Security and Privacy Workgroup

Security and Privacy workgroup header image of blue lcok in cloud and data web

Purpose 

Quarterly Security Scorecards:

To provide guidance and oversight on security and privacy practices, ensuring consistent standards, risk mitigation, and protection of sensitive information. 

Goals 

  • To provide guidance to ensure UT-HIP is configured securely and in full compliance with regulatory standards. 
  • To develop and update policies and procedures to support ongoing, compliant operation of UT-HIP. 
  • To ensure all data handling and protection practices align with HIPAA requirements, including the safeguarding of protected health information (PHI) through appropriate administrative, technical, and physical controls 

UT-HIP Security and Privacy Strategy 

The UT-HIP Information Security Program is designed to protect the confidentiality, integrity, and availability of systems and data through a combination of policies, standards, and technical controls. As the threat landscape continues to evolve and technology advances, maintaining a strong and adaptable information security program is essential to safeguarding sensitive data and supporting consumers that utilize the platform. 

Security Operations Center 24x7 Monitoring 

Systems and infrastructure within the Azure cloud environment are monitored 24x7 to maintain consistent visibility in both security and operational health. This continuous monitoring supports the timely identification of anomalies, potential threats, and system issues, enabling efficient investigation and response by UT-HIP Security. 

I1 HITRUST Certified 

Completion of the industry-recognized I1 HITRUST Assessment demonstrates the platform’s alignment with leading security practices. The assessment evaluates the implementation of controls across nineteen technology domains. Annual security assessments help ensure the platform's continued alignment with evolving industry best practices, strengthening trust and accountability for consumers and stakeholders. 

Security and Privacy Leadership 

Chair: John Flores, Associate Vice President Information Security & Chief Information Security Officer, The University of Texas Medical Branch at Galveston 

Vice Chair: Tim Boughal, Chief Enterprise Risk & Compliance Officer Interim, UT-HIP Privacy and Compliance Liaison, The University of Texas at Austin Dell Medical School 

The University of Texas at Austin Dell Medical School 
  • Tim Boughal, Vice Chair, Chief Enterprise Risk & Compliance Officer Interim, UT-HIP Privacy and Compliance Liaison 
The University of Texas Health Science Center at Houston 
  • ShuRon Green, Executive Director, UT Health Intelligence Platform 
  • Richard Anselme, Deputy Chief of Information Security 
  • Christina Solis, Sr. Legal Privacy Officer 
The University of Texas Health Science Center at San Antonio 
  • Jessica Saldivar, Chief Compliance Officer 
  • Michael Schnabel, Sr. VP and Chief Information Officer 
  • Angelife Pardo, Director of Privacy 
The University of Texas MD Anderson Cancer Center 
  • Matthew Bourgeois, Sr. Legal Officer and Executive Director 
  • Lessley Stoltenberg, Vice President & Chief Information Security Officer 
The University of Texas Medical Branch at Galveston 
  • John Flores, Chair, Associate Vice President Information Security & Chief Information Security Officer 
  • Cecily Martinez, Compliance Attorney and Privacy Officer 
  • August Voytek, Lead Security Analyst 
The University of Texas Rio Grande Valley Medical School  
  • Bertram Oparaku, Deputy Chief Compliance Officer 
  • Kevin Crouse, Chief Information Security Officer 
The University of Texas Southwestern Medical Center 
  • Natalie A. Ramello, Assistant Vice President and Privacy Officer 
  • Manmohan Singh, Assistant Vice President of Information Security 
The University of Texas System 
  • Sean Griffin, Deputy Vice Chancellor 
  • Jennifer Kennedy, Associate Systemwide Compliance Officer, Privacy and Data Protection Officer 
  • George Finney, Chief Information Security Officer 
  • Bobby Yanez, HIPAA Security Officer 
The University of Texas at Tyler Health Science Center 
  • Kevin T Kjosa, Assistant VP of Information Security 
  • Jennifer Rau-hug, Chief Compliance Officer