Brad Gaylord
Principal National IT Compliance @Kaiser Permanente
Signup · Get unlimited contacts
WORK HISTORY
Principal National IT Compliance @Kaiser Permanente
Greenwood Village, CO, US
Kaiser Permanente -\"Thrive\"• One of the principal architects of the comprehensive KP Information Security Control (ISC) framework, recently extended to include 20+ additional sources of information security requirements from applicable regulatory requirements and industry standards to strengthen the ISC’s coverage of security and privacy requirements in the areas of electronic Protected Health Information (ePHI), personally identifiable information (PII), medical devices, cloud controls, and more. • Provided guardrails for 60 guidance documents that were written by contractors in 2018. This guidance communicated efficient ways to adopt the ISC controls, enabling business, infrastructure, application, and project management teams within KP to effectively apply risk principles to challenging business situations that need to comply with the security requirements of the HIPAA Security Rule, PCI DSS, SOX, and other applicable regulations and standards• Defined and refined the architecture of the original ISC catalog between 2015 and 2017, based on the security controls in NIST Special Publication 800-53 Revision 4. The ISC is the framework used at KP for employing and evaluating security requirements derived from regulations and industry standards.• Developed, maintained and enhanced a rigorous risk-based HIPAA work program to assess applicable controls that address HIPAA Security Rule requirements for administrative, physical, and technical safeguards.• Prior to 2015, performed security control assessments of healthcare systems across all KP IT business units and regions, in all phases of the IT solution delivery life cycle. Assessed compliance with applicable requirements in the HIPAA Security Rule and PCI DSS. Reviewed deliverables produced by other assessors in all phases of assessment planning, fieldwork and reporting.
EDUCATION
Mitchell Hamline School of Law
Certificate, Cybersecurity and Privacy Law
Western Colorado University
BA, Bachelor of Arts in Mathematics
University of Phoenix
MBA, Master of Business Administration
Kansas State University
MS, Master of Science in Computer Science
Stevens Institute of Technology
MCPM, Master’s Certification in Project Management
SKILLS
ABOUT BRAD GAYLORD
Experienced IT Risk Management professional with a current background in assessing the design and implementation of effective internal controls. Comfortable working with stakeholders at all levels, including IT / business executives, process owners, IT project managers, developers and users. Excellent communication skills and a strong process-oriented understanding of IT:• Proficient at quickly mastering new environments and methodologies.• Excellent verbal, written, interpersonal and project management skills.• Dedicated to producing process-based solutions with measurable results.• Skilled in the management of internal and external corporate relationships.15+ years of IT Risk, Security, Compliance and Audit Coordination experience:• Technology Risk Management• Governance of Enterprise IT• Secure Software Lifecycle• IT Security Management• IT Service Management• IT Audit / Internal Audit• Information Privacy• Data Protection
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.