<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>HealthcareInfoSecurity.com  RSS Syndication</title>
<link>http://www.healthcareinfosecurity.com/rssFeeds.php?type=main</link>
<description>HealthcareInfoSecurity.com RSS News Feeds on healthcare information security news, regulations, blogs and education</description>
<pubDate>Wed, 30 May 2012 20:22:28 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/healthcareinfosecurity/com" /><feedburner:info uri="healthcareinfosecurity/com" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>9 Principles to Battle Botnets</title>
			<link>http://www.healthcareinfosecurity.com/9-principles-to-battle-botnets-a-4812</link>
			<guid>http://www.healthcareinfosecurity.com/9-principles-to-battle-botnets-a-4812</guid>
			<description>&lt;img src="http://docs.healthcareinfosecurity.com/files/images_articles/4812_bot_net_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Feds, Business Team Up to Limit Harm Caused by Botnets&lt;/b&gt;&lt;br&gt;The proliferation of botnets and malware in cyberspace threatens to undermine the efficiencies, innovation and economic growth of the Internet and diminishes the trust and confidence of online users.</description>
			</item>
			<item>
			<title>Pension Hack Exposed 123,000 Accounts</title>
			<link>http://www.healthcareinfosecurity.com/pension-hack-exposed-123000-accounts-a-4811</link>
			<guid>http://www.healthcareinfosecurity.com/pension-hack-exposed-123000-accounts-a-4811</guid>
			<description>&lt;img src="http://docs.healthcareinfosecurity.com/files/images_articles/4811_logo_thrift_savings_plan_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;What Was the Motivation Behind the Federal Attack?&lt;/b&gt;&lt;br&gt;An attack on the Thrift Savings Plan exposed personal details about more than 120,000 federal pension participants. Learn why one expert says the breach could have serious long-term implications.</description>
			</item>
			<item>
			<title>NIST Issues Long-Awaited Cloud Guidance</title>
			<link>http://www.healthcareinfosecurity.com/nist-issues-long-awaited-cloud-guidance-a-4810</link>
			<guid>http://www.healthcareinfosecurity.com/nist-issues-long-awaited-cloud-guidance-a-4810</guid>
			<description>&lt;img src="http://docs.healthcareinfosecurity.com/files/images_articles/4810_NIST_logo_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;SP 800-146 Describes Cloud's Strengths, Weaknesses&lt;/b&gt;&lt;br&gt;The National Institute of Standards and Technology's guidance recommends how and when cloud computing is appropriate, addresses risk management issues and indicates the limits of current knowledge and areas for future research and analysis.</description>
			</item>
			<item>
			<title>Top 4 Malware-Related Issues for 2012</title>
			<link>http://www.healthcareinfosecurity.com/top-4-malware-related-issues-for-2012-a-4808</link>
			<guid>http://www.healthcareinfosecurity.com/top-4-malware-related-issues-for-2012-a-4808</guid>
			<description>&lt;img src="http://docs.healthcareinfosecurity.com/files/images_articles/4808_artid_4808_175x175.jpg" align=right hspace=4&gt;&lt;b&gt;Mobile Attacks, Trojans on Social Media Among Biggest Threats&lt;/b&gt;&lt;br&gt;What are the top four malware-related issues that all organizations should focus on this year? Andreas Baumhof of ThreatMetrix shares insights based on five years of malware analysis.</description>
			</item>
			<item>
			<title>Notice of ... Virtual Lifetime Electronic Record</title>
			<link>http://www.healthcareinfosecurity.com/agency-releases/notice-virtual-lifetime-electronic-record-r-2689</link>
			<guid>http://www.healthcareinfosecurity.com/agency-releases/notice-virtual-lifetime-electronic-record-r-2689</guid>
			<description>In a notice of a new system of records, the Department of Veterans Affairs is seeking comments on proposed privacy practices for the Virtual Lifetime Electronic Record project now in development. The VLER effort is a long-term project of the VA and the Department of Defense designed to pave the way for improved sharing of records among providers treating veterans, members of the armed services and others.</description>
			</item>
			<item>
			<title>Nationwide Health Information Network: Conditions for Trusted Exchange</title>
			<link>http://www.healthcareinfosecurity.com/agency-releases/nationwide-health-information-network-conditions-for-trusted-r-2688</link>
