<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Web-Tones</title>
    
    <link rel="alternate" type="text/html" href="http://www.lawtechtv.com/home/" />
    <id>tag:typepad.com,2003:weblog-269685</id>
    <updated>2013-05-22T08:39:34-04:00</updated>
    <subtitle>res ipsa loquitur (the web speaks for itself and loudly)</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Web-tones" /><feedburner:info uri="web-tones" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
        <title>IDAHO State University Gets Whacked with $400K HIPAA Fine!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/mjfs0gmDDwU/idaho-state-get-whacked-with-400k-hipaa-fine.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2013/05/idaho-state-get-whacked-with-400k-hipaa-fine.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef01910268fe5f970c</id>
        <published>2013-05-22T08:39:34-04:00</published>
        <updated>2013-05-22T15:44:23-04:00</updated>
        <summary>See below. Expect this to be par for the course anytime a significant breach happen, and they are going to happen all the time over the next 3 to 5 years. $50K would have bought a significant amount of compliance...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;See below. Expect this to be par for the course anytime a significant breach happen, and they are going to happen all the time over the next 3 to 5 years. $50K would have bought a significant amount of compliance protection. Now ISU will pay that (or more) and still have to pay $400K to HHS. I would venture to say that HHS simply let ISU off the hook for Privacy Rule violations that they likely found.&lt;/p&gt;&#xD;
&lt;p&gt;You can expect that the worse may not be over for ISU. Some enterprising law firm will file a class action lawsuit and, in any case, ISU has to pay the costs of notification. If the Ponemon institute is correct about the cost per record this will be a significant chunk of change,&lt;/p&gt;&#xD;
&lt;p&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/p&gt;&#xD;
&lt;p&gt;&lt;strong&gt;&lt;span style="color: #0000ff;"&gt;Idaho State University (ISU) has agreed to pay $400,000 to the U.S. &#xD;
Department of Health Human Services (HHS) for violations of the Health &#xD;
Insurance Portability and Accountability Act of 1996 (HIPAA) Security &#xD;
Rule&lt;/span&gt;&lt;/strong&gt;.  This settlement involves&#xD;
 the breach of unsecured electronic protected health information (ePHI) &#xD;
of 17,500 individuals who were patients at an ISU clinic.&lt;/p&gt;&#xD;
&lt;p&gt;The Office for Civil Rights (OCR) opened its investigation after ISU &#xD;
notified HHS that the ePHI of approximately 17,500 individuals was &#xD;
accessible at its Pocatello Family Medicine Clinic because an ISU server&#xD;
 firewall was disabled. &#xD;
 OCR investigators found that ISU did not apply proper security measures&#xD;
 and policies to address risks to ePHI and did not have in place &#xD;
procedures for routine review of information system activity which could&#xD;
 have detected the breach in the firewall much sooner.&#xD;
 Overall, ISU failed to ensure the uniform implementation of required &#xD;
Security Rule protections at each of its covered clinics. &#xD;
&lt;/p&gt;&#xD;
 &#xD;
The &#xD;
Resolution Agreement can be found on the OCR website at&#xD;
&lt;a href="http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/isu-agreement.html" target="_blank"&gt;&#xD;
http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/isu-agreement.html&lt;/a&gt;.&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=mjfs0gmDDwU:A1-WhN-bRVU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=mjfs0gmDDwU:A1-WhN-bRVU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=mjfs0gmDDwU:A1-WhN-bRVU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?i=mjfs0gmDDwU:A1-WhN-bRVU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=mjfs0gmDDwU:A1-WhN-bRVU:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=mjfs0gmDDwU:A1-WhN-bRVU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>



