The Campus Covered Components (CCC) Program provides HIPAA Security Rule assessments to help covered components understand their current compliance and security posture, identify areas for improvement, and support ongoing risk management activities.

This page provides guidance and resources to assist covered components throughout the assessment process, including information on assessment expectations, documentation, roles and responsibilities, and next steps following completion.

ISORA GRC

ISORA Governance, Risk, and Compliance (GRC) is an information security risk assessment tool used by the CCC Program to evaluate components’ compliance with the HIPAA Security Rule through targeted risk assessments.

This tool uses the following terminology:

  • Advisor: Has read-only access to everything for the given unit. 
    • Assigned to the ISO.
  • Assessment Manager: Responsible for completing and overseeing the assessment, including acknowledging the final assessment response. This role can assign responsibilities and delegate sections. 
    • Assigned to the HIPAA Security Official (Primary Contact)
  • IT Staff: Assists the Assessment Manager with completing the assessment.
    • Assigned to the HIPAA Security Official’s Team (Secondary Contacts)

See How To Fill Out a Survey Questionnaire for more information about the application and its features.

Getting Started with the Assessment Process

The assessment workflow outlines each stage of the process, from initial preparation and assessment completion through review, acknowledgment and follow-up activities. 

The information below provides an overview of the steps involved and what covered components can expect throughout the assessment lifecycle.

  • Program Introduction: The CCC Team contacts the Covered Component and schedules an introductory meeting to review the program and assessment process.
  • Assessment Launch: The assessment is launched in ISORA, and HIPAA Contacts begin working on it.
  • Midpoint Check-In: The CCC Team checks in to review progress, answer questions, and provide support before the due date.
  • Assessment Review: After submission, the CCC Team reviews the responses and prepares the assessment results.
  • Security Leadership Review: Findings are reviewed with the Information Security Officer (ISO) and Chief Information Security Officer (CISO).
  • Report Meeting: The CCC Team meets with HIPAA Contacts to review results and discuss areas requiring follow-up.
  • Risk Mitigation: A mitigation plan is developed, and HIPAA Contacts work to address identified action items.
  • Follow-Up: Check-in meetings are held as needed until priority action items are addressed.

Contact Information

Throughout the process, the CCC team works closely with key partners across campus to support coordination, communication, and HIPAA Security Rule compliance, including: