<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; PGP</title>
	<atom:link href="http://www.experiordata.com/blog/category/pgp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Symantec has acquired PGP Corporation and GuardianEdge Technologies</title>
		<link>http://www.experiordata.com/blog/2010/04/29/symantec-has-acquired-pgp-corporation-and-guardianedge-technologies/</link>
		<comments>http://www.experiordata.com/blog/2010/04/29/symantec-has-acquired-pgp-corporation-and-guardianedge-technologies/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 13:39:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PGP]]></category>
		<category><![CDATA[guardianedge]]></category>
		<category><![CDATA[PGP. acquistion]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=421</guid>
		<description><![CDATA[Symantec acquires PGP and GuardianEdge Technologies]]></description>
			<content:encoded><![CDATA[<p>Big day today in the software security space. PGP Corporation and GuardianEdge Technologies (both competitors in the whole disk encryption market) have been acquired by Symantec Corporation. The acquisition provides much-needed applications to Symantec&#39;s industry-leading security software stack.</p>
<p>&nbsp;</p>
<p>Symantec has seen competitors such as CheckPoint, Sophos, and McAfee acquire key encryption technology platforms like Pointsec, Utimaco, and Safeboot. They will now have a strong whole disk encryption story, as well as solutions for file and e-mail encryption.&nbsp;</p>
<p>&nbsp;</p>
<p>The GuardianEdge Technologies (GE) acquisition will provide Symantec with direct access to GE&#39;s large base of government customers. Certainly GE has a client base in the commercial sector as well. There is clearly some overlap between PGP and GE products. Both provide a lot of value to the end users in terms of security features.</p>
<p>&nbsp;</p>
<p>Healthcare organizations that are looking to comply with the HITECH Act and protect PHI using encryption will be very pleased. Symantec has a significant market share in endpoint security products and those customers that need to deploy encryption will be happy to entrust the Symantec brand to their organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/04/29/symantec-has-acquired-pgp-corporation-and-guardianedge-technologies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PGP Encryption Smackdown &#8211; Supports Mac Snow Leopard, Linux, Boot Camp, SSD drive support</title>
		<link>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/</link>
		<comments>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 19:32:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=391</guid>
		<description><![CDATA[PGP Corporation announced an update to its products line. PGP now supports Red Hat &#38; Ubuntu Linux, Mac OSX Snow Leopard, and Boot Camp on Mac OSX computers. In addition, PGP has updated its whole disk encryption technology to include a Hybrid Cryptographic Optimizer (HCO) technology to deliver faster run times for PGP Whole Disk [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PGP Corporation - encryption" href="http://www.pgp.cpm">PGP Corporation</a> announced an update to its products line. PGP now supports Red Hat &amp; Ubuntu Linux, Mac OSX Snow Leopard, and Boot Camp on Mac OSX computers. In addition, PGP has updated its whole disk encryption technology to include a Hybrid Cryptographic Optimizer (HCO) technology to deliver faster run times for PGP Whole Disk Encryption.</p>
<p><br class="spacer_" /></p>
<p>Customers can now use PGP Universal Server to centrally manage encryption for their multi-platform environment. A single web-based user interface can be used to manage encryption end points using Microsoft Windows, Apple Mac, Red Hat Linux, and Ubuntu Linux. PGP is the only encryption vendor that delivers encryption solutions across multiple platforms. Multi-platform support is especially important with the popularity of netbooks, and the forthcoming Apple tablet device, which is reported to be using the Mac OSX operating system.</p>
<p><br class="spacer_" /></p>
<p>PGP also added functionality for e-mail encryption in Microsoft Outlook. Using Microsoft Outlook users can now click &#8220;sign and encrypt&#8221; buttons to automatically encrypt emails.</p>
<p><br class="spacer_" /></p>
<p>Experior Data is a PGP SILVER Partner and helps organizations implement data encryption solutions.</p>
<p><br class="spacer_" /></p>
<p>More information about these new releases is available on the <a title="PGP releases new encryption products" href="http://www.pgp.com/insight/newsroom/press_releases/new_data_protection_solutions_for_mac_linux.html" target="_blank">PGP web site</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disk encryption is not enough for HIPAA HITECH Act Compliance</title>
		<link>http://www.experiordata.com/blog/2010/01/19/disk-encryption-is-not-enough-for-hipaa-hitech-act-compliance/</link>
		<comments>http://www.experiordata.com/blog/2010/01/19/disk-encryption-is-not-enough-for-hipaa-hitech-act-compliance/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 06:41:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=384</guid>
		<description><![CDATA[Whole disk encryption is not enough for HIPAA and HITECH Act compliance. Encryption solutions must not only protect data at rest but also data in use.]]></description>
