<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Laptop Security Blog &#187; Health Security</title>
	<atom:link href="http://blog.absolute.com/category/health-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.absolute.com</link>
	<description>Laptop Security blog by Absolute Software</description>
	<lastBuildDate>Fri, 20 Nov 2009 21:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Blue Cross Worker Has Laptop Stolen After Breaking Protocol</title>
		<link>http://blog.absolute.com/blue-cross-worker-has-laptop-stolen-after-breaking-protocol/</link>
		<comments>http://blog.absolute.com/blue-cross-worker-has-laptop-stolen-after-breaking-protocol/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 16:00:54 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Absolute Software]]></category>
		<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Laptop Security]]></category>
		<category><![CDATA[Laptop Tracking]]></category>
		<category><![CDATA[LoJack for Laptops]]></category>
		<category><![CDATA[healthcare breach]]></category>
		<category><![CDATA[medical breach]]></category>
		<category><![CDATA[medical privacy]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1764</guid>
		<description><![CDATA[A Blue Cross and Blue Shield Association employee broke protocol by transferring the names, addresses, Social Security numbers and provider identification numbers of about 800,000 doctors to his personal laptop.
Unfortunately, his computer was stolen from his car this past August but, as of yet, there haven’t been any signs of identity theft.
The affected physicians have [...]]]></description>
			<content:encoded><![CDATA[<p>A Blue Cross and Blue Shield Association employee broke protocol by transferring the names, addresses, Social Security numbers and provider identification numbers of about 800,000 doctors to his personal laptop.</p>
<p>Unfortunately, his computer was stolen from his car this past August but, as of yet, there haven’t been any signs of identity theft.</p>
<p>The affected physicians have been informed and, thankfully, no patient information was included in the database.</p>
<p>A representative for the health insurance company was quoted in the <em><a href="http://www.chicagotribune.com/business/chi-thu-notebook-1015-oct15,0,4209340.story">Chicago Tribune</a></em> as saying: &#8220;At this point, we have no evidence that the data was misused.  We think this was a random criminal act. Regardless, we take these kinds of breaches extremely seriously and so we are alerting all doctors in the database.&#8221;</p>
<p>In an attempt to offset any negative consequences associated with the theft of the laptop, the Blue Cross association is offering crediting monitoring services to the individuals whose Social Security information was exposed.</p>
<p>It goes without saying that this is really a worst-case scenario, since so many could be affected by this breach and the laptop hasn’t been recovered.  This is an unfortunate example of how the mistakes of a single person could after thousands of people. </p>
<p>In a situation like this, using a program like <a href="http://www.absolute.com/products/computrace-complete">Computrace</a> would be helpful since sensitive data can be deleted remotely and the Theft Recovery Team will work with local police to try to find the stolen laptop &#8211; and the thief who stole it. And once the they have the laptop back, Computrace can be used to help determine if files were accessed post-theft. While it would still be important to be vigilant for signs of identity theft, the risk would be considerably lower.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/blue-cross-worker-has-laptop-stolen-after-breaking-protocol/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Medical Students Leak Patient Information on the Internet</title>
		<link>http://blog.absolute.com/medical-students-leak-patient-information-on-the-internet/</link>
		<comments>http://blog.absolute.com/medical-students-leak-patient-information-on-the-internet/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 16:00:17 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[medical privacy]]></category>
		<category><![CDATA[medical security leak]]></category>
		<category><![CDATA[patient confidentiality]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1707</guid>
		<description><![CDATA[There are many types of information that people don’t want to share with the world but someone’s personal medical history is probably at the top of that list.  The reasons we visit the doctor’s office can vary from mundane to downright embarrassing (or even scary), so it’s no surprise that many patients really depend on [...]]]></description>
