Laserfiche WebLink
Statement of Work <br />This Statement of Work is entered into and made effective this day _/_/ 2017 (Effective <br />Date") by and between Tieton Group LLC ("Tieton Group") and Kittitas County ("Client"). <br />This Statement of Work is governed by the terms and conditions set forth in the Tieton Group <br />LLC Master Services Agreement, mutually executed between Tieton Group and Kittitas County <br />on / /2017. <br />Proiect Scone <br />Tieton Group LLC will conduct an assessment of the current HIPAA information security controls <br />implemented at Kittitas County. This will include interviews with County staff and review of <br />County policies, standards, practices and processes. The assessment results will be compared <br />with the HIPAA Security Rule standard of security controls in order to determine any gaps that <br />may exist. The assessment and associated deliverable are intended to underscore those areas <br />where the county is doing well in addressing HIPAA security requirements and also highlight <br />those areas where further attention is needed. <br />Project Objectives: <br />Provide rapid determination of the gaps between current practices and the HIPAA <br />Security Rule requirements. The HIPAA Security Rule requirements include: <br />a. 164.308 Administration Safeguards <br />b. 164.310 Physical Safeguards <br />c. 164.312 Technical Safeguards <br />d. 164.314 Organizational Requirements <br />• Generate a summary list of recommended next steps that outlines a HIPAA compliance <br />roadmap. <br />• Provide a prioritization to the current level of ePHI data risk by ranking issues found <br />High, Medium and Low. <br />• Provide documentation of recommended corrective actions to mitigate the identified <br />security exposures. <br />• Provide practical solutions to mitigate the deficiencies. <br />• As an initial phase of this project, Tieton Group will first confirm which county <br />departments should be included in the scope of this HIPAA assessment. <br />The proposed HIPAA Gap Assessment is not a compliance audit. It is an assessment of the <br />current state of Kittitas County documented and undocumented policies, standards, practices <br />and processes as measured against the HIPAA Security Rule requirements. <br />