			<content:encoded><![CDATA[<p>In the coming months healthcare IT administrators will see many products come to market that claim to solve the compliance issues of safeguarding unsecured protected health information (PHI). A bit of caution and understanding of the issues is required here:</p>
<p><br class="spacer_" /></p>
<p>- Whole disk encryption is clearly needed for mobile devices</p>
<p><br class="spacer_" /></p>
<p>- Whole disk encryption protects data when computers are TURNED OFF. This means that while you&#8217;re using the laptop the data is in use, and is not encrypted.</p>
<p><br class="spacer_" /></p>
<p>- Additional levels of data protection is needed to protected the data while computers are in use. For example, critical data files should be encrypted automatically regardless of whether the computer is turned on or off. <strong>Whole disk encryption does not do this.</strong></p>
<p><br class="spacer_" /></p>
<p>- Files containing PHI that are transferred on a network need to be encrypted. <strong>Whole disk encryption does not do this.</strong></p>
<p><br class="spacer_" /></p>
<p><strong>- </strong>What about e-mails containing PHI? More importantly, what about those that use Microsoft Outlook and store data in archive (.pst) files?</p>
<p><br class="spacer_" /></p>
<p>So why is whole disk encryption not enough? What happens if a worm invades your computer and transfers documents of a certain file type to a remote location. Whole disk encryption will not help you in this situation.</p>
<p><br class="spacer_" /></p>
<p>It&#8217;s important for any encryption solution to not only encrypt the hard drive but also to encrypted files on the hard drive so that they remain encrypted while the computer is on.</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/01/19/disk-encryption-is-not-enough-for-hipaa-hitech-act-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security for Meaningful Use: Part 2 &#8211; Electronic Access to Protected Health Information (PHI)</title>
		<link>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/</link>
		<comments>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 17:34:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Health Insurance Portability and Accountability Act]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[Pretty Good Privacy]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=352</guid>
		<description><![CDATA[Standards Set for Providing Secure Access to Patient Records





Image via Wikipedia



According to the Initial Set of Standards for Electronic Health Records patients must be provided with their health information (most certainly protected health information -PHI- under HIPAA) electronically and securely within 96 hours.


&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification [...]]]></description>
			<content:encoded><![CDATA[<h2>Standards Set for Providing Secure Access to Patient Records</h2>
<p><br class="spacer_" /></p>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png"><img title="Sample patient record view from VistA Imaging" src="http://upload.wikimedia.org/wikipedia/en/thumb/8/8f/VistA_Img.png/300px-VistA_Img.png" alt="Sample patient record view from VistA Imaging" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:VistA_Img.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>According to the <a title="Initial set of standards for certified electronic health records (EHRs) released by HHS/CMS" href="http://www.experiordata.com/blog/2009/12/31/regulation-bonanza-hhs-releases-two-interim-rules-on-123009/">Initial Set of Standards</a> for <a class="zem_slink" title="Electronic health record" rel="wikipedia" href="http://en.wikipedia.org/wiki/Electronic_health_record">Electronic Health Records</a> patients must be provided with their health information (most certainly <strong>protected</strong> health information -PHI- under <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a>) electronically <strong>and</strong> securely within 96 hours.</p>
<p><br class="spacer_" /></p>
<address>
<p>&#8220;Consistent with the HIT Policy Committee&#8217;s recommendations, we propose the following additional clarification of this objective. Electronic copies may be provided through a number of secure electronic methods (for example, personal health record (</p>
</address>
<address>
<p>PHR), patient portal, CD, <a class="zem_slink" title="Universal Serial Bus" rel="wikipedia" href="http://en.wikipedia.org/wiki/Universal_Serial_Bus">USB</a> drive).</p>
<p><br class="spacer_" /></p>
<p>Provide patients with timely electronic access to their health information (including lab results, problem list, medication lists, allergies) within 96 hours of the information being available to the EP. Also, consistent with the HIT Policy Committee recommendations, we propose the following additional clarification of this objective. Electronic access may be provided by a number of <span style="font-style: normal;"><strong>s</strong></span><strong>ecure electronic methods (for example, PHR, patient portal, CD, USB drive).</strong> Timely is defined as within 96 hours of the information being available to the EP either through the receipt of final lab results or a patient interaction that updates the EP&#8217;s knowledge of the patient&#8217;s health. We judge 96 hours to be a reasonable amount of time to ensure that certified EHR technology is up to date. We welcome comment on if a shorter or longer time is advantageous.&#8221;</p>
</address>
<address> </address>