			<content:encoded><![CDATA[<p>There are many types of information that people don’t want to share with the world but someone’s personal medical history is probably at the top of that list.  The reasons we visit the doctor’s office can vary from mundane to downright embarrassing (or even scary), so it’s no surprise that many patients really depend on the rules surrounding confidentiality to protect this very private information.<a href="http://blog.absolute.com/uploads/doctor.jpg"><img style="border-bottom: 0px; border-left: 0px; display: inline; margin-left: 0px; border-top: 0px; margin-right: 0px; border-right: 0px" title="doctor" src="http://blog.absolute.com/uploads/doctor_thumb.jpg" border="0" alt="doctor" width="184" height="244" align="right" /></a></p>
<p>Unfortunately, medical students may not realize the importance of patient privacy, which is evidenced by the fact that we’ve started seeing disclosures more and more through the use of social networking tools and modern technology.  For example, one surgeon found the fact that his patient had the words “hot rod” tattooed on his genitals so funny that he took a picture and shared it with his colleagues. </p>
<p>As <a href="http://www.cnn.com/2009/HEALTH/09/22/medical.students.internet/">CNN reports</a>, 60% of medical schools “have had students post inappropriate or unprofessional information on the Web.”  While most of this information pertained to their own behavior, 13% of them shared content that violated patient privacy.  Incredibly, there were even instances when some students were so descriptive that their patients were identifiable. </p>
<p>Incredibly, only 38% of the affected schools had policies in effect to deal with inappropriate sharing on the internet but, at least, 11% of the remaining schools were working on creating guidelines. </p>
<p>This illustrates the fact that many professions have not had to deal with internet security issues on this level but, while some are trying to actively address the issues, the public is at risk in the meantime. </p>
<p>image: sxu.hu</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/medical-students-leak-patient-information-on-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HITECH Act Strengthens Health Privacy Requirements</title>
		<link>http://blog.absolute.com/hitech-act-strengthens-health-privacy-requirements/</link>
		<comments>http://blog.absolute.com/hitech-act-strengthens-health-privacy-requirements/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 20:37:40 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[hitech act]]></category>
		<category><![CDATA[legislature]]></category>
		<category><![CDATA[regulations]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1399</guid>
		<description><![CDATA[The Health Information Technology for Economic and Clinical Health (HITECH) Act, which was signed into law in February 2009, will come into effect on February 17, 2010. This new Act, in addition to encouraging doctors and hospitals to use electronic health care records systems, changes privacy requirements. The new privacy requirements strengthen those requirements already [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0437092.gif" alt="" width="192" height="192" />The <a href="http://nhcaa.org/eweb/StartPage.aspx"><strong>Health Information Technology for Economic and Clinical Health</strong> (HITECH) </a><a href="http://democrats.science.house.gov/Media/File/Commdocs/HealthIT%20Bill.pdf">Act</a>, which was <a href="http://www.nixonpeabody.com/publications_detail3.asp?ID=2621">signed</a> into law in February 2009, will come into effect on February 17, 2010. This new Act, in addition to encouraging doctors and hospitals to use electronic health care records systems, changes privacy requirements. The new privacy requirements strengthen those requirements already mandated by <a href="http://blog.absolute.com/essential-elements-of-hipaa-compliance/">HIPAA</a>.</p>
<p><strong>Some of the changes that HITECH will mandate, in regards to privacy requirements, include:</strong></p>
<ul>
<li>Definition of Personal Health Information (PHI) expanded</li>
<li>Stronger data breach notification requirements</li>
<li>Increased penalties for HIPAA violations and more aggressive enforcement, including criminal cases</li>
<li>Subjects business associates to civil and criminal penalties for violating HIPAA requirements</li>
<li>Defined guidelines on how to protect PHI</li>
</ul>
<p>In terms of data breaches, HITECH will require that individuals be notified if their PHI has been accessed and that information was unsecured, unencrypted or not deleted from a computer using an a method that meets the standard (such as the Computrace Data Delete feature). The act requires that vendors notify the individual of the breach even if identity theft is not probable, which is a much <strong>stronger requirement than many State notification requirements</strong>.</p>
<p>Though the effective date for HITECH is not until February, 2010, in August of this year the US Department of Health and Human Services (HHS) and the Federal Trade Commission (FTC) will synchronize their respective regulations and issue interim final regulations.</p>
