<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; breach notification</title>
	<atom:link href="http://www.experiordata.com/blog/tag/breach-notification/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Government is Serious: Breach Notifications WILL be posted</title>
		<link>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/</link>
		<comments>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 04:22:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=411</guid>
		<description><![CDATA[HHS OCR names covered entities and business associates involved in data breaches over 500 records of PHI lost. Unencrypted PHI that is breached must be reported to HHS and mass media.]]></description>
			<content:encoded><![CDATA[<p>The government is naming names! Today the Office of Civil Rights, part of the Department of Health and Human Services, did what they they said all along that they will do &#8211; post the names of covered entities AND business associates who are involved in data breaches. The somewhat <a title="OCR list of covered entities and business associates with breaches of PHI" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/postedbreaches.html" target="_blank">lengthly list</a> provides an insight into the organizations involved in breaches of unsecured protected health information (PHI).</p>
<p><br class="spacer_" /></p>
<p>Protected Health Information (PHI) is a term used widely in HIPAA. PHI is information that can identify and individual, such as name, address, social security number, and clinical information about the individual. Part of the American Recovery and Reinvestment Act (ARRA) called the HITECH Act, section 13402, specifically requires a covered entity or business associate to notify HHS and the mass media of breaches of uprotected PHI involving more than 500 records. PHI that is encrypted is considered <em>protected </em>and, therefore, provides a safe harbor against breach notification.</p>
<p><br class="spacer_" /></p>
<p>Among those involved in the data breaches are hospitals, clinics, dentists, insurance companies, private medical practices (though it&#8217;s unclear as to why their names are being withheld), universities, state governments, and several Blue Cross Blue shield organizations.</p>
<p><br class="spacer_" /></p>
<p>More importantly, business associates &#8211; which are essentially service providers to covered entities &#8211; are not only listed but are named. Most of them are IT services providers to covered entities.</p>
<p><br class="spacer_" /></p>
<p>Data at rest appears to be the most common form of breach, most likely a result of lost laptops, backup tapes, and a seemingly missing server.</p>
<p><br class="spacer_" /></p>
<p>Data encryption provides a safe harbor against breach notification and should be implemented in places where PHI is stored.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/23/the-government-is-serious-breach-notifications-will-be-posted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blue Cross Blue Shield of Tennessee to explain data breach</title>
		<link>http://www.experiordata.com/blog/2010/01/11/blue-cross-blue-shield-of-tennessee-to-explain-data-breach/</link>
		<comments>http://www.experiordata.com/blog/2010/01/11/blue-cross-blue-shield-of-tennessee-to-explain-data-breach/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 05:49:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[breach notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=378</guid>
		<description><![CDATA[Blue Cross Blue Shield of Tennessee customers will be receiving an explanation of the data breach incident, according to the Chattanooga Times Free Press.

