Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Friday, August 26, 2016

SMBs Subject to New Fines for HIPAA Compliance Issues

August 26, 2016 - There’s a new warning from the government to small businesses. Safeguard your company, or else.

The US Health and Human Services Office for Civil Rights (OCR) said they would investigate small security breaches. Normally they investigate breaches affecting more than 500 people, but now they’re investigating breaches affecting less than that number.

"The news from The US Health and Human Services Office for Civil Rights should be a wakeup call to small business," Ebba Blitz, CEO of Alertsec. "If the OCR uncovers widespread HIPAA compliance issues, that could mean small companies are at risk for new fines."

This is important because smaller companies who need encryption don’t have to pay for an IT department or cumbersome software. They can get enterprise-level encryption software that would be unavailable otherwise.  This is crucial to small businesses who are required by HIPAA to encrypt their laptops.

"According to the Ponemon Institute more than half of all data breaches emanate from a lost or stolen unencrypted laptop," Ebba said. "When we work and live with sensitive information at our fingertips this information needs to be safe. Not only is a breach damaging to patients and clients, ultimately it will affect you brand and revenue. Protecting health information will soon be an issue that will move from the IT departments to the boards."

OCR listed that factors will spark an investigation:
•         the size of the breach;
•         whether theft of or improper disposal of unencrypted Protected Health Information (PHI) occurred;
•         whether unwanted intrusions to IT systems (for example, by hacking) occurred;
•         the amount, nature and sensitivity of the PHI involved; or
•         cases where an entity has numerous breaches involving similar issues.

This makes encryption more important than ever before. If a laptop is lost or stolen (more than 1 million laptops are lost in the USA every year, according to Ponemon) the information can be hacked. However, if the computer is encrypted it can’t.

Friday, October 18, 2013

GAO: Centers for Medicare and Medicaid Services Needs to Pursue a Solution for Removing Social Security Numbers from Cards

The GAO recommends that CMS initiate an IT project to develop a solution for SSN removal and incorporate such a project into plans for ongoing IT modernization initiatives. HHS agreed with GAO's recommendations, if certain constraints were addressed. However, GAO maintains that its recommendations are warranted as originally stated.

What they really need to do is de-identify and anonymize data.

Of course, we have books that will help solve the problem.

Guide to the De-Identification of Personal Health Information 

In this book Khaled El Emam, the founder and CEO of Privacy Analytics, Inc., offers compelling practical and legal reasons why de-identification should be one of the main approaches to protecting patients’ privacy, this book outlines a proven, risk-based methodology for the de-identification of sensitive health information. It situates and contextualizes this risk-based methodology and provides a general overview of its steps. The book supplies a detailed case for why de-identification is important as well as best practices to help you pin point when it is necessary to apply de-identification in the disclosure of personal health information.

The Complete Book of Data Anonymization: From Planning to Implementation

Data anonymization provides a systematic and integrated approach to privacy protection that goes far beyond simple data-masking or network security from external or internal theft. In book, Balaji Raghunathan of Infosys Ltd. discusses the analysis, planning, set-up, and governance, this timely manual illuminates the entire process of adapting and implementing anonymization tools and programs to increase the success of privacy protection in vulnerable organizations. Providing a 360 degree view of data privacy protection, it details data anonymization patterns, automation/tool capabilities, and the key factors for success in disguising the person behind the data.

Wednesday, October 9, 2013

Jay Trinckes to Speak at Financial, Operations Management/Information Technology Conference

Jay Trinckes will speak at the Financial, Operations Management/Information Technology Conference, November 12-14, 2013.

His topic is “Avoid Penalties: Ensuring Compliance with the September23, 2103 HIPAA Privacy and Security Omnibus Rule.”

Jay is the author of The Definitive Guide to Complying with the HIPAA/HITECH Privacy and Security Rules and The Executive MBA in Information Security.