<p>Healthcare organizations will need to address these new HITECH requirements by strengthening their data security measures. Computerworld has put together <a href="http://www.computerworld.com/s/article/9134549/Five_Steps_to_HITECH_Preparedness?taxonomyId=144&amp;pageNumber=2">5 Steps to HITECH Preparedness</a> that&#8217;s very worth the read.</p>
<p><em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/hitech-act-strengthens-health-privacy-requirements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Care Spending Lost to Fraud</title>
		<link>http://blog.absolute.com/health-care-spending-lost-to-fraud/</link>
		<comments>http://blog.absolute.com/health-care-spending-lost-to-fraud/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 15:49:24 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[statistics]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1306</guid>
		<description><![CDATA[The National Health Care Anti-Fraud Association (NHCAA) estimates that 3% of all healthcare spending &#8211; about $68 billion &#8211; is lost to fraud each year in the United States. The FBI / CDC estimate that figure could be as high as 10%, or $226 billion.
In the past, we&#8217;ve talked a great deal about the impact [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0437092.gif" alt="" width="192" height="192" />The <a href="http://nhcaa.org/eweb/StartPage.aspx">National Health Care Anti-Fraud Association</a> (NHCAA) <a href="http://www.nhcaa.org/eweb/DynamicPage.aspx?webcode=anti_fraud_resource_centr&amp;wpscode=TheProblemOfHCFraud">estimates</a> that <strong>3% of all healthcare spending</strong> &#8211; about $68 billion &#8211; <strong>is lost to fraud each year in the United States</strong>. The FBI / CDC estimate that figure could be as high as 10%, or $226 billion.</p>
<p>In the past, we&#8217;ve talked a great deal about the impact that fraud has on businesses and on consumers, including those affected by <a href="http://blog.absolute.com/the-dangers-of-medical-identity-theft/">medical fraud</a>. But we have yet to talk about the cost &#8211; the billions of dollars &#8211; this fraud is costing all of us in other ways.</p>
<blockquote><p>Whether you have employer-sponsored health insurance or you purchase your own insurance policy, health care fraud inevitably translates into higher premiums and out-of-pocket expenses for consumers, as well as reduced benefits or coverage. For employers—private and government alike—health care fraud increases the cost of providing insurance benefits to employees and, in turn, increases the overall cost of doing business.</p></blockquote>
<p>The NHCAA estimated in 2007 that $2.26 trillion was spent on health care and the 4 billion health insurance claims processed in the US. They conservatively estimated that <strong>$68 billion of this was lost to fraud</strong>, quite an astounding figure. The majority of health care fraud was found to be committed by a small number of <strong>dishonest health care providers</strong> submitting false claims to insurers and to public programs. Other types of provider-initiated fraud can be found <a href="http://www.nhcaa.org/eweb/DynamicPage.aspx?webcode=anti_fraud_resource_centr&amp;wpscode=TheProblemOfHCFraud">here</a>.</p>
<p>This abuse of claims can have damaging effects on patients who may find themselves victims of medical identity theft, with their insurance benefits affected by misuse. In addition to providers, organized criminal groups and individuals also perpetrate health care fraud. The report includes examples of <strong>crime rings</strong> that shifted from illegal drug trafficking to medical fraud schemes, resulting in millions of dollars in fraud.</p>
<p>If you want to learn more about health care fraud, <a href="http://www.nhcaa.org/eweb/DynamicPage.aspx?webcode=anti_fraud_resource_centr&amp;wpscode=TheProblemOfHCFraud">read here.</a></p>
<p>Hat tip to <a href="http://ivebeenmugged.typepad.com/my_weblog/2009/04/medical-fraud-statistics.html">I&#8217;ve been mugged</a> ; Via <a href="http://www.dotmed.com/news/story/8192/">dotmed</a> ; <em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/health-care-spending-lost-to-fraud/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Keeping Healthcare Data Secure</title>
		<link>http://blog.absolute.com/keeping-healthcare-data-secure/</link>
		<comments>http://blog.absolute.com/keeping-healthcare-data-secure/#comments</comments>
		<pubDate>Tue, 14 Apr 2009 16:16:37 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[healthcare]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1270</guid>
		<description><![CDATA[Absolute Software has released a list of the Top Five Healthcare Practices for Keeping Data Secure. These best practices will be valuable as healthcare moves forward with technology, particularly since the American Recovery and REinvestment Act (ARRA) was signed in February.

