<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Datamountain</title>
	<atom:link href="http://www.datamountain.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.datamountain.com</link>
	<description>Saving Your Assets. All Day. Everyday.</description>
	<lastBuildDate>Sat, 21 Jan 2012 21:45:31 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>December 2010 HIPAA-HITECH Compliance eNewsletter Published</title>
		<link>http://www.datamountain.com/news/december-2010-hipaa-hitech-compliance-enewsletter-published/</link>
		<comments>http://www.datamountain.com/news/december-2010-hipaa-hitech-compliance-enewsletter-published/#comments</comments>
		<pubDate>Thu, 02 Dec 2010 16:29:30 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=2113</guid>
		<description><![CDATA[Dear Data-Diligent Reader, Our December 2010 HIPAA-HITECH eNewsletter has been published. Link to our December 2010 HIPAA-HITECH Compliance eNewsletter to learn more &#8230; HIPAA-HITECH data protection and security updates, alerts and tips of importance to everyone striving to protect their valuable business, client and patient data. We continue to feature HIPAA Security Rule and HITECH [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>Our<a title="October 2010 HIPAA-HITECH Compliance eNewsletter" href="http://www.datamountain.com/resources/data-protection-enewsletters/"> December 2010 HIPAA-HITECH eNewsletter </a>has been published.</p>
<div><strong>Link to our <a title="October 2010 HIPAA-HITECH Compliance eNewsletter" href="http://www.datamountain.com/resources/data-protection-enewsletters/">December 2010 HIPAA-HITECH Compliance eNewsletter </a>to learn more</strong> &#8230; HIPAA-HITECH data protection and security updates, alerts and tips of importance to everyone striving to protect their valuable business, client and patient data.</div>
<p>We continue to feature HIPAA Security Rule and HITECH Act data security updates, including the link to the <a title="HHS Wall of Shame" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html" target="_blank">US Department of Health and Human Services&#8217; &#8220;Wall of Shame&#8221; </a>&#8211; its Data Breach Notification web page.</p>
<p>Attend our Upcoming Complimentary Live Webinar on:</p>
<ul>
<li><strong><a title="How to Revitalize Your HIPAA-HITECH Compliance Program" href="https://www1.gotomeeting.com/register/773374513" target="_blank">How to Revitalize Your HIPAA-HITECH Compliance Program</a> </strong></li>
</ul>
<p>Please <a title="September 2010 HIPAA-HITECH eNewsletter" href="http://www.datamountain.com/resources/data-protection-enewsletters/">enjoy our analysis and links to industry articles and white papers </a>that we&#8217;ve researched and assembled for you. I&#8217;m confident you&#8217;ll find a nugget or two among them!</p>
<p><em><strong>We would love to hear your thoughts. Please comment below!</strong></em></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a>. View one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fdecember-2010-hipaa-hitech-compliance-enewsletter-published%2F&amp;title=December%202010%20HIPAA-HITECH%20Compliance%20eNewsletter%20Published" id="wpa2a_2"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/december-2010-hipaa-hitech-compliance-enewsletter-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Compare Server Online Backup and Recovery Service Providers</title>
		<link>http://www.datamountain.com/news/how-to-compare-server-online-backup-and-recovery-service-providers/</link>
		<comments>http://www.datamountain.com/news/how-to-compare-server-online-backup-and-recovery-service-providers/#comments</comments>
		<pubDate>Thu, 18 Nov 2010 15:00:05 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[HIPAA Security Law]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1619</guid>
		<description><![CDATA[Dear Data-Diligent Reader, IT professionals are increasingly looking to online backup and recovery (or “cloud storage”) services when it comes to server data protection. These solutions are especially relevant for small to medium-sized businesses and for the remote offices of larger enterprises. But with all the choices today, how do you decide what is right [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>IT professionals are increasingly looking to online backup and recovery (or “cloud storage”) services when it comes to server data protection. These solutions are especially relevant for small to medium-sized businesses and for the remote offices of larger enterprises. But with all the choices today, how do you decide what is right for your company?</p>
<p>The factors driving interest in online backup and recovery solutions include: workforce dependency on 24&#215;7 access to business data; price and consistency of a Software-as-a-Service (SaaS) subscription model over costlier onsite options; and easier compliance with burgeoning requirements to protect distributed information (in all formats) and ensure business continuity.</p>
<p>The scope, strengths, and weaknesses of the various categories of online backup and recovery service provider should be evaluated in the context of the current and forward-looking requirements of corporate customers. Requirements range from full system (versus data only) backup and restore to comprehensive business continuity best practices and support. Understanding these strengths and weaknesses can help businesses clarify their server protection requirements and better align their selection criteria and focus with their business goals.</p>
<p>Unlike workstations and laptops, servers:</p>
<p>• Are usually left running, rather than frequently powered on and off, and are not mobile<br />
• Require broader bandwidth requirements due to the volume of the data to be protected<br />
• Store a wide variety of data types of varying importance and recovery or retention requirements</p>
<p><strong>Category 1: Service Providers Leveraging Investments In Core Business Resources</strong> These service providers includes companies whose entry into online backup and recovery is driven by a desire to leverage pre-existing investments in core business resources. These include 1) business continuity and disaster recovery and 2) telecommunications vendors.</p>
<p><strong>Category 2: Niche Developers and Service Providers</strong> Service providers in this category concentrate on niche solutions and market opportunities. These include:<br />
1) “Point solution” backup and recovery services using their own software exclusively for backup and recovery and<br />
