<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; Encyption</title>
	<atom:link href="http://www.experiordata.com/blog/category/encyption/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Safeguarding Health Information: Building Assurance through HIPAA Security NIST Conference</title>
		<link>http://www.experiordata.com/blog/2010/05/11/safeguarding-health-information-building-assurance-through-hipaa-security-nist-conference/</link>
		<comments>http://www.experiordata.com/blog/2010/05/11/safeguarding-health-information-building-assurance-through-hipaa-security-nist-conference/#comments</comments>
		<pubDate>Tue, 11 May 2010 10:35:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Washington DC]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=429</guid>
		<description><![CDATA[&#160;
We will be tweeting live from the NIST HIPAA security conference on 5/11 and 5/12. If you use twitter we will be using the #NISTHIPAA hashtag. To see our tweets you &#160;can go to search.twitter.com and search for #NISTHIPAA after 9:30 am. You can also follow @experiordata
]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>We will be tweeting live from the <a href="http://www.nist.gov/public_affairs/confpage/100511b.htm">NIST HIPAA security conference </a>on 5/11 and 5/12. If you use twitter we will be using the #NISTHIPAA hashtag. To see our tweets you &nbsp;can go to search.twitter.com and search for #NISTHIPAA after 9:30 am. You can also follow @experiordata</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/11/safeguarding-health-information-building-assurance-through-hipaa-security-nist-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Government is Serious: Breach Notifications WILL be posted</title>
		<link>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/</link>
		<comments>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 04:22:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=411</guid>
		<description><![CDATA[HHS OCR names covered entities and business associates involved in data breaches over 500 records of PHI lost. Unencrypted PHI that is breached must be reported to HHS and mass media.]]></description>
			<content:encoded><![CDATA[<p>The government is naming names! Today the Office of Civil Rights, part of the Department of Health and Human Services, did what they they said all along that they will do &#8211; post the names of covered entities AND business associates who are involved in data breaches. The somewhat <a title="OCR list of covered entities and business associates with breaches of PHI" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/postedbreaches.html" target="_blank">lengthly list</a> provides an insight into the organizations involved in breaches of unsecured protected health information (PHI).</p>
<p><br class="spacer_" /></p>
<p>Protected Health Information (PHI) is a term used widely in HIPAA. PHI is information that can identify and individual, such as name, address, social security number, and clinical information about the individual. Part of the American Recovery and Reinvestment Act (ARRA) called the HITECH Act, section 13402, specifically requires a covered entity or business associate to notify HHS and the mass media of breaches of uprotected PHI involving more than 500 records. PHI that is encrypted is considered <em>protected </em>and, therefore, provides a safe harbor against breach notification.</p>
<p><br class="spacer_" /></p>
<p>Among those involved in the data breaches are hospitals, clinics, dentists, insurance companies, private medical practices (though it&#8217;s unclear as to why their names are being withheld), universities, state governments, and several Blue Cross Blue shield organizations.</p>
<p><br class="spacer_" /></p>
<p>More importantly, business associates &#8211; which are essentially service providers to covered entities &#8211; are not only listed but are named. Most of them are IT services providers to covered entities.</p>
<p><br class="spacer_" /></p>
<p>Data at rest appears to be the most common form of breach, most likely a result of lost laptops, backup tapes, and a seemingly missing server.</p>
<p><br class="spacer_" /></p>
<p>Data encryption provides a safe harbor against breach notification and should be implemented in places where PHI is stored.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PGP Encryption Smackdown &#8211; Supports Mac Snow Leopard, Linux, Boot Camp, SSD drive support</title>
		<link>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/</link>
		<comments>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 19:32:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=391</guid>
