<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption</title>
	<atom:link href="http://www.experiordata.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Social media security policies in healthcare</title>
		<link>http://www.experiordata.com/blog/2010/05/18/social-media-security-policies-in-healthcare/</link>
		<comments>http://www.experiordata.com/blog/2010/05/18/social-media-security-policies-in-healthcare/#comments</comments>
		<pubDate>Tue, 18 May 2010 04:09:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=450</guid>
		<description><![CDATA[Sharon Finney provides best practices for policies on social media in healthcare.]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Sharon Finney from Adventist Health System in Winter Park, Florida prepared an excellent&nbsp;<a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-5-social-media-finney-adventist.pdf" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Sharon Finney Adventist Health System social media presentation">presentation</a>&nbsp;at the 2010 NIST HIPAA conference. She shared her experience in developing and implementing a comprehensive, risk-based policy at her organization.</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Sharon talked about the creation of a corporate policy and standard of conduct for social media. In order to be successful in creating these documents you must have executive buy-in from an &ldquo;executive sponsor&rdquo;. This sponsor is typically a VP of Marketing or PR.</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Sharon recommends assembling a team that includes representatives from legal, HR, compliance, data security, and IT departments to help shape and implement the social media policies. She recommends the following steps:</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></p>
<ul style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; ">
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a policy on social media &#8211; define scope of use such as who has legitimate business reasons (marketing, HR, communications, training, outreach, etc).</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a standard of conduct manual so that employees know how they should conduct themselves online. Ensure that proper disclaimers are placed. Look at HP, IBM, Microsoft standards of conduct as a goods start.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Watch out for exceptions to policies. If you grant too many exceptions the exceptions become the rule. Create a tedious exception policy to discourage exceptions.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Define your organization&rsquo;s risk tolerance.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Define sanctions for non-compliance and ensure employees know them.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a plan for monitoring including who will be doing the monitoring, what is being monitored, and the frequency of monitoring.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a quarterly audit policy trickled down to department heads to ensure that they review how their direct reports spend time online.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Clearly define what employees should and should not do (Adventist has about 36 points).</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a policy on monitoring and enforce it. Setup alerts for certain conditions.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Implement DLP (Data Loss Prevention) technologies to prevent critical data (like PHI) from leaving your network.</span></li>
</ul>
<div><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></div>
<div><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">You should also create an incident response plan that includes all the appropriate parties. Ensuring that all employees are properly trained and understand the policy and standards is the key to success.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/18/social-media-security-policies-in-healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Summary of Breach Notification for Unsecured PHI</title>
		<link>http://www.experiordata.com/blog/2010/05/17/summary-of-breach-notification-for-unsecured-phi/</link>
		<comments>http://www.experiordata.com/blog/2010/05/17/summary-of-breach-notification-for-unsecured-phi/#comments</comments>
		<pubDate>Tue, 18 May 2010 02:35:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=447</guid>
		<description><![CDATA[Unsecured PHI means PHI not encrypted or properly destroyed. Presentation by NIST specialist Christine Heide, JD. ]]></description>
			<content:encoded><![CDATA[<p>Christina Heide, JD recently presented at the 2010 NIST HIPAA conference and provided a <a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-3a-breach-notification-heide-ocr.pdf" target="_blank">presentation</a>&nbsp;about the how breach notification works. She reiterated that breach notification applies to unsecured PHI, which means protected health information not secured by encryption or properly destroyed.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/17/summary-of-breach-notification-for-unsecured-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>White House is Concerned About Protecting PHI</title>
		<link>http://www.experiordata.com/blog/2010/05/17/white-house-is-concerned-about-protecting-phi/</link>
		<comments>http://www.experiordata.com/blog/2010/05/17/white-house-is-concerned-about-protecting-phi/#comments</comments>
		<pubDate>Tue, 18 May 2010 01:28:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Cyber Security Coordinator]]></category>
		<category><![CDATA[Cyber Security Czar]]></category>
		<category><![CDATA[Howard Schmidt]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=443</guid>
		<description><![CDATA[Howard Schmidt talks about cyber security as it pertains to protected health information and HIPAA security rule.]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><a href="http://www.whitehouse.gov/blog/2009/12/22/introducing-new-cybersecurity-coordinator" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Howard Schmidt talks about data security at the NIST 2010 HIPAA conference">Howard Schmidt</a>, Obama administration&#39;s cyber security czar, prepared&nbsp;a fantastic presentation about the four guiding principles of his&nbsp;<a href="http://www.whitehouse.gov/cybersecurity" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="White House Cybersecurity Page">cyber security</a>&nbsp;plan:</span></p>
<p>&nbsp;</p>
<ul>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><strong>Deterrence</strong>&nbsp;is a primary factor in preventing cyber security threats. Applying strong protectionlike two factor authentication, one time passwords, smart cards, and implementing standard data protection systems were mentioned.<br />
		<font class="Apple-style-span" color="#222222"><span class="Apple-style-span" style="line-height: normal; "></p>
<p>		</span></font></span></li>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-family: Arial, Verdana, sans-serif; font-size: 12px; line-height: 16px; "><strong>Resilience</strong>&nbsp;is the ability to recover from an attack. Designing systems that are able to recover from an attack is paramount to national security, and especially protected health information (PHI). It was noted (in a different part) of the NIST Conference that doctors relying on Health information systems (HIT) need to ensure that a disaster recovery and backup plan is in place and is tested regularly. A doctor&rsquo;s office or a hospital would be nearly impossible to operate if access to PHI is not available after moving entirely to electronic medical records.