<h2><span style="font-style: normal;">How to Secure Health Records</span></h2>
<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg"><img title="USB Vacuum Cleaner, a giveaway from an IBM event" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/77/USBVacuumCleaner.jpg/300px-USBVacuumCleaner.jpg" alt="USB Vacuum Cleaner, a giveaway from an IBM event" width="300" height="225" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:USBVacuumCleaner.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-style: normal;">You may be wondering how can patient information be secured. The best way to secure information is by encrypting the </span><span style="font-style: normal;">media. However, note that <strong>patients must be able to decrypt the information</strong> on their own computer equipment. One of the product Experior Data implements is called <a title="PGP Portable allows you to encrypt data on removable media but lets people decrypt it on other computers without requiring special software to be installed" href="http://www.pgp.com/products/portable/index.html" target="_blank">PGP Portable</a>. For example, the patient provides a USB drive for you to copy the PHI onto it. PGP Portable encrypts the entire USB device after the information is copied to it. The patient must provide a passphrase during the <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> process. When the patient goes home he/she inserts the USB drive into their home computer and is prompted for the passphrase. After the passphrase is entered access to the patient information is provided.</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://projecthealthdesign.typepad.com/project_health_design/2009/08/hies-are-beginning-to-link-patients-directly-to-their-own-health-data.html">HIEs are Beginning to Link Patients Directly to their Own Health Data</a> (projecthealthdesign.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://chilmarkresearch.com/2009/09/23/pushing-onc-to-act-on-consumers-behalf/">Pushing ONC to Act on Consumer&#8217;s Behalf</a> (chilmarkresearch.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.medicineandtechnology.com/2009/12/medfusion-maintains-leadership-in.html">Medfusion Maintains Leadership in Patient Portal Performance</a> (medicineandtechnology.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.wsj.com/health/2009/12/30/how-to-get-20-billion-for-using-electronic-medical-records/">How to Get $20 Billion for Using Electronic Medical Records</a> (blogs.wsj.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/76960f38-a396-49b1-bf12-c9961f5125fc/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=76960f38-a396-49b1-bf12-c9961f5125fc" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/31/security-for-meaningful-use-part-2-electronic-access-to-protected-health-information-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon CMO: Protection of data at rest not important? Really?</title>
		<link>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/</link>
		<comments>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 20:30:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[verizon]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=244</guid>
		<description><![CDATA[Seems like it&#8217;s been a tough week for Verizon to try and prove their point about how encryption is unimportant to securing protected health information (PHI).
..
According to ModernHealthcare.com Peter Tippett, Vice President of Technology and Innovation and Chief Medical Officer, recently said  &#8220;Encryption of data at rest in a database, for example, typically provides “no [...]]]></description>
			<content:encoded><![CDATA[<p>Seems like it&#8217;s been a tough week for Verizon to try and prove their point about how encryption is unimportant to securing <a class="zem_slink" title="Protected health information" rel="wikipedia" href="http://en.wikipedia.org/wiki/Protected_health_information">protected health information</a> (PHI).</p>
<p>..</p>
<p>According to <a title="Modern Healthcare" href="www.ModernHealthcare.com" target="_blank">ModernHealthcare.com</a> Peter Tippett, Vice President of Technology and Innovation and Chief Medical Officer, recently said  &#8220;Encryption of data at rest in a database, for example, typically provides “no value” against a large majority of hacking and malicious code threats, and “end-user devices like PCs, laptops and PDAs” are “orders of magnitude less important targets in the real world than is perceived (and databases are several orders of magnitude more important than end-user devices).”</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 250px;">
<dt class="wp-caption-dt"><a href="http://www.flickr.com/photos/80425071@N00/23860934"><img title="Ostrich" src="http://farm1.static.flickr.com/18/23860934_6b5b7ed93b_m.jpg" alt="Ostrich" width="240" height="160" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image by <a href="http://www.flickr.com/photos/80425071@N00/23860934">Spartacus007</a> via Flickr</dd>
</dl>
</div>
</div>
<p>In addition, Tippett says  current security standards and methods are “too complex, are based on dogma instead of science, are both ineffective and inefficient, and are too static.”</p>
<p>..</p>
<p>But facts and reality prove otherwise. The following RECENT breaches were revealed while Verizon is literally putting its head in the sand and marginalizing encryption  (and all of them could have protected patient information had encryption been installed):</p>