		<description><![CDATA[PGP Corporation announced an update to its products line. PGP now supports Red Hat &#38; Ubuntu Linux, Mac OSX Snow Leopard, and Boot Camp on Mac OSX computers. In addition, PGP has updated its whole disk encryption technology to include a Hybrid Cryptographic Optimizer (HCO) technology to deliver faster run times for PGP Whole Disk [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PGP Corporation - encryption" href="http://www.pgp.cpm">PGP Corporation</a> announced an update to its products line. PGP now supports Red Hat &amp; Ubuntu Linux, Mac OSX Snow Leopard, and Boot Camp on Mac OSX computers. In addition, PGP has updated its whole disk encryption technology to include a Hybrid Cryptographic Optimizer (HCO) technology to deliver faster run times for PGP Whole Disk Encryption.</p>
<p><br class="spacer_" /></p>
<p>Customers can now use PGP Universal Server to centrally manage encryption for their multi-platform environment. A single web-based user interface can be used to manage encryption end points using Microsoft Windows, Apple Mac, Red Hat Linux, and Ubuntu Linux. PGP is the only encryption vendor that delivers encryption solutions across multiple platforms. Multi-platform support is especially important with the popularity of netbooks, and the forthcoming Apple tablet device, which is reported to be using the Mac OSX operating system.</p>
<p><br class="spacer_" /></p>
<p>PGP also added functionality for e-mail encryption in Microsoft Outlook. Using Microsoft Outlook users can now click &#8220;sign and encrypt&#8221; buttons to automatically encrypt emails.</p>
<p><br class="spacer_" /></p>
<p>Experior Data is a PGP SILVER Partner and helps organizations implement data encryption solutions.</p>
<p><br class="spacer_" /></p>
<p>More information about these new releases is available on the <a title="PGP releases new encryption products" href="http://www.pgp.com/insight/newsroom/press_releases/new_data_protection_solutions_for_mac_linux.html" target="_blank">PGP web site</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security for Meaningful Use: Part 2 &#8211; Electronic Access to Protected Health Information (PHI)</title>
		<link>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 17:34:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=352</guid>
		<description><![CDATA[Standards Set for Providing Secure Access to Patient Records





Image via Wikipedia



According to the Initial Set of Standards for Electronic Health Records patients must be provided with their health information (most certainly protected health information -PHI- under HIPAA) electronically and securely within 96 hours.


&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification [...]]]></description>
			<content:encoded><![CDATA[<h2>Standards Set for Providing Secure Access to Patient Records</h2>
<p><br class="spacer_" /></p>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png"><img title="Sample patient record view from VistA Imaging" src="http://upload.wikimedia.org/wikipedia/en/thumb/8/8f/VistA_Img.png/300px-VistA_Img.png" alt="Sample patient record view from VistA Imaging" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>According to the <a title="Initial set of standards for certified electronic health records (EHRs) released by HHS/CMS" href="http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/">Initial Set of Standards</a> for <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Records</a> patients must be provided with their health information (most certainly <strong>protected</strong> health information -PHI- under <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a>) electronically <strong>and</strong> securely within 96 hours.</p>
<p><br class="spacer_" /></p>
<address>
<p>&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification of this objective. Electronic copies may be provided through a number of secure electronic methods (for example, personal health record (</p>
</address>
<address>
<p>PHR), patient portal, CD, <a class="zem_slink" title="Universal Serial Bus" rel="wikipedia" href="http://en.wikipedia.org/wiki/Universal_Serial_Bus">USB</a> drive).</p>
<p><br class="spacer_" /></p>
<p>Provide patients with timely electronic access to their health information (including lab results, problem list, medication lists, allergies) within 96 hours of the information being available to the EP. Also, consistent with the HIT Policy Committee recommendations, we propose the following additional clarification of this objective. Electronic access may be provided by a number of <span style="font-style: normal;"><strong>s</strong></span><strong>ecure electronic methods (for example, PHR, patient portal, CD, USB drive).</strong> Timely is defined as within 96 hours of the information being available to the EP either through the receipt of final lab results or a patient interaction that updates the EP&#8217;s knowledge of the patient&#8217;s health. We judge 96 hours to be a reasonable amount of time to ensure that certified EHR technology is up to date. We welcome comment on if a shorter or longer time is advantageous.&#8221;</p>
</address>
<address> </address>