<p>
		</span></li>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); font-family: Arial, Verdana, sans-serif; font-size: 12px; line-height: 16px; "><strong>Privacy</strong>&nbsp;is important to the White House. It&rsquo;s clear that legislation and the regulations that follow have privacy in mind. An good example is the Breach Notification law written into section 13402 in the HITECH ACt, part of the American Recovery and Reinvestment Act of 2009 (ARRA). The HITECH Act specifically provides safe harbors in case of a breach of encrypted PHI. The government is clearly incentivizing the use of data encryption to protect privacy.
<p>		</span></li>
</ul>
<ul>
<li><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><strong>Partnerships</strong>&nbsp;with private industry were mentioned as well, although not in too much detail. Perhaps the White House wants to make sure that whatever steps they put in place have transparency to the public and the private industry.</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/17/white-house-is-concerned-about-protecting-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Management Framework recommended by NIST for HITECH Act and HIPAA Compliance</title>
		<link>http://www.experiordata.com/blog/2010/05/14/risk-management-framework-recommended-by-nist-for-hitech-act-and-hipaa-compliance/</link>
		<comments>http://www.experiordata.com/blog/2010/05/14/risk-management-framework-recommended-by-nist-for-hitech-act-and-hipaa-compliance/#comments</comments>
		<pubDate>Fri, 14 May 2010 15:22:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[RMF]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=432</guid>
		<description><![CDATA[&#160;
&#160;
In order to help the government and private industry standardize on a risk management process NIST created the RMF -&#160;Risk Management Framework. The framework into 6 steps:

	&#160;

Categorize the information systems
Select security controls
Implement security controls
Access security controls
Authorize information systems
Monitor security controls

At the 2010 NIST HIPAA Security Conference&#160;presentation,&#160;Pat Toth, a computer scientist working for&#160;NIST&#160;, discussed the importance [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>&nbsp;</p>
<p>In order to help the government and private industry standardize on a risk management process NIST created the RMF -&nbsp;<a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-1b-risk-assessment-toth-nist.pdf" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Risk Management Framework created by NIST - used to create risk management analysis for HIPAA HITECH Act compliance">Risk Management Framework</a>. The framework into 6 steps:</p>
<p>
	&nbsp;</p>
<ul style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; ">
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Categorize the information systems</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Select security controls</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Implement security controls</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Access security controls</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Authorize information systems</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Monitor security controls</li>
</ul>
<p>At the 2010 NIST HIPAA Security Conference&nbsp;<a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-1b-risk-assessment-toth-nist.pdf" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Pat Toth presentation at HIPAA NIST security conference">presentation</a>,&nbsp;Pat Toth, a computer scientist working for&nbsp;<a href="http://www.nist.gov/" style="color: rgb(54, 82, 114); text-decoration: underline; ">NIST</a>&nbsp;, discussed the importance of the integrating risk management and security into your enterprise computing environment. &nbsp;Security is often thought of as an after-the-fact process that becomes important after IT systems and applications are deployed. Toth pointed out that our perception of security&rsquo;s role needs to change in order to protect the our healthcare information systems.</p>
<p>&nbsp;</p>
<div>The HIPAA security rule specifically requires that a risk assessment be performed on IT systems that contain PHI (protected health information). Rather than creating the assessment from scratch the RMF is a great place to start your research and perhaps implement the steps recommended by NIST to secure your HIT systems.</div>
<div>.</div>
<div>&nbsp;</div>
<div>The RMF is of particular importance for helping to obtain a safe harbor from penalties in the HIPAA security rule, particularly when deciding to implement (or not implement) technologies like data encryption. For example: if you decide that encryption is not needed in your environment and an incident happens where PHI is breached you will need to show the reason behind your decisions to HHS OCR (U.S Department of Health and Human Services, Office of Civil Rights).</div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/14/risk-management-framework-recommended-by-nist-for-hitech-act-and-hipaa-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safeguarding Health Information: Building Assurance through HIPAA Security NIST Conference</title>