<ul>
<li><a title="Blue Cross Blue Shield loses 68 hard drives with protected health information (PHI)" href="http://www.msnbc.msn.com/id/33977885/" target="_blank">68 Computer hard drives </a>belonging to <a class="zem_slink" title="Blue Cross and Blue Shield Association" rel="wikipedia" href="http://en.wikipedia.org/wiki/Blue_Cross_and_Blue_Shield_Association">Blue Cross Blue Shield</a> &#8220;walked out&#8221; of a datacenter, along with social security numbers and other information belonging to 2 million clients.</li>
<li><a title="HealthNet loses hard drive with patient information" href="http://www.scmagazineus.com/the-data-breach-blog/section/1263/" target="_self">HealthNet loses an external hard drive</a> with personal financial and medical information belonging to 1.5 million clients.</li>
<li><a title="U.S Army loses hard drive with 60,000 records" href="http://www.armytimes.com/news/2009/11/army_breach_111309w/" target="_blank">US Army</a> loses hard drive with 60,000 with social security numbers and other personal information.</li>
<li>A<a title="Guam Memorial Hospital loses laptop" href="http://www.kuam.com/Global/story.asp?S=11509903" target="_blank"> laptop</a> containing clinical information on 2,000 patients was stolen from the Guam Memorial Hospital.</li>
</ul>
<p>And all this within 2 weeks! The fact is that data in use, like data at rest, and data in motion needs to be encrypted if it contains protected health information.</p>
<p>..</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/blue-cross-blue-shield-data-breach.html">Blue Cross Blue Shield Data Breach Investigation Extends Credit Protection for Providers to 2 Years</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-net-data-breach-15-million.html">Health Net Data Breach &#8211; 1.5 Million Records At Risk With Missing Portable Hard Drive</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/laptop-heist-exposes-doctors-personal-data">Laptop Heist Exposes Doctors&#8217; Personal Data</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/10/blue-cross-physicians-warning-potential.html">Blue Cross Physicians Warning &#8211; Potential Data Breach With Stolen Laptop Computer</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www10.nytimes.com/2009/11/25/health/policy/25bankruptcy.html%3F_r%3D5%26partner%3Drss%26amp%3Bemc%3Drss&amp;a=9887412&amp;rid=ddb01d91-1efe-4f93-ba81-d409929f5e90&amp;e=fa24b82b77fed5879e428c661f2c40b9">From the Hospital Room to Bankruptcy Court</a> (nytimes.com)</li>
<li class="zemanta-article-ul-li"><a href="http://iflizwerequeen.com/?p=4723">A member of Blue Cross Blue Shield comes over to the side of the people</a> (iflizwerequeen.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/ddb01d91-1efe-4f93-ba81-d409929f5e90/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ddb01d91-1efe-4f93-ba81-d409929f5e90" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting started with encryption</title>
		<link>http://www.experiordata.com/blog/2009/08/25/getting-started-with-encryption/</link>
		<comments>http://www.experiordata.com/blog/2009/08/25/getting-started-with-encryption/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 14:45:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[bios]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[ms excel]]></category>
		<category><![CDATA[ms word]]></category>
		<category><![CDATA[screen saver]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=60</guid>
		<description><![CDATA[Encryption can be intidating. The technology is filled with technical security jargon like encryption keys, hash, key length, etc. In most organizations the least common denominators are often devices  used the most &#8211; laptops, tablet PCs, and desktop computers. These devices are used to work with patient data and store information that is the most [...]]]></description>
			<content:encoded><![CDATA[<p>Encryption can be intidating. The technology is filled with technical security jargon like encryption keys, hash, key length, etc. In most organizations the least common denominators are often devices  used the most &#8211; laptops, tablet PCs, and desktop computers. These devices are used to work with patient data and store information that is the most vulnerable to theft, misuse, and unauthorized access. These devices are often serviced and replaced. How many times have you replaced a broken hard drive? How many computers have you replaced in the last 3 years?<br class="spacer_" /></p>
<p>Fortunately, the most vulnerable devices are the easiest secure. If you have serveral computers you would like to secure, or if you have a tablet or laptop that you use when you travel, installing <a class="zem_slink" title="Full disk encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Full_disk_encryption">Whole Disk Encryption</a> (WDE) software such as <a href="http://www.pgp.com/products/wholediskencryption/index.html" target="_blank">PGP Whole Disk Encryption</a> is an easy way to get started.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>WDE simply encrypts your entire hard drive. After installing the software you can encrypt your entire hard drive. The software operates in the background while you work and does not affect your computer&#8217;s performance. It may take several hours for your hard drive be become encrypted. After completion, you will need to enter a password every time your computer boots. If your computer is stolen the thief will not be able to access your computer because the password will not be known to him/her. More importantly, your hard drive will not be able to be analyzed by forensic or other hard drive reading software. All your data will essentially become &#8220;scrambled&#8221; to anyone trying to view the contents of your hard drive.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>It&#8217;s important that you understand technologies that <strong><span style="text-decoration: underline;">WILL NOT</span> </strong>protect your information:</p>