<h2><span style="font-style: normal;">How to Secure Health Records</span></h2>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg"><img title="USB Vacuum Cleaner, a giveaway from an IBM event" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/77/USBVacuumCleaner.jpg/300px-USBVacuumCleaner.jpg" alt="USB Vacuum Cleaner, a giveaway from an IBM event" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-style: normal;">You may be wondering how can patient information be secured. The best way to secure information is by encrypting the </span><span style="font-style: normal;">media. However, note that <strong>patients must be able to decrypt the information</strong> on their own computer equipment. One of the product Experior Data implements is called <a title="PGP Portable allows you to encrypt data on removable media but lets people decrypt it on other computers without requiring special software to be installed" href="http://www.pgp.com/products/portable/index.html" target="_blank">PGP Portable</a>. For example, the patient provides a USB drive for you to copy the PHI onto it. PGP Portable encrypts the entire USB device after the information is copied to it. The patient must provide a passphrase during the <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> process. When the patient goes home he/she inserts the USB drive into their home computer and is prompted for the passphrase. After the passphrase is entered access to the patient information is provided.</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://projecthealthdesign.typepad.com/project_health_design/2009/08/hies-are-beginning-to-link-patients-directly-to-their-own-health-data.html">HIEs are Beginning to Link Patients Directly to their Own Health Data</a> (projecthealthdesign.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://chilmarkresearch.com/2009/09/23/pushing-onc-to-act-on-consumers-behalf/">Pushing ONC to Act on Consumer&#8217;s Behalf</a> (chilmarkresearch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.medicineandtechnology.com/2009/12/medfusion-maintains-leadership-in.html">Medfusion Maintains Leadership in Patient Portal Performance</a> (medicineandtechnology.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.wsj.com/health/2009/12/30/how-to-get-20-billion-for-using-electronic-medical-records/">How to Get $20 Billion for Using Electronic Medical Records</a> (blogs.wsj.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/76960f38-a396-49b1-bf12-c9961f5125fc/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=76960f38-a396-49b1-bf12-c9961f5125fc" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nurse from a Toronto health clinic loses USB drive with 83,000 patient records</title>
		<link>http://www.experiordata.com/blog/2009/12/23/nurse-from-a-toronto-health-clinic-loses-usb-drive-with-83000-patient-records/</link>
		<comments>http://www.experiordata.com/blog/2009/12/23/nurse-from-a-toronto-health-clinic-loses-usb-drive-with-83000-patient-records/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 19:56:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=308</guid>
		<description><![CDATA[Nurse in Toronto loses USB drive with 83,000 patient records.]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Toronto.jpg"><img title="Toronto" src="http://upload.wikimedia.org/wikipedia/commons/thumb/9/91/Toronto.jpg/300px-Toronto.jpg" alt="Toronto" width="300" height="170" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Toronto.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-size: 14px;"><span style="font-family: arial,helvetica,sans-serif;"><br />
 </span></span></p>
<p><span style="font-size: 14px;"><span style="font-family: arial,helvetica,sans-serif;">Not a good day for our friends in Canada. Apparently, a nurse from a health clinic in a <a class="zem_slink" title="Toronto" rel="wikipedia" href="http://en.wikipedia.org/wiki/Toronto">Toronto</a> area clinic copied health information for 83,000 people to a USB drive..and subsequently lost the drive. Not good.</span></span></p>
<p><span style="font-size: 14px;"><span style="font-family: arial,helvetica,sans-serif;"><br />
 </span></span></p>
<p><span style="font-size: 14px;">&#8220;<span class="Apple-style-span" style="color: #000000; font-family: Arial, sans-serif; line-height: 18px;">A health department nurse was taking a USB key containing the records to her car in <a class="zem_slink" title="Whitby, Ontario" rel="geolocation" href="http://maps.google.com/maps?ll=43.8797222222,-78.9416666667&amp;spn=0.1,0.1&amp;q=43.8797222222,-78.9416666667%20%28Whitby%2C%20Ontario%29&amp;t=h">Whitby</a>, Ont., to take it to a remote clinic site on Dec. 15 when the device was lost. A search failed to turn it up.</span></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;"><span style="font-size: 14px;"><span class="Apple-style-span" style="color: #000000; font-family: Arial, sans-serif; line-height: 18px;">&#8220;We believe it was lost on regional property. We have some video surveillance tape data to indicate that was the case,&#8221; said Dr. Robert Kyle, chief medical officer of health for <a class="zem_slink" title="Regional Municipality of Durham" rel="wikipedia" href="http://en.wikipedia.org/wiki/Regional_Municipality_of_Durham">Durham Region</a>.