<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: hipaa]]></title>
    <link>http://securityratty.com/tag/hipaa</link>
    <description></description>
    <pubDate>Tue, 24 Jun 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[New health-care privacy laws heighten need for HIPAA compliance in California]]></title>
      <link>http://securityratty.com/article/7a8600babb9dd9b8d92cc0b40aa087f2</link>
      <guid>http://securityratty.com/article/7a8600babb9dd9b8d92cc0b40aa087f2</guid>
      <description><![CDATA[California Gov. Arnold Schwarzenegger has signed two HIPAA-like bills that set new security requirements, breach-disclosure rules and fines for health care organizations operating in that...]]></description>
      <content:encoded><![CDATA[California Gov. Arnold Schwarzenegger has signed two HIPAA-like bills that set new security requirements, breach-disclosure rules and fines for health care organizations operating in that state.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:27851d20edf51ed1f2fc8f055ce21f67:0SW2KVUaWdvHkCEoDwDPMA%2BGydWxqG8dg2ls0459p%2FE9kgoreOyCD3hHG%2FWzJTrRjxesYdL1s0kg'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d8758858dffc1d6f975f7c3788ee4e1b:%2FtqY%2B1ZnVxGu470W02C0mgGGv%2FjHzk%2Fav%2FWn5dUXZPhlaUe2adPPN0Q7aJAjOVaC%2FpWPb93%2F9GI2Sw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:c170ba29c884f45390fe05ae2707af20:p12V8yfNnf8%2BFxr07ncC5jLYLTTZsw5B33IsJ2oBvPvqLH66Qm98bdstUr2eC%2FQRvnI8li%2FjKwrRTQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7cb195cc47aedb2f066ce49137af45bf:hEY9BPF0VZcXqXGVp7Zzvhci%2FC8ywfDY8WyYxB5foNWLNbumdvR8IFOeZDp2DGX12g168Yo4IUGb5g%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=11ba3706e6254b3ee7288884af3a298c" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=11ba3706e6254b3ee7288884af3a298c" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/health care organizations">health care organizations</category>
      <category domain="http://securityratty.com/tag/california gov">california gov</category>
      <category domain="http://securityratty.com/tag/hipaa-like bills">hipaa-like bills</category>
      <category domain="http://securityratty.com/tag/arnold schwarzenegger">arnold schwarzenegger</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/fines">fines</category>
      <category domain="http://securityratty.com/tag/rules">rules</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=11ba3706e6254b3ee7288884af3a298c">New health-care privacy laws heighten need for HIPAA compliance in California</source>
    </item>
    <item>
      <title><![CDATA[California privacy laws heighten need for HIPAA compliance]]></title>
      <link>http://securityratty.com/article/33c54a53d129a7fe812bd565175e4b68</link>
      <guid>http://securityratty.com/article/33c54a53d129a7fe812bd565175e4b68</guid>
      <description><![CDATA[Healthcare organizations that operate in California have two more good reasons to be sure that they comply with the data security and privacy requirements of the federal HIPAA...]]></description>
      <content:encoded><![CDATA[Healthcare organizations that operate in California have two more good reasons to be sure that they comply with the data security and privacy requirements of the federal HIPAA law.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=461?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=461?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Mon, 06 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/federal hipaa law">federal hipaa law</category>
      <category domain="http://securityratty.com/tag/data security">data security</category>
      <category domain="http://securityratty.com/tag/california">california</category>
      <category domain="http://securityratty.com/tag/healthcare organizations">healthcare organizations</category>
      <category domain="http://securityratty.com/tag/privacy requirements">privacy requirements</category>
      <category domain="http://securityratty.com/tag/reasons">reasons</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <source url="http://www.networkworld.com/news/2008/100708-california-privacy-laws-heighten-need.html?fsrc=rss-security">California privacy laws heighten need for HIPAA compliance</source>
    </item>
    <item>
      <title><![CDATA[Feds finally put teeth into HIPAA enforcement]]></title>
      <link>http://securityratty.com/article/98f3f6f111ea4eb29ba626234e508379</link>
      <guid>http://securityratty.com/article/98f3f6f111ea4eb29ba626234e508379</guid>
