Governance, Risk & Compliance: GRC

Your one-stop hub for strategic frameworks and best practices that integrate governance, risk management, and compliance into daily operations. Explore insights and real‑world examples that turn complex mandates into clear, resilient programs.

HITECH Act, Building on HIPAA, Comes with Obligations, a Carrot and a Stick

HIPAA compliance is a core daily activity always on the minds of healthcare professionals, not just the domain of compliance officers. Violations of HIPAA’s privacy and security rules can result in civil and criminal penalties. HIPAA was amended with the HITECH Act, which provides additional protections and penalties for health information and encourages the use of electronic health records. The HITECH Act of 2009 mandated ...

By |2025-04-28T02:12:17+00:00February 9th, 2023|Compliance, IT Risk & Cybersecurity|

Security Fundamentals — The Services and Processes You Must Get Right.

Complimentary Gartner® Research Report: Security Fundamentals — The Services and Processes You Must Get Right How to communicate the value of your security program: Insights from Gartner Security and risk management leaders are responsible for reducing organizational threats from many risks while constantly communicating the value of security and risk programs to different people and departments, each with different needs and expectations. Download this complimentary ...

By |2023-02-07T09:39:05+00:00February 7th, 2023|Governance, Risk & Compliance: GRC, IT Risk & Cybersecurity|

EU’s Digital Operational Resilience Act: Your Guide to ICT Risk Management

The EU's Digital Operational Resilience Act (DORA), due to be enforced in 2023/24, introduces EU-wide laws to ensure the operational resilience of the financial services industry. The proposal builds on current ICT risk management requirements and combines preexisting EU initiatives into a single regulation. This means along with other actions; organisations’ ICT risk management frameworks must be periodically evaluated to identify any deficiencies or gaps. ...

HIPAA’s HITECH Act Calls for a Best-Practice IT Risk Program

The HITECH Act, which amended the Health Insurance Portability and Accountability Act (HIPAA), prescribes that healthcare organizations should implement a best practice IT risk program that conforms to HHS/OIG guidance. In order to improve privacy and security protections for healthcare data, HITECH incentivizes the adoption and use of health information technology by providers. In the event of a cyber event, institutions that have had a ...

By |2025-08-21T15:31:33+00:00January 25th, 2023|Compliance, IT Risk & Cybersecurity|

2023 GRC Trends and Predictions

In 2023, organizations worldwide will face increased external pressures on multiple fronts. These outside pressures will vary from new ESG requirements and an uncertain business climate to increased costs, supply chain volatility and regulatory change and perhaps, as recent years have shown us, the completely unexpected. SAI360’s 2023 Trends and Predictions for GRC include: 1. Increased focus on ESG Environmental, Social, Governance (ESG) is top ...

Five Healthcare Compliance Trends For 2023

Any list of 2023 healthcare compliance trends should start with what is currently going on healthcare. An increasing number of healthcare organizations have transitioned from paper-based recordkeeping systems to more efficient digital processes that save time and eliminate human errors. In addition, the pandemic accelerated the adoption of telehealth visits, digital payment options, and data-sharing capabilities that rely on the internet. Digitization can drive great ...

By |2025-04-28T02:10:22+00:00January 12th, 2023|Compliance|