</span></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;"><span style="font-size: 14px;"><span class="Apple-style-span" style="color: #000000; font-family: Arial, sans-serif; line-height: 18px;">The privacy commission office was advised Monday by the Durham Region health department that the device was missing, said spokesman Bob Spence.</span></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;"><span style="font-size: 14px;"><span class="Apple-style-span" style="color: #000000; font-family: Arial, sans-serif; line-height: 18px;">The USB key contained the names, addresses, phone numbers, dates of birth and health card numbers of patients who attended H1N1 flu vaccination clinics in the region between Oct. 23 and Dec. 15.&#8221;</span></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 1em; padding-left: 0px; margin: 0px; border: 0px initial initial;"><span style="font-size: 14px;"><a onclick="window.open(this.href, '', 'resizable=no,status=no,location=no,toolbar=no,menubar=no,fullscreen=no,scrollbars=no,dependent=no'); return false;" href="http://bit.ly/Toronto-USB"><span class="Apple-style-span" style="color: #000000; font-family: Arial, sans-serif; line-height: 18px;">View the full The Canadian Press article</span></a></span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.healthzone.ca/health/newsfeatures/article/741816--health-records-of-thousands-lost-in-durham">Health records of thousands lost in Durham</a> (healthzone.ca)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.cbc.ca/canada/toronto/story/2009/12/22/health-information.html%3Fref%3Drss&amp;a=10647118&amp;rid=2329fa97-9950-476e-a5d0-9a107f83bf5b&amp;e=0de92100f12b713f13437617c539ea2b">Thousands of health records lost in Durham</a> (cbc.ca)</li>
<li class="zemanta-article-ul-li"><a href="http://www.nationalpost.com/news/story.html?id=2371723">Over 80,000 Ontario health records missing</a> (nationalpost.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/2329fa97-9950-476e-a5d0-9a107f83bf5b/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=2329fa97-9950-476e-a5d0-9a107f83bf5b" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/23/nurse-from-a-toronto-health-clinic-loses-usb-drive-with-83000-patient-records/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Even Dilbert is serious about data encryption</title>
		<link>http://www.experiordata.com/blog/2009/12/17/even-dilbert-is-serious-about-data-encryption/</link>
		<comments>http://www.experiordata.com/blog/2009/12/17/even-dilbert-is-serious-about-data-encryption/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 05:39:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[dilbert]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=304</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><a href="http://dilbert.com/strips/comic/2009-11-19/" title="Dilbert.com"><img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/70000/4000/100/74150/74150.strip.gif" border="0" alt="Dilbert.com" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/17/even-dilbert-is-serious-about-data-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Net Breach Notification Letter</title>
		<link>http://www.experiordata.com/blog/2009/12/14/health-net-breach-notification-letter/</link>
		<comments>http://www.experiordata.com/blog/2009/12/14/health-net-breach-notification-letter/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 15:46:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[HITECH Act]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=301</guid>
		<description><![CDATA[An example of a breach notification letter from Health Net.]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:AlanisMorissette.01.jpg"><img title="{{pt|A cantora canadense Alanis Morissette dur..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/b/bd/AlanisMorissette.01.jpg/300px-AlanisMorissette.01.jpg" alt="{{pt|A cantora canadense Alanis Morissette dur..." width="300" height="428" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:AlanisMorissette.01.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 210px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Health_Net_vert_no_tag_color.png"><img title="Health Net, Inc." src="http://upload.wikimedia.org/wikipedia/en/f/fb/Health_Net_vert_no_tag_color.png" alt="Health Net, Inc." width="200" height="127" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Health_Net_vert_no_tag_color.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-size: 12px;">As Alanis Morrissette would say &#8220;And isn&#8217;t it ironic &#8230; don&#8217;t you think&#8221;. A relative just received a <a onclick="window.open(this.href, 'HealthNet Breach Notification Letter', 'resizable=yes,status=yes,location=yes,toolbar=yes,menubar=no,fullscreen=no,scrollbars=no,dependent=no'); return false;" href="http://experiordata.com/images/HealthNet_Breach.PDF">breach notification letter from from Health Net</a>. </span></p>
<p><span style="font-size: 12px;">Some wording we find interesting:</span></p>
