The U.S. Health Insurance Portability and Accountability Act (HIPAA) has required compliance from covered entities (CEs) since 2003. The Department of Health and Human Services (HHS) is the Federal agency with regulatory oversight for compliance; with the Office of Civil Rights (OCR) responsible for Privacy Rule enforcement and the Centers for Medicare and Medicaid Services (CMS) responsible for Security Rule enforcement. Why two different offices to perform enforcement activities? No good reason was ever given.
I was just out looking on the HHS’s HIPAA compliance and enforcement site.
On May 12, 2008, they provided some interesting statistics from their enforcement activities from the past 5 years. Looks like they love Excel and the graphing capabilities! 🙂 I want to share some of the statistics with you…
HIPAA Complaints And Associated Resolutions Since 2003
May 22nd, 200845 U.S. Breach Notice Laws…And Still Counting
May 21st, 2008Yesterday I posted a link to my quick reference list of breach notice laws.
I created that document at the beginning of this month, and Doug Markiewicz told me today in a comment to that post that there are two additional laws, one signed since I created my most recent list; thanks Doug!
43 U.S. Breach Notice Laws…And Counting
May 20th, 2008There are currently 43 breach response laws in the U.S.; this includes the District of Columbia and Puerto Rico.
SEC Regulation S-P Proposals To Improve The Security Of Customer Information Within Brokerage Shops
May 16th, 2008Do you work for a brokage house, have a subsidiary that is a brokerage house, or do any type of work with a brokerage house? If so, then you should be aware of the Securities and Exchange Commission (SEC) proposed changes to Regulation S-P in March of this year.
In general, the proposed amendments to Regulation S-P…
CAN-SPAM: Record Judgment Along With Updated Rules
May 15th, 2008I was at the Secure360 conference (a fabulous event, btw) this week, and I’m just getting to an important current topic: CAN-SPAM.
On Monday (5/12) the FTC announced an update to the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM) law.
Addressing the Insider Threat
May 13th, 2008My May issue of “IT Compliance in Realtime” is now available!
The first article I have within this issue is, “Addressing the Insider Threat.”
Here is the unformatted text of the article; download the PDF to get the much nicer, prettier, formatted version…
At the Secure 360 Conference
May 12th, 2008Tomorrow and Wednesday I’m doing some sessions at the Secure 360 conference in St. Paul, Minnesota. I’m really looking forward to also seeing the other sessions while here (yes, I’ve arrived and getting some work done in my room)!
Happy Mother’s Day!
May 11th, 2008Happy Mother’s Day! It was a gorgeous day here in central Iowa! I did business work all morning, but then took off at 3:00pm, went out with my family to a restaurant we all love, and then did some gardening; tomatoes, turnips, watermelon, peppers, pumpkins, sunflowers and sweet corn this year…plus a few pretty assorted annuals! The fruit trees, red buds, crab apple trees, Russian olives, and wigelias are all in full bloom right now…and the scent of the breeze is spectacular! 🙂
In honor of Mother’s Day I quickly scanned the news and blog sites to see what types of interesting information I could find relating to mother’s day and privacy. I didn’t find much, but here is a bit of what I found…
A Couple Of Little Known HIPAA Facts
May 8th, 2008Last week I was contacted by Corey Goodman, a reporter for HCPro, about a story he is doing that sounds like it will be quite interesting! He is collecting examples and anecdotes about “little know HIPAA facts” and asked me to contribute some for his article.
I anticipate that he will be cutting the couple of little known facts I provided to him down quite a bit, so I wanted to provide them here not only as a future reference for myself, but also for those of you who may be interested!