			<guid>http://www.healthcareinfosecurity.com/agency-releases/nationwide-health-information-network-conditions-for-trusted-r-2688</guid>
			<description>This request for information seeks comments on plans for voluntary national standards, including privacy and security guidelines, for health information exchanges. The announcement poses 66 questions.</description>
			</item>
			<item>
			<title>Medicare and Medicaid Programs; Electronic Health Record Incentive Program, Stage 2</title>
			<link>http://www.healthcareinfosecurity.com/agency-releases/medicare-medicaid-programs-electronic-health-record-incentive-r-2654</link>
			<guid>http://www.healthcareinfosecurity.com/agency-releases/medicare-medicaid-programs-electronic-health-record-incentive-r-2654</guid>
			<description>This proposed rule outlines requirements, including privacy and security provisions, for a hospital or physician practice to qualify as a "meaningful user" of certified electronic health record software to qualify for Stage 2 of the HITECH Act EHR incentive program.</description>
			</item>
			<item>
			<title>HIT Standards, Implementation Specifications and Certification Criteria for Electronic Health Record Technology</title>
			<link>http://www.healthcareinfosecurity.com/agency-releases/hit-standards-implementation-specifications-certification-r-2653</link>
			<guid>http://www.healthcareinfosecurity.com/agency-releases/hit-standards-implementation-specifications-certification-r-2653</guid>
			<description>This proposed rule outlines requirements, including privacy and security provisions, for electronic health record software certified as qualifying for Stage 2 of the HITECH Act EHR incentive program.</description>
			</item>
			<item>
			<title>HIPAA Compliance Audits: How to Prepare</title>
			<link>http://www.healthcareinfosecurity.com/webinars/hipaa-compliance-audits-how-to-prepare-w-280</link>
			<guid>http://www.healthcareinfosecurity.com/webinars/hipaa-compliance-audits-how-to-prepare-w-280</guid>
			<description>&lt;p&gt;The HITECH Act called for HIPAA compliance audits as part of an effort to help ensure compliance with its privacy and security provisions. The HHS Office for Civil Rights has completed the first 20 pilot audits, and it plans to complete another 95 by the end of this year.&lt;/p&gt;

&lt;p&gt;Those to be audited will be notified in phases in months ahead. How can you help ensure your organization is well-prepared if it's selected? By learning from the experiences of those who've been through the audit experience.&lt;/p&gt;

&lt;p&gt;This webinar will feature timely insights from an experienced consultant who aided a client with its audit, from start to finish.&lt;/p&gt;

&lt;p&gt;The protocol for these assessments presents a rigorous audit experience that emphasizes the need for readiness, consultant Mac McMillan stresses.&lt;/p&gt;
  
&lt;p&gt;McMillan's experience advising a client who was audited provided valuable direct visibility into how these audits are conducted, the expectations of the auditors and the process. This session is designed to chronicle that experience and provide insights into how to improve your readiness posture.&lt;/p&gt;

&lt;p&gt;In this webinar, you'll learn:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;What the audit process looks like and what to expect;&lt;/li&gt;
&lt;li&gt;How to prepare for the document request requirements;&lt;/li&gt;
&lt;li&gt;How to prepare your staff for successful interaction with the auditors;&lt;/li&gt;
&lt;li&gt;How to prepare all your departments for the audit process;&lt;/li&gt;
&lt;li&gt;How to review your information security program to understand weaknesses;&lt;/li&gt;
&lt;li&gt;How to prepare your response.&lt;/li&gt;
&lt;/ul&gt;</description>
			</item>
			<item>
			<title>IT Security Risk Analysis for Meaningful Use: What We've Learned</title>
			<link>http://www.healthcareinfosecurity.com/webinars/security-risk-analysis-for-meaningful-use-what-weve-learned-w-278</link>
			<guid>http://www.healthcareinfosecurity.com/webinars/security-risk-analysis-for-meaningful-use-what-weve-learned-w-278</guid>
			<description>Prompted by the EHR Meaningful Use Incentive Program, many hospitals and eligible providers are taking a fresh look at the HIPAA Security Rule requirement for regular IT security risk analysis (SRA). Nearly 100 hospitals have chosen Redspin to help them conduct their SRA and attest to meaningful use. 