2) Providers who use other vendors’ specialized solutions to address niche markets in specific verticals, company size, or geographic regions.</p>
<p><strong>Category 3: Broader Spectrum Service Providers</strong> Like the point solution and licensed software developers, these service providers own and maintain their own software. Most obtained their backup and recovery technology through the acquisition of the original software developer, but the important point is they continue to invest in its maintenance and extension. These service providers typically offer most of the essential features for server backup and recovery.  Backup and recovery is offered as part of a broader spectrum of information management and data protection services</p>
<p>It is important to recognize the different categories of online backup and recovery service providers. Recognizing the basic differences in their business drivers and focus, potential resources, and core competencies is key when it comes to assessing their capabilities.  By understanding these larger business criteria, businesses can better focus and align their business goals with the right partner when it comes to online backup and recovery.</p>
<p>You should be able to compare the various providers against their ability to address your requirements for server backup and recovery functionality, administration and support.</p>
<p>We believe that that choosing a cloud storage vendor is an important decision.  Contact us to learn how we may be able to help you.</p>
<p><strong><em>We would love to hear your thoughts. Please comment below!</em></strong></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a> . Attend our Complimentary Live Webinars on data protection, online data backup and recovery and data security. <a href="/resources/data-protection-webinars/" target="_blank">Register today!</a> Or, view one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fhow-to-compare-server-online-backup-and-recovery-service-providers%2F&amp;title=How%20to%20Compare%20Server%20Online%20Backup%20and%20Recovery%20Service%20Providers" id="wpa2a_4"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/how-to-compare-server-online-backup-and-recovery-service-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More Data? More Choices!</title>
		<link>http://www.datamountain.com/news/more-data-more-choices/</link>
		<comments>http://www.datamountain.com/news/more-data-more-choices/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 15:00:59 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[HIPAA Security Law]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1623</guid>
		<description><![CDATA[Dear Data-Diligent Reader, Today most companies are facing challenges when it comes to protecting their data.  There’s more of it.  And protecting the data properly is more important than ever.  But there are also more choices.  How do you decide what is right for you? Start by understanding what your data protection strategy should be. [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>Today most companies are facing challenges when it comes to protecting their data.  There’s more of it.  And protecting the data properly is more important than ever.  But there are also more choices.  How do you decide what is right for you? Start by understanding what your data protection strategy should be.</p>
<p>Your business relies on its data. There’s more of it than ever, but more important, its value keeps multiplying. Companies are putting their information to work in new ways as they connect systems, transform business processes, and extend their relationships over the Internet with customers, partners and suppliers. Unfortunately, the risks from data loss or exposure have grown, too. The always-on world of e-commerce and companies’ increasingly distributed and mobile workforces have made data more vulnerable. Moreover, senior executives have to worry about maintaining regulatory compliance while mitigating the risk of litigation.</p>
<p><strong>Do You Have A Data Protection Strategy?</strong> How can you ensure that your company is embracing the right combination of technologies and processes for a complete data protection strategy? Unfortunately, it’s easy to make the wrong choices.  Some companies assume a do-it-yourself approach, which can leave them open to unidentified risks.</p>
<p>An outsourcing partner who provides online disk-based backup can solve a number of the issues that organizations confront when supporting their business continuity, data retention and security requirements. The key advantage is that the data, stored off-site, is protected from unauthorized access and will survive a disaster.</p>
<p>Online backup combines better cost characteristics with superior reliability and world-class security. The great news for smaller businesses and remote offices of larger businesses<br />
is that online disk-based backup services have matured in technology reliability and decreased in cost.  Today, online backup is often less expensive than tape backup alternatives.</p>
<p><strong>Get Ready For Your Annual Data Protection Physical! </strong>Companies have different requirements when it comes to their recovery needs, data sensitivity, retention requirements and cost.  And these can evolve and change. Deciding which backup solution, or solutions, to use is just the start of what should be an annual process of testing data protection and recovery strategies to ensure they remain in line with business requirements. A great plan, a great vendor and getting data off-site are a good start, but you need to test the whole process, not only to ensure everyone knows what they are doing but to identify potential gaps in the process that need attention. And as the business changes, your plan needs to change with it to meet any new requirements.  </p>
<p><strong><em>We would love to hear your thoughts. Please comment below!</em></strong></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a> . Attend our Complimentary Live Webinars on data protection, online data backup and recovery and data security. <a href="/resources/data-protection-webinars/" target="_blank">Register today!</a> Or, view one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fmore-data-more-choices%2F&amp;title=More%20Data%3F%20More%20Choices%21" id="wpa2a_6"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/more-data-more-choices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Selling Cloud Storage To Your CFO (I know one!)</title>
		<link>http://www.datamountain.com/news/selling-cloud-storage-to-your-cfo/</link>