      <description><![CDATA[The federal government has signed a stringent settlement deal the first of its kind with a health care provider over 'possible violations' of HIPAA's data security...]]></description>
      <content:encoded><![CDATA[The federal government has signed a stringent settlement deal &mdash; the first of its kind &mdash; with a health care provider over 'possible violations' of HIPAA's data security rules.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:5164a4610d33d79618997fde01306359:rU0rXKnE3YLz9xgSzwMAYEX4eLrDroNkRr6b54q6OHoLui07DpdfGRBLTLpF8aqXsd2ELSxZVgDhlHNEob%2FL%2F5DbYkEWusmXlMqlXDA2gCk%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:78ddc8b1c138ef00e9313aedf3f6263b:mwkX6m71TsdqinMLVnX3fxsGClR2gUuIA%2FRNhIRnu6ZOEhSMCTvPP4812WHURbtMedvD1Fs7iS0rmqD6RBqIlKZsTzD7RNp09%2FwurnIHkb8%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:7a62b6063be4560b8097340d7dad9cde:qA2g9aNz04%2BHdpjktpwwKjeFPfCQm3bYqgQk17K6wq4L4uNKipcvXCI%2F%2BumRKEj6k6%2BYeG9JW1lUK%2BC6k93YrM4f0xvLyUPq4%2FHiNqZTBvM%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:5656b4251b79d3f89bd6ee93b69f34fc:8B0KQMIW5mnqJXj%2FdgK9lwTpMbWPEYfJYeJDkfN5BeJKZ4F4UG%2FeMu%2BwQR0QpkBkG6LaFz3X0ZRz6PrAr9TcMP56TpxIqpT%2Fja0eUWVsnz8%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=7742e3499c9ff0af9094f13633ce0fb9"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=7742e3499c9ff0af9094f13633ce0fb9"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=7742e3499c9ff0af9094f13633ce0fb9" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 01:39:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/health care provider">health care provider</category>
      <category domain="http://securityratty.com/tag/stringent settlement deal">stringent settlement deal</category>
      <category domain="http://securityratty.com/tag/data security rules">data security rules</category>
      <category domain="http://securityratty.com/tag/hipaa">hipaa</category>
      <category domain="http://securityratty.com/tag/federal government">federal government</category>
      <category domain="http://securityratty.com/tag/violations">violations</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=7742e3499c9ff0af9094f13633ce0fb9">Feds finally put teeth into HIPAA enforcement</source>
    </item>
    <item>
      <title><![CDATA[A Few More Words on DLP and Compliance]]></title>
      <link>http://securityratty.com/article/16543edb37f97e4484ed9be5f504d9c6</link>
      <guid>http://securityratty.com/article/16543edb37f97e4484ed9be5f504d9c6</guid>
      <description><![CDATA[Today I was thinking about DLP again :-) (yes, I know that &quot;content monitoring and protection&quot; - CMF - is a better description) Specifically, I was thinking about DLP and compliance. At first, it was...]]></description>
      <content:encoded><![CDATA[<p>Today I was thinking about DLP again :-) (yes, I know that &quot;content monitoring and protection&quot; - <a href="http://securosis.com">CMF</a> - is a better description) Specifically, I was thinking about DLP and compliance. At first, it was truly amazing to me that DLP vendors &quot;under-utilize&quot; compliance in their messaging. In other words, they don't push the &quot;C-word&quot; as strongly as many other security companies. Compliance dog doesn't snarl at you from their front pages and it doesn't bite you in you ass when you read the whitepapers, etc. Sure, it is mentioned there, but, seemingly, as an after-thought.</p>  <p>For example, Reconnex that was recently absorbed by McAfee, touts &quot;information protection&quot; before compliance. Similarly, my friends from <a href="http://www.nextiernetworks.com">nexTier</a> only mention &quot;compliance&quot; on <a href="http://www.nextiernetworks.com/solutions.html">a few pages</a>. Even newly unveiled DLP resource&#160; (<a href="http://www.dlpindepth.org/">DLP In-Depth portal</a>) only contains a little bit&#160; of information on how DLP solutions help with various compliance projects. People tout &quot;data protection&quot;, &quot; data security&quot;, &quot;data governance&quot; (aka &quot;we know big words - bigger than you&quot;) or even &quot;data risk management&quot; (aka &quot;we are confused about what we sell&quot;)</p>  <p>I decide to explore this curious phenomenon. </p>  <p>Initially, I thought that it was <a href="http://chuvakin.blogspot.com/2008/05/reverse-compliance-or-as-proof-of.html">reverse compliance</a> at work? People not wanting to know what content packs up and leaves their network. Then I thought that maybe DLP vendors just aren't &quot;the bandwagon jumping kind&quot; (yeah, right!) Then I thought that they are &quot;beyond compliance&quot; already :-)</p>  <p>But you know what? I actually think that it is something different, much more sinister. It is the ominous <a href="http://chuvakin.blogspot.com/2008/04/rsa-impressions-2-compliance.html">checklist mentality</a> (<a href="http://chuvakin.blogspot.com/2007/02/so-is-security-art.html">here</a> too)!