		<link>http://www.experiordata.com/blog/2010/05/11/safeguarding-health-information-building-assurance-through-hipaa-security-nist-conference/</link>
		<comments>http://www.experiordata.com/blog/2010/05/11/safeguarding-health-information-building-assurance-through-hipaa-security-nist-conference/#comments</comments>
		<pubDate>Tue, 11 May 2010 10:35:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Washington DC]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=429</guid>
		<description><![CDATA[&#160;
We will be tweeting live from the NIST HIPAA security conference on 5/11 and 5/12. If you use twitter we will be using the #NISTHIPAA hashtag. To see our tweets you &#160;can go to search.twitter.com and search for #NISTHIPAA after 9:30 am. You can also follow @experiordata
]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>We will be tweeting live from the <a href="http://www.nist.gov/public_affairs/confpage/100511b.htm">NIST HIPAA security conference </a>on 5/11 and 5/12. If you use twitter we will be using the #NISTHIPAA hashtag. To see our tweets you &nbsp;can go to search.twitter.com and search for #NISTHIPAA after 9:30 am. You can also follow @experiordata</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/11/safeguarding-health-information-building-assurance-through-hipaa-security-nist-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Symantec has acquired PGP Corporation and GuardianEdge Technologies</title>
		<link>http://www.experiordata.com/blog/2010/04/29/symantec-has-acquired-pgp-corporation-and-guardianedge-technologies/</link>
		<comments>http://www.experiordata.com/blog/2010/04/29/symantec-has-acquired-pgp-corporation-and-guardianedge-technologies/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 13:39:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PGP]]></category>
		<category><![CDATA[guardianedge]]></category>
		<category><![CDATA[PGP. acquistion]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=421</guid>
		<description><![CDATA[Symantec acquires PGP and GuardianEdge Technologies]]></description>
			<content:encoded><![CDATA[<p>Big day today in the software security space. PGP Corporation and GuardianEdge Technologies (both competitors in the whole disk encryption market) have been acquired by Symantec Corporation. The acquisition provides much-needed applications to Symantec&#39;s industry-leading security software stack.</p>
<p>&nbsp;</p>
<p>Symantec has seen competitors such as CheckPoint, Sophos, and McAfee acquire key encryption technology platforms like Pointsec, Utimaco, and Safeboot. They will now have a strong whole disk encryption story, as well as solutions for file and e-mail encryption.&nbsp;</p>
<p>&nbsp;</p>
<p>The GuardianEdge Technologies (GE) acquisition will provide Symantec with direct access to GE&#39;s large base of government customers. Certainly GE has a client base in the commercial sector as well. There is clearly some overlap between PGP and GE products. Both provide a lot of value to the end users in terms of security features.</p>
<p>&nbsp;</p>
<p>Healthcare organizations that are looking to comply with the HITECH Act and protect PHI using encryption will be very pleased. Symantec has a significant market share in endpoint security products and those customers that need to deploy encryption will be happy to entrust the Symantec brand to their organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/04/29/symantec-has-acquired-pgp-corporation-and-guardianedge-technologies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Government is Serious: Breach Notifications WILL be posted</title>
		<link>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/</link>
		<comments>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 04:22:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=411</guid>
		<description><![CDATA[HHS OCR names covered entities and business associates involved in data breaches over 500 records of PHI lost. Unencrypted PHI that is breached must be reported to HHS and mass media.]]></description>
			<content:encoded><![CDATA[<p>The government is naming names! Today the Office of Civil Rights, part of the Department of Health and Human Services, did what they they said all along that they will do &#8211; post the names of covered entities AND business associates who are involved in data breaches. The somewhat <a title="OCR list of covered entities and business associates with breaches of PHI" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/postedbreaches.html" target="_blank">lengthly list</a> provides an insight into the organizations involved in breaches of unsecured protected health information (PHI).</p>
<p><br class="spacer_" /></p>
<p>Protected Health Information (PHI) is a term used widely in HIPAA. PHI is information that can identify and individual, such as name, address, social security number, and clinical information about the individual. Part of the American Recovery and Reinvestment Act (ARRA) called the HITECH Act, section 13402, specifically requires a covered entity or business associate to notify HHS and the mass media of breaches of uprotected PHI involving more than 500 records. PHI that is encrypted is considered <em>protected </em>and, therefore, provides a safe harbor against breach notification.</p>
