Which compliance laws or standards does the health care organization mentioned in the handson steps have to comply with (consider these: health insurance portability and accountability act [hipaa], gramm-leach-bliley act [glba], and family educational rights and privacy act [ferpa])? how does this impact the scope and boundary of its it risk management plan?