Know the consequences of a data breach
Assess your organization&#8217;s situation
Implement a comprehensive data security plan
Secure [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0437092.gif" alt="" width="192" height="192" />Absolute Software has released a list of the <a href="http://www.absolute.com/company/news-releases-content.asp?CSID=Healthcare-09"><strong>Top Five Healthcare Practices for Keeping Data Secure</strong></a>. These best practices will be valuable as healthcare moves forward with technology, particularly since the American Recovery and REinvestment Act (ARRA) was signed in February.</p>
<ol>
<li>Know the consequences of a data breach</li>
<li>Assess your organization&#8217;s situation</li>
<li>Implement a comprehensive data security plan</li>
<li>Secure data on mobile computers</li>
<li>Create a data breach policy</li>
</ol>
<p>Learn more about these 5 steps and ARRA <a href="http://www.absolute.com/company/news-releases-content.asp?CSID=Healthcare-09">here</a>.</p>
<p>Considering the most recent hospital data breach in Miami has <a href="http://www.miamiherald.com/business/personal-finance/story/960623.html">affected 200,000</a>, and that data breaches in healthcare data breaches are <a href="http://blog.absolute.com/average-cost-per-breached-record-rises-to-202/">more costly</a> than breaches in other sectors, it&#8217;s a good idea to take all the steps you can to protect the data of your patients, clients and employees in this sector. A data breach is costly in any sector, but it&#8217;s important you understand how a data breach can impact, and be prevented, in <em>yours.</em></p>
<p><em>Image: clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/keeping-healthcare-data-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Breaches in the Healthcare Sector</title>
		<link>http://blog.absolute.com/data-breaches-in-the-healthcare-sector/</link>
		<comments>http://blog.absolute.com/data-breaches-in-the-healthcare-sector/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 16:47:16 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[report]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1153</guid>
		<description><![CDATA[Dartmouth College&#8217;s Center for Digital Strategies recently released a study about &#8220;Data Hemorrhages in the Health-Care Sector&#8220;. The study examines the consequences of data breaches, from privacy violations to medical fraud to identity theft (financial and medical). The analysis demonstrates substantial vulnerability for the healthcare sector.