&#8220;This week, BCBS will provide updated data to the public on exactly how many customers were exposed when 57 hard drives were pilfered in October from a storage closet at the insurer&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Blue Cross Blue Shield of Tennessee customers will be receiving an explanation of the data breach incident, according to the <a title="Chattanooga Times Free Press article about Blue Cross Blue Shield of Tennessee data breach" href="http://www.timesfreepress.com/news/2010/jan/10/customers-alerted-to-bluecross-data-breach/" target="_blank">Chattanooga Times Free Press</a>.</p>
<p><br class="spacer_" /></p>
<address>&#8220;<span style="font-size: xx-small;">This week, BCBS will provide updated data to the public on exactly how many customers were exposed when 57 hard drives were pilfered in October from a storage closet at the insurer&#8217;s Eastgate Town Center branch, said company spokeswoman Mary Thompson.</span></address>
<address><span style="font-size: xx-small;"><br />
 </span></address>
<address><span style="font-size: xx-small;">&#8216;We&#8217;ve reach a critical mass with our analysis of the information, and this week we think we can update the public,&#8221; Ms. Thompson said. &#8220;We&#8217;re going to be doing a really full breakdown of how many were potentially exposed.&#8217;&#8221;</span></address>
<address></address>
<address><span style="font-size: xx-small;"><br />
 </span></address>
<address></address>
<p><span style="font-style: normal;"><span style="font-size: small;">BCBS goes on further to say that the data on the hard drives was &#8220;scrambled&#8221; in way that would make it difficult for others to access it. It remains to be see what &#8220;scrambled&#8221; really means. </span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/01/11/blue-cross-blue-shield-of-tennessee-to-explain-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Net Breach Notification Letter</title>
		<link>http://www.experiordata.com/blog/2009/12/14/health-net-breach-notification-letter/</link>
		<comments>http://www.experiordata.com/blog/2009/12/14/health-net-breach-notification-letter/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 15:46:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[HITECH Act]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=301</guid>
		<description><![CDATA[An example of a breach notification letter from Health Net.]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:AlanisMorissette.01.jpg"><img title="{{pt|A cantora canadense Alanis Morissette dur..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/b/bd/AlanisMorissette.01.jpg/300px-AlanisMorissette.01.jpg" alt="{{pt|A cantora canadense Alanis Morissette dur..." width="300" height="428" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:AlanisMorissette.01.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 210px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Health_Net_vert_no_tag_color.png"><img title="Health Net, Inc." src="http://upload.wikimedia.org/wikipedia/en/f/fb/Health_Net_vert_no_tag_color.png" alt="Health Net, Inc." width="200" height="127" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Health_Net_vert_no_tag_color.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><span style="font-size: 12px;">As Alanis Morrissette would say &#8220;And isn&#8217;t it ironic &#8230; don&#8217;t you think&#8221;. A relative just received a <a onclick="window.open(this.href, 'HealthNet Breach Notification Letter', 'resizable=yes,status=yes,location=yes,toolbar=yes,menubar=no,fullscreen=no,scrollbars=no,dependent=no'); return false;" href="http://experiordata.com/images/HealthNet_Breach.PDF">breach notification letter from from Health Net</a>. </span></p>
<p><span style="font-size: 12px;">Some wording we find interesting:</span></p>
<p><br class="spacer_" /></p>
<p><span class="Apple-style-span" style="font-size: 10px;">&#8220;The purpose of this letter is to inform you of a matter involving an unencrypted portable computer disk drive was discovered missing from a Health Net office&#8221;.</span></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p>What&#8217;s interesting about this sentence is that they use the term &#8220;unencrypted&#8221;. So the majority of the general public does not know what this term means. However, Health Net indirectly acknowledges that the drive should have been encrypted, and perhaps they will implement encryption in their company.</p>
<p><br class="spacer_" /></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.geeksaresexy.net/2009/12/23/kindle-users-bypass-copy-protection-and-regional-restrictions/">Kindle users bypass copy protection and regional restrictions</a> (geeksaresexy.net)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/4fecc401-3b32-4a29-8198-433ff04590b5/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=4fecc401-3b32-4a29-8198-433ff04590b5" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/14/health-net-breach-notification-letter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Accountability and Trust Act &#8211; H.R. 2221</title>
		<link>http://www.experiordata.com/blog/2009/12/09/data-accountability-and-trust-act-h-r-2221/</link>
		<comments>http://www.experiordata.com/blog/2009/12/09/data-accountability-and-trust-act-h-r-2221/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 02:38:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[breach notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=290</guid>
		<description><![CDATA[



Image via Wikipedia





The House of Representatives passed the Data Accountability and Trust Act  (HR 2221) today:

 
&#8220;A bill to protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a security breach&#8221; 
 