		<comments>http://www.datamountain.com/news/selling-cloud-storage-to-your-cfo/#comments</comments>
		<pubDate>Thu, 04 Nov 2010 15:00:12 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[HIPAA Security Law]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1617</guid>
		<description><![CDATA[Dear Data-Diligent Reader, Chief Financial Officers typically care about three things when it comes to assessing new investments in IT.  They are:  1) Speed, 2) Focus and 3) Affordability.   I know this first hand! The key is to understand how replacing your current server and/or PC data protection processes with a cloud storage solution would [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>Chief Financial Officers typically care about three things when it comes to assessing new investments in IT.  They are:  1) Speed, 2) Focus and 3) Affordability.   I know this first hand! The key is to understand how replacing your current server and/or PC data protection processes with a cloud storage solution would address these three areas of concern.</p>
<p>In today’s economic environment, every spending proposal needs to have solid justification.  Often just speaking about a shift to a “pay-as-you-go” model is enough to get the CFO’s attention.  But the appeal of cloud storage extends beyond its financial benefits.  Here are three key benefits companies are realizing today when adopting cloud storage:</p>
<p><strong>Focus:</strong> Companies want to focus on their core competencies, and outsource the rest to experts.  Are you still doing your own payroll?  Using a cloud storage provider allows your IT department to focus on projects that drive the business, such as customer service or e-commerce applications.  And cloud storage providers have the expertise to optimize their operations for better efficiencies.</p>
<p><strong>Speed:</strong> How often have you been involved in IT projects that took longer than expected?  Chances are your CFO has felt the same pain.  Quick ROI is everything, and when it comes to competing for funding, decisions are being made about when companies can expect to see valuable returns for their investments.  This theme is a key one driving the adoption of cloud computing today.</p>
<p><strong>Affordability:</strong> In addition to the “pay-as-you-go” model, cloud storage is appealing because it offers flexibility.  As a company you aren’t paying up front, predicting your storage requirements and investing in the hardware and software to support those requirements.  Instead you pay for what you use.  As you scale or reduce your demand.</p>
<p>With capital at a premium, and companies looking for faster returns from their investments, another appeal of cloud storage services is that they typically can be funded from the Operating Expense (OpEx) budget, without sunken Capital Expenditures (“CAPEX”).  This approach allows you to match the cost of the service to the period in which it is consumed.</p>
<p>If you aren’t already outsourcing your data backup and recovery, then its time you took a look at the cloud storage model.  Today’s solutions can provide you and your company with the technical functionality to protect your data better than you can probably do it in-house, with none of the headaches.  The 1-2-3 message of “Focus + Speed + Affordability” is often enough to cause any company to evaluate cloud storage. </p>
<p>Data Mountain has been providing world-class cloud storage solutions since 2003, through our service partner, Iron Mountain Digital, and we truly understand what it takes to securely protect corporate information in the cloud.  Contact us to learn more if you think we may be able to help you.</p>
<p><strong><em>We would love to hear your thoughts. Please comment below!</em></strong></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a> . Attend our Complimentary Live Webinars on data protection, online data backup and recovery and data security. <a href="/resources/data-protection-webinars/" target="_blank">Register today!</a> Or, view one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fselling-cloud-storage-to-your-cfo%2F&amp;title=Selling%20Cloud%20Storage%20To%20Your%20CFO%20%28I%20know%20one%21%29" id="wpa2a_8"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/selling-cloud-storage-to-your-cfo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Three Important HIPAA-HITECH Compliance Webinars</title>
		<link>http://www.datamountain.com/news/three-important-hipaa-hitech-compliance-webinars/</link>
		<comments>http://www.datamountain.com/news/three-important-hipaa-hitech-compliance-webinars/#comments</comments>
		<pubDate>Wed, 03 Nov 2010 15:16:02 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Business Associate]]></category>
		<category><![CDATA[business associate contract]]></category>
		<category><![CDATA[Guidance on Risk]]></category>
		<category><![CDATA[hipaa compliance]]></category>
		<category><![CDATA[HIPAA risk analysis]]></category>
		<category><![CDATA[hipaa security assessment]]></category>
		<category><![CDATA[HIPAA-HITECH]]></category>
		<category><![CDATA[hipaa-hitech assessment]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=2104</guid>
		<description><![CDATA[Just a short note to let you know we are offering three (3) 90 minute Complimentary Live Webinars that you have requested. During the month of November, we are pleased to offer: 11/11, 330pm ET &#8211; Are Your Business Associate Contracts HITECH Ready? 11/16, 330pm ET &#8211; How to Revitalize Your HIPAA-HITECH Compliance Program  11/30, 330pm ET &#8211; How [...]]]></description>
			<content:encoded><![CDATA[<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;">Just a short note to let you know we are offering three (3) 90 minute Complimentary Live Webinars that you have requested. During the month of November, we are pleased to offer:</span></span></div>
<div style="text-align: left;">
<ul>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong><a title="Are Your Business Associate Contracts HITECH Ready?" rel="1111, 330pm ET - Are Your Buisness Associate Contracts HITECH Ready?" href="https://www1.gotomeeting.com/register/170726377" target="_blank">11/11, 330pm ET &#8211; Are Your Business Associate Contracts HITECH Ready?</a></strong></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong><a title="How To Revitalize Your HIPAA-HITECH Compliance Program" rel="1116, 330pm ET - How to Revitalize Your HIPAA-HITECH Compliance Program" href="https://www1.gotomeeting.com/register/498778288" target="_blank"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong>11/16, 330pm ET &#8211; </strong></span></span>How to Revitalize Your HIPAA-HITECH Compliance Program</a> </strong></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong><a title="How To Conduct a HIPAA Security Risk Analysis" rel="1130, 330pm ET - How to Conduct a HIPAA Security Risk Analysis" href="https://www1.gotomeeting.com/register/773374513" target="_blank"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong>11/30, 330pm ET &#8211; </strong></span></span>How to Conduct a HIPAA Security Risk Analysis</a></strong></span></span></span></span></li>