While engaging an external firm is not mandatory, it enables healthcare providers to more efficiently use their internal resources while leveraging expertise that they may not have in-house.
&lt;p&gt;&lt;p&gt;  
In this webinar, Dan Berger, Redspin's President and CEO, will share his company's vast experience helping healthcare organizations meet the requirements of the HIPAA Security Rule. See how compliance with regulations is necessary but not sufficient as it relates to safeguarding PHI from data breaches. Learn why even the SRA itself is only a first step - and how reducing IT security risk requires an ongoing process of testing, remediation, validation and re-testing. See how web applications, business associates, and mobile/BYOD are often overlooked as security risks yet pose significant threats. Gain a deeper understanding for how to make IT security an integral part of your overall risk management program and corporate culture.
&lt;p&gt;
Redspin promotes Meaningful Healthcare IT Security ® - a process-driven approach for healthcare firms to achieve continuous and durable improvements in IT security. The program provides a systematic reduction of vulnerabilities over time, even as organizations add new employees, systems, applications and customers.&lt;p&gt;
Attend this webinar to gain answers to the following questions: 
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;What is the best governance strategy to employ to reduce IT security risk?&lt;/li&gt;
&lt;li&gt;Which 3 common areas of IT security vulnerability are the most prevalent in the healthcare industry?&lt;/li&gt;
&lt;li&gt;How can healthcare providers better prepare themselves as enforcement of HIPAA increases (audits, breach penalties, resolution agreements)?&lt;/li&gt;
&lt;li&gt;Beyond the SRA: How can health organizations deal with new areas of risk such as applications, business associates, mobile and BYOD?&lt;/li&gt;
&lt;li&gt;How can healthcare providers promote a "culture of compliance," or better yet, "a culture of security?"
&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>2012 Cloud Security Agenda: Expert Insights on Security and Privacy in the Cloud</title>
			<link>http://www.healthcareinfosecurity.com/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</link>
			<guid>http://www.healthcareinfosecurity.com/webinars/2012-cloud-security-agenda-expert-insights-on-security-privacy-in-cloud-w-276</guid>
			<description>What are organizations' top cloud security concerns, and how are security leaders addressing these concerns through policy, technology and improved vendor management?
&lt;p&gt;&lt;p&gt;
This is the key question posed by the 2012 Cloud Security Survey.
&lt;p&gt;
No longer just an emerging technology practice, cloud computing today is embraced globally as a means of gaining efficient access to critical applications, processes and storage. It's now common for organizations to rely on cloud service providers for functions and business applications such as customer relationship management, messaging or storage via a public, private or hybrid cloud. Further, industry-specific cloud-based applications such as electronic health records or mobile banking and payment applications are emerging at an unprecedented pace.
&lt;p&gt;
But these engagements come with questions about risks:
&lt;ul&gt;
&lt;li&gt;What are your cloud service provider's security and privacy measures, and have they been audited?&lt;/li&gt;
&lt;li&gt;Where geographically is cloud data being stored, and how do operational practices comply with government, industry and organizational privacy regulations?&lt;/li&gt;
&lt;li&gt;How is a multi-tenant cloud environment managed, and in the event of system compromise - what will be the incident response escalation process?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
Yes, cloud computing is about efficiencies and new technologies, but it's also about security, privacy and an organization's reputation.