<p><br class="spacer_" /></p>
<p><span class="Apple-style-span" style="font-size: 10px;">&#8220;The purpose of this letter is to inform you of a matter involving an unencrypted portable computer disk drive was discovered missing from a Health Net office&#8221;.</span></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p>What&#8217;s interesting about this sentence is that they use the term &#8220;unencrypted&#8221;. So the majority of the general public does not know what this term means. However, Health Net indirectly acknowledges that the drive should have been encrypted, and perhaps they will implement encryption in their company.</p>
<p><br class="spacer_" /></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.geeksaresexy.net/2009/12/23/kindle-users-bypass-copy-protection-and-regional-restrictions/">Kindle users bypass copy protection and regional restrictions</a> (geeksaresexy.net)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/4fecc401-3b32-4a29-8198-433ff04590b5/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=4fecc401-3b32-4a29-8198-433ff04590b5" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/14/health-net-breach-notification-letter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon CMO: Protection of data at rest not important? Really?</title>
		<link>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/</link>
		<comments>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 20:30:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[verizon]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=244</guid>
		<description><![CDATA[Seems like it&#8217;s been a tough week for Verizon to try and prove their point about how encryption is unimportant to securing protected health information (PHI).
..
According to ModernHealthcare.com Peter Tippett, Vice President of Technology and Innovation and Chief Medical Officer, recently said  &#8220;Encryption of data at rest in a database, for example, typically provides “no [...]]]></description>
			<content:encoded><![CDATA[<p>Seems like it&#8217;s been a tough week for Verizon to try and prove their point about how encryption is unimportant to securing <a class="zem_slink" title="Protected health information" rel="wikipedia" href="http://en.wikipedia.org/wiki/Protected_health_information">protected health information</a> (PHI).</p>
<p>..</p>
<p>According to <a title="Modern Healthcare" href="www.ModernHealthcare.com" target="_blank">ModernHealthcare.com</a> Peter Tippett, Vice President of Technology and Innovation and Chief Medical Officer, recently said  &#8220;Encryption of data at rest in a database, for example, typically provides “no value” against a large majority of hacking and malicious code threats, and “end-user devices like PCs, laptops and PDAs” are “orders of magnitude less important targets in the real world than is perceived (and databases are several orders of magnitude more important than end-user devices).”</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 250px;">
<dt class="wp-caption-dt"><a href="http://www.flickr.com/photos/80425071@N00/23860934"><img title="Ostrich" src="http://farm1.static.flickr.com/18/23860934_6b5b7ed93b_m.jpg" alt="Ostrich" width="240" height="160" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image by <a href="http://www.flickr.com/photos/80425071@N00/23860934">Spartacus007</a> via Flickr</dd>
</dl>
</div>
</div>
<p>In addition, Tippett says  current security standards and methods are “too complex, are based on dogma instead of science, are both ineffective and inefficient, and are too static.”</p>
<p>..</p>
<p>But facts and reality prove otherwise. The following RECENT breaches were revealed while Verizon is literally putting its head in the sand and marginalizing encryption  (and all of them could have protected patient information had encryption been installed):</p>
<ul>
<li><a title="Blue Cross Blue Shield loses 68 hard drives with protected health information (PHI)" href="http://www.msnbc.msn.com/id/33977885/" target="_blank">68 Computer hard drives </a>belonging to <a class="zem_slink" title="Blue Cross and Blue Shield Association" rel="wikipedia" href="http://en.wikipedia.org/wiki/Blue_Cross_and_Blue_Shield_Association">Blue Cross Blue Shield</a> &#8220;walked out&#8221; of a datacenter, along with social security numbers and other information belonging to 2 million clients.</li>
<li><a title="HealthNet loses hard drive with patient information" href="http://www.scmagazineus.com/the-data-breach-blog/section/1263/" target="_self">HealthNet loses an external hard drive</a> with personal financial and medical information belonging to 1.5 million clients.</li>
<li><a title="U.S Army loses hard drive with 60,000 records" href="http://www.armytimes.com/news/2009/11/army_breach_111309w/" target="_blank">US Army</a> loses hard drive with 60,000 with social security numbers and other personal information.</li>