    <feedburner:origLink>http://www.lawtechtv.com/home/2013/05/idaho-state-get-whacked-with-400k-hipaa-fine.html</feedburner:origLink></entry>
    <entry>
        <title>A Business Associate Just Notified You of a Serious Breach: What now?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/KF9cxgs8cx8/this-article-provides-guidance-regarding-on-to-expect-and-what-you-should-do-once-a-business-associate-has-notified-you-of.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2013/05/this-article-provides-guidance-regarding-on-to-expect-and-what-you-should-do-once-a-business-associate-has-notified-you-of.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef017eeabb21d2970d</id>
        <published>2013-05-01T10:54:56-04:00</published>
        <updated>2013-05-01T10:55:33-04:00</updated>
        <summary>This article provides guidance regarding what to expect, and what you should do, once a Business Associate has notified you of a breach. By now, you should already have a plan in place that helps you respond to this dreaded...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="HHS Omnibus Rule" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="HIPAA Breach Notificaiton" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="HIPAA Checklist" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;a href="http://r20.rs6.net/tn.jsp?e=0016thK4Xjvhj1LzNWErRIX8pba7rtEWSDwiL12oQSq1gic8JNkiNDm2xIcEFnNFh8pVst7Ma-Qs8-Ygf99U8R7DXahapikiCFnZc-cO8i-1Qcroj9yyD0Iv3eHK_HOl5XOLeeZD_Ii5byrRI-o9Krt-sGtRoihJm-4pK-Odnx3SaY=" target="_blank"&gt;&lt;img alt="Webtones Pointer" border="0" height="41" src="https://origin.ih.constantcontact.com/fs009/1102637029146/img/35.gif" width="42"&gt;&lt;/img&gt;&lt;/a&gt; This article provides guidance regarding what to expect, and what you should do, once a Business Associate has notified you of a breach. By now, you should already have a plan in place that helps you respond to this dreaded predicament. However, we know from experience that many of you don't, and even if you do, read on, you may learn something new. &#xD;
&lt;div&gt;&#xD;
&lt;p&gt;The approach we take in the article is to use the breach notification process as a backdrop to point out a number of "holes" you may have in your HIPAA/HITECH compliance initiative, ones that you are likely not even aware of.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;img alt="HITECH / HIPAA Newsletter" border="0" height="48" hspace="5" src="https://origin.ih.constantcontact.com/fs009/1102637029146/img/11.gif" vspace="5" width="64"&gt;&lt;/img&gt;&lt;strong&gt;Tracking Security Incidents&lt;/strong&gt;&lt;strong&gt;? &lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;div&gt;&#xD;
&lt;div&gt;The term "security incident" means the &lt;strong&gt;attempted or successful&lt;/strong&gt; unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. An attempt qualifies as an incident. &lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;If you are not rigorously tracking incidents, then you can't possibly know when you have a breach. One of the first questions that an HHS auditor is going ask is "show me the system (i.e. the policies, processes and tracking mechanism) your organization uses to track security incident?" If you can't adequately answer this most basic of questions, you may be in &lt;a href="http://r20.rs6.net/tn.jsp?e=0016thK4Xjvhj1LzNWErRIX8pba7rtEWSDwiL12oQSq1gic8JNkiNDm2xIcEFnNFh8pVst7Ma-Qs8-Ygf99U8R7DW8mRR9zu7RI9_ITBQepgbiwWlPjTMJwNjuCRbZusaIbvi9Asz7_Z_BfR1DyqTKban0ZoDOZjUOApNOg1Vn_ECv8DHlXsNSAk8bPIr06qn_mmLSKdATSWjEjRRituHSytg==" target="_blank"&gt;willful neglect land&lt;/a&gt; five minutes into the audit.&lt;/div&gt;&#xD;