The report indicates that data breaches are coming from all [...]]]></description>
			<content:encoded><![CDATA[<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/j0437092.gif" alt="" width="192" height="192" />Dartmouth College&#8217;s Center for Digital Strategies recently released a study about &#8220;<a href="http://mba.tuck.dartmouth.edu/digital/Research/ResearchProjects/ResearchInadvertent.html"><strong>Data Hemorrhages in the Health-Care Sector</strong></a>&#8220;. The study examines the consequences of data breaches, from privacy violations to medical fraud to identity theft (financial and medical). The analysis demonstrates substantial vulnerability for the healthcare sector.</p>
<p>The report indicates that data breaches are coming from all sides of the healthcare sector: hospitals, physicians, laboratories, and outsourced service providers. The paper looks in particular at <strong>medical identity theft,</strong> a dangerous outcome we&#8217;ve <a href="http://blog.absolute.com/the-dangers-of-medical-identity-theft/">discussed previously.</a></p>
<p>The report pays special attention to inadvertent <strong>data losses over peer-to-peer (P2P) networks.</strong> The analysis uncovered thousands of files containing medical information on publicly available file sharing networks. That data may have gotten there inadvertently &#8211; from malware or from a bad filesystem that had confidential files with music files.</p>
<blockquote><p>&#8220;We found multiple files from major health-care firms that contained private employee and patient information for literally tens of thousands of individuals, including addresses, Social Security Numbers, birth dates, and treatment billing information. Disturbingly, we also found private patient information including medical diagnoses and psychiatric evaluations.&#8221;</p></blockquote>
<p>The report indicates that the risk of patient information disclosures on P2P networks is higher than if a laptop or data device is lost. The report found that tracking and stopping medical data breaches is more complex given the <strong>fragmented nature of the US healthcare system</strong>.</p>
<p>This report reminds us of the importance of a strong <strong>data access policy</strong>. Who can access what data and where &#8211; can data be transfered to other devices? <a href="http://www.absolute.com/solutions-secure-asset-tracking.asp">Computrace</a> can help in that, with our Secure Asset Tracking® telling you where your devices are and what software/hardware is installed on them. Like with other aspects of data security, choose a layered process containing the right technology, processes and policies to help protect confidential information.</p>
<p>Hat tip to the <a href="http://blog.privcom.gc.ca/index.php/2009/03/04/%E2%80%9Ctrust-meit%E2%80%99s-bleeding%E2%80%9D/">privacy commissioner</a>, <a href="http://www.scmagazineus.com/Medical-data-leakage-rampant-on-P2P-networks/article/127216">SC Magazine</a> ; <em>Image: Clipart</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/data-breaches-in-the-healthcare-sector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HITRUST Releases Security Framework</title>
		<link>http://blog.absolute.com/hitrust-releases-security-framework/</link>
		<comments>http://blog.absolute.com/hitrust-releases-security-framework/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 16:53:01 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Surveys & Reports]]></category>
		<category><![CDATA[hitrust]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[security standards]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=1131</guid>
		<description><![CDATA[A group of over 60 companies in the health care industry have came together last year to create a set of security &#38; privacy best practices that will go above and beyond those laid out in the Health Insurance Portability and Accountability Act (HIPAA). The Health Information Trust Alliance (HITRUST) consortium this week released a [...]]]></description>
			<content:encoded><![CDATA[<p>A group of over 60 <a href="http://www.hitrustalliance.org/council.php">companies</a> in the health care industry have came together <a href="http://blog.absolute.com/hitrust-plans-health-security-framework/">last year</a> to create a set of <strong>security &amp; privacy best practices</strong> that will go above and beyond those laid out in the <img style="margin: 5px; float: right;" src="http://blog.absolute.com/wp/wp-content/uploads/logo03.gif" alt="" width="170" height="75" />Health Insurance Portability and Accountability Act (HIPAA). The <strong><a href="http://www.hitrustalliance.org/">Health Information Trust Alliance</a></strong> (HITRUST) consortium this week <a href="http://www.hitrustalliance.net/news/index.php?a=24">released</a> a <a href="http://www.hitrustalliance.net/csf/">Common Security Framework</a> (CSF) &#8220;for industry in commitment to greater electronic health information protection and growing regulatory compliance.&#8221;</p>
