Posts Tagged ‘Information Security’
Wednesday, January 10th, 2007
Today I received notice that the Centers for Medicare & Medicaid Services (CMS) just issued a new publication, “Security Guidance for Remote Use‚Äù which is actually dated 12/28/2006.
“This document is intended to provide HIPAA covered entities with general information on the risks and possible mitigation strategies for remote use of Electronic Protected Health Information (EPHI).”
(more…)
Tags:awareness and training, CMS, encryption, government, HIPAA, Information Security, IT compliance, patient privacy, policies and procedures, privacy
Posted in Information Security, Laws & Regulations, Privacy and Compliance | No Comments »
Wednesday, January 10th, 2007
On January 4th the 110th U.S. congress convened for the first time, and they did not waste any time introducing many new bills. 12 of them have privacy impacts. You can find more information about each of these at the THOMAS (Library of Congress) site. However, as of today (1/10/2007), the full texts for most of these bills are not yet available online.
From the Senate:
(more…)
Tags:awareness and training, data protection law, education, employment, government, Information Security, internet, IT compliance, privacy, social security numbers, surveillance, telecommunications, travel
Posted in government, Laws & Regulations, Privacy and Compliance | 2 Comments »
Monday, January 8th, 2007
Tags:awareness and training, government, identity fraud, identity theft, Information Security, IT compliance, privacy, Swift
Posted in identity theft, Privacy and Compliance | 1 Comment »
Friday, January 5th, 2007
Today I read a story appearing in the Des Moines Register, “Computer breach at UNI exposes some personal data” about a breach that occurred at one my alma maters, the University of Northern Iowa.
It bothered me the non-chalant way in which a computer breach was described as being “a pretty typical breach” by the Assoc. VP for Information Technology.
It makes it sound as though such breaches are to be expected. If appropriate safeguards are in place, though, these types of breaches should not occur.
(more…)
Tags:awareness and training, computer breach, Information Security, IT compliance, privacy, privacy breach
Posted in Information Security, Privacy Incidents | No Comments »
Thursday, January 4th, 2007
Yesterday (January 3) Michigan’s governor, Jennifer M. Granholm, signed a new identity theft and breach notification law, SB 309.
“Today’s technology has taken commerce and communication to new heights, but it also puts citizens at additional risk of identity theft as ever-increasing amounts of personal information are stored and transmitted electronically,” Granholm said. “While I am pleased to sign legislation that provides critical information to consumers, we must do more to provide our citizens with the tools they need to truly protect themselves.”
(more…)
Tags:awareness and training, breach notice law, identity theft, Information Security, IT compliance, Michigan, privacy, privacy breach
Posted in Laws & Regulations, Privacy and Compliance | 2 Comments »
Wednesday, January 3rd, 2007
On December 19, 2006, a computer systems administrator, Andy Lin, for Medco Health Solutions, Inc. was indicted by a federal grand jury in the U.S. District Court for the District of New Jersey for attempting to disable his employer’s corporate computer servers through the use of a concealed malicious software program.
Today (January 3) Lin is being arraigned. If convicted, he could get 20 years in prison and a fine of $500,000; $250,000 for each of the two charges.
(more…)
Tags:awareness and training, Information Security, insider threat, IT compliance, logic bomb, privacy, privacy breach
Posted in Information Security | No Comments »
Tuesday, January 2nd, 2007
I ran across an interesting news report,”Nissan data leak puts 5 million at risk”
I was surprised I did not see this report on any of U.S. news sites. The report is very vague. It just indicates a “leak” occurred between May 2003 and February 2004. A small excerpt:
(more…)
Tags:awareness and training, breach response, Information Security, IT compliance, NISSAN, privacy, privacy breach
Posted in Privacy and Compliance, Privacy Incidents | No Comments »
Friday, December 29th, 2006
A great article was published on Law.com today written by Ryan Sulkin, “First Line of Defense Against Data Security Breaches: Employees.”
There are several points made that I hope business leaders read and take to heart.
(more…)
Tags:awareness and training, FFIEC, FTC, GLBA, government, HIPAA, Information Security, IT compliance, PCI, privacy
Posted in Information Security, Laws & Regulations, Privacy and Compliance | No Comments »
Thursday, December 28th, 2006
The Pittsburgh Post-Gazette ran an interesting story today, “Spread of records stirs fears of privacy erosion.”
Basically this describes the trials and tribulations of a woman was denied disability benefits from her insurer following a car accident because of notes made by her psychologist. Reportedly the psychologist notes were intermingled with her general medical records.
(more…)
Tags:awareness and training, government, HIPAA, Information Security, IT compliance, patient privacy, privacy
Posted in Laws & Regulations, Privacy and Compliance, Privacy Incidents | No Comments »