&lt;div&gt; &lt;/div&gt;&#xD;
&lt;div&gt;Ok, so let's assume that for the purpose of this article you, as the &lt;a href="http://r20.rs6.net/tn.jsp?e=0016thK4Xjvhj1LzNWErRIX8pba7rtEWSDwiL12oQSq1gic8JNkiNDm2xIcEFnNFh8pVst7Ma-Qs8-Ygf99U8R7DXahapikiCFnZc-cO8i-1Qcroj9yyD0Iv3eHK_HOl5XO4PdO21HogJRXMWnEEGBXnvtFtolNdRRfqrS2SRK3dSRiOEhV8R9V-zymKV7pAe6y" target="_blank"&gt;covered entity&lt;/a&gt;, have a state of the art security incident tracking system in place. What we really want to know is "What kind of tracking system does your &lt;a href="http://r20.rs6.net/tn.jsp?e=0016thK4Xjvhj1LzNWErRIX8pba7rtEWSDwiL12oQSq1gic8JNkiNDm2xIcEFnNFh8pVst7Ma-Qs8-Ygf99U8R7DXahapikiCFnZc-cO8i-1Qcroj9yyD0Iv3eHK_HOl5XO4PdO21HogJRXMWnEEGBXnvtFtolNdRRftxKLSiulvaVnIVgFlr5LLM5PXqwYYAqFzDpTAuiGPvo=" target="_blank"&gt;business associate&lt;/a&gt; have in place?" If the answer is "we don't have a clue," then may the HIPAA gods help you if it turns out that in fact, despite "catching" this incident, there is no business associate system in place at all.  &lt;/div&gt;&#xD;
&lt;/div&gt;&#xD;
&lt;p&gt;&lt;img alt="Key Contract Sections" border="0" height="32" hspace="5" src="https://origin.ih.constantcontact.com/fs009/1102637029146/img/31.png" vspace="5" width="32"&gt;&lt;/img&gt;&lt;strong&gt;How Do You Know It's a Breach?&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;p&gt; In order to determine whether Breach Notification is triggered you need to follow a methodology that is mandated by the &lt;a href="http://r20.rs6.net/tn.jsp?e=0016thK4Xjvhj1LzNWErRIX8pba7rtEWSDwiL12oQSq1gic8JNkiNDm2xIcEFnNFh8pVst7Ma-Qs8-Ygf99U8R7DXahapikiCFnZc-cO8i-1Qcroj9yyD0Iv3eHK_HOl5XO4PdO21HogJRXMWnEEGBXnvRtphjz6Lv1uf1vZYMQF6E=" target="_blank"&gt;Breach Notification Rule&lt;/a&gt; ("Rule"). Although the &lt;a href="http://r20.rs6.net/tn.jsp?e=0016thK4Xjvhj1LzNWErRIX8pba7rtEWSDwiL12oQSq1gic8JNkiNDm2xIcEFnNFh8pVst7Ma-Qs8-Ygf99U8R7DXahapikiCFnZc-cO8i-1Qcroj9yyD0Iv3eHK_HOl5XO4PdO21HogJRXMWnEEGBXnvRtphjz6Lv1uf1vZYMQF6E=" target="_blank"&gt;Rule&lt;/a&gt; contains a basic methodology that is inherent in its text, it is not presented as such in the regulations. HIPAA/HITECH remain descriptive as opposed to prescriptive. That is, the regulations inform you as to what is required, but have very little (mostly nothing) to say about how you should go about complying. &lt;/p&gt;&#xD;
&lt;p&gt;The methodology consists of a three part analytical framework which we turn our attention to next. Although the framework only consists of three parts, it is significantly more complex than it first appears.&lt;/p&gt;&#xD;
&lt;p&gt;SIgnup for our &lt;a href="http://store.hipaasurvivalguide.com/free-hitech-hipaa-newsletter-registration.html" target="_self"&gt;FREE Newsletter&lt;/a&gt; or wait until it appears in the &lt;a href="http://store.hipaasurvivalguide.com/news.html" target="_self"&gt;archives&lt;/a&gt; to read the rest of the article.&lt;/p&gt;&#xD;
&lt;p&gt; &lt;/p&gt;&#xD;
&lt;/div&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=KF9cxgs8cx8:xsWD2RiHXvM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=KF9cxgs8cx8:xsWD2RiHXvM:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=KF9cxgs8cx8:xsWD2RiHXvM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?i=KF9cxgs8cx8:xsWD2RiHXvM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=KF9cxgs8cx8:xsWD2RiHXvM:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=KF9cxgs8cx8:xsWD2RiHXvM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>