</ul>
</div>
<div>
<div>
<table style="width: 610px; height: 201px;" border="0" cellspacing="3" cellpadding="3">
<tbody>
<tr valign="top">
<td width="40%" valign="top">
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><a title="Are Your Business Associate Contracts HITECH Ready?" href="https://www1.gotomeeting.com/register/170726377" target="_blank"><img class="alignleft size-full wp-image-1224" title="logo_hta" src="http://hipaasecurityassessment.com/wp-content/uploads/2010/11/BA_Contract_documentation_iStock_000004968090XSmall_200x132.jpg" alt="" width="200" height="132" /></a></span></span></div>
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"> </span></span></div>
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: verdana, geneva;"><span style="color: #00906f;"><span style="font-size: 12pt;"><strong><span style="color: #000088;"><a title="text_Are Your Business Associate Contracts HITECH Ready" rel="Are Your Business Associate Contracts HITECH Ready?" href="https://www1.gotomeeting.com/register/170726377">Are Your Business Associate Contracts HITECH Ready?</a></span></strong></span></span></span></span></span></div>
</td>
<td width="60%">
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><strong><a title="Are Your Business Associate Contracts HITECH Ready?" rel="Register Now - Are Your Business Associate Contracts HITECH Ready? " href="https://www1.gotomeeting.com/register/170726377" target="_blank">Register Now! - Are Your Business Associate Contracts HITECH Ready? </a></strong></span></span></span></span></span></span></span></span></span></span></div>
<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Learn from Mayra Scheuermann, Esq. and Carlos Leyva, Esq. why you need HITECH-ready Business Associate (BA) Contracts. In this webinar, attendees will benefit by learning: </span></span></span></span></span></span></span></span></span></span></div>
<ul style="text-align: left;">
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">How frequently BAs are invloved in data breaches</span></span></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Reporting requirements of BAs</span></span></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">New BA contract requirements</span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Tools and resources available to make your BA contracts HITECH-ready</span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">View a demo of our </span></span></span></span><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><a title="BA Agreement ToolKit" rel="HIPAA-HITECH Business Associate Contract ToolKit™" href="http://hipaasecurityassessment.com/hipaa-compliance-software/hipaa-hitech-business-associate-agreement/" target="_blank">HIPAA-HITECH Business Associate Contract ToolKit™</a></span></span></span></span></span></span></li>
</ul>
</td>
</tr>
</tbody>
</table>
</div>
<div>
<table style="width: 610px; height: 201px;" border="0" cellspacing="3" cellpadding="3">
<tbody>
<tr valign="top">
<td width="40%" valign="top">
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><a title="image_How To Revitalize Your HIPAA-HITECH Compliance Program" href="https://www1.gotomeeting.com/register/498778288" target="_blank"><img class="alignleft size-full wp-image-1224" title="logo_hta" src="http://hipaasecurityassessment.com/wp-content/uploads/2010/07/HIPPA_Security_Assessment_Toolkit_icon_200x180.jpg" alt="" width="200" height="180" /></a></span></span></div>
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"> </span></span></div>
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: verdana, geneva;"><span style="color: #00906f;"><span style="font-size: 12pt;"><strong><span style="color: #000088;"><a title="How To Revitalize Your HIPAA-HITECH Compliance Program" rel="How to Revitalize Your HIPAA-HITECH Compliance Program" href="https://www1.gotomeeting.com/register/498778288" target="_blank">How to Revitalize Your HIPAA-HITECH Compliance Program</a></span></strong></span></span></span></span></span></div>
</td>
<td width="60%">
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><a title="How To Revitalize Your HIPAA-HITECH Compliance Program" rel="HOW TO REVITALIZE YOUR HIPAA-HITECH COMPLIANCE PROGRAM - Register Now" href="https://www1.gotomeeting.com/register/498778288" target="_blank"><strong>Register Now! &#8211; HOW TO REVITALIZE YOUR HIPAA-HITECH COMPLIANCE PROGRAM </strong></a></span></span></span></span></span></span></span></span></span></span></div>
<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Whether you&#8217;re a Covered Entity (CE), a Business Associate (BA) or a subcontractor, if you receive, store, process or transmit ePHI, you need to attend.  In this webinar, attendees will: </span></span></span></span></span></span></span></span></span></span></div>
<ul style="text-align: left;">
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Review the HIPAA Security Final Rule</span></span></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Learn about major changes brought about by The HITECH Act</span></span></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Learn about the new Civil Monetary Penalty System</span></span></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Learn practical, actionable steps to take today to mitigate risk and help assure compliance</span></span></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Learn how to jump-start their program with a HIPAA Security Evaluation (45 CFR §164.308(a)(8))</span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">View a demo of our </span></span></span></span><a title="HIPAA Security Assessment ToolKit(tm)" rel="HIPAA-HITECH Security Assessment ToolKit™" href="http://hipaasecurityassessment.com/hsa-toolkit-videos/" target="_blank"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">HIPAA-HITECH Security Assessment ToolKit™</span></span></span></span></a></span></span></li>
</ul>
</td>
</tr>
</tbody>
</table>
</div>
<div>
<table style="width: 610px; height: 201px;" border="0" cellspacing="3" cellpadding="3">
<tbody>
<tr valign="top">
<td width="40%" valign="top">