<blockquote><p>“Until now, the lack of widely accepted information security standards has kept many providers on the health care IT sidelines, and has been a source of apprehension for many patients when it came to electronically sharing their medical information&#8230; the HITRUST framework should help accelerate the adoption of technologies that will dramatically improve the safety and efficiency of America’s health care system.&#8221; &#8211; <em>Randall N. Spratt, Chief Information Officer and Executive Vice President, McKesson</em></p></blockquote>
<p><a href="http://www.hitrustalliance.net/csf/"><img style="margin: 5px; float: left" src="http://blog.absolute.com/wp/wp-content/uploads/csf-brochure-2009-thumb1.jpg" alt="" width="107" height="137" /></a>The CSF is a certifiable framework that will provide organizations with <strong>structure and clarity related to information security for the healthcare industry</strong>, something more and more important as health information moves online and as data becomes more portable.</p>
<p>The framework is based upon <strong>recognized standards </strong>such as COBIT, NIST and ISO 270001. The framework is meant to scale according to the type, size and complexity of the organization and follows a <strong>risk-based approach </strong>that can evolve based on needs and changes in the industry and regulatory environment.</p>
<p>The stimulus bill that was <a href="http://www.scmagazineus.com/Stimulusbillincludesprotectionfordigitalhealthcarerecords/article/126694/">passed</a> in January in the U.S. called for the <strong>computerization of health care records within 5 years.</strong> The legislation contained stringent privacy and security controls above and beyond HIPAA, just like the new HITRUST CSF does.</p>
<p>Via <a href="http://www.scmagazineus.com/Group-unveils-first-of-its-kind-standard-to-secure-patient-data/article/128168/">SC Magazine</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/hitrust-releases-security-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare Compliance Courses from HCCS</title>
		<link>http://blog.absolute.com/healthcare-compliance-courses-from-hccs/</link>
		<comments>http://blog.absolute.com/healthcare-compliance-courses-from-hccs/#comments</comments>
		<pubDate>Fri, 12 Sep 2008 18:47:32 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Security Policy]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[courses]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[hipaa]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=588</guid>
		<description><![CDATA[Health Care Compliance Strategies (HCCS) announced this week three new versions of its online compliance courses.
HCCS is a provider of online healthcare compliance and competency training. The three courses they provide are:

HCCS Professional Compliance
Corporate Compliance
HIPAA for Health Plans

The courses are aimed at physicians, billing staff and other employees. They teach fraud awareness, coding and documentation, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hccs.com/">Health Care Compliance Strategies</a> (HCCS) <a href="http://www.newswiretoday.com/news/39533/">announced</a> this week three new versions of its <strong>online compliance courses.</strong></p>
<p>HCCS is a provider of online healthcare compliance and competency training. The three courses they provide are:</p>
<ul>
<li>HCCS Professional Compliance</li>
<li>Corporate Compliance</li>
<li>HIPAA for Health Plans</li>
</ul>
<p>The courses are aimed at physicians, billing staff and other employees. They teach fraud awareness, coding and documentation, risk areas, how to build a compliance program, provider relationships, HIPAA awareness, electronic transactions and enforcement.</p>
<p>The courses change whenever rules, regulations, laws or other information is updated. Given that employees form one of the largest &#8220;issues&#8221; in any security program, online and interactive courses are a great way to enhance your training program. Also visit <a href="http://www.absolute.com/markets/healthcare.asp">Absolute Software&#8217;s website</a> to learn how we can help with healthcare computer security.</p>
<p>&#8212;-</p>
<p><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/header-art1.gif" alt="" width="158" height="64" /><br />
