduate of Harvard College and Harvard Law School. She works with companies throughout the country to bring their benefit programs into compliance with the ACA, HIPAA, ERISA, GINA, the ADA, the Tax Code, and state laws. She advises on compliance for health plans, wellness plans, retirement plans, and any other employee benefit a company might dream up. Tabby has particular experience in the areas of healthcare reform and health information privacy. Tabby also conducts HIPAA audits, prepares HIPAA privacy and security policies, responds to breach situations, and conducts HIPAA training and risk assessments for health plans. In addition, Tabby represents companies in private and agency audits of health and retirement plans and consults on all compliance matters relating to employer-sponsored benefits.
5:15 p.m.
Compliance Concerns for New Business Associates, including Technology Vendors
Anne Kimbol, JD, LLM, CIPP/US, CHPC
Assistant General Counsel and Chief Privacy Officer, HITRUST; Former General Counsel, Texas Health Services Authority, Frisco, TX
Assistant General Counsel and Chief Privacy Officer, HITRUST; Former General Counsel, Texas Health Services Authority, Frisco, TX
Anne Kimbol is the Assistant General Counsel and Chief Privacy Officer for HITRUST. In this role, she works on legal issues for the company and leads the company’s efforts in the areas of privacy and related policy.
Chris Wargo, MBA
Managing Partner, Infolock, Washington, DC
Managing Partner, Infolock, Washington, DC
Chris Wargo is the Managing Partner of Infolock, a data advisory consulting firm based in Arlington, VA. Overseeing sales, marketing, and business development activities of the firm, Chris has been integral in the development of key strategic alliances that have accelerated Infolock’s growth, and his leadership has helped transform Infolock into one of the region’s leading data governance consulting firms. Prior to co-founding Infolock, Chris held management roles in the financial services and staffing industries, leading teams in both sales and operations. Chris is a Certified Information Systems Security Professional (CISSP) and a Certified Information Systems Auditor (CISA), and a Board Member of the Virginia Chapter of HIMSS.
Shane Whitlatch, MBA
General Manager, Healthcare, FairWarning, Inc., Saint Petersburg, FL
General Manager, Healthcare, FairWarning, Inc., Saint Petersburg, FL
At FairWarning®, as the General Manager for the Healthcare business, Shane Whitlatch is responsible for oversight and management of all aspects of the healthcare business – the core business of FairWarning. Since joining FairWarning® in 2008, the customer community has grown from 20 to over 350 enterprise customers across 6 countries. Prior to FairWarning®, Mr. Whitlatch held multiple executive roles in high growth software companies including OpenNetwork Technologies (acquired by BMC), LifeServ Technologies (acquired in 2004), and Pyxis (acquired by Cardinal Health, now CareFusion). Shane is also the co-founder and a founding judge in the Next Generation Entrepreneurship program in partnership with the Pinellas Education Foundation, a program designed to identify, encourage and educate high school students in the skills required to create their own businesses. Shane is an active member of the Tampa Bay community, and serves as a director on numerous community and faith-based organizations.
Iliana Peters, JD, LLM
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Shareholder, Polsinelli; Former Acting Deputy Director, Health Information Privacy, Office for Civil Rights, US Department of Health and Human Services, Washington, DC (Moderator)
Iliana L. Peters is a shareholder for Polsinelli, PC. For more than twelve years, she both developed health information privacy and security policy, including on emerging technologies and cyber threats, for the Department of Health and Human Services, and enforced HIPAA regulations, as both the Senior Advisor for HIPAA Enforcement for over six years, and as Acting Deputy Director for HIPAA. As a CISSP, Iliana works hard to bridge the gap between legal requirements for the security of health data and security industry best practices, so that clients can better understand data security issues and jargon. She is excited to bring her extensive experience drafting, implementing, and enforcing health privacy and security regulations and guidance to a practice that focuses on helping clients develop and implement good data privacy and security practices to avoid risk, and helping clients prepare for and recover from emerging cyber threats.