This reference is useful for looking at overall gap analysis categories for a comprehensive HIPAA implementation. The information security component should be used as input to the Utah workgroup. See the entire brief at http://www.ahima.org/journal/pb/99.04.html