    <feedburner:origLink>http://www.lawtechtv.com/home/2013/05/this-article-provides-guidance-regarding-on-to-expect-and-what-you-should-do-once-a-business-associate-has-notified-you-of.html</feedburner:origLink></entry>
    <entry>
        <title>Mobile Devices under HITECH Training Module Now Available</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/Qw-QN2b1S14/mobile-devices-under-hitech-training-module-now-available.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2013/04/mobile-devices-under-hitech-training-module-now-available.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef017c38b35a3c970b</id>
        <published>2013-04-17T15:51:54-04:00</published>
        <updated>2013-04-17T15:50:20-04:00</updated>
        <summary>Digital Download Omnibus Rule Ready™ Our Mobile Devices under HITECH Training Module is now available in the HSG Store. Our Subscribers get this product, like all our new products and updates, as part of their Subscription Plan. Mobile Devices Under...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="HIPAA Compliance" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="HIPAA Training" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt; &#xD;
&lt;a class="asset-img-link" href="https://kd123.infusionsoft.com/app/manageCart/addProduct?productId=41" style="display: inline;" target="_self"&gt;&lt;img alt="Mobile_Devices_Cover" class="asset  asset-image at-xid-6a00d8341e18e853ef017c38b19216970b" src="http://www.lawtechtv.com/.a/6a00d8341e18e853ef017c38b19216970b-120wi" title="Mobile_Devices_Cover"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/strong&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size: 1.17em; color: #ff7f00;"&gt;Digital Download &lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&#xD;
&lt;h3&gt;&lt;em&gt;&lt;span style="color: #ff7f00;"&gt;O&lt;/span&gt;&lt;span style="color: #0000bf;"&gt;mnibus&lt;/span&gt; &lt;span style="color: #ff7f00;"&gt;R&lt;/span&gt;&lt;span style="color: #0000bf;"&gt;ule&lt;/span&gt; &lt;span style="color: #ff7f00;"&gt;R&lt;/span&gt;&lt;span style="color: #0000bf;"&gt;eady&lt;/span&gt;&lt;/em&gt;&lt;span style="color: #ff7f00;"&gt;&lt;strong&gt;™&lt;/strong&gt;&lt;/span&gt;&lt;/h3&gt;&#xD;
&lt;p&gt;Our &lt;strong&gt;&lt;span style="color: #0000ff;"&gt;Mobile Devices under HITECH Training Module&lt;/span&gt;&lt;/strong&gt; is now available in the &lt;a href="http://store.hipaasurvivalguide.com/mobile-devices-under-hitech-training-module.html" target="_self"&gt;HSG Store&lt;/a&gt;. Our &lt;a href="http://store.hipaasurvivalguide.com/hipaa-survival-guide-subscription-plan.html" target="_self"&gt;Subscribers&lt;/a&gt; get this product, like all our new products and updates, as part of their &lt;a href="http://store.hipaasurvivalguide.com/hipaa-survival-guide-subscription-plan.html" target="_self"&gt;Subscription Plan&lt;/a&gt;.&lt;/p&gt;&#xD;
&lt;p&gt;&lt;span style="color: #0000ff;"&gt;&lt;strong&gt;Mobile Devices Under HITECH &lt;/strong&gt;&lt;/span&gt;– Our Mobile Devices Under HITECH Training Module gets you up to speed on how Mobile Devices have impacted the HIPAA Rules including: 1) the HIPAA Security Rule; 2) the HIPAA Privacy Rule; and 3) the Breach Notification Rule. We walk you through Mobile Device (phones, pads, laptops, etc.) challenges created by locally stored PHI, asset management, bring your own device ("BYOD"), wireless networks and audits, as well as the best practices that help you meet these challenges. It short, we present an overiew of what your mobile compliance initiative ("MDI") should consist of, keeping in mind that &lt;em&gt;&lt;strong&gt;&lt;span style="color: #ff7f00;"&gt;most PHI data breaches occur as a result of Mobile Devices&lt;/span&gt;&lt;/strong&gt;&lt;/em&gt;.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=Qw-QN2b1S14:iDmIXfTZt9c:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=Qw-QN2b1S14:iDmIXfTZt9c:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=Qw-QN2b1S14:iDmIXfTZt9c:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?i=Qw-QN2b1S14:iDmIXfTZt9c:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=Qw-QN2b1S14:iDmIXfTZt9c:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=Qw-QN2b1S14:iDmIXfTZt9c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>