<li>A<a title="Guam Memorial Hospital loses laptop" href="http://www.kuam.com/Global/story.asp?S=11509903" target="_blank"> laptop</a> containing clinical information on 2,000 patients was stolen from the Guam Memorial Hospital.</li>
</ul>
<p>And all this within 2 weeks! The fact is that data in use, like data at rest, and data in motion needs to be encrypted if it contains protected health information.</p>
<p>..</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/blue-cross-blue-shield-data-breach.html">Blue Cross Blue Shield Data Breach Investigation Extends Credit Protection for Providers to 2 Years</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-net-data-breach-15-million.html">Health Net Data Breach &#8211; 1.5 Million Records At Risk With Missing Portable Hard Drive</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/laptop-heist-exposes-doctors-personal-data">Laptop Heist Exposes Doctors&#8217; Personal Data</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/10/blue-cross-physicians-warning-potential.html">Blue Cross Physicians Warning &#8211; Potential Data Breach With Stolen Laptop Computer</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www10.nytimes.com/2009/11/25/health/policy/25bankruptcy.html%3F_r%3D5%26partner%3Drss%26amp%3Bemc%3Drss&amp;a=9887412&amp;rid=ddb01d91-1efe-4f93-ba81-d409929f5e90&amp;e=fa24b82b77fed5879e428c661f2c40b9">From the Hospital Room to Bankruptcy Court</a> (nytimes.com)</li>
<li class="zemanta-article-ul-li"><a href="http://iflizwerequeen.com/?p=4723">A member of Blue Cross Blue Shield comes over to the side of the people</a> (iflizwerequeen.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/ddb01d91-1efe-4f93-ba81-d409929f5e90/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ddb01d91-1efe-4f93-ba81-d409929f5e90" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do your tablet, laptop, and desktop PCs need encryption if you use web-based EMR/EHR/PHR?</title>
		<link>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/</link>
		<comments>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 15:01:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[emr]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[phr]]></category>
		<category><![CDATA[web app]]></category>
		<category><![CDATA[web-based emr]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=188</guid>
		<description><![CDATA[



Image via Wikipedia



There has been much debate about security of endpoint devices like tablet PCs, desktops, and laptops where web-based EMR packages are used. There is a potential false sense of security by assuming that just because an EMR or PMR app is web-based then data at rest encryption, like whole disk encryption, is not [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Tablet.jpg"><img title="Photo of HP Tablet PC running MS Windows Table..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/4/4f/Tablet.jpg/300px-Tablet.jpg" alt="Photo of HP Tablet PC running MS Windows Table..." width="300" height="314" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Tablet.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>There has been much debate about security of endpoint devices like tablet PCs, desktops, and laptops where web-based EMR packages are used. There is a potential false sense of security by assuming that just because an EMR or PMR app is web-based then data at rest encryption, like whole disk encryption, is not required since no local data is stored. However, consider these possible scenarios:</p>
<p><span style="color: #808080;"><br />
 </span></p>
<p>- <a class="zem_slink" title="Protected health information" rel="wikipedia" href="http://en.wikipedia.org/wiki/Protected_health_information">Protected health information</a> (PHI) is exported from an EMR, practice management, or even an accounting  app and is stored locally in a <a class="zem_slink" title="Text file" rel="wikipedia" href="http://en.wikipedia.org/wiki/Text_file">text file</a> or a Microsoft Office document.</p>
<p><br class="spacer_" /></p>
<p>- If you use mainframes and use terminal emulators a user could do a &#8220;print screen&#8221; to save the image locally.</p>
<p><br class="spacer_" /></p>
<p>- E-mail attachments containing PHI could be saved locally.</p>
<p><br class="spacer_" /></p>
<p>- Web browser temp and cookie files could contain clues about how data is accessed and retrieved.</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 133px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Outlook_2007.png"><img title="Microsoft Office Outlook" src="http://upload.wikimedia.org/wikipedia/en/b/b0/Outlook_2007.png" alt="Microsoft Office Outlook" width="123" height="123" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Outlook_2007.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>- E-mail clients that have a local store could be used. The  local store, like a personal folder file (<a class="zem_slink" title="Personal Storage Table" rel="wikipedia" href="http://en.wikipedia.org/wiki/Personal_Storage_Table">.pst</a>) file in Microsoft Outlook, could contain PHI. Also, in a Microsoft Exchange environment the end user could inadvertently enable the AutoArchive feature where older content is stored locally on the computer in a .pst file.</p>