&#160; You know, DLP is newer than&#160; most regulations (PCI DSS, HIPAA, FISMA, etc) and - what a shock! - the documentation for these mandates just doesn't mention DLP (or CMF) by name. Sure, they talk about data protection (e.g. PCI DSS Requirements 3 and 4), but mostly in terms of encryption, access control, <a href="http://www.loglogic.com">logging</a> (of course!).</p>  <p>Also, PCI DSS directly and explicitly says &quot;get a firewall&quot;, &quot;deploy <a href="http://www.loglogic.com">log management</a>&quot;, &quot;get scanned&quot;, &quot;install and update AV&quot; - but where is DLP? Ain't there...</p>  <p>Yes, Virginia, folks who &quot;go by the book&quot; and just &quot;do the minimum&quot; are missing out on the chance to procure DLP while their compliance budgets are still flowing. To me that means that many still don't get the <em>&quot;compliance+&quot; model</em> - <strong>buy for compliance -&gt; use for security, operations, having fun, etc. </strong>Think what <a href="http://www.nextiernetworks.com">a good DLP solution</a>&#160; will do for you in discovering regulated data across the entire organization, blocking those pesky email with SSNs, PHI (hi, HIPAA) and CCs (hi, PCI) as well as solving plenty of other problems ...</p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=PKkyjK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=PKkyjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=xsv29K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=xsv29K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=cyhlHK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=cyhlHK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/366024281" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 10:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dlp">dlp</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/dlp in-depth portal">dlp in-depth portal</category>
      <category domain="http://securityratty.com/tag/procure dlp">procure dlp</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data governance">data governance</category>
      <category domain="http://securityratty.com/tag/pci dss requirements">pci dss requirements</category>
      <category domain="http://securityratty.com/tag/mention dlp">mention dlp</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/366024281/few-more-words-on-dlp-and-compliance.html">A Few More Words on DLP and Compliance</source>
    </item>
    <item>
      <title><![CDATA[One security implementer shares his single sign-on best practices ]]></title>
      <link>http://securityratty.com/article/a38b1d545fd920eb2b8bbeba17835258</link>
      <guid>http://securityratty.com/article/a38b1d545fd920eb2b8bbeba17835258</guid>
      <description><![CDATA[At the recent SSO Summit I moderated a panel of single sign-on implementers. One of them, Christopher Paidhrin HIPAA &amp; IT security officer for ACS Healthcare Solutions, was kind enough to let me share...]]></description>
      <content:encoded><![CDATA[At the recent SSO Summit I moderated a panel of single sign-on implementers. One of them, Christopher Paidhrin HIPAA & IT security officer for ACS Healthcare Solutions, was kind enough to let me share with you his "best practices" list which he calls: "To Do & Not To Do: SSO implementation lessons learned."]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/acs healthcare solutions">acs healthcare solutions</category>
      <category domain="http://securityratty.com/tag/single sign-on implementers">single sign-on implementers</category>
      <category domain="http://securityratty.com/tag/sso implementation lessons">sso implementation lessons</category>
      <category domain="http://securityratty.com/tag/recent sso summit">recent sso summit</category>
      <category domain="http://securityratty.com/tag/christopher paidhrin hipaa">christopher paidhrin hipaa</category>
      <category domain="http://securityratty.com/tag/security officer">security officer</category>
      <category domain="http://securityratty.com/tag/practices">practices</category>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <category domain="http://securityratty.com/tag/panel">panel</category>
