<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Experior Data Encryption Blog &#187; audit</title>
	<atom:link href="http://www.experiordata.com/blog/tag/audit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Social media security policies in healthcare</title>
		<link>http://www.experiordata.com/blog/2010/05/18/social-media-security-policies-in-healthcare/</link>
		<comments>http://www.experiordata.com/blog/2010/05/18/social-media-security-policies-in-healthcare/#comments</comments>
		<pubDate>Tue, 18 May 2010 04:09:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[dlp]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=450</guid>
		<description><![CDATA[Sharon Finney provides best practices for policies on social media in healthcare.]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Sharon Finney from Adventist Health System in Winter Park, Florida prepared an excellent&nbsp;<a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-5-social-media-finney-adventist.pdf" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Sharon Finney Adventist Health System social media presentation">presentation</a>&nbsp;at the 2010 NIST HIPAA conference. She shared her experience in developing and implementing a comprehensive, risk-based policy at her organization.</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Sharon talked about the creation of a corporate policy and standard of conduct for social media. In order to be successful in creating these documents you must have executive buy-in from an &ldquo;executive sponsor&rdquo;. This sponsor is typically a VP of Marketing or PR.</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Sharon recommends assembling a team that includes representatives from legal, HR, compliance, data security, and IT departments to help shape and implement the social media policies. She recommends the following steps:</span></p>
<p><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></p>
<ul style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; ">
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a policy on social media &#8211; define scope of use such as who has legitimate business reasons (marketing, HR, communications, training, outreach, etc).</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a standard of conduct manual so that employees know how they should conduct themselves online. Ensure that proper disclaimers are placed. Look at HP, IBM, Microsoft standards of conduct as a goods start.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Watch out for exceptions to policies. If you grant too many exceptions the exceptions become the rule. Create a tedious exception policy to discourage exceptions.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Define your organization&rsquo;s risk tolerance.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Define sanctions for non-compliance and ensure employees know them.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a plan for monitoring including who will be doing the monitoring, what is being monitored, and the frequency of monitoring.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a quarterly audit policy trickled down to department heads to ensure that they review how their direct reports spend time online.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Clearly define what employees should and should not do (Adventist has about 36 points).</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Create a policy on monitoring and enforce it. Setup alerts for certain conditions.</span></li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; "><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">Implement DLP (Data Loss Prevention) technologies to prevent critical data (like PHI) from leaving your network.</span></li>
</ul>
<div><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; "><br />
	</span></div>
<div><span class="Apple-style-span" style="color: rgb(51, 51, 51); line-height: 16px; ">You should also create an incident response plan that includes all the appropriate parties. Ensuring that all employees are properly trained and understand the policy and standards is the key to success.</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/18/social-media-security-policies-in-healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

