This session will look at what a good risk program should cover in order to be compliant with HIPAA regulations. The participants will come away with the right building blocks of a good risk program and compare theirs to this presentation. It will answer the following question:Do I have all the necessary components for a Risk Program?Have I considered Threat Actors and Key Applications?What about Medical IOT and Third Parties?How do I keep my risk program current?What kind of metrics do I need to monitor the risk program?