      <source url="http://www.networkworld.com/newsletters/dir/2008/081108id2.html?fsrc=rss-security">One security implementer shares his single sign-on best practices </source>
    </item>
    <item>
      <title><![CDATA[Yes Virginia there really are HIPAA police]]></title>
      <link>http://securityratty.com/article/d0bc1624fe44937818753412e25aeeaa</link>
      <guid>http://securityratty.com/article/d0bc1624fe44937818753412e25aeeaa</guid>
      <description><![CDATA[One of the things that I have always not understood about HIPAA is what teeth do these regulations have and who is going to enforce them. There are plenty of firms willing to take your money and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the things that I have always not understood about <a class="zem_slink" rel="wikipedia" title="Health Insurance Portability and Accountability Act" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> is what teeth do these regulations have and who is going to enforce them.&nbsp; There are plenty of firms willing to take your money and rubber stamp you HIPAA compliant, but who is going to say your not HIPAA compliant and why should you care. Finally reading <a href="http://security.blogs.techtarget.com/2008/07/24/hipaa-violations-cost-seattle-health-care-provider/">this article in Security Bytes</a> it looks like the federal government has stepped up to enforce HIPAA and have put some bite behind the bark. Providence Health in Seattle was fined 100k by US Department of Heath and Human Services for losing data containing patients information.&nbsp; </p>&nbsp; <p>I say good for the HHS!&nbsp; A few well publicized fines where people had to pay real money will go further in getting people to take HIPAA seriously than all of the other dog barking and warnings that have taken place to date.&nbsp; The same goes for other regulations and statues on compliance as well.&nbsp; Lets hear about some financial sanctions or penalties around <a class="zem_slink" rel="wikipedia" title="PCI DSS" href="http://en.wikipedia.org/wiki/PCI_DSS">PCI</a> and you will see a drastic rise in compliance there as well.&nbsp; Rules and regulations without enforcement serve no purpose at all and hurt more than they help.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/deane-waldman/shoot-hipaa-the-hippo_b_109753.html">Deane Waldman: Shoot HIPAA the Hippo</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.cbc.ca/health/story/2008/05/05/fhealth-digitalrecords.html">Online health records: Convenience vs. privacy</a></li>

<li class="zemanta-article-ul-li"><a href="http://valleywag.com/368365/hospital-to-fire-13-employees-who-snooped-on-britneys-records">Hospital to fire 13 employees who snooped on Britney's records [Hipaa Hurray]</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10789_3-9879608-57.html?part=rss&amp;subj=news">DHS: U.S. health care records are the target of foreign hackers</a></li></ul></fieldset>

<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/6559114c-ee1e-4ac7-88f1-2c49c262e632/" class="zemanta-pixie-a"><img alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=6559114c-ee1e-4ac7-88f1-2c49c262e632" class="zemanta-pixie-img" style="border: medium none ; float: right;" /></a></div></div>
]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 11:58:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hipaa">hipaa</category>
      <category domain="http://securityratty.com/tag/enforce">enforce</category>
      <category domain="http://securityratty.com/tag/enforce hipaa">enforce hipaa</category>
      <category domain="http://securityratty.com/tag/records hipaa hurray">records hipaa hurray</category>
      <category domain="http://securityratty.com/tag/hipaa compliant">hipaa compliant</category>
      <category domain="http://securityratty.com/tag/health care records">health care records</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <category domain="http://securityratty.com/tag/online health records">online health records</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/yes-virginia-th.html">Yes Virginia there really are HIPAA police</source>
    </item>
    <item>
      <title><![CDATA[Yes Virginia there really are HIPAA police]]></title>
      <link>http://securityratty.com/article/32e9a69dd0414f72767bec1ca3e39a8c</link>
      <guid>http://securityratty.com/article/32e9a69dd0414f72767bec1ca3e39a8c</guid>