And in other news, <a href="http://www.absolute.com/company/news-releases-content.asp?CSID=asis">Absolute Software</a> has added another conference to its schedule &#8211; the <a href="http://www.asisonline.org/education/programs/noframe/2008seminar/default.html">ASIS 2008 conference</a> in Atlanta, Georgia.</p>
<p><strong>Meet Absolute at the Booth</strong></p>
<p>Location: Booth 2425<br />
Dates: Monday &#8211; Wednesday, September 15-17, 2008<br />
Time: 9:00 am &#8211; 4:30 pm</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/healthcare-compliance-courses-from-hccs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HITRUST plans Health Security Framework</title>
		<link>http://blog.absolute.com/hitrust-plans-health-security-framework/</link>
		<comments>http://blog.absolute.com/hitrust-plans-health-security-framework/#comments</comments>
		<pubDate>Mon, 25 Aug 2008 16:00:51 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=518</guid>
		<description><![CDATA[A group of over 60 voting companies in the health care industry have come together to create a set of security &#38; privacy best practices that will go above and beyond those laid out in the Health Insurance Portability and Accountability Act (HIPAA). The new consortium that will create these best practices is called the [...]]]></description>
			<content:encoded><![CDATA[<p>A group of over 60 voting <a href="http://www.hitrustalliance.org/council.php">companies</a> in the health care industry have come together to create a set of <strong>security &amp; privacy best practices</strong> that will go above and beyond those laid out in the <img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/logo03.gif" alt="" width="170" height="75" />Health Insurance Portability and Accountability Act (HIPAA). The new consortium that will create these best practices is called the <strong><a href="http://www.hitrustalliance.org/">Health Information Trust Alliance</a></strong> (HITRUST).</p>
<p>The <strong><a href="http://www.hhs.gov/ocr/hipaa/">HIPAA standards</a> </strong>are aimed to protect the privacy of personal health information by giving patients more control over their information and setting boundaries on the use and release of health records. HIPAA requires that companies adopt privacy procedures and to ensure they&#8217;re followed, but many in the health care industry<strong> feel that more can be done </strong>to secure the privacy of patient information.</p>
<p>According to a survey HITRUST commissioned earlier this year, 96% of health information technology executives think it&#8217;s<strong> important to have a uniform way to verify the security of sensitive healthcare information</strong>. 85% of those surveyed think the health industry should pull together to create the comprehensive framework, which is exactly what HITRUST is now doing.</p>
<p>The new consortium, HITRUST, aims to develop a <strong>Common Security Framework</strong> (CSF) &#8211; a set of tools to aid organizations in protec<a href="http://www.hitrustalliance.org/programs/"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/wp-content/uploads/csf-brochure-2009-thumb.jpg" border="0" alt="" width="107" height="137" /></a>ting information and managing the risks, costs and complexities in managing these assets. They have published an overview of the framework and its components <a href="http://www.hitrustalliance.org/HITRUST%202009%20CSF%20Brochure.pdf">here</a> [PDF].</p>
<blockquote><p>The issues surrounding the protection of health information are complex and diverse but critical to the broad adoption, utilization of and confidence in health information systems, medical technologies and electronic exchanges.</p>
<p>Standardizing a higher level of information security will build greater trust and efficiencies in the electronic flow of information through the healthcare system and will instill confidence within regulators, business partners and consumers.</p></blockquote>
<p>The document outlines<strong> challenges faced in protecting electronic health information </strong>including: risk and liability from data breaches, confusion about implementation and baseline security controls, complexities involved with inconsistent standards and varying interpretations, and outside scrutiny from regulators, auditors, partners and customers.</p>
<p>The HITRUST CSF is aimed to help organizations that create, store, access or exchange electronic health information. The CSF framework includes <strong>three parts</strong>: an Information Security Implementation Manual, a Standards and Regulations Cross-Reference Matrix and a Readiness Assessment Toolkit. You can view a sample of the Security Implementation Manual, one part of CSF, <a href="http://www.hitrustalliance.org/HITRUST%202009%20CSF%20Implementation%20Manual%20Sample.pdf">here</a> [PDF]. The CSF is <a href="http://www.hitrustalliance.org/news/index.php?a=8">expected</a> to be released <strong>January 2009. </strong></p>