<p><br class="spacer_" /></p>
<p>In a recent <a title="Are You Secured? article in ADVANCE for HIM journal" href="http://health-information.advanceweb.com/editorial/content/editorial.aspx?cc=210501" target="_blank">Advance for HIM article entitled &#8220;Are you Secured&#8221;</a>, Daniela Crivianu-Gaita, chief information officer at The Hospital for Sick Children, Toronto. writes:</p>
<p><br class="spacer_" /></p>
<p>&#8220;Facilities can opt to encrypt parts of their IT system, but full-disk encryption ensures the organization is covered in the event of a breach. &#8220;Temporary files created by various applications, the operating system swap file and hidden partitions may contain sensitive data,&#8221; said Daniela Crivianu-Gaita, chief information officer at The Hospital for Sick Children, Toronto. &#8220;Full-disk encryption is the only approach that assures all the data on the local hard disks is encrypted.&#8221;</p>
<p><br class="spacer_" /></p>
<p>The point is that just because the EMR or other app that is web-based is used in you environment it doesn&#8217;t meant that data at rest protection should be ignored. Installing whole disk encryption to protect data at rest could provide peace of mind and protection against unwanted breach notification should that device be lost or stolen. With the strict enforcement of breach notification rules coming to fruition in February, 2010 it&#8217;s better to be safe then sorry by implementing encryption as specified in the HITECH Act within ARRA.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://docinthemachine.com/2009/11/09/encrypt/">Encrypt EHR &#8211; Else HIPAA Violations Need Be Reported To Government &amp; Media</a> (docinthemachine.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/d8317ec0-b99d-4d68-b2de-7fdfcd765465/"><img class="zemanta-pixie-img" style="border: medium none ; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=d8317ec0-b99d-4d68-b2de-7fdfcd765465" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>To BitLocker or to Not BitLocker? &#8211; that&#8217;s a great question!</title>
		<link>http://www.experiordata.com/blog/2009/11/19/to-bitlocker-or-to-not-bitlocker-thats-a-great-question/</link>
		<comments>http://www.experiordata.com/blog/2009/11/19/to-bitlocker-or-to-not-bitlocker-thats-a-great-question/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 06:04:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[BitLocker Drive Encryption]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows Server 2003]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=175</guid>
		<description><![CDATA[



Image via CrunchBase



BitLocker, Microsoft&#8217;s disk encryption technology that comes with Windows 7 Ultimate, can throw the system admin into a boondogle. Sure it&#8217;s easy to just use what is &#8220;in the box&#8221; and call it a day. However, be prepared for a long&#8230;very long day in getting BitLocker deployed and managed.
..
Microsoft has traditionally added feature [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 200px;">
<dt class="wp-caption-dt"><a href="http://www.crunchbase.com/product/windows"><img title="Image representing Windows as depicted in Crun..." src="http://www.crunchbase.com/assets/images/resized/0002/1545/21545v2-max-450x450.png" alt="Image representing Windows as depicted in Crun..." width="190" height="66" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://www.crunchbase.com">CrunchBase</a></dd>
</dl>
</div>
</div>
<p><a class="zem_slink" title="BitLocker Drive Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption">BitLocker</a>, <a class="zem_slink" title="Microsoft" rel="homepage" href="http://www.microsoft.com">Microsoft</a>&#8217;s disk encryption technology that comes with Windows 7 Ultimate, can throw the system admin into a boondogle. Sure it&#8217;s easy to just use what is &#8220;in the box&#8221; and call it a day. However, be prepared for a long&#8230;very long day in getting BitLocker deployed and managed.</p>
<p><span style="color: #808080;">..</span></p>
<p>Microsoft has traditionally added feature after feature to their products. But that doesn&#8217;t necessarily mean you have to use them (or actually, should use them). Before we discuss BitLocker think of the last time someone used the e-mail server that comes with Windows <a class="zem_slink" title="Windows Server 2003" rel="homepage" href="http://www.microsoft.com/windowsserver2003/">Server 2003</a> (yes, it really does come with a basic POP3 server). Ok, give up? That&#8217;s probably because most of the corporate world uses Microsoft Exchange. How about using Windows Servers as internet firewalls. Possible? Yes. Practical? No. Microsoft adds these features to help sell the core product. The can say &#8220;well, you don&#8217;t need a mail server. Server 2003 has one built-in&#8221;, even though we all know that the only purpose for it is to use it in some lab.</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 125px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Sushiusb.jpg"><img title="A USB flash drive in the shape of a piece of i..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/d/de/Sushiusb.jpg/300px-Sushiusb.jpg" alt="A USB flash drive in the shape of a piece of i..." width="115" height="97" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Sushiusb.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="color: #888888;">..</span></p>