 
This bill essentially creates a nationwide breach [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Socseccardfront.png"><img title="Scanned image of author's US Social Security card." src="http://upload.wikimedia.org/wikipedia/commons/thumb/b/be/Socseccardfront.png/300px-Socseccardfront.png" alt="Scanned image of author's US Social Security card." width="300" height="180" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Socseccardfront.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 14px;">The House of Representatives passed the <a onclick="window.open(this.href, '', 'resizable=no,status=no,location=no,toolbar=no,menubar=no,fullscreen=no,scrollbars=no,dependent=no'); return false;" href="http://www.govtrack.us/congress/billtext.xpd?bill=h111-2221">Data Accountability and Trust Act  (HR 2221)</a> today:</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><br />
 </span></p>
<p style="margin-left: 40px;"><span style="font-size: 12px;">&#8220;<span class="Apple-style-span" style="color: #333333;">A bill to protect consumers by requiring reasonable security policies and procedures to protect data containing personal information, and to provide for nationwide notice in the event of a security breach&#8221; </span><br />
 </span></p>
<p style="margin-left: 40px;"> </p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 14px;"><span class="Apple-style-span" style="color: #333333;">This bill essentially creates a nationwide breach notification law that requires companies who hold personal information notify people about the breach. In addition to breach notification, the bill also requires companies who store electronic personal information to establish proper security policies and establish a security policy coordinator. Personal information is defined as:</span></span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><br />
 </span></p>
<p style="margin-left: 40px;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 12px;">&#8220;an individual’s first name or initial and last name, or address, or phone number, in combination with any 1 or more of the following data elements for that individual:</span></span></p>
<p style="margin-left: 40px;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 12px;">(i) Social Security number.</span></span></p>
<p style="margin-left: 40px;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 12px;">(ii) Driver’s license number or other State identification number.</span></span></p>
<p style="margin-left: 40px;"><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 12px;">(iii) Financial account number, or credit or debit card number, and any required security code, access code, or password that is necessary to permit access to an individual’s financial account.&#8221;</span></span></p>
<p style="margin-left: 40px;"> </p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 14px;">The fines are steep and could be as high as $11,000 per violation up to $5,000,000.</span></span></p>
<p><br class="spacer_" /></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 14px;">Notification may happen via postal mail or e-mail (if e-mail is the primary communication method and if consent to communicate via e-mail was previously given).</span></span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><br />
 </span></p>
<p><span style="font-family: arial,helvetica,sans-serif;"><span style="font-size: 14px;">The Bill provides an exemption from breach notification if encryption is used. However, it also mandates that the Federal Trade Commission explore other technologies and report back to Congress 270 days after enactment. With terminology like &#8220;renders data in electronic form unreadable or indecipherable&#8221; it&#8217;s unlikely that anything other than encryption would qualify :</span></span></p>
<p style="margin-left: 40px;"> </p>
<p style="margin-left: 40px;"> </p>
<p style="margin-left: 40px;"><span style="font-size: 12px;">&#8220;(A) ENCRYPTION- The encryption of data in electronic form shall establish a presumption that no reasonable risk of identity theft, fraud, or other unlawful conduct exists following a breach of security of such data. Any such presumption may be rebutted by facts demonstrating that the encryption has been or is reasonably likely to be compromised.</span></p>
<p style="margin-left: 40px;"><span style="font-size: 12px;"><br />
 </span></p>
<p style="margin-left: 40px;"><span style="font-size: 12px;">(B) ADDITIONAL METHODOLOGIES OR TECHNOLOGIES- Not later than 270 days after the date of the enactment of this Act, the Commission shall, by rule pursuant to section 553 of title 5, United States Code, identify any additional security methodology or technology, other than encryption, which renders data in electronic form unreadable or indecipherable, that shall, if applied to such data, establish a presumption that no reasonable risk of identity theft, fraud, or other unlawful conduct exists following a breach of security of such data. Any such presumption may be rebutted by facts demonstrating that any such methodology or technology has been or is reasonably likely to be compromised. In promulgating such a rule, the Commission shall consult with relevant industries, consumer organizations, and data security and identity theft prevention experts and established standards setting bodies.&#8221;</span></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.lanechase.net/blog/finance/learn-these-helpful-ways-to-reduce-your-risk-of-identity-theft">Learn These Helpful Ways to Reduce Your Risk of Identity Theft</a> (lanechase.net)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/health-net-healthcare-data-breach-affects15-million">Health Net healthcare data breach affects1.5 million</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.lanechase.net/blog/finance/identity-theft-what-it-means-to-financial-security">Identity Theft &#8211; Do You Know What it Means to Your Financial Security?</a> (lanechase.net)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/cd3a1dda-e3d4-45d3-8e21-9ed369781203/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=cd3a1dda-e3d4-45d3-8e21-9ed369781203" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/09/data-accountability-and-trust-act-h-r-2221/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHI not encrypted? See the breach notification web site you never want to vist:</title>
		<link>http://www.experiordata.com/blog/2009/12/08/phi-not-encrypted-see-the-breach-notification-web-site-you-never-want-to-vist/</link>
		<comments>http://www.experiordata.com/blog/2009/12/08/phi-not-encrypted-see-the-breach-notification-web-site-you-never-want-to-vist/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 05:12:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=278</guid>
		<description><![CDATA[



Image via Wikipedia



Yes, we have found the one web site we hope you never have to visit &#8211; even the name is enough to give us the chills: Notice to the Secretary of HHS of Breach of Unsecured Protected Health Information. Even the URL is eerily blunt: http://transparency.cit.nih.gov.