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><a title="image_How to Conduct a HIPAA Security Risk Analysis" href="https://www1.gotomeeting.com/register/773374513" target="_blank"><img class="alignleft size-full wp-image-1224" title="logo_hta" src="http://hipaasecurityassessment.com/wp-content/uploads/2010/11/risk_analysis_iStock_000010738312XSmall_200x300.jpg" alt="" width="200" height="300" /></a></span></span></div>
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: verdana, geneva;"><span style="color: #00906f;"><span style="font-size: 12pt;"><strong><span style="color: #000088;"><a title="How To Conduct a HIPAA Security Risk Analysis" rel="How To Conduct a HIPAA Security Risk Analysis" href="https://www1.gotomeeting.com/register/773374513" target="_blank">How to Conduct a HIPAA Security Risk Analysis </a></span></strong></span></span></span></span></span></div>
</td>
<td width="60%">
<div style="text-align: center;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><strong>Register Now! - How to Conduct a HIPAA Security Risk Analysis</strong></span></span></span></span></span></span></div>
<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: tahoma, arial, helvetica, sans-serif;"><span style="font-size: 11pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 18pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">A HIPAA Security Risk Analysis (§164.308(a)(1)(ii)(A)) is also required by law to be performed by every Covered Entity and Business Associate. Discover how to achieve HIPAA-HITECH compliance with this Required Implementation Specification. In this webinar, attendees will learn about: </span></span></span></span></span></span></span></span></span></span></div>
<ul>
<li style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 18pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Risk Analysis essentials</span></span></span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 18pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Specific requirements outlined in HHS/OCR Final Guidance</span></span></span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 18pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-size: 10pt;">A Practical Risk Analysis Methodology</span></span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 18pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-size: 10pt;">Step-by-Step Instructions for completing a HIPAA Risk Analysis</span></span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 18pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-size: 10pt;">Resources available to help you</span></span></span></span></span></span></span></li>
<li style="text-align: left;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">Our </span></span></span></span><a title="HIPAA Security Risk Analysis ToolKit(tm)" href="http://hipaasecurityassessment.com/hipaa-compliance-software/hipaa-hitech-security-risk-analysis-toolkit/" target="_blank"><span style="font-family: helvetica;"><span style="font-size: 12pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;">HIPAA-HITECH Risk Analysis ToolKit™</span></span></span></span></a></span></span></li>
</ul>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;">We hope you can join us and benefit from our expertise! <strong>Register today:</strong></span></span></div>
<div style="text-align: left;">
<ul>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong><a title="Are Your Business Associate Contracts HITECH Ready?" rel="1111, 330pm ET - Are Your Buisness Associate Contracts HITECH Ready?" href="https://www1.gotomeeting.com/register/170726377" target="_blank">11/11, 330pm ET &#8211; Are Your Business Associate Contracts HITECH Ready?</a></strong></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong><a title="How To Revitalize Your HIPAA-HITECH Compliance Program" rel="1116, 330pm ET - How to Revitalize Your HIPAA-HITECH Compliance Program" href="https://www1.gotomeeting.com/register/498778288" target="_blank"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong>11/16, 330pm ET &#8211; </strong></span></span>How to Revitalize Your HIPAA-HITECH Compliance Program</a> </strong></span></span></span></span></li>
<li><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong><a title="How To Conduct a HIPAA Security Risk Analysis" rel="1130, 330pm ET - How to Conduct a HIPAA Security Risk Analysis" href="https://www1.gotomeeting.com/register/773374513" target="_blank"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><strong>11/30, 330pm ET &#8211; </strong></span></span>How to Conduct a HIPAA Security Risk Analysis</a></strong></span></span></span></span></li>
</ul>
<p><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;">Write to us with any questions you may have!</span></span></p>
</div>
<div> </div>
<div>
<table style="width: 626px; height: 105px;" border="0" cellspacing="0" cellpadding="0">
<tbody>
<tr style="text-align: center;">
<td width="250" valign="top">
<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;"><a href="mailto:bob.chaput@h3ca.com">bob.chaput@H3CA.com</a></span></span></div>
<div style="text-align: left;"><span style="font-size: 10pt;"><span style="font-family: verdana, geneva;">800-704-3394</span></span></div>
</td>
</tr>
</tbody>
</table>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fthree-important-hipaa-hitech-compliance-webinars%2F&amp;title=Three%20Important%20HIPAA-HITECH%20Compliance%20Webinars" id="wpa2a_10"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/three-important-hipaa-hitech-compliance-webinars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>November 2010 HIPAA-HITECH Compliance eNewsletter Published</title>
		<link>http://www.datamountain.com/news/november-2010-hipaa-hitech-compliance-enewsletter-published/</link>
		<comments>http://www.datamountain.com/news/november-2010-hipaa-hitech-compliance-enewsletter-published/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 15:55:25 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection enewsletter]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data protection services firm]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Security Rule]]></category>
		<category><![CDATA[HIPAA-HITECH]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[online data backup and recovery]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=2093</guid>
