The purpose of the Risk Analysis Update Policy is:
- To gather intelligence from agencies, the Office of the Inspector General (OIG), the Federal Computer Incident Response Center (FedCIRC), mass media, virus alerts, and/or vendors to update potential risks to the confidentiality, integrity and availability of electronic patient health information (EPHI).
- To identify sources of information regarding potential risks to the organization.
- To assist in the identification and implementation of risk management policies to reduce the risks uncovered by security inspections.