<p>And here comes BitLocker. Yes, it can encrypt hard drives. Yes, it can encrypt <a class="zem_slink" title="USB flash drive" rel="wikipedia" href="http://en.wikipedia.org/wiki/USB_flash_drive">USB flash drives</a>. But before you pay the extra $19.99 per user for your corporate Windows 7 deployment first consider these limitations and facts about how BitLocker is deployed:</p>
<p><span style="color: #888888;">..</span></p>
<p><!--StartFragment--></p>
<ul>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">BIOS must be compatible with <a class="zem_slink" title="Trusted Platform Module" rel="wikipedia" href="http://en.wikipedia.org/wiki/Trusted_Platform_Module">TPM</a> version 1.2 and support USB device boot </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Requires TPM chip </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Requires TPM management snap-in configuration to save <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption key</a> to a USB device </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">TPM PIN management (help desk must maintain a list of TPM PINs in case user forgets) </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">No complexity or content rules available for TPM PIN </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">No single sign-on (TPM PIN not related to AD auth info) </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Admin rights needed to perform initial encryption </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Requires management of TPM “owner passwords” </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Requires you to maintain recovery keys that match Bitlocker keys created on each computer </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Requires <a class="zem_slink" title="Active Directory" rel="wikipedia" href="http://en.wikipedia.org/wiki/Active_Directory">Active Directory</a> Schema extensions to be installed on 2003 and 2008 servers (don&#8217;t you love &#8220;extending the schema&#8221;?)<br />
</span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Recovery options require a TPM PIN </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">No centralized reporting </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">Policies managed by GPOs (because they&#8217;re so easy to manage now)<br />
</span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">No separating of duties – recovery codes stored in AD, propogated to all DCs. </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">No support for smart cards or tokens at pre-boot (cold boot and firewire-method HD attacks come to mind)<br />
</span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">For USB encryption – recovery keys are not managed centrally – give user ability to “print out” recovery key or store it elsewhere in a file (no key management) </span></span></li>
<li><span style="font-family: Calibri,Verdana,Helvetica,Arial;"><span style="font-size: 11pt;">USB encryption -&gt; not possible to write to non-Windows 7 machines once encrypted with Windows 7</span></span></li>
</ul>
<p><span style="color: #888888;">..</span></p>
<p>So after all the time you&#8217;ve spent just to get this far you now have an encryption system that is only Windows 7 specific. Are your legacy XP clients encrypted? No. The Macs in the marketing department? No. The Linux devices in development? No. Use a smart card or token at pre-boot? No.  Can you write to USB drives encrypted with Win 7 on non-Win 7 machines? No. Are there separation of duties? Nope.</p>
<p><span style="color: #888888;">..</span></p>
<p>Before rolling out BitLocker take into consideration not only the software limitations but also the time involved to learn the infrastructure needed to deploy it properly. Create a lab with several PCs and a server and  do real-world testing and see for yourself. BitLocker can be a great tool for personal use, or in a very small business (under 15 users). But beyond that&#8230;beware of the boondoggle.</p>
<p><!--EndFragment--></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.theregister.co.uk/2009/10/23/filesharing_crypto/">Anti-filesharing laws revive crypto fears for spooks</a> (theregister.co.uk)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><span class="zem-script more-related pretty-attribution"><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/19/to-bitlocker-or-to-not-bitlocker-thats-a-great-question/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
