Overheard and Noted: "eRisk Hub is an unparalleled resource for absolutely everything you need to deal effectively with a breach - before and after it happens."                             "eRisk Hub puts everything at your fingertips. It's not a data dump - it's the best of the best."
REGISTER   |   NEWSLETTER SIGNUP   |   CONTACT US   
 
Healthcare Data Breaches
Total Number Reported: 63
Latest Incident
University Health System
State: Nevada
# of Records: 7,526
Type of Breach: Theft
See more at www.HHS.gov

Featured Articles
The Intersection of Business Continuity and Data Breach Preparedness

New Data Breach Legislation

Data Breaches: A Sidewalk Sale of Consumer and Personal Information

The “Should” Rule of Cloud Computing

Social Networking: Setting Boundaries in a Borderless Brave New World


Cyber Risk News
Zurich UK cops $4m data loss fine

Conn. AG investigates Yale med school data breach

Milton Hospital apologizes for breach of confidentiality

Portland psychologist's laptop stolen; 4,000 patients face possible identity breach

Thousands of online banking customers have accounts emptied by 'most dangerous trojan virus ever created'


Security Wire
Microsoft to address DLL load hijacking flaw, issues new tool
 
Researchers, ISPs fail to contain notorious Pushdo botnet
 
CA to acquire Arcot Systems for SaaS identity management
 
Security information sharing is a shared responsibility
 
Intel-McAfee marriage could fuel renewed chip security interest
 
Are You Already Violating Multiple New Data Security Compliance Deadlines?
by John F. Mullen, Sr and Mark C. Stephenson, Nelson Levine de Luca & Horst

Multiple new statutes and rules are imposing deadlines on businesses and organizations that hold sensitive personal data records. These deadlines are fast approaching or have already passed. Failure to comply with new regulations may result in sanctions or provide ammunition for plaintiffs who bring suit alleging negligent protection of private personal data.

HIPAA Privacy and Security Rules/HITECH:

In 2009, Congress enacted the HITECH Act, amending HIPAA Privacy and Security Rules. The HITECH rules are now in full effect and organizations that are Covered Entities or Business Associates are obliged to comply. Under the amended rules, "Business Associates" must, among other things, designate a HIPAA security officer, conduct a written risk analysis as to potential risks and vulnerabilities to confidential, protected health information that the Business Associate holds, establish policies and procedures for the implementation of the HIPAA Security Rules, and provide security awareness and training for the workforce. As of February 22, 2010, Health and Human Services ("HHS") will impose sanctions on Business Associates for breaches of confidentiality of personal health information that violate these data security rules.

FTC Identity Theft Red Flag Rules:

The FTC's Red Flag Rules become effective June 1, 2010. The rules require financial institutions and creditors with "covered accounts" to create and implement an identity theft prevention program to identify and address the "red flags" of identity theft, consider the nature of the covered entity’s business, the risks at issue, and update its program periodically.

Whether a business or organization is a creditor under the Rules will require a case-by-case analysis based on its activities, not its industrial classification. The rules define a "creditor" as any business that regularly extends, renews or continues credit, participates in the decision to extend credit or defers payment for goods or services and bills customers later. It is a very broad definition.

To continue reading, you must be a subscriber.
SUBSCRIBE NOW
FOR FULL ACCESS
TO THE eRISK HUB.
SUBSCRIBE NOW
Ask about our
enterprise solution

eRISK HUB PRO