Yes, folks. If you suffer a breach you will [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:US-DeptOfHHS-Logo.svg"><img title="Logo of the United States Department of Health..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/1/15/US-DeptOfHHS-Logo.svg/300px-US-DeptOfHHS-Logo.svg.png" alt="Logo of the United States Department of Health..." width="300" height="300" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:US-DeptOfHHS-Logo.svg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>Yes, we have found the one web site we hope you never have to visit &#8211; even the name is enough to give us the chills: <a onclick="window.open(this.href, '', 'resizable=yes,status=no,location=yes,toolbar=no,menubar=no,fullscreen=no,scrollbars=no,dependent=no'); return false;" href="http://transparency.cit.nih.gov/breach/index.cfm">Notice to the Secretary of HHS of Breach of Unsecured Protected Health Information</a>. Even the URL is eerily blunt: http://<strong>transparency.</strong>cit.nih.gov.</p>
<p><br class="spacer_" /></p>
<p>Yes, folks. If you suffer a breach you will need to report it to HHS. Interestingly, the web site is hosted by the Center for Information Technology of the National Institute of Health.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/edf1062b-fc9f-4ed9-9b7f-d82f9a2a66ba/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=edf1062b-fc9f-4ed9-9b7f-d82f9a2a66ba" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/08/phi-not-encrypted-see-the-breach-notification-web-site-you-never-want-to-vist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Resource for State Breach Notification Laws</title>
		<link>http://www.experiordata.com/blog/2009/12/02/resource-for-state-breach-notification-laws/</link>
		<comments>http://www.experiordata.com/blog/2009/12/02/resource-for-state-breach-notification-laws/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 04:40:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[breach notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=267</guid>
		<description><![CDATA[In addition to Federal breach notification laws each state has its own breach notification law. We found a great cross reference resource for you to use in case you&#39;re wondering about the breach notification laws in your state.
	&#160;
Law Blog 2.0 &#8211; Summary of 50 State&#160;Security Breach Notification&#160;Laws (scroll down to see the map)
Code: H3MQYQC7J26W

