The HIPAA privacy and security rules provide federal protection for individually identifiable health information. Consider a physician practice that is transitioning from being paper based to electronic medical records. The receptionist area contains both hanging folders and the desktop computer on which the practice management system runs. During the transition, a patient's health information (valued asset) will exist in two states: on paper in a hanging folder and in an electronic record on a computer.

1) Identify and evaluate the risks for each state in terms of:

a) Threats
b) Vulnerabilities
c) Probability of a breach (low, medium, or high).

2) In your answer include a discussion of authentication, integrity, and accountability.