		<description><![CDATA[Dear Data-Diligent Reader, Our November  2010 HIPAA-HITECH eNewsletter has been published. Link to our November 2010 HIPAA-HITECH Compliance eNewsletter to learn more &#8230; HIPAA-HITECH data protection and security updates, alerts and tips of importance to everyone striving to protect their valuable business, client and patient data. We continue to feature HIPAA Security Rule and HITECH Act data [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>Our <a title="October 2010 HIPAA-HITECH Compliance eNewsletter" href="http://www.datamountain.com/resources/data-protection-enewsletters/">November  2010 HIPAA-HITECH eNewsletter </a>has been published.</p>
<div><strong>Link to our <a title="October 2010 HIPAA-HITECH Compliance eNewsletter" href="http://www.datamountain.com/resources/data-protection-enewsletters/">November 2010 HIPAA-HITECH Compliance eNewsletter </a>to learn more</strong> &#8230; HIPAA-HITECH data protection and security updates, alerts and tips of importance to everyone striving to protect their valuable business, client and patient data.</div>
<p>We continue to feature HIPAA Security Rule and HITECH Act data security updates, including the link to the <a title="HHS Wall of Shame" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html" target="_blank">US Department of Health and Human Services&#8217; &#8220;Wall of Shame&#8221; </a>&#8211; its Data Breach Notification web page.</p>
<p>Attend our Upcoming Complimentary Live Webinars on:</p>
<ul>
<li><strong><a title="Are Your Business Associate Agreements HITECH Ready?" href="http://e2ma.net/go/8765947145/3201818/99981367/36048/goto:https:/www1.gotomeeting.com/register/170726377" target="_blank">Are Your Business Associate Agreements HITECH Ready?</a></strong></li>
<li><strong><a title="How to Conduct a HIPAA Security Risk Analysis" href="http://e2ma.net/go/8765947145/3201818/99981368/36048/goto:https:/www1.gotomeeting.com/register/773374513" target="_blank">How To Conduct a HIPAA Security Risk Analysis</a></strong></li>
<li><strong><a title="How To Revitalize Your HIPAA-HITECH Compliance Program" href="http://e2ma.net/go/8765947145/3201818/99981369/36048/goto:https:/www1.gotomeeting.com/register/498778288" target="_blank">How to Revitalize Your HIPAA-HITECH Compliance Program </a></strong></li>
</ul>
<p>Please <a title="September 2010 HIPAA-HITECH eNewsletter" href="http://www.datamountain.com/resources/data-protection-enewsletters/">enjoy our analysis and links to industry articles and white papers </a>that we&#8217;ve researched and assembled for you. I&#8217;m confident you&#8217;ll find a nugget or two among them!</p>
<p><em><strong>We would love to hear your thoughts. Please comment below!</strong></em></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a>. View one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fnovember-2010-hipaa-hitech-compliance-enewsletter-published%2F&amp;title=November%202010%20HIPAA-HITECH%20Compliance%20eNewsletter%20Published" id="wpa2a_12"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/november-2010-hipaa-hitech-compliance-enewsletter-published/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Going Green?  Go Underground!</title>
		<link>http://www.datamountain.com/news/going-green-go-underground/</link>
		<comments>http://www.datamountain.com/news/going-green-go-underground/#comments</comments>
		<pubDate>Thu, 28 Oct 2010 15:03:12 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[HIPAA Security Law]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1614</guid>
		<description><![CDATA[Dear Data-Diligent Reader, For some companies, including Marriott, abandoned mines and military bunkers offer a subterranean safe haven from hurricanes and other threats. But there are additional advantages to be realized when it comes to protecting your data underground. Our service partner, Iron Mountain, is among the oldest and best known providers of underground storage [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>For some companies, including Marriott, abandoned mines and military bunkers offer a subterranean safe haven from hurricanes and other threats. But there are additional advantages to be realized when it comes to protecting your data underground.</p>
<p>Our service partner, Iron Mountain, is among the oldest and best known providers of underground storage and data center space. Known for storing everything from backup tapes to old movie reels in its repurposed limestone mine in rural Pennsylvania, Iron Mountain has seen its electronic storage and leased data center space business increase significantly.  With 60,000 square feet of available data center space and another 145 acres undeveloped in the facility, Iron Mountain has plenty of room for more.</p>
<p>What is driving an interest in Iron Mountain’s underground and other specialized hardened data centers? Some companies have found that there is a general lack of high-end infrastructure &#8211; enterprise-class data center space. Others have very specific requirements to protect them from natural disasters.</p>
<p>Not all hardened data centers are created equal.  While computer systems may be protected in a bunker, critical infrastructure needed during a disaster, such as generators, fuel tanks and air conditioning cooling towers, may be above ground. That could be a problem if the catastrophe you need to worry about is a tornado.</p>
<p>Are you going to pay a premium if you locate your computing resources in such a hardened environment?   IT executives say they&#8217;ve driven deals where the total cost of ownership is competitive with above-ground facilities. Because they&#8217;re repurposing existing space that the government or a mine operator paid to build, providers say they don&#8217;t have to pass on the original construction costs for the structures and can afford to be cost competitive.</p>
<p>Another consideration is that these underground facilities tend to be in rural, out-of-the-way locations. The facilities may be too far away from a company&#8217;s primary data center, and finding local lodging for staff in a disaster situation may be difficult. Marriott International wanted a hardened, secure facility in a location that was within a day&#8217;s drive from Marriott&#8217;s Bethesda, Md., headquarters.  That led them to Iron Mountain’s underground facility in Pennsylvania.</p>
<p>Underground facilities do have a few other advantages. The limestone floors at Iron Mountain’s facility have a virtually unlimited load rating, while the walls maintain a constant temperature of about 55 degrees and act like a heat sink for some of the waste heat that comes off data center equipment. The limestone walls absorb 1.5 BTUs per hour per sq. foot of wall space.</p>
<p><strong>Cool stuff</strong><br />