	&#160;
]]></description>
			<content:encoded><![CDATA[<p>In addition to Federal breach notification laws each state has its own breach notification law. We found a great cross reference resource for you to use in case you&#39;re wondering about the breach notification laws in your state.<br />
	&nbsp;</p>
<p><a href="http://law2point0.com/wordpress/2009/09/15/50-state-security-breach-notice-law/" target="_blank">Law Blog 2.0 &#8211; Summary of 50 State&nbsp;Security Breach Notification&nbsp;Laws </a>(scroll down to see the map)</p>
<p>Code: <span class="status">H3MQYQC7J26W</span></p>
<p>
	&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/12/02/resource-for-state-breach-notification-laws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon CMO: Protection of data at rest not important? Really?</title>
		<link>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/</link>
		<comments>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 20:30:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PGP]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[laptops]]></category>
		<category><![CDATA[verizon]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=244</guid>
		<description><![CDATA[Seems like it&#8217;s been a tough week for Verizon to try and prove their point about how encryption is unimportant to securing protected health information (PHI).
..
According to ModernHealthcare.com Peter Tippett, Vice President of Technology and Innovation and Chief Medical Officer, recently said  &#8220;Encryption of data at rest in a database, for example, typically provides “no [...]]]></description>
			<content:encoded><![CDATA[<p>Seems like it&#8217;s been a tough week for Verizon to try and prove their point about how encryption is unimportant to securing <a class="zem_slink" title="Protected health information" rel="wikipedia" href="http://en.wikipedia.org/wiki/Protected_health_information">protected health information</a> (PHI).</p>
<p>..</p>
<p>According to <a title="Modern Healthcare" href="www.ModernHealthcare.com" target="_blank">ModernHealthcare.com</a> Peter Tippett, Vice President of Technology and Innovation and Chief Medical Officer, recently said  &#8220;Encryption of data at rest in a database, for example, typically provides “no value” against a large majority of hacking and malicious code threats, and “end-user devices like PCs, laptops and PDAs” are “orders of magnitude less important targets in the real world than is perceived (and databases are several orders of magnitude more important than end-user devices).”</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 250px;">
<dt class="wp-caption-dt"><a href="http://www.flickr.com/photos/80425071@N00/23860934"><img title="Ostrich" src="http://farm1.static.flickr.com/18/23860934_6b5b7ed93b_m.jpg" alt="Ostrich" width="240" height="160" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image by <a href="http://www.flickr.com/photos/80425071@N00/23860934">Spartacus007</a> via Flickr</dd>
</dl>
</div>
</div>
<p>In addition, Tippett says  current security standards and methods are “too complex, are based on dogma instead of science, are both ineffective and inefficient, and are too static.”</p>
<p>..</p>
<p>But facts and reality prove otherwise. The following RECENT breaches were revealed while Verizon is literally putting its head in the sand and marginalizing encryption  (and all of them could have protected patient information had encryption been installed):</p>
<ul>
<li><a title="Blue Cross Blue Shield loses 68 hard drives with protected health information (PHI)" href="http://www.msnbc.msn.com/id/33977885/" target="_blank">68 Computer hard drives </a>belonging to <a class="zem_slink" title="Blue Cross and Blue Shield Association" rel="wikipedia" href="http://en.wikipedia.org/wiki/Blue_Cross_and_Blue_Shield_Association">Blue Cross Blue Shield</a> &#8220;walked out&#8221; of a datacenter, along with social security numbers and other information belonging to 2 million clients.</li>
<li><a title="HealthNet loses hard drive with patient information" href="http://www.scmagazineus.com/the-data-breach-blog/section/1263/" target="_self">HealthNet loses an external hard drive</a> with personal financial and medical information belonging to 1.5 million clients.</li>
<li><a title="U.S Army loses hard drive with 60,000 records" href="http://www.armytimes.com/news/2009/11/army_breach_111309w/" target="_blank">US Army</a> loses hard drive with 60,000 with social security numbers and other personal information.</li>
<li>A<a title="Guam Memorial Hospital loses laptop" href="http://www.kuam.com/Global/story.asp?S=11509903" target="_blank"> laptop</a> containing clinical information on 2,000 patients was stolen from the Guam Memorial Hospital.</li>
</ul>
<p>And all this within 2 weeks! The fact is that data in use, like data at rest, and data in motion needs to be encrypted if it contains protected health information.</p>
<p>..</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/blue-cross-blue-shield-data-breach.html">Blue Cross Blue Shield Data Breach Investigation Extends Credit Protection for Providers to 2 Years</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-net-data-breach-15-million.html">Health Net Data Breach &#8211; 1.5 Million Records At Risk With Missing Portable Hard Drive</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/laptop-heist-exposes-doctors-personal-data">Laptop Heist Exposes Doctors&#8217; Personal Data</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/10/blue-cross-physicians-warning-potential.html">Blue Cross Physicians Warning &#8211; Potential Data Breach With Stolen Laptop Computer</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www10.nytimes.com/2009/11/25/health/policy/25bankruptcy.html%3F_r%3D5%26partner%3Drss%26amp%3Bemc%3Drss&amp;a=9887412&amp;rid=ddb01d91-1efe-4f93-ba81-d409929f5e90&amp;e=fa24b82b77fed5879e428c661f2c40b9">From the Hospital Room to Bankruptcy Court</a> (nytimes.com)</li>
<li class="zemanta-article-ul-li"><a href="http://iflizwerequeen.com/?p=4723">A member of Blue Cross Blue Shield comes over to the side of the people</a> (iflizwerequeen.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/ddb01d91-1efe-4f93-ba81-d409929f5e90/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ddb01d91-1efe-4f93-ba81-d409929f5e90" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/25/verizon-cmo-protection-of-data-at-rest-not-important-really/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Net starts breach notification to 1.5 million people</title>
		<link>http://www.experiordata.com/blog/2009/11/19/health-net-starts-breach-notification-to-1-5-million-people/</link>
		<comments>http://www.experiordata.com/blog/2009/11/19/health-net-starts-breach-notification-to-1-5-million-people/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 15:46:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[healthnet]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=214</guid>
		<description><![CDATA[



Image via Wikipedia



Health Net, a Woodland Hills, California-based managed healthcare provider realized that a missing hard drive contained protected health information (PHI). It affected 1.5 million customers, and 466,000 in Connecticut alone.