&lt;p&gt;
The 2012 Cloud Security Survey was crafted with assistance from leading experts in cloud computing, security and privacy, with a mission to:
&lt;ul&gt;
&lt;li&gt;Chart the latest cloud trends, including types of cloud implementations most common by industry and region;&lt;/li&gt;
&lt;li&gt;Gauge organizations' top cloud security concerns, from vendor security to data governance and breach preparedness;&lt;/li&gt;
&lt;li&gt;Predict the top areas of investment for organizations most concerned about cloud security.&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;
This webinar will draw upon survey results and expert insight from a special roundtable panel to discuss:
&lt;p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Top Security Concerns&lt;/b&gt; - Are organizations more concerned about where their data is stored, or whether a malicious insider might be a threat to it?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Success Factors&lt;/b&gt; - On a scale with cost savings and availability of services, how does security now rank among elements critical to a successful cloud computing implementation?&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Protective Measures&lt;/b&gt; - What are some of the practices organizations are employing, from instituting more stringent contracts to enforcing third-party audits and even participating in mock security exercises with cloud service providers?&lt;/li&gt;
&lt;/ul&gt;
&lt;/p&gt;</description>
			</item>
			<item>
			<title>5 Best Practices for Disaster Recovery &amp; HIPAA Compliance</title>
			<link>http://www.healthcareinfosecurity.com/webinars/5-best-practices-for-disaster-recovery-hipaa-compliance-w-275</link>
			<guid>http://www.healthcareinfosecurity.com/webinars/5-best-practices-for-disaster-recovery-hipaa-compliance-w-275</guid>
			<description>Fact: 2.5 Million Healthcare facilities must become HIPAA compliant by 2015.
&lt;p&gt;
The primary goal of any healthcare provider is providing healthcare on demand to a wide array of patients. An equally important goal is the ability to financially sustain the practice and its employees. Finally, there is the goal of protecting patient's records which is now government mandated by HIPAA regulations. 
&lt;p&gt;
Chances are, choosing a disaster recovery (DR) solution to support your healthcare organization is a critical step in becoming HIPAA and HITECH compliant, as well as improving business continuity and security.  Choose the wrong DR solution can cause unnecessary downtime and dataloss.  Choose the right DR solution and you become a hero to your organization...and to your bottom line by reducing your total cost of ownership and putting your HIT dollars to good use.
&lt;p&gt;
Join this webinar to help steer you disaster recovery and compliance in the right direction. 
&lt;p&gt; 
HEROware, a leader in business continuity, HIPAA and HITECH compliant appliance-based DR solutions, and Kaseya, the leader in IT service solutions, will discuss details on how to navigate this complex process, including: 
&lt;ul&gt;
&lt;li&gt;How HIPAA and HITECH requirements impact the need for DR solutions&lt;/li&gt;
&lt;li&gt;Implementing 5 best practices for a successful DR program&lt;/li&gt;
&lt;li&gt;Pros and cons between various DR solution methodologies&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
You'll also hear from HEROware/Kaseya customer, Dan Gross, as he discusses his real-life DR implementation and steps to success. Don't miss this opportunity to leverage these lessons learned for your healthcare organization!</description>
			</item>
			<item>
			<title>Five Application Security Tips</title>
			<link>http://www.healthcareinfosecurity.com/interviews/five-application-security-tips-i-1571</link>
			<guid>http://www.healthcareinfosecurity.com/interviews/five-application-security-tips-i-1571</guid>
			<description>Many organizations aren't devoting enough resources to ensure that applications for &lt;a href=" http://www.healthcareinfosecurity.com/mobility-c-212"&gt;&lt;b&gt;mobile devices&lt;/b&gt;&lt;/a&gt; are secure, says security expert Jeff Williams. He offers five tips for adequately addressing mobile &lt;a href=" http://www.healthcareinfosecurity.com/application-security-c-205"&gt;&lt;b&gt;application security&lt;/b&gt;&lt;/a&gt;.</description>