<p><br class="spacer_" /></p>
<p>Among those involved in the data breaches are hospitals, clinics, dentists, insurance companies, private medical practices (though it&#8217;s unclear as to why their names are being withheld), universities, state governments, and several Blue Cross Blue shield organizations.</p>
<p><br class="spacer_" /></p>
<p>More importantly, business associates &#8211; which are essentially service providers to covered entities &#8211; are not only listed but are named. Most of them are IT services providers to covered entities.</p>
<p><br class="spacer_" /></p>
<p>Data at rest appears to be the most common form of breach, most likely a result of lost laptops, backup tapes, and a seemingly missing server.</p>
<p><br class="spacer_" /></p>
<p>Data encryption provides a safe harbor against breach notification and should be implemented in places where PHI is stored.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 steps for breach notification protection</title>
		<link>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/</link>
		<comments>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 14:37:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=399</guid>
		<description><![CDATA[Using encryptio to protect phi creates a safe harbor against breach notification. 3 steps to help you comply with breach notification safe harbor in HITECH Act/HIPAA Security rule.]]></description>
			<content:encoded><![CDATA[<p>Beginning on February 18, HHS will have the legal authority to enforce the breach notification laws set forth last year as part of section 13402 of the HITECH Act,  within the American Recovery &amp; Reinvestment Act (ARRA). The penalties can now be up to $1.5 million and require media notification in cases where 500 or more records are breached. Business associates, as well as covered entities, must now comply with the HITECH Act breach notification rule (which essentially makes modifications to the <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> Security Rule).</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<ol>
<li>Perform an extensive security review and indentify where electronic protected health information (PHI or ePHI) resides on your IT systems. </li>
<li>Create a plan on protecting PHI.
<ul>
<li>Data <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> provides a <a class="zem_slink" title="Safe harbor" rel="wikipedia" href="http://en.wikipedia.org/wiki/Safe_harbor">safe harbor</a> from breach notification. Determine where PHI can be encrypted.</li>
<li>Identify public facing extranet portals and web applications that can allow access to PHI.</li>
<li>Identify databases that hold PHI.</li>
<li>Execute the plan </li>
</ul>
<ul>
</ul>
<ul>
</ul>
</li>
<li> Implement data encryption where practical.
<ul>
</ul>
<ul>
<li>For databases, implement a database security product to monitor database requests and protect from intrusion.</li>
</ul>
<ul>
<li>For web apps, implement a web application security product to protect from <a class="zem_slink" title="Cross-site scripting" rel="wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting">cross-site scripting</a> and various attacks to access databases to PHI.</li>
</ul>
<ul>
<li>Protect endpoints such as laptops, tablets, etc with data at rest encryption by implementing whole disk encryption,</li>
</ul>
<ol> </ol>
</li>
</ol>
<p><br class="spacer_" /></p>
<p>Experior Data helps customers plan and execute data security assessments and technology implementation for healthcare. Our proprietary Technical Security Audit includes a personalized review of your IT systems and well as a vulnerability scan of all your network components.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/09/hitech-act-security-breach-rules-now-effective-federales-give-a-sixmonth-pass.html">HITECH Act security breach rules now effective; federales give a six-month pass. Now&#8217;s the time to kick compliance efforts into high gear</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/jonneiditz/hitech-and-state-breach-notification">HITECH and State Breach Notification</a> (slideshare.net)</li>
<li class="zemanta-article-ul-li"><a href="http://yro.slashdot.org/story/09/09/19/2157217/Using-Encryption-Garners-Exemption-For-Data-Breach-Notification?from=rss">Using Encryption Garners Exemption For Data Breach Notification</a> (yro.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules-whos-ready.html">Son of HIPAA Breach Notification Rules and Business Associate Requirements: Who&#8217;s Ready?</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://hunscher.typepad.com/futurehit/2010/01/the-cost-of-fear-why-docs-dont-embrace-technology.html">The Cost of Fear | Why Docs Don&#8217;t Embrace Technology (Dr. Rob)</a> (hunscher.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/February2010/01/c5838.html&amp;a=12426180&amp;rid=3a0266f6-3270-43a7-9d5d-72d3000b6dd6&amp;e=11c996da2d350263f04bcb67deeb4620">PGP Corporation to Announce Acquisition</a> (newswire.ca)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/3a0266f6-3270-43a7-9d5d-72d3000b6dd6/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=3a0266f6-3270-43a7-9d5d-72d3000b6dd6" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PGP Encryption Smackdown &#8211; Supports Mac Snow Leopard, Linux, Boot Camp, SSD drive support</title>
