Skip to main content
Case studyFortune 100: 80% less compliance workRead the Story
RiskWatch
Blog · Compliance · 55 articles

Compliance articles and guides.

Framework deep-dives and regulatory analysis: HIPAA, ISO 27001, SOC 2, PCI DSS, GDPR, NIST, CMMC, and how to prepare for the audits that follow.

All compliance articles

55 posts
Risk management
Feb 21, 20245 min

Oil and Gas Risk Management

Oil and Gas Industry The oil and gas industry is a volatile one, inundated by a number of risks and regulations which range from worker safety to environmental concern. It is designated as a…

Risk management
Feb 18, 20243 min

What is a Gap Analysis?

Gap Analysis A gap analysis is a necessary component of risk management that is, at times, unclear to those in risk, security, and compliance positions. This leaves the question of, “What is a gap…

Insights
Feb 13, 20245 min

The CAN-SPAM Act

What Is the CAN-SPAM Act? The CAN-SPAM Act essentially dictates what can and cannot be done in regards to commercial messaging, including what can happen if you’re noncompliant. Formally referred to…

Risk management
Feb 9, 20244 min

Risk Management in Banking

Risk management in banking has largely been focused on compliance with regulations and standards in recent times. This practice primarily stems from the regulations and culture that emerged during…

HIPAA
Jan 20, 20245 min

Top Five Risks in Healthcare

Top Five Risks Facing the Healthcare Industry The healthcare industry faces unprecedented risks and compounding regulatory compliance requirements. They’re particularly vulnerable due to their heavy…

Risk management
Jan 7, 20243 min

Service Provider Risk and Compliance

Service Provider Risk and Compliance In our continuing effort to educate on the importance of risk assessment and compliance, this week we wanted to touch base on service provider risk and what you…

Risk management
Oct 8, 20234 min

Cyber Risk Assessments

## Cyber Risk Assessments RiskWatch offers over 50 prebuilt content libraries that are ready for use in our platform. These libraries contain industry standards and regulations, lending subject…

GDPR
Sep 22, 20214 min

What is GDPR?

GDPR Defined The General Data Protection Regulation (GDPR) is a data privacy and security law that was passed by the European Union back in 2018. It quickly made its reputation as one of the toughest…

Compliance
Sep 14, 20215 min

What is GRC?

GRC Defined GRC is an acronym for governance, risk, and compliance; it’s a term that refers to an organization’s strategy and management for each of those three components. GRC is a structured…

Insights
Oct 28, 20204 min

NIST SP 800-171

Who is NIST? The US National Institute of Standards and Technology (NIST) is an organization with the goal of improving economic security and quality of life. They pursue this goal by promoting…

GDPR
Jan 3, 20203 min

California Consumer Privacy Act (CCPA)

What is the California Consumer Privacy Act? The California Consumer Privacy Act (CCPA) exists to provide California residents with more control over their data and information on how it is being…

HIPAA
Oct 10, 20193 min

5 Steps for Healthcare Compliance

Healthcare Compliance As a highly regulated, high-risk industry, healthcare organizations place the utmost concern on compliance. Healthcare compliance protects both patients and staff, and widely…

Compliance
Jan 31, 20193 min

COBIT Compliance and Framework

The Value of Cobit Compliance With today’s prevalence of technology in the workplace, we can’t stress enough the importance of cybersecurity and keeping an effective cyber framework in place. As…

Insights
Jan 12, 20192 min

The Government Shutdown and Potential Risks

Risks During the Government Shutdown Today marks 21 days into the government shutdown, and we can’t help but worry about the state of safety and regulations. Nine out of fifteen federal departments…

Compliance
Dec 5, 20183 min

IT Compliance Management: The What and Why

IT Compliance Management IT compliance management can be difficult for many organizations that don’t understand the requirements of cyber data, especially when you have to consider standards such as…

Vendor risk
Oct 10, 20183 min

Supplier Audits and What You Need to Know

Performing Supplier Audits If you’re in business with a supplier, you’re going to want to make sure you perform regular audits as their business practices directly impact yours. Supplier audits are…

Compliance
Sep 26, 20182 min

A Closer Look at IT Compliance

Importance of Implementing IT Compliance With the vast majority of businesses going digital, IT compliance is now more prevalent than ever. With that said, we wanted to utilize this blog post as an…

HIPAA
Aug 23, 20182 min

How to Prepare for a Security Audit

The Unnecessary Torture of Security Audits From financial services to healthcare, nearly every industry gets audited for security, and no one looks forward to it. Just the thought of getting audited…

ISO 27001
May 30, 20182 min

Information Risk: ISO 27001

What is it? ISO 27001 is an international standard that provides a process for an Information Security Management System (ISMS). An ISMS is a framework containing policies and procedures for an…

GDPR
Apr 18, 20182 min

Five Must Knows About GDPR

What is GDPR? A trending topic these days is the latest data regulation that businesses all around the world will soon follow—GDPR. For those of you who don’t already know what GDPR is, let’s start…

HIPAA
Nov 13, 20123 min

The IT Risk Assessment and HIPAA Compliance

The positions “Risk Analysis,” at front-and-center in the first section of HIPAA – the Administrative Safeguards. Yet, it is rare to find that a formal IT Risk Assessment has been completed, and…

HIPAA
Sep 21, 20124 min

Healthcare Provider to Pay $1.5M HIPAA Fine

Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Ear Associates Inc. (MEEI) has agreed to pay the U.S. Department of Health…

HIPAA
Sep 19, 20124 min

Another Big Fine After a Small Breach

HIPAA Investigation Leads to Sanctions For the second time in three months, federal authorities have issued a hefty financial penalty stemming from a HIPAA compliance investigation after a relatively…

Insights
Sep 13, 20122 min

Mobile, Cloud Security Guidance Needed

Smaller Institutions Could Benefit from Regulators’ Help Last year, federal regulators issued FFIEC authentication guidance for online transactions. But, unfortunately, regulators apparently don’t…

GDPR
Sep 7, 20124 min

Investigation Prompts Privacy Dispute

Hospital, Attorney General, at Odds Over Records Access A criminal and public health investigation in New Hampshire involving a former hospital worker who allegedly infected dozens of patients with…

HIPAA
Sep 4, 20122 min

HITECH Stage 2: How to Prepare

Federal Privacy Officer Offers Insights What’s the best way to prepare to comply with HITECH Stage 2 privacy and security requirements? Federal privacy officer Joy Pritts advises healthcare…

HIPAA
Aug 31, 20126 min

HITECH Stage 2 Rules: An Analysis

Experts Sort Through Privacy, Security Provisions Some privacy and security experts that have dug into the 1,446 pages of final rules for Stage 2 of the HITECH electronic health record incentive…

GDPR
Aug 13, 20122 min

Google to Pay $22.5 Million FTC Fine

Penalty Resulted from Deceptive Cookie Practices Search engine giant Google Inc. will pay $22.5 million to settle Federal Trade Commission charges that it misrepresented its privacy promises to users…

Cyber incident
Aug 13, 20123 min

6 Steps to Handle IT Security Incidents

The National Institute of Standards and Technology has issued a revision of its guidance to help organizations establish programs to manage computer security incidents. NIST, in Special Publication…

HIPAA
Oct 6, 20112 min

Why Bother with a HIPAA Risk Analysis Anyway?

People tell me all the time that their management doesn’t want them to do a risk analysis, even if it’s a requirement. Sometime they say that they have no budget to fix anything – so why bother? Even…

Get started

Put insights into action

Try the platform behind the posts. 30-day free trial, no credit card required.

No credit card required · 30-day free trial · Cancel anytime

Request a Demo