<p><span style="color: #ffffff;">..</span></p>
<p>- File deletion &#8211; deleting files on your hard drive does not erase them permanently. When you &#8220;delete&#8221; a file on your computer you are simply removing the pointer to the data in the hard drive&#8217;s directory. Until your data is overwritten by new data the old data remains on the hard drive and is able to be retrieved by even the most rudimentary tools on the Internet.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>- Password protecting files &#8211; Using password protection features in Microsoft Word, Excel, and even Quickbooks does not protect your information. It simply forces you to enter a password before viewing the data. There are many tools that are available that can easily recover these passwords. In addition, passwords don&#8217;t encrypt data. They are a method of very basic access control. If you password protect your document it can easily be recovered by data recovery and simple forensics applications.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>- Screen saver passwords &#8211; Although these should be used and activated when you&#8217;re away from your powered-on computer, they do not protect your data. A simple restart of the computer will bypass screen saver passwords.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>- Computer passwords &#8211; Computer passwords should be set so that you are prompted to enter a password when you start up your computer. However, these can easily be recovered by many programs found on the Internet. They also don&#8217;t encrypt the contents of your hard drive.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>- BIOS passwords &#8211; Most PCs have an option to set  BIOS passwords. BIOS is a small program in every computer that runs very briefly when you turn your computer on. BIOS tells the computer the most basic information about your computer such as the amount of memory in your computer, size of hard drive, number of hard drivers, etc. This information is used to load your operating system (Microsoft Windows, Apple MAC OS, etc). A setting in BIOS could be made to require a BIOS password before your computer even loads Windows. Although it may be deterent to the casual unauthorized user, such as a snooping co-worker, BIOS passwords are easily reset by anyone with rudimentary technical skills. Sometimes it may require that the computer be opened and certain buttons are pressed inside the computer. But it can easily be defeated. And BIOS passwords do not encrypt data.</p>
<p><span style="color: #ffffff;">..</span></p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:FileVault_in_Leopard.png"><img title="FileVault in the System Preferences under Security" src="http://upload.wikimedia.org/wikipedia/en/thumb/7/71/FileVault_in_Leopard.png/300px-FileVault_in_Leopard.png" alt="FileVault in the System Preferences under Security" width="300" height="231" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:FileVault_in_Leopard.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>- Apple FileVault, Windows EFS &#8211; These are useful options for encrypting data. In both cases (Apple</p>
<p>and Windows) these are only file-level encryption technologies. Apple&#8217;s FileVault is superior because it encrypts your entire user profile. Windows EFS is complex to maintain and restore in case you switch computers. However, these technologies encrypt only certain files or directories. If you accidentally move information out of the encrypted directories that information will not be encrypted. These also don&#8217;t prevent basic access to the operating system of the computer. For example, if your Mac is stolen and you enable FileVault the thief can still access your computer.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>Although installing whole disk encryption on a few computers is acceptable, deploying individual encryption applications on many computers is not efficient or recommended.  Installing software like PGP Whole Disk Encryption on many computers without a central management system could present administrative challenges of manually maintaining encryption keys and leaves open the possibility of not being able to access encrypted computers after an employee leaves. Vendors like PGP offer a management console that can take away the administrative burden  of maintaining many computers. Before deploying WDE refer to an expert that can set up your environment so you can properly manage your encrypted computers centrally.</p>
<p><br class="spacer_" /></p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/1f11a395-c9e5-492f-b06d-69ddecc7c7f3/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=1f11a395-c9e5-492f-b06d-69ddecc7c7f3" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/08/25/getting-started-with-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