      <description><![CDATA[One of the things that I have always not understood about HIPAA is what teeth do these regulations have and who is going to enforce them. There are plenty of firms willing to take your money and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the things that I have always not understood about <a class="zem_slink" rel="wikipedia" title="Health Insurance Portability and Accountability Act" href="http://en.wikipedia.org/wiki/Health_Insurance_Portability_and_Accountability_Act">HIPAA</a> is what teeth do these regulations have and who is going to enforce them.&nbsp; There are plenty of firms willing to take your money and rubber stamp you HIPAA compliant, but who is going to say your not HIPAA compliant and why should you care. Finally reading <a href="http://security.blogs.techtarget.com/2008/07/24/hipaa-violations-cost-seattle-health-care-provider/">this article in Security Bytes</a> it looks like the federal government has stepped up to enforce HIPAA and have put some bite behind the bark. Providence Health in Seattle was fined 100k by US Department of Heath and Human Services for losing data containing patients information.&nbsp; </p>&nbsp; <p>I say good for the HHS!&nbsp; A few well publicized fines where people had to pay real money will go further in getting people to take HIPAA seriously than all of the other dog barking and warnings that have taken place to date.&nbsp; The same goes for other regulations and statues on compliance as well.&nbsp; Lets hear about some financial sanctions or penalties around <a class="zem_slink" rel="wikipedia" title="PCI DSS" href="http://en.wikipedia.org/wiki/PCI_DSS">PCI</a> and you will see a drastic rise in compliance there as well.&nbsp; Rules and regulations without enforcement serve no purpose at all and hurt more than they help.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.huffingtonpost.com/deane-waldman/shoot-hipaa-the-hippo_b_109753.html">Deane Waldman: Shoot HIPAA the Hippo</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.cbc.ca/health/story/2008/05/05/fhealth-digitalrecords.html">Online health records: Convenience vs. privacy</a></li>

<li class="zemanta-article-ul-li"><a href="http://valleywag.com/368365/hospital-to-fire-13-employees-who-snooped-on-britneys-records">Hospital to fire 13 employees who snooped on Britney's records [Hipaa Hurray]</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10789_3-9879608-57.html?part=rss&amp;subj=news">DHS: U.S. health care records are the target of foreign hackers</a></li></ul></fieldset>

<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/6559114c-ee1e-4ac7-88f1-2c49c262e632/" class="zemanta-pixie-a"><img alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=6559114c-ee1e-4ac7-88f1-2c49c262e632" class="zemanta-pixie-img" style="border: medium none ; float: right;" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=XQSA85"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=XQSA85" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=qHfO6J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=qHfO6J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=xF8DFJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=xF8DFJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=LSj7GJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=LSj7GJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=icR7BJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=icR7BJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=l8Ddqj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=l8Ddqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Ka0I2j"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Ka0I2j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/345972583" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 11:01:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hipaa">hipaa</category>
      <category domain="http://securityratty.com/tag/enforce">enforce</category>
      <category domain="http://securityratty.com/tag/enforce hipaa">enforce hipaa</category>
      <category domain="http://securityratty.com/tag/records hipaa hurray">records hipaa hurray</category>
      <category domain="http://securityratty.com/tag/hipaa compliant">hipaa compliant</category>
      <category domain="http://securityratty.com/tag/health care records">health care records</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/regulations">regulations</category>
      <category domain="http://securityratty.com/tag/online health records">online health records</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/345972583/yes-virginia-th.html">Yes Virginia there really are HIPAA police</source>
    </item>
    <item>
