<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Avoid Breach Notification - Experior helps PHI Encryption &#187; Security</title>
	<atom:link href="http://www.experiordata.com/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.experiordata.com/blog</link>
	<description>Encrypt your PHI, and avoid breach notification</description>
	<lastBuildDate>Tue, 18 May 2010 04:09:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>3 steps for breach notification protection</title>
		<link>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/</link>
		<comments>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 14:37:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Section 13402]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=399</guid>
		<description><![CDATA[Using encryptio to protect phi creates a safe harbor against breach notification. 3 steps to help you comply with breach notification safe harbor in HITECH Act/HIPAA Security rule.]]></description>
			<content:encoded><![CDATA[<p>Beginning on February 18, HHS will have the legal authority to enforce the breach notification laws set forth last year as part of section 13402 of the HITECH Act,  within the American Recovery &amp; Reinvestment Act (ARRA). The penalties can now be up to $1.5 million and require media notification in cases where 500 or more records are breached. Business associates, as well as covered entities, must now comply with the HITECH Act breach notification rule (which essentially makes modifications to the <a class="zem_slink" title="Health Insurance Portability and Accountability Act" rel="wikipedia" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> Security Rule).</p>
<p><br class="spacer_" /></p>
<p><br class="spacer_" /></p>
<ol>
<li>Perform an extensive security review and indentify where electronic protected health information (PHI or ePHI) resides on your IT systems. </li>
<li>Create a plan on protecting PHI.
<ul>
<li>Data <a class="zem_slink" title="Encryption" rel="wikipedia" href="http://en.wikipedia.org/wiki/Encryption">encryption</a> provides a <a class="zem_slink" title="Safe harbor" rel="wikipedia" href="http://en.wikipedia.org/wiki/Safe_harbor">safe harbor</a> from breach notification. Determine where PHI can be encrypted.</li>
<li>Identify public facing extranet portals and web applications that can allow access to PHI.</li>
<li>Identify databases that hold PHI.</li>
<li>Execute the plan </li>
</ul>
<ul>
</ul>
<ul>
</ul>
</li>
<li> Implement data encryption where practical.
<ul>
</ul>
<ul>
<li>For databases, implement a database security product to monitor database requests and protect from intrusion.</li>
</ul>
<ul>
<li>For web apps, implement a web application security product to protect from <a class="zem_slink" title="Cross-site scripting" rel="wikipedia" href="http://en.wikipedia.org/wiki/Cross-site_scripting">cross-site scripting</a> and various attacks to access databases to PHI.</li>
</ul>
<ul>
<li>Protect endpoints such as laptops, tablets, etc with data at rest encryption by implementing whole disk encryption,</li>
</ul>
<ol> </ol>
</li>
</ol>
<p><br class="spacer_" /></p>
<p>Experior Data helps customers plan and execute data security assessments and technology implementation for healthcare. Our proprietary Technical Security Audit includes a personalized review of your IT systems and well as a vulnerability scan of all your network components.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/09/hitech-act-security-breach-rules-now-effective-federales-give-a-sixmonth-pass.html">HITECH Act security breach rules now effective; federales give a six-month pass. Now&#8217;s the time to kick compliance efforts into high gear</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.slideshare.net/jonneiditz/hitech-and-state-breach-notification">HITECH and State Breach Notification</a> (slideshare.net)</li>
<li class="zemanta-article-ul-li"><a href="http://yro.slashdot.org/story/09/09/19/2157217/Using-Encryption-Garners-Exemption-For-Data-Breach-Notification?from=rss">Using Encryption Garners Exemption For Data Breach Notification</a> (yro.slashdot.org)</li>
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules-whos-ready.html">Son of HIPAA Breach Notification Rules and Business Associate Requirements: Who&#8217;s Ready?</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://hunscher.typepad.com/futurehit/2010/01/the-cost-of-fear-why-docs-dont-embrace-technology.html">The Cost of Fear | Why Docs Don&#8217;t Embrace Technology (Dr. Rob)</a> (hunscher.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/February2010/01/c5838.html&amp;a=12426180&amp;rid=3a0266f6-3270-43a7-9d5d-72d3000b6dd6&amp;e=11c996da2d350263f04bcb67deeb4620">PGP Corporation to Announce Acquisition</a> (newswire.ca)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/3a0266f6-3270-43a7-9d5d-72d3000b6dd6/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=3a0266f6-3270-43a7-9d5d-72d3000b6dd6" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script><br />
