<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Experior Data Encryption Blog &#187; RMF</title>
	<atom:link href="http://www.experiordata.com/blog/tag/rmf/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Risk Management Framework recommended by NIST for HITECH Act and HIPAA Compliance</title>
		<link>http://www.experiordata.com/blog/2010/05/14/risk-management-framework-recommended-by-nist-for-hitech-act-and-hipaa-compliance/</link>
		<comments>http://www.experiordata.com/blog/2010/05/14/risk-management-framework-recommended-by-nist-for-hitech-act-and-hipaa-compliance/#comments</comments>
		<pubDate>Fri, 14 May 2010 15:22:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Regulation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[RMF]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=432</guid>
		<description><![CDATA[&#160; &#160; In order to help the government and private industry standardize on a risk management process NIST created the RMF -&#160;Risk Management Framework. The framework into 6 steps: &#160; Categorize the information systems Select security controls Implement security controls Access security controls Authorize information systems Monitor security controls At the 2010 NIST HIPAA Security [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>&nbsp;</p>
<p>In order to help the government and private industry standardize on a risk management process NIST created the RMF -&nbsp;<a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-1b-risk-assessment-toth-nist.pdf" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Risk Management Framework created by NIST - used to create risk management analysis for HIPAA HITECH Act compliance">Risk Management Framework</a>. The framework into 6 steps:</p>
<p>
	&nbsp;</p>
<ul style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; ">
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Categorize the information systems</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Select security controls</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Implement security controls</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Access security controls</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Authorize information systems</li>
<li style="list-style-type: none; background-image: url(http://media.techtarget.com/hitke/v1.3/images/misc/bullet_square_999999.png); background-repeat: no-repeat; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 10px; margin-top: 0px; margin-right: 0px; margin-bottom: 2px; margin-left: 15px; background-position: 0px 6px; ">Monitor security controls</li>
</ul>
<p>At the 2010 NIST HIPAA Security Conference&nbsp;<a href="http://csrc.nist.gov/news_events/HIPAA-May2010_workshop/presentations/1-1b-risk-assessment-toth-nist.pdf" style="color: rgb(54, 82, 114); text-decoration: underline; " target="_blank" title="Pat Toth presentation at HIPAA NIST security conference">presentation</a>,&nbsp;Pat Toth, a computer scientist working for&nbsp;<a href="http://www.nist.gov/" style="color: rgb(54, 82, 114); text-decoration: underline; ">NIST</a>&nbsp;, discussed the importance of the integrating risk management and security into your enterprise computing environment. &nbsp;Security is often thought of as an after-the-fact process that becomes important after IT systems and applications are deployed. Toth pointed out that our perception of security&rsquo;s role needs to change in order to protect the our healthcare information systems.</p>
<p>&nbsp;</p>
<div>The HIPAA security rule specifically requires that a risk assessment be performed on IT systems that contain PHI (protected health information). Rather than creating the assessment from scratch the RMF is a great place to start your research and perhaps implement the steps recommended by NIST to secure your HIT systems.</div>
<div>.</div>
<div>&nbsp;</div>
<div>The RMF is of particular importance for helping to obtain a safe harbor from penalties in the HIPAA security rule, particularly when deciding to implement (or not implement) technologies like data encryption. For example: if you decide that encryption is not needed in your environment and an incident happens where PHI is breached you will need to show the reason behind your decisions to HHS OCR (U.S Department of Health and Human Services, Office of Civil Rights).</div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/05/14/risk-management-framework-recommended-by-nist-for-hitech-act-and-hipaa-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