The green aspect of going underground is what attracted Marriott International. It wanted to move from an outsourced &#8220;cold site&#8221; disaster recovery service to managing its own hot site backup data center. And it wanted to make sure the facility followed the company&#8217;s focus on environmentally friendly best practices.</p>
<p>Last year, the hospitality business completed the build-out of a 9,000 sq. foot remote backup data center at Iron Mountain’s Underground. Although the extreme level of security, including armed guards, exceeded their requirements, the idea of reusing an old mine rather than breaking new ground appealed to Marriott.</p>
<p>Energy efficiency also factored into Marriott&#8217;s decision. While Marriott&#8217;s data center uses a traditional chiller as its primary cooling system, the backup is a prototype free cooling system. That prototype, designed by Iron Mountain, uses an air-to-air heat exchanger, drawing 55-degree air from the unused space within the mine. Iron Mountain also is experimenting with a system that would pull cool water from an underground lake within the mine.</p>
<p><strong><em>We would love to hear your thoughts. Please comment below!</em></strong></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a> . Attend our Complimentary Live Webinars on data protection, online data backup and recovery and data security. <a href="/resources/data-protection-webinars/" target="_blank">Register today!</a> Or, view one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fgoing-green-go-underground%2F&amp;title=Going%20Green%3F%20%20Go%20Underground%21" id="wpa2a_14"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/going-green-go-underground/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Establishing a Data Retention Policy</title>
		<link>http://www.datamountain.com/news/establishing-a-data-retention-policy/</link>
		<comments>http://www.datamountain.com/news/establishing-a-data-retention-policy/#comments</comments>
		<pubDate>Thu, 21 Oct 2010 15:00:22 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[HIPAA Security Law]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1611</guid>
		<description><![CDATA[Dear Data-Diligent Reader, Establishing a policy on how long data must be retained sounds easy enough. It isn&#8217;t. For starters, not all data is the same.  If you are protecting everything, or are uncertain if data is being protected properly, then it is time to build and implement a data retention policy. Some companies realize [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>Establishing a policy on how long data must be retained sounds easy enough. It isn&#8217;t. For starters, not all data is the same.  If you are protecting everything, or are uncertain if data is being protected properly, then it is time to build and implement a data retention policy.</p>
<p>Some companies realize they need a proper data retention policy when they examine their storage costs.  Others realize gaps when they go through a litigation hold.</p>
<p>What happens if your company requires you to retain certain data forever? One company’s IT director related how for several years they had been forbidden to overwrite any data related to e-mail, home directories, financial systems and several other document repositories and systems. Being barred from overwriting backup tapes comes at a cost – they were spending about US$40,000 a month just for new tapes. More costs arose because they were prohibited from overwriting the hard drives of departed employees. At least that cost was alleviated recently with a new initiative to capture images of those hard drives before reassigning them to other employees.  It wasn’t until the IT director spoke to the company’s inside counsel that they created an appropriate retention policy that allowed them to move away from their “protect everything” policy.</p>
<p>Data retention policies are fairly straightforward documents that establish how long information must be kept on hand, unaltered. The problem is that different types of data must be retained for different lengths of time. Most data-retention policies open with a policy statement, followed by a retention schedule that lists every possible type of information that the company could have in its stores and the required retention period. There are also special instructions for archiving and for the ultimate destruction of the data, once the time limit has been exceeded. The policy is also likely to include procedures for retaining information when litigation is under way.</p>
<p>A comprehensive data-retention schedule requires a considerable amount of data-gathering. For example, you need to know the general nature of all data held in servers, in storage, on backup tapes and on individual PCs. That includes both active data &#8212; e-mail, chat logs, UNIX system logs, and firewall and VPN logs, for example &#8212; and inactive data such as documentation related to sales, service, legal and finance.</p>
<p>Another complication arises from being a global organization.  You need to look across the various markets that you serve and understand relevant data retention and privacy requirements. Some regulations extend to e-mail messages containing price negotiations. The key is to develop a policy to keep employees from deleting data that they think would hurt the company if discovered.</p>
<p>Creating a data retention policy is not easy.  Just identifying the various data custodians can be a challenge. But this shouldn’t be a task that you ignore.  Just like having a good disaster recovery plan, having a data retention policy will pay dividends, both when it comes to finding and presenting the data that you need in a hurry, and through storage cost reductions.    Here is <a href="http://www.computerworld.com/s/article/9089018/Four_tips_for_crafting_a_document_retention_policy">link</a> to a good article that can help you get started.</p>
<p><strong><em>We would love to hear your thoughts. Please comment below!</em></strong></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a> . Attend our Complimentary Live Webinars on data protection, online data backup and recovery and data security. <a href="/resources/data-protection-webinars/" target="_blank">Register today!</a> Or, view one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Festablishing-a-data-retention-policy%2F&amp;title=Establishing%20a%20Data%20Retention%20Policy" id="wpa2a_16"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/establishing-a-data-retention-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Security Evaluation &#8211; HIPAA Risk Analysis &#8211; Explained</title>