<br />
 </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2010/02/16/3-steps-for-breach-notification-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interim Final Rule on Enforcement Issued</title>
		<link>http://www.experiordata.com/blog/2009/11/17/interim-final-rule-on-enforcement-issued/</link>
		<comments>http://www.experiordata.com/blog/2009/11/17/interim-final-rule-on-enforcement-issued/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 21:04:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[Law firms]]></category>
		<category><![CDATA[Regulation]]></category>
		<category><![CDATA[Rulings]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[HITECH Act]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.experiordata.com/blog/?p=169</guid>
		<description><![CDATA[According to Bricker &#38; Eckler, LLP
&#8230;
&#8220;On October 30, 2009, the Department of Health and Human Services (HHS) issued an interim final rule pertaining to the enforcement provisions of the HI-TECH Act. The final rule serves to conform HIPAA’s enforcement regulations to the revisions to the HIPAA statutes made by the HI-TECH Act.&#8221;
&#8230;
This is the government&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>According to <a title="Bricker &amp; Eckler, LL" href="http://www.bricker.com/legalservices/industry/hcare/ealerts/rc/rc37.asp" target="_blank">Bricker &amp; Eckler, LLP</a></p>
<p><span style="color: #c0c0c0;">&#8230;</span></p>
<p>&#8220;On October 30, 2009, the Department of Health and Human Services (HHS) issued an <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/enforcementrule/enfifr.pdf">interim final rule</a> pertaining to the enforcement provisions of the HI-TECH Act. The final rule serves to conform HIPAA’s enforcement regulations to the revisions to the HIPAA statutes made by the HI-TECH Act.&#8221;</p>
<p><span style="color: #c0c0c0;">&#8230;</span></p>
<p>This is the government&#8217;s way of saying &#8220;we&#8217;re made a rule, and we are now going to enforce it&#8221;. The enforcement ruling is an indicative of the federal government&#8217;s interest in protecting the privacy and identity of patients. As patient records get converted from paper to electronic security has become a very important part of the healthcare IT ecosystem.</p>
<p><span style="color: #c0c0c0;">..</span></p>
<p>Bricker and Echler, LLC go on further to say &#8220;The HI-TECH Act significantly increased the penalty amounts for HIPAA violations, as reflected in the final rule. Covered entities should understand the financial risks associated with HIPAA non-compliance and the changes to the available affirmative defenses. It is critical to have an effective HIPAA compliance program to avoid HIPAA violations and to identify and correct HIPAA violations in a timely manner, which can shield the organization from substantial financial penalties&#8221;</p>
<p><span style="color: #c0c0c0;">..</span></p>
<p>Related articles by Zemanta</p>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://healthblawg.typepad.com/healthblawg/2009/11/son-of-hipaa-breach-notification-rules.html">Son of HIPAA Breach Notification Rules</a> (healthblawg.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://docinthemachine.com/2009/11/09/encrypt/">Encrypt EHR &#8211; Else HIPAA Violations Need Be Reported To Government &amp; Media</a> (docinthemachine.com)</li>
<li class="zemanta-article-ul-li"><a href="http://medicareupdate.typepad.com/medicare_update/2009/10/hcfacreport2008.html">HHS Releases 2008 Health Care Fraud and Abuse Control Program Report</a> (medicareupdate.typepad.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/2009/11/05/stimulus-fuels-gold-rush_n_347311.html">Stimulus Fuels Gold Rush For Electronic Health Systems</a> (huffingtonpost.com)</li>
<li class="zemanta-article-ul-li"><a href="http://healthcarebloglaw.blogspot.com/2009/11/hipaa-enforcement-meets-hitech-hipaa.html">HIPAA Enforcement Meets HITECH: HIPAA Administrative Simplification: Enforcement Rule</a> (healthcarebloglaw.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://healthcarebloglaw.blogspot.com/2009/10/arra-hitech-health-care-information.html">ARRA &#8211; HITECH: Health Care Information Breach Notification Regulations Now In Effect</a> (healthcarebloglaw.blogspot.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/0f8109dd-4181-4d3b-a3fb-759163ab8308/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=0f8109dd-4181-4d3b-a3fb-759163ab8308" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><br />
<script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></p>
<p> </span></div>
]]></content:encoded>
			<wfw:commentRss>http://www.experiordata.com/blog/2009/11/17/interim-final-rule-on-enforcement-issued/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