      <title><![CDATA[Employee fraud hits Baptist Health in Arkansas]]></title>
      <link>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</link>
      <guid>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/2/08

Organization
Baptist Health

Baptist Health is the largest not-for-profit healthcare organization in Arkansas

Contractor/Consultant/Branch
None...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/baptisthealth.jpg" width="120" align="right" height="274"><font size="2"><b>Date Reported: </b><br>7/2/08<br><br><b>Organization: </b><br><a href="http://www.baptist-health.org/">Baptist Health*</a><br><br><font size="1">*Baptist Health is the largest not-for-profit healthcare organization in Arkansas</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, and reason for coming to Baptist Health"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"LITTLE ROCK (AP) - A North Little Rock woman has been arrested for using financial information from patients at Baptist Health to illegally obtain Wal-Mart gift cards for her own use. The hospital has notified about 1,800 patrons of the ID theft."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wxvt.com/Global/story.asp?S=8609129&amp;nav=menu1344_2">Associated Press via WXVT Channel 15 News</a> <br><a href="http://arkansasmatters.com/content/fulltext/news/?cid=80211">KARK Channel 4 News</a> <br><a href="http://www.nwanews.com/adg/News/230290/">Arkansas Democrat-Gazette</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Toby Manthey, Arkansas Democrat-Gazette<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Baptist Health has sent letters warning about 1,800 patients that the hospital system’s records may have been breached<br><span style="font-style: italic;">[Evan] Uh, "may have been breached"?!</span><br><br>The notification came after the arrest of a Baptist Health employee at a Wal-Mart store on 25 counts of financial identity fraud.<br><span style="font-style: italic;">[Evan] Wouldn't life be grand if we could trust our employees?&nbsp; Maybe, I suppose.</span><br><br>The letters, mailed last week, follow the firing of the woman in early June<br><br>North Little Rock police say Tamara Hill, 30, of that city worked at Baptist Health Medical Center-North Little Rock in the emergency department.<br><br>Hill, an admissions clerk, was arrested May 30 at the Wal-Mart<br><br>Ebony Flowers, 25, also of North Little Rock, was arrested at the store the same day on three counts of identity fraud<br><br>Flowers was listed in a police report as a janitor for the North Little Rock School District<br><span style="font-style: italic;">[Evan] Key word is "was".</span><br><br>Baptist Health recorded more than 950,000 patient visits systemwide in 2007, a number that includes repeat visits.<br><br>Mark Lowman, spokesman for the Little Rock-based Baptist Health system, confirmed that the system fired the employee after notification of the arrest.<br><br>Police reports say the women used a victim’s personal information to obtain temporary Wal-Mart "account authorization numbers" - credit cards, essentially - used to buy Wal-Mart gift cards.<br><br>The victim reported to police that he had not authorized the transactions<br><br>the same victim confirmed he was a Baptist Health patient<br><br>He expressed appreciation of the handling of the case by the system and by the North Little Rock police. <br><br>Among the items found during a search connected with the arrest of Hill was personal information for 24 other people, including "screen shots" - printouts showing the exact appearance of the images on a computer screen - that showed victims’ personal information.<br><span style="font-style: italic;">[Evan] This seems like confirmation that "may have been breached" is not all that accurate.</span><br><br>Also found were four Wal-Mart gift cards and $ 1,490 in cash<br><br>Police found a small bag of marijuana on Flowers, according to the reports. In a search connected with her arrest, they also discovered a. 25-caliber magazine with six bullets, as well as a receipt for four of the gift cards and information on three-identity theft victims.<br><span style="font-style: italic;">[Evan] A thug.</span><br><br>The U. S. Secret Service is helping with the investigation. <br><br>"Due to a breach of our information systems security policies, there is a possibility that some personal information, such as your name, address, date of birth, Social Security number, and reason for coming to Baptist Health, was accessed by an unauthorized person."<br><span style="font-style: italic;">[Evan] This is from the letter to the victims.