What you will find here
- Written for
- Chief executives, boards, general counsel and compliance leadership.
- Subjects
- Governance, cyber risk, regulatory readiness and executive reporting.
- Every article
- Carries its author, its publication date and the date it was last substantively revised.
Articles
-
Regulatory and Framework Readiness
What Healthcare Organizations Must Implement Under the ONC Cures Act Information Blocking Rule
The 21st Century Cures Act's information blocking rule makes interference with electronic health information sharing potentially unlawful. Healthcare providers and health IT developers face civil monetary penalties without clear ownership of compliance obligations spanning clinical operations, legal interpretation, vendor contracts and security policy. Leadership requires a defined strategy, governance structure and accountability framework to demonstrate good-faith compliance.
-
AI and Emerging Technology Governance
What Healthcare Organizations Must Implement When Using AI for Prior Authorization, Claims Processing or Utilization Management
Healthcare organizations deploying AI in prior authorization, claims processing or utilization management face a compliance landscape without a single federal standard. CMS requirements, state laws, FTC data security obligations and HIPAA rules converge on these systems, yet no single executive typically owns the cross-functional work of establishing governance, documenting decisions and maintaining defensibility. This article explains what regulations apply, who should own compliance at the executive level, and the practical steps leadership must take to satisfy regulatory expectations without stalling deployment.
-
Compliance
What Healthcare Organizations Must Implement When Using Patient Data for Quality Improvement, Research or Population Health Analytics
Healthcare organizations using patient data for quality improvement, research or population health analytics face specific requirements under the HIPAA Privacy Rule. Leadership is accountable for de-identification procedures, authorization protocols and governance frameworks, yet these requirements often lack clear ownership. This article explains what HIPAA permits for treatment, payment, healthcare operations, research and public health purposes, when authorization is required, what constitutes proper de-identification, and who inside the organization must own compliance.
-
Regulatory Compliance
What Healthcare Organizations Must Prepare for Under CMS's Cybersecurity and Patient Safety Conditions of Participation
The Centers for Medicare & Medicaid Services proposed in 2024 adding cybersecurity requirements to Medicare and Medicaid Conditions of Participation. Hospital and health system leadership need to understand what the proposed rule would require, when it may take effect, and how to establish the executive ownership necessary for timely compliance.
-
Regulatory Compliance
What Healthcare Organizations Must Report to ASPR Under the Cyber Incident Reporting Rule
The proposed Cyber Incident Reporting Rule requires healthcare delivery organizations to report qualifying cyber incidents to the Administration for Strategic Preparedness and Response. This article explains what constitutes a reportable incident, who is covered, reporting timelines, and what information must be submitted—along with who inside the organization should own compliance with this obligation.
-
Regulatory Compliance
What Healthcare Organizations Must Report Under the 72-Hour Breach Notification Rule
The HIPAA Breach Notification Rule requires covered entities to report breaches of protected health information to HHS within 72 hours, but many healthcare organizations lack clear accountability for making that determination. This article explains what triggers the reporting requirement, who decides whether a breach is reportable, and how executive leadership can establish adequate governance before an incident occurs.
-
Regulatory and Framework Readiness
What Insurance Entities Must Implement Under the NAIC Insurance Data Security Model Law Amendments
Insurance carriers, MGAs, and brokerages operating in states adopting amendments to the NAIC Insurance Data Security Model Law face updated requirements for risk assessment, incident response, and third-party oversight. Leadership is often accountable for compliance without clear ownership or a defined path to implementation. This article explains the regulatory obligations, identifies who owns each component, and outlines practical next steps for establishing executive accountability.
-
Regulatory and Framework Readiness
What Investment Advisers Must Implement Under the SEC's October 2023 Safeguarding Rule for Client Assets
The SEC's amended custody rule establishes specific safeguarding, recordkeeping, and account statement obligations for registered investment advisers. Leadership must assign clear ownership of both custody procedures and the underlying cybersecurity controls that prevent unauthorized access to client assets. Without executive coordination, compliance becomes fragmented across operations, compliance, and technology functions.
-
Regulatory Compliance
What Investment Advisers Must Implement Under the SEC's Outsourcing Rule for Recordkeeping and Third-Party Service Providers
The SEC's October 2023 amendments to Rule 204-2 impose new requirements when registered investment advisers outsource recordkeeping or other functions. This article explains what must be in third-party agreements, what must be monitored, who is accountable, and how vCISO leadership provides the executive ownership needed to meet these obligations.
-
Regulatory Compliance
What Is Changing in Security Regulation for Financial Services
Financial services firms face a complex and shifting set of security requirements from federal regulators, including data safeguards under the Gramm-Leach-Bliley Act, breach notification obligations, and the FTC's authority to pursue unfair or deceptive practices. Compliance is rarely a static checklist; obligations evolve as frameworks such as the NIST Cybersecurity Framework are updated and as enforcement priorities shift. Leadership is accountable, but clarity on who owns the regulatory position, how controls map to obligations, and how progress is measured often remains absent. Heights Consulting Group provides executive ownership through vCISO leadership that closes this gap, translating regulatory requirements into defensible strategy and providing the governance reporting boards and leadership need.
-
Cloud Security
What Must Be in Place Before Migrating Electronic Health Records to a Cloud Environment
Healthcare organizations moving EHR data to cloud infrastructure face clear regulatory requirements: HIPAA business associate agreements, encryption of protected health information at rest and in transit, technical access controls, comprehensive audit logging, and functioning breach notification procedures. Leadership is accountable for these security outcomes, but often lacks a clear owner for the sequence of work, risk decisions, and ongoing governance. This article explains what federal and state health data privacy laws require, who inside the organization should own each element, and how to structure the effort so progress can be measured and reported.
-
Cloud Security Architecture
What Must Be in Place Before Operating a SaaS Platform in a FedRAMP High Authorization Boundary
FedRAMP High authorization requires substantially more restrictive controls, additional documentation, and continuous monitoring capabilities beyond Moderate. SaaS providers must implement expanded baseline controls, enhanced testing procedures, and organizational processes before pursuing High authorization. Without clear executive ownership of this regulatory position, organizations risk misallocated effort and authorization delays.
How these are written
Nothing here is generated filler, and nothing is published without an accountable author.
-
Written by a named author
Every article carries a byline that links to a real profile. There are no house bylines and no invented contributors.
-
Dated honestly
The original publication date and the date of the last substantive revision are both shown, and neither is refreshed to look current.
-
Sourced where it matters
Where an article relies on published guidance or a regulation, the source is cited so you can check it yourself.
-
Aimed at a decision
Each piece is written to help leadership decide something, not to demonstrate technical depth to other practitioners.
Bring clear ownership to your cybersecurity program.
Start with a confidential conversation about your organization, obligations, current security program, and the decisions in front of leadership.
Or reach us directly at (407) 908-7001 or info@heightscg.com.