		<link>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/</link>
		<comments>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 19:32:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=391</guid>
		<description><![CDATA[PGP Corporation announced an update to its products line. PGP now supports Red Hat &#38; Ubuntu Linux, Mac OSX Snow Leopard, and Boot Camp on Mac OSX computers. In addition, PGP has updated its whole disk encryption technology to include a Hybrid Cryptographic Optimizer (HCO) technology to deliver faster run times for PGP Whole Disk [...]]]></description>
			<content:encoded><![CDATA[<p><a title="PGP Corporation - encryption" href="http://www.pgp.cpm">PGP Corporation</a> announced an update to its products line. PGP now supports Red Hat &amp; Ubuntu Linux, Mac OSX Snow Leopard, and Boot Camp on Mac OSX computers. In addition, PGP has updated its whole disk encryption technology to include a Hybrid Cryptographic Optimizer (HCO) technology to deliver faster run times for PGP Whole Disk Encryption.</p>
<p><br class="spacer_" /></p>
<p>Customers can now use PGP Universal Server to centrally manage encryption for their multi-platform environment. A single web-based user interface can be used to manage encryption end points using Microsoft Windows, Apple Mac, Red Hat Linux, and Ubuntu Linux. PGP is the only encryption vendor that delivers encryption solutions across multiple platforms. Multi-platform support is especially important with the popularity of netbooks, and the forthcoming Apple tablet device, which is reported to be using the Mac OSX operating system.</p>
<p><br class="spacer_" /></p>
<p>PGP also added functionality for e-mail encryption in Microsoft Outlook. Using Microsoft Outlook users can now click &#8220;sign and encrypt&#8221; buttons to automatically encrypt emails.</p>
<p><br class="spacer_" /></p>
<p>Experior Data is a PGP SILVER Partner and helps organizations implement data encryption solutions.</p>
<p><br class="spacer_" /></p>
<p>More information about these new releases is available on the <a title="PGP releases new encryption products" href="http://www.pgp.com/insight/newsroom/press_releases/new_data_protection_solutions_for_mac_linux.html" target="_blank">PGP web site</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/01/22/pgp-encryption-smackdown-supports-mac-snow-leopard-linux-boot-camp-ssd-drive-support/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disk encryption is not enough for HIPAA HITECH Act Compliance</title>
		<link>http://www.experiordata.com/blog/2010/01/19/disk-encryption-is-not-enough-for-hipaa-hitech-act-compliance/</link>
		<comments>http://www.experiordata.com/blog/2010/01/19/disk-encryption-is-not-enough-for-hipaa-hitech-act-compliance/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 06:41:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=384</guid>
		<description><![CDATA[Whole disk encryption is not enough for HIPAA and HITECH Act compliance. Encryption solutions must not only protect data at rest but also data in use.]]></description>
			<content:encoded><![CDATA[<p>In the coming months healthcare IT administrators will see many products come to market that claim to solve the compliance issues of safeguarding unsecured protected health information (PHI). A bit of caution and understanding of the issues is required here:</p>
<p><br class="spacer_" /></p>
<p>- Whole disk encryption is clearly needed for mobile devices</p>
<p><br class="spacer_" /></p>
<p>- Whole disk encryption protects data when computers are TURNED OFF. This means that while you&#8217;re using the laptop the data is in use, and is not encrypted.</p>
<p><br class="spacer_" /></p>
<p>- Additional levels of data protection is needed to protected the data while computers are in use. For example, critical data files should be encrypted automatically regardless of whether the computer is turned on or off. <strong>Whole disk encryption does not do this.</strong></p>
<p><br class="spacer_" /></p>
<p>- Files containing PHI that are transferred on a network need to be encrypted. <strong>Whole disk encryption does not do this.</strong></p>
<p><br class="spacer_" /></p>
<p><strong>- </strong>What about e-mails containing PHI? More importantly, what about those that use Microsoft Outlook and store data in archive (.pst) files?</p>
<p><br class="spacer_" /></p>
<p>So why is whole disk encryption not enough? What happens if a worm invades your computer and transfers documents of a certain file type to a remote location. Whole disk encryption will not help you in this situation.</p>
<p><br class="spacer_" /></p>
<p>It&#8217;s important for any encryption solution to not only encrypt the hard drive but also to encrypted files on the hard drive so that they remain encrypted while the computer is on.</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/01/19/disk-encryption-is-not-enough-for-hipaa-hitech-act-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
