Risk Assessment Factors

Risk Assessment Factors

  1. Nature and extent of PHI
  2. Unauthorized person who accessed
  3. Whether PHI was viewed/acquired
  4. Mitigation measures taken

**Financial Services Compliance**:
- **PCI-DSS**: Forensic investigator requirements
- **SOX**: Evidence preservation for financial data
- **GLBA**: Safeguards and notification rules
- **NY DFS**: 72-hour notification requirement