</span><br><br>No information in the patient’s "medical records" and no information about the patient’s diagnosis or prognosis was accessed<br><br>while no "medical record" information was accessed, the letter mentioned the patient’s "reason for coming" to the system possibly was accessed<br><br>Lowman said a reason stated by a patient using the system isn’t considered medical information because the reason is a layman’s explanation, not one from a medical professional.<br><span style="font-style: italic;">[Evan] This is Mark Lowman, spokesman for the Little Rock-based Baptist Health system</span><br><br>He said the breach wouldn’t violate the Health Insurance Portability and Accountability Act, or HIPAA. <br><br>But Pam Dixon, executive director of the San Diego-based World Privacy Forum, a privacy advocacy group, thinks all the information mentioned in the letter falls under HIPAA.<br><br>"It doesn’t matter that [it’s not ] a prognosis or diagnosis," she said. <br><span style="font-style: italic;">[Evan] Splitting hairs.&nbsp; The bottom line is that confidential personal information was stolen and there are victims.&nbsp; Whether or not it is a HIPAA violation seems somewhat irrelevant.</span><br><br>Dixon found the system’s letter lacking in several respects, such as clarifying the exact meaning of a "reason for coming to Baptist Health." The letter also should have mentioned when and for how long the breach occurred, she said.<br><br>"Almost all breach letters have that," Dixon added.<br><span style="font-style: italic;">[Evan] Almost all breach letters have what?&nbsp; A mention about for how long the breach occurred?&nbsp; I must be reading some of the wrong breach letters because it seems to me that this information is 50/50 at best.&nbsp; Also missing is the "we have no reason to believe that the information will be misused", but this one doesn't fit does it?</span><br><br>Dixon said Baptist Health should have offered in the letter to set up free credit monitoring for victims.<br><span style="font-style: italic;">[Evan] Why?&nbsp; One year (or two) of credit monitoring is almost useless.&nbsp; Credit monitoring alerts a victim after fraud has already occurred and one year (or two) of monitoring is too limited for information that has a much longer lifespan.&nbsp; I guess credit monitoring would be better than nothing, but not by much.</span><br><br>Lowman said the health system continually conducts audits to know which staff members are accessing what information, and whether or not the access is appropriate.<br><span style="font-style: italic;">[Evan] Good!</span><br><br>"We’re always looking to provide better audits and better oversight of private, confidential and protected information," Lowman said.<br><span style="font-style: italic;">[Evan] And Good!</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Preventing and detecting employee fraud has always been a challenge.&nbsp; This doesn't mean we give up though.&nbsp; We have some tools at our disposal such as employee background checks, role-based access control, segregation of duties, and job rotation to name a few.<br><br>I don't think that these two crooks are anything more than common criminals.&nbsp; The fact of the matter is that identity theft and fraud are very easy crimes to commit and require very little skill. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/10/baptisthealth.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 20:00:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/confidential personal information">confidential personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/baptist health system">baptist health system</category>
      <category domain="http://securityratty.com/tag/health system">health system</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/victims personal information">victims personal information</category>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/baptist health">baptist health</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <source url="http://breachblog.com/2008/07/10/baptisthealth.aspx">Employee fraud hits Baptist Health in Arkansas</source>
    </item>
    <item>
      <title><![CDATA[You Are "A Security Idiot" If ...]]></title>
      <link>http://securityratty.com/article/c84adde9760f33765fd8c0a9d17245b7</link>
      <guid>http://securityratty.com/article/c84adde9760f33765fd8c0a9d17245b7</guid>
      <description><![CDATA[you

Misspell both HIPAA and SOX (how the f does one misspell SOX
Confuse &quot; risks &quot; and &quot; threats