&#8220;The company reported the breach Wednesday to State Attorneys Generals offices in Arizona, Connecticut, New Jersey and New York. Health Net said it was [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 210px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Health_Net_vert_no_tag_color.png"><img title="Health Net, Inc." src="http://upload.wikimedia.org/wikipedia/en/f/fb/Health_Net_vert_no_tag_color.png" alt="Health Net, Inc." width="200" height="127" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Health_Net_vert_no_tag_color.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><a class="zem_slink" title="Health Net" rel="homepage" href="http://www.healthnet.com">Health Net</a>, a <a class="zem_slink" title="Woodland Hills, Los Angeles, California" rel="geolocation" href="http://maps.google.com/maps?ll=34.16833,-118.605&amp;spn=0.1,0.1&amp;q=34.16833,-118.605%20%28Woodland%20Hills%2C%20Los%20Angeles%2C%20California%29&amp;t=h">Woodland Hills, California</a>-based managed healthcare provider realized that a missing hard drive contained protected health information (PHI). It affected 1.5 million customers, and 466,000 in Connecticut alone.</p>
<p><br class="spacer_" /></p>
<p>&#8220;The company reported the breach Wednesday to State Attorneys Generals offices in Arizona, Connecticut, New Jersey and New York. Health Net said it was beginning the <a class="zem_slink" title="Data security" rel="wikipedia" href="http://en.wikipedia.org/wiki/Data_security">data security</a> breach notification process of sending out letters to its customers. The company said it expects to send notification</p>
<p>letters the week of Nov. 30.&#8221;, according to a <a title="Health Net Data Breach Article" href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1374839,00.html#" target="_blank">SearchSecurity News</a> article.</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Richard_Blumenthal_at_West_Hartford_library_opening.jpg"><img title="Connecticut Attorney General Richard Blumentha..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/c/c3/Richard_Blumenthal_at_West_Hartford_library_opening.jpg/300px-Richard_Blumenthal_at_West_Hartford_library_opening.jpg" alt="Connecticut Attorney General Richard Blumentha..." width="113" height="160" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Richard_Blumenthal_at_West_Hartford_library_opening.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>Connecticut Attorney General <a class="zem_slink" title="Richard Blumenthal" rel="wikipedia" href="http://en.wikipedia.org/wiki/Richard_Blumenthal">Richard Blumenthal</a> comments: &#8220;My investigation will seek to establish what happened and why the company kept its customers and the state in the dark for so long,&#8221; Blumenthal said in a statement. &#8220;The company&#8217;s failure to safeguard such sensitive information and inform consumers of its loss &#8212; leaving them naked to <a class="zem_slink" title="Identity Theft" rel="wikinvest" href="http://www.wikinvest.com/concept/Identity_Theft">identity theft</a> &#8212; may have violated state and federal laws.&#8221;</p>
<p><br class="spacer_" /></p>
<p>Although disk encryption could not have prevented the drive from being lost it certainly could have prevented unsecured protected health information from being accessible to unauthorized individuals. Federal breach notification rules under HIPAA/ARRA/HITECH Act took effect in September, 2009, but will be start being enforced until February, 2010.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www10.nytimes.com/2009/09/12/technology/internet/12hack.html%3F_r%3D5%26partner%3Drss%26amp%3Bemc%3Drss&amp;a=7586126&amp;rid=ceeb7a49-78eb-4910-bb8f-dc57a91f3616&amp;e=34cd348c53af092ae74ce7737521055e">Hacker Pleads Guilty in Vast Theft of Card Numbers</a> (nytimes.com)</li>
<li class="zemanta-article-ul-li"><a href="http://seattletimes.nwsource.com/html/sports/2010284518_apusdomainnametheft.html?syndication=rss">NJ man indicted in Web name theft, sale on eBay</a> (seattletimes.nwsource.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.cnn.com/2009/CRIME/08/28/US.hacker.plea.agreement/index.html%3Firef%3Dnewssearch&amp;a=7322191&amp;rid=ceeb7a49-78eb-4910-bb8f-dc57a91f3616&amp;e=6689d3d6970e21b82fb6875bb201a461">Man pleads guilty in massive ID theft case</a> (cnn.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.cnn.com/2009/CRIME/08/28/US.hacker.plea.agreement/index.html&amp;a=7276002&amp;rid=ceeb7a49-78eb-4910-bb8f-dc57a91f3616&amp;e=c6f89fa5f3336e006edfc147e0464b31">Plea deal reached in huge credit-card data theft</a> (cnn.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.wired.com/threatlevel/2009/08/gonzalezguiltyplea/">TJX Hacker Agrees to Guilty Plea; Faces 15 to 25 Years</a> (wired.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.telegraph.co.uk/technology/6045562/Identity-theft-Three-accused-over-biggest-bank-card-scam-in-US-history.html&amp;a=6995108&amp;rid=ceeb7a49-78eb-4910-bb8f-dc57a91f3616&amp;e=93f21514acba34e38a5a3d3a446a5e75">Identity theft: Three accused over biggest bank card scam in US history</a> (telegraph.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://blog.deurainfosec.com/health-net-healthcare-data-breach-affects15-million">Health Net healthcare data breach affects1.5 million</a> (deurainfosec.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.wired.com/threatlevel/2009/11/healthnet">Health Insurer Loses 1.5 Million Patient Records</a> (wired.com)</li>
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2009/11/health-net-data-breach-15-million.html">Health Net Data Breach &#8211; 1.5 Million Records At Risk With Missing Portable Hard Drive</a> (ducknetweb.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/ceeb7a49-78eb-4910-bb8f-dc57a91f3616/"><img class="zemanta-pixie-img" style="border: medium none ; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=ceeb7a49-78eb-4910-bb8f-dc57a91f3616" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/19/health-net-starts-breach-notification-to-1-5-million-people/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do your tablet, laptop, and desktop PCs need encryption if you use web-based EMR/EHR/PHR?</title>
		<link>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/</link>
		<comments>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 15:01:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Encyption]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[emr]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[phr]]></category>
		<category><![CDATA[web app]]></category>
		<category><![CDATA[web-based emr]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=188</guid>
		<description><![CDATA[