    <feedburner:origLink>http://www.lawtechtv.com/home/2013/04/mobile-devices-under-hitech-training-module-now-available.html</feedburner:origLink></entry>
    <entry>
        <title>Excellent Summary of Patients' Access Rights Under HITECH/Omnibus Rule!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/618FAcL4EV0/excellent-summary-of-patients-access-rights-under-hitech.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2013/04/excellent-summary-of-patients-access-rights-under-hitech.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef017d42ade291970c</id>
        <published>2013-04-10T08:38:26-04:00</published>
        <updated>2013-04-10T08:39:22-04:00</updated>
        <summary>This article does an excellent job of summarizing the new and/or modified access rights that patients now have under HITECH as finalized by the Omnibus Rule. As the articles suggests, almost universally CEs and BAs will need to retrain staff...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="HHS Omnibus Rule" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="HIPAA Compliance" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="HITECH/HIPAA" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;This &lt;a href="http://aishealth.com/archive/hipaa0413-01" target="_self"&gt;article&lt;/a&gt; does an excellent job of summarizing the new and/or modified access rights that patients now have under &lt;a href="http://www.hipaasurvivalguide.com/hitech-act-text.php" target="_self"&gt;HITECH&lt;/a&gt; as finalized by the Omnibus Rule.&lt;/p&gt;&#xD;
&lt;p&gt;As the articles suggests, almost universally CEs and BAs will need to retrain staff and implement processes that were "minimalist" or did not exist at all heretofor. For many reasons, but primarily because &lt;a href="http://www.lawtechtv.com/home/2012/03/data-protection-officer-coming-to-a-theatre-near-you.html" target="_self"&gt;HIPAA was an unenforced paper tiger before HITECH&lt;/a&gt;, CEs and BAs that believed they were "mostly compliant" are in for a rude awakening. &lt;/p&gt;&#xD;
&lt;p&gt;Hopefully for these organizations it is not an HHS Audit or a lawsuit that awakens their slumber.&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=618FAcL4EV0:tGZ1oTmqXKU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=618FAcL4EV0:tGZ1oTmqXKU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=618FAcL4EV0:tGZ1oTmqXKU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?i=618FAcL4EV0:tGZ1oTmqXKU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=618FAcL4EV0:tGZ1oTmqXKU:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=618FAcL4EV0:tGZ1oTmqXKU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>



    <feedburner:origLink>http://www.lawtechtv.com/home/2013/04/excellent-summary-of-patients-access-rights-under-hitech.html</feedburner:origLink></entry>
    <entry>
        <title>Google Reader Gone &amp; Google Basks in its own Ignorance!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Web-tones/~3/DCKS7cnUP1I/google-reader-gone-google-basks-in-its-own-ignorance.html" />
        <link rel="replies" type="text/html" href="http://www.lawtechtv.com/home/2013/04/google-reader-gone-google-basks-in-its-own-ignorance.html" />
        <id>tag:typepad.com,2003:post-6a00d8341e18e853ef017ee9fa0df3970d</id>
        <published>2013-04-04T09:00:09-04:00</published>