<p>Via <a href="http://www.informationweek.com/blog/main/archives/2008/08/the_security_an.html">information week</a> <small>Tags: <a rel="tag" href="http://technorati.com/tag/hitrust">hitrust</a>, <a rel="tag" href="http://technorati.com/tag/hipaa">hipaa</a>, <a rel="tag" href="http://technorati.com/tag/health+information">health information</a>, <a rel="tag" href="http://technorati.com/tag/health+industry">health industry</a>, <a rel="tag" href="http://technorati.com/tag/health+privacy">health privacy</a>, <a rel="tag" href="http://technorati.com/tag/healthcare">healthcare</a>, <a rel="tag" href="http://technorati.com/tag/private+information">private information</a>, <a rel="tag" href="http://technorati.com/tag/csf">csf</a>, <a rel="tag" href="http://technorati.com/tag/common+security+framework">common security framework</a>, <a rel="tag" href="http://technorati.com/tag/security+framework">security framework</a>, <a rel="tag" href="http://technorati.com/tag/data+security">data security</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/hitrust-plans-health-security-framework/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>HIPAA Examined</title>
		<link>http://blog.absolute.com/hipaa-examined/</link>
		<comments>http://blog.absolute.com/hipaa-examined/#comments</comments>
		<pubDate>Tue, 17 Jun 2008 16:46:33 +0000</pubDate>
		<dc:creator>arieanna</dc:creator>
				<category><![CDATA[Health Security]]></category>
		<category><![CDATA[Privacy & Security Laws]]></category>

		<guid isPermaLink="false">http://blog.absolute.com/?p=358</guid>
		<description><![CDATA[Tech News World has done a 2-part series about HIPAA. Part 1: Privacy vs. Portability and Part 2: Seeking Balance. It&#8217;s a very well-done examination of the state of the Health Insurance Portability and Accountability Act (HIPAA), some of which I will synthesize below. Given that HIPAA is often misunderstood in basics and in application, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hipaa.org/"><img style="margin: 5px; float: right" src="http://blog.absolute.com/wp/../uploads/hipaaorgnc.jpg" border="0" alt="" width="207" height="38" /></a>Tech News World has done a 2-part series about <a href="http://www.hipaa.org/">HIPAA.</a> Part 1: <a href="http://www.crmbuyer.com/story/63119.html">Privacy vs. Portability</a> and <a href="http://www.technewsworld.com/story/63216.html">Part 2: Seeking Balance.</a> It&#8217;s a very well-done examination of the state of the Health Insurance Portability and Accountability Act (HIPAA), some of which I will synthesize below. Given that HIPAA is often misunderstood in basics and in application, it&#8217;s a great refresher series.</p>
<p><strong>HIPAA Concerns:</strong></p>
<ul>
<li>There is a push for health information to become more liquid, but the privacy and security framework does not exist yet</li>
<li>The technologies being designed now will have a huge impact on how health information is accessed, stored and shared</li>
<li>Post-HIPAA privacy and security protections need to be adopted in law and in best practices</li>
<li>HIPAA compliance was a heavy burden at initial inception, but there has been no proof that HIPAA has in any way had negative effects on patient care</li>
<li>Staff training and education must be ongoing for new, and old, employees</li>
<li><em>Continue reading about the concerns <a href="http://www.crmbuyer.com/story/63119.html">here.</a></em></li>
</ul>
<p><strong>HIPAA Myths:</strong></p>
<ul>
<li>That it weakened, rather than strengthened, rights to health information privacy</li>
<li>HIPAA is all we need in the digital age</li>
<li>HIPAA &#8220;covered entities&#8221; cover every use of personal health information</li>
<li><em>Check out the full examination of these myths <a href="http://www.technewsworld.com/story/63216.html">here.</a></em></li>
</ul>
<p>Logo: ; <small>Tags: <a rel="tag" href="http://technorati.com/tag/hipaa">hipaa</a>, <a rel="tag" href="http://technorati.com/tag/health+privacy">health privacy</a>, <a rel="tag" href="http://technorati.com/tag/privacy+information">privacy information</a>, <a rel="tag" href="http://technorati.com/tag/health+information">health information</a>, <a rel="tag" href="http://technorati.com/tag/information">information</a>, <a rel="tag" href="http://technorati.com/tag/legislation">legislation</a>, <a rel="tag" href="http://technorati.com/tag/law">law</a>, <a rel="tag" href="http://technorati.com/tag/security">security</a></small></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.absolute.com/hipaa-examined/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