Image via Wikipedia



There has been much debate about security of endpoint devices like tablet PCs, desktops, and laptops where web-based EMR packages are used. There is a potential false sense of security by assuming that just because an EMR or PMR app is web-based then data at rest encryption, like whole disk encryption, is not [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 310px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Tablet.jpg"><img title="Photo of HP Tablet PC running MS Windows Table..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/4/4f/Tablet.jpg/300px-Tablet.jpg" alt="Photo of HP Tablet PC running MS Windows Table..." width="300" height="314" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Tablet.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>There has been much debate about security of endpoint devices like tablet PCs, desktops, and laptops where web-based EMR packages are used. There is a potential false sense of security by assuming that just because an EMR or PMR app is web-based then data at rest encryption, like whole disk encryption, is not required since no local data is stored. However, consider these possible scenarios:</p>
<p><span style="color: #808080;"><br />
 </span></p>
<p>- <a class="zem_slink" title="Protected health information" rel="wikipedia" href="http://en.wikipedia.org/wiki/Protected_health_information">Protected health information</a> (PHI) is exported from an EMR, practice management, or even an accounting  app and is stored locally in a <a class="zem_slink" title="Text file" rel="wikipedia" href="http://en.wikipedia.org/wiki/Text_file">text file</a> or a Microsoft Office document.</p>
<p><br class="spacer_" /></p>
<p>- If you use mainframes and use terminal emulators a user could do a &#8220;print screen&#8221; to save the image locally.</p>
<p><br class="spacer_" /></p>
<p>- E-mail attachments containing PHI could be saved locally.</p>
<p><br class="spacer_" /></p>
<p>- Web browser temp and cookie files could contain clues about how data is accessed and retrieved.</p>
<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 133px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Outlook_2007.png"><img title="Microsoft Office Outlook" src="http://upload.wikimedia.org/wikipedia/en/b/b0/Outlook_2007.png" alt="Microsoft Office Outlook" width="123" height="123" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Outlook_2007.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>- E-mail clients that have a local store could be used. The  local store, like a personal folder file (<a class="zem_slink" title="Personal Storage Table" rel="wikipedia" href="http://en.wikipedia.org/wiki/Personal_Storage_Table">.pst</a>) file in Microsoft Outlook, could contain PHI. Also, in a Microsoft Exchange environment the end user could inadvertently enable the AutoArchive feature where older content is stored locally on the computer in a .pst file.</p>
<p><br class="spacer_" /></p>
<p>In a recent <a title="Are You Secured? article in ADVANCE for HIM journal" href="http://health-information.advanceweb.com/editorial/content/editorial.aspx?cc=210501" target="_blank">Advance for HIM article entitled &#8220;Are you Secured&#8221;</a>, Daniela Crivianu-Gaita, chief information officer at The Hospital for Sick Children, Toronto. writes:</p>
<p><br class="spacer_" /></p>
<p>&#8220;Facilities can opt to encrypt parts of their IT system, but full-disk encryption ensures the organization is covered in the event of a breach. &#8220;Temporary files created by various applications, the operating system swap file and hidden partitions may contain sensitive data,&#8221; said Daniela Crivianu-Gaita, chief information officer at The Hospital for Sick Children, Toronto. &#8220;Full-disk encryption is the only approach that assures all the data on the local hard disks is encrypted.&#8221;</p>
<p><br class="spacer_" /></p>
<p>The point is that just because the EMR or other app that is web-based is used in you environment it doesn&#8217;t meant that data at rest protection should be ignored. Installing whole disk encryption to protect data at rest could provide peace of mind and protection against unwanted breach notification should that device be lost or stolen. With the strict enforcement of breach notification rules coming to fruition in February, 2010 it&#8217;s better to be safe then sorry by implementing encryption as specified in the HITECH Act within ARRA.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://docinthemachine.com/2009/11/09/encrypt/">Encrypt EHR &#8211; Else HIPAA Violations Need Be Reported To Government &amp; Media</a> (docinthemachine.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/d8317ec0-b99d-4d68-b2de-7fdfcd765465/"><img class="zemanta-pixie-img" style="border: medium none ; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=d8317ec0-b99d-4d68-b2de-7fdfcd765465" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/19/do-your-tablet-laptop-and-desktop-pcs-need-encryption-if-you-use-web-based-emrehrphr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Congress to HHS: Remove the harm assessment!</title>
		<link>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/</link>
		<comments>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/#comments</comments>
		<pubDate>Sat, 03 Oct 2009 19:15:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[ARRA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[congress]]></category>
		<category><![CDATA[media notification]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=143</guid>
		<description><![CDATA[