			</item>
			<item>
			<title>Why Boards of Directors Don't Get It</title>
			<link>http://www.healthcareinfosecurity.com/interviews/boards-directors-dont-get-it-i-1569</link>
			<guid>http://www.healthcareinfosecurity.com/interviews/boards-directors-dont-get-it-i-1569</guid>
			<description>IT risk management, cyber insurance, privacy - these are hot topics for security leaders, but not for their boards of directors. Why do senior executives still fail to see IT risks as business risks?</description>
			</item>
			<item>
			<title>How to Respond to Hacktivism</title>
			<link>http://www.healthcareinfosecurity.com/interviews/how-to-respond-to-hacktivism-i-1568</link>
			<guid>http://www.healthcareinfosecurity.com/interviews/how-to-respond-to-hacktivism-i-1568</guid>
			<description>Hacktivist attacks will increase, and researcher Gregory Nowak says organizations can take proactive steps to reduce exposure and protect brand reputation. Why, then, are many organizations failing?</description>
			</item>
			<item>
			<title>Intelligent Defense Against Intruders</title>
			<link>http://www.healthcareinfosecurity.com/interviews/intelligent-defense-against-intruders-i-1565</link>
			<guid>http://www.healthcareinfosecurity.com/interviews/intelligent-defense-against-intruders-i-1565</guid>
			<description>Imagine a computer network that can fool intruders into seeing configurations that in reality don't exist, making it hard for them to invade the system. That's what Scott DeLoach is trying to figure out how to do.</description>
			</item>
			<item>
			<title>Israel Seen Fanning Flame of New Spyware</title>
			<link>http://www.healthcareinfosecurity.com/blogs/israel-seen-fanning-flame-new-spyware-p-1280</link>
			<guid>http://www.healthcareinfosecurity.com/blogs/israel-seen-fanning-flame-new-spyware-p-1280</guid>
			<description>&lt;b&gt;Top Government Official Hints Israel is Behind Complex Malware&lt;/b&gt;&lt;br /&gt;Israel is being blamed - or, perhaps, taking credit - for the creation of Flame, the sophisticated cyberspyware that has targeted organizations in the Middle East, especially its mortal enemy, the government of Iran.</description>
			</item>
			<item>
			<title>2006 VA Breach: Assessing the Impact</title>
			<link>http://www.healthcareinfosecurity.com/blogs/2006-va-breach-assessing-impact-p-1279</link>
			<guid>http://www.healthcareinfosecurity.com/blogs/2006-va-breach-assessing-impact-p-1279</guid>
			<description>&lt;b&gt;Significant Action Taken, Lots More to Do&lt;/b&gt;&lt;br /&gt;It's been six years since the Department of Veterans Affairs experienced a huge breach. What breach-prevention steps has the VA taken since then, and what's left to be done?</description>
			</item>
			<item>
			<title>Court Clarifies HIPAA's Criminal Rules</title>
			<link>http://www.healthcareinfosecurity.com/blogs/court-clarifies-hipaas-criminal-rules-p-1274</link>
			<guid>http://www.healthcareinfosecurity.com/blogs/court-clarifies-hipaas-criminal-rules-p-1274</guid>
			<description>&lt;b&gt;When Can You Get Prison Time?&lt;/b&gt;&lt;br /&gt;A U.S. appellate court decision in a case involving a jail term for a HIPAA violator offers an important reminder of the potential consequences for accessing patient records without a valid reason.</description>
			</item>
			<item>
			<title>The Business Case for Continuity Planning</title>
			<link>http://www.healthcareinfosecurity.com/blogs/business-case-for-continuity-planning-p-1272</link>
			<guid>http://www.healthcareinfosecurity.com/blogs/business-case-for-continuity-planning-p-1272</guid>
			<description>&lt;b&gt;Small, Mid-Size Enterprises Especially Need to Develop Strategy&lt;/b&gt;&lt;br /&gt;Why do so many small and mid-sized enterprises continue to believe that business continuity planning is just for the big guys? And how do we go about convincing them otherwise? Here are some tips.</description>
			</item></channel></rss>

