Back

Include disseminating and communicating events surrounding instances of desirable conduct and undesirable conduct in the communication protocols.


CONTROL ID
12824
CONTROL TYPE
Communicate
CLASSIFICATION
Preventive

SUPPORTING AND SUPPORTED CONTROLS




This Control directly supports the implied Control(s):
  • Establish, implement, and maintain communication protocols., CC ID: 12245

There are no implementation support Controls.


SELECTED AUTHORITY DOCUMENTS COMPLIED WITH




  • Provide multiple pathways to report progress toward objectives, and the actual or potential occurrence of undesirable and desirable conduct, conditions, and events. (OCEG GRC Capability Model, v. 3.0, P6 Notification, OCEG GRC Capability Model, v 3.0)
  • A description of the acts or omissions and injuries upon which the final adverse action was based, and such other information as the Secretary determines by regulation is required for appropriate interpretation of information reported under this section. (§ 1128E(b)(2)(D), Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, 104th Congress)
  • The name and TIN (as defined in section 7701(a)(41) of the Internal Revenue Code of 1986) of any health care provider, supplier, or practitioner who is the subject of a final adverse action. (§ 1128E(b)(2)(A), Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, 104th Congress)
  • The name (if known) of any health care entity with which a health care provider, supplier, or practitioner, who is the subject of a final adverse action, is affiliated or associated. (§ 1128E(b)(2)(B), Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, 104th Congress)