Image via Wikipedia



In a strongly-worded letter sent and signed by six congressmen to HHS Secretary Kathleen Sebelius the message was clear: remove the harm assessment that lawmakers rejected when writing the privacy regulations into ARRA. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 218px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg"><img title="Kansas Governor :en:Kathleen Sebelius speaks w..." src="http://upload.wikimedia.org/wikipedia/commons/1/1d/Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg" alt="Kansas Governor :en:Kathleen Sebelius speaks w..." width="208" height="332" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Sebelius_speaking_with_troops_in_Pakistan%2C_27_Nov%2C_2005%2C_cropped.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>In a strongly-worded <a title="Letter from Congress to HHS asking to remove harm standard from breach notification" href="http://energycommerce.house.gov/Press_111/20091001/sebelius_letter.pdf" target="_blank">letter</a> sent and signed by six congressmen to <a class="zem_slink" title="United States Secretary of Health and Human Services" rel="wikipedia" href="http://en.wikipedia.org/wiki/United_States_Secretary_of_Health_and_Human_Services">HHS Secretary</a> <a class="zem_slink" title="Kathleen Sebelius" rel="wikipedia" href="http://en.wikipedia.org/wiki/Kathleen_Sebelius">Kathleen Sebelius</a> the message was clear: remove the harm assessment that lawmakers rejected when writing the <a class="zem_slink" title="Privacy" rel="wikipedia" href="http://en.wikipedia.org/wiki/Privacy">privacy</a> regulations into <a title="American Recovery and Reinvestment Act of 2009" href="http://www.experiordata.com/images/american_recovery_reinvestment_act.pdf" target="_blank">ARRA</a>. The harm standard essentially says that in case of a breach the covered entity must make an assessment of whether or not the breach can cause reputational, financial, and other types of harm.  This leaves open the possibility that a covered entity could decide to act in its own interest and make the decision not to follow the directives written into the <a title="Interim final ruling on breach notification" href="http://www.experiordata.com/images/interim_final_ruling.pdf" target="_blank">breach notification ruling</a>.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>There are, of course, two sides of the sword. On one hand it&#8217;s difficult to enforce a policy with subjective elements present, such as the harm assessment. It is unlikely that a covered entity would risk the substantial fines, now as high as $1.5 million, and the possibility of criminal prosecution to avoid notification in case a serious breach occurs. However, the harm assessment leaves that possibility open.</p>
<p><span style="color: #ffffff;">..</span></p>
<p>A drawback to removing the harm assessment is that it is possible that, ironically, that too many breach notifications are sent to people, thereby creating a &#8220;boy that cries wolf&#8221; effect. In a perfect world breaches would never happen, so there would not need to be a reason to notify people. However, we all know that not to be the reality. Breaches do occur, intentional or not. And people need to be notified as soon as possible. Should covered entities be given the privilege of deciding the severity of the harm and potentially choosing not to notify people? We shall see the next steps Congress and HHS will take.</p>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/f109c045-b7ee-4c5f-b033-6660b8cf7572/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=f109c045-b7ee-4c5f-b033-6660b8cf7572" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
</span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/10/03/congress-to-hhs-remove-the-harm-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