        <updated>2013-04-11T18:41:29-04:00</updated>
        <summary>Google has announced that Google Reader will no longer be after July 1, 2013. This is proof that Google doesn't get how its products are used by enterprises large and small. Thousands of businesses (probably hundreds of thousands) have made...</summary>
        <author>
            <name>Carlos Leyva</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://www.lawtechtv.com/home/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Google has announced that &lt;a href="http://techcrunch.com/2013/03/20/google-starts-removing-links-to-reader-from-its-top-menus/" target="_self"&gt;Google Reader will no longer be after July 1, 2013&lt;/a&gt;. This is proof that Google doesn't get how its products are used by enterprises large and small. Thousands of businesses (probably hundreds of thousands) have made Reader an integral part of their information gathering strategy. In short, it is used as a way to keep up with the industry they operate in (in my case a certain niche within the legal industry). For me it's integral to how I run my practice.&lt;/p&gt;&#xD;
&lt;p&gt;I also use Google Apps to run a part of my practice. I now have a lot less faith that Apps is here to stay for the long run. Here's the point, now that Google has broken trust with its users, why would any business person in their right mind commit to another Google product for its business?&lt;/p&gt;&#xD;
&lt;h1&gt;&lt;a href="http://www.officeonthecloud.com/Graphics/quotefirebrick.gif"&gt;&lt;img alt="HSGLogo" src="http://www.officeonthecloud.com/Graphics/quotefirebrick.gif" title="HSGLogo"&gt;&lt;/img&gt;&lt;/a&gt;This is by far the most stupid&lt;/h1&gt;&#xD;
&lt;h1&gt;decision made by an enterprise&lt;/h1&gt;&#xD;
&lt;h1&gt;information technology company&lt;/h1&gt;&#xD;
&lt;h1&gt;in thirty years...&lt;/h1&gt;&#xD;
&lt;p&gt;This is a decision made by clueless/arrogant engineers that are now too rich to remotely identify what it means for a business to commit to something that is mission critical. To add insult to injury, despite the fact that it is not July 1, 2013 yet, Google has removed access to Reader from Gmail. They appear to be celebrating their own ignorance by pissing off millions of users even more.&lt;/p&gt;&#xD;
&lt;h1&gt;&lt;a href="http://www.officeonthecloud.com/Graphics/quotefirebrick.gif"&gt;&lt;img alt="HSGLogo" src="http://www.officeonthecloud.com/Graphics/quotefirebrick.gif" title="HSGLogo"&gt;&lt;/img&gt;&lt;/a&gt;The 'Do no Evil' slogan has now&lt;/h1&gt;&#xD;
&lt;h1&gt;been replaced with 'We are Google'&lt;/h1&gt;&#xD;
&lt;h1&gt; &lt;/h1&gt;&#xD;
&lt;h1&gt;&lt;span style="font-size: 2em;"&gt;we are free to be&lt;/span&gt;&lt;/h1&gt;&#xD;
&lt;h1&gt;&lt;span style="font-size: 2em;"&gt;as stupid as we &lt;/span&gt;&lt;/h1&gt;&#xD;
&lt;h1&gt;&lt;span style="font-size: 2em;"&gt;want to be!&lt;/span&gt;&lt;/h1&gt;&#xD;
&lt;p&gt; &lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=DCKS7cnUP1I:0cbf191XrMo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=DCKS7cnUP1I:0cbf191XrMo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=DCKS7cnUP1I:0cbf191XrMo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?i=DCKS7cnUP1I:0cbf191XrMo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=DCKS7cnUP1I:0cbf191XrMo:l6gmwiTKsz0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=l6gmwiTKsz0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Web-tones?a=DCKS7cnUP1I:0cbf191XrMo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Web-tones?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>



    <feedburner:origLink>http://www.lawtechtv.com/home/2013/04/google-reader-gone-google-basks-in-its-own-ignorance.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 -->