Think that &quot; Trojan is a vulnerability &quot; AND &quot; DoS is a vulnerability

Quote &quot; Insiders are 80% &quot;...]]></description>
      <content:encoded><![CDATA[... you:<br /><ol><li>Misspell <span style="font-weight: bold;">both </span>HIPAA and SOX (how the f does one misspell SOX?)</li><li>Confuse "<span style="font-weight: bold;">risks</span>" and "<span style="font-weight: bold;">threats</span>"</li><li>Think that "<span style="font-weight: bold;">Trojan is a vulnerability</span>" AND "<span style="font-weight: bold;">DoS is a vulnerability</span>"<br /></li><li>Quote "<span style="font-weight: bold;">Insiders are 80%</span>" without thinking for one darn second</li><li>Think that a loss of "<span style="font-weight: bold;">$20 million</span> is catastrophic to any company"</li><li>Talk about "<span style="font-weight: bold;">NIST compliance</span>"<br /></li></ol>Please add your faves to the list and we can create an official list to be used to expose fake experts.  If you think that nobody in our industry is that stupid ... think again. F*ck!<br /><br /><span style="font-style: italic;">To be explained later :-)</span><span style="font-style: italic;"><br /></span><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=efjvvI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=efjvvI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jKxxQI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jKxxQI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=wXHfAI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=wXHfAI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/320696521" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 06:26:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/misspell sox">misspell sox</category>
      <category domain="http://securityratty.com/tag/sox">sox</category>
      <category domain="http://securityratty.com/tag/expose fake experts">expose fake experts</category>
      <category domain="http://securityratty.com/tag/official list">official list</category>
      <category domain="http://securityratty.com/tag/misspell">misspell</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/nist compliance">nist compliance</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/fck">fck</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/320696521/you-are-security-idiot-if.html">You Are "A Security Idiot" If ...</source>
    </item>
    <item>
      <title><![CDATA[Defining "Compliance"]]></title>
      <link>http://securityratty.com/article/14196fe845b823a5c3e6afe7dd3aa467</link>
      <guid>http://securityratty.com/article/14196fe845b823a5c3e6afe7dd3aa467</guid>
      <description><![CDATA[As part of the RSA Compliance Solutions team I meet with companies all over the world to discuss their security challenges and priorities. Inevitably I spend much of my time discussing ... you guessed...]]></description>
      <content:encoded><![CDATA[As part of the RSA Compliance Solutions team I meet with companies all over the world to discuss their security challenges and priorities.  Inevitably I spend much of my time discussing ... you guessed it ... compliance.  
<P>
It is eye-opening to see how differently our customers and partners, as well as folks within RSA, define compliance.  From what I've seen, most will immediately gravitate towards the notion of meeting the stated or implied security requirements within governmental mandates, such as <a href="http://www.rsa.com/glossary/default.asp?id=1047">Sarbanes-Oxley</a> and <a href="http://www.rsa.com/glossary/default.asp?id=1024">HIPAA</a>.  In addition, "compliance" certainly conjures up images of the <a href="http://www.rsa.com/glossary/default.asp?id=1093">PCI Data Security Standard</a>, which isn't surprising considering how many organizations these requirements impact.

<B>What we don't tend to see initially is a broader view of compliance... </b>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/define compliance">define compliance</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/security challenges">security challenges</category>
      <category domain="http://securityratty.com/tag/requirements impact">requirements impact</category>
      <category domain="http://securityratty.com/tag/broader view">broader view</category>
      <category domain="http://securityratty.com/tag/conjures">conjures</category>
      <category domain="http://securityratty.com/tag/hipaa">hipaa</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1295">Defining "Compliance"</source>
    </item>
  </channel>
</rss>