		<link>http://www.datamountain.com/news/hipaa-compliance-assessment-hipaa-risk-analysis-explained/</link>
		<comments>http://www.datamountain.com/news/hipaa-compliance-assessment-hipaa-risk-analysis-explained/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 17:05:25 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Business Associate]]></category>
		<category><![CDATA[Covered Entity]]></category>
		<category><![CDATA[Guidance on Risk]]></category>
		<category><![CDATA[HIPAA Compliance Assessment]]></category>
		<category><![CDATA[HIPAA Policies and Procedures]]></category>
		<category><![CDATA[HIPAA risk analysis]]></category>
		<category><![CDATA[HIPAA Security Compliance Assessment]]></category>
		<category><![CDATA[HIPAA Security Compliance program]]></category>
		<category><![CDATA[HIPAA Security Final Rule]]></category>
		<category><![CDATA[HIPAA Security Risk Analysis]]></category>
		<category><![CDATA[Meaningful Use]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=2075</guid>
		<description><![CDATA[Compliance assessment? Security Evaulation? Risk Assessment? Risk Analysis? Compliance Analysis? Huh? Lots of confusion continues to swirl around the difference between a HIPAA Security Evaluation versus HIPAA Security Risk Analysis.  No wonder, the terms are often used interchangeably. Let’s end the confusion… Technically, one might argue when it comes to regulatory compliance of any type, [...]]]></description>
			<content:encoded><![CDATA[<h2><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri;"><span style="color: #000000;">Compliance assessment? Security Evaulation? Risk Assessment? Risk Analysis? Compliance Analysis?</span></span></span></h2>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri;"><span style="color: #000000;">Huh?</span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri;"><span style="color: #000000;">Lots of confusion continues to swirl around the difference between a HIPAA Security Evaluation versus HIPAA Security Risk Analysis.<span style="mso-spacerun: yes;">  </span>No wonder, the terms are often used interchangeably.</span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri;"><span style="color: #000000;">Let’s end the confusion…</span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri;"><span style="color: #000000;">Technically, one might argue when it comes to regulatory compliance of any type, three types of assessments can be completed:</span></span></span></p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="color: #000000;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: ignore;"><span style="font-family: Calibri;">1.</span><span style="font: 7pt 'times new roman';">      </span></span></span><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">Compliance Assessments</span></strong><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"> (<strong>Evaluation,</strong> in HIPAA Security Final Rule parlance) answer questions like: “Where do we stand with respect to the regulations?” and “How well are we achieving ongoing compliance?”</span></span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="color: #000000;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: ignore;"><span style="font-family: Calibri;">2.</span><span style="font: 7pt 'times new roman';">      </span></span></span><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">Risk Assessments (Analysis</span></strong><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">, in HIPAA Security Final Rule parlance) answer questions like: “What is our risk exposure to information assets (e.g., PHI)?” and “What do we need to do to mitigate risks?” </span></span></span></p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="color: #000000;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="mso-list: ignore;"><span style="font-family: Calibri;">3.</span><span style="font: 7pt 'times new roman';">      </span></span></span><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">Readiness Assessments</span></strong><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"> answer questions like “Have we implemented adequate privacy safeguards?”, “Have we implemented adequate security safeguards?” and are we ready for audit.</span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri; color: #000000;"> </span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;">We focus on the first two in this post becuase these are the ones you must complete.  <strong>Both are Required by the HIPAA Security Final Rule.</strong></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri; color: #000000;"> </span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;">A thorough <a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-assessment-toolkit/" target="_blank"><strong style="mso-bidi-font-weight: normal;">HIPAA Security Compliance Evaluation</strong></a> broadly covers all aspects of the law including all 18 Standards and 42 Implementation specifications that comprise the Administrative, Physical and Technical Safeguards (CFR 164.308, 310, 312) in the <a href="http://www.datamountain.com/files/HIPAA_Security_Final_Rule.pdf">HIPAA Security Final Rule</a>.<span style="mso-spacerun: yes;">  </span>Additionally, this evaluation must cover CFR 164.314 and 316 related to Organizational Requirements, Policies and Procedures and Documentation.<span style="mso-spacerun: yes;">  </span></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;"><span style="mso-spacerun: yes;"> </span></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;"><span style="mso-spacerun: yes;">As indicated above, completing this <a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-assessment-toolkit/" target="_blank"><strong>HIPAA Security Compliance Evaluation</strong></a> is required by every Covered Entity and Business Associate.  The language of the law is in 45 C.F.R. § 164.308(a)(8):</span></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;"><span style="mso-spacerun: yes;"> </span></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; padding-left: 30px; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;"><span style="mso-spacerun: yes;"><strong>Standard:</strong> <strong>Evaluation.</strong> <em>Perform a periodic technical and non-technical evaluation, based initially upon the standards implemented under this rule and subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, which establishes the extent to which an entity&#8217;s security policies and procedures meet the requirements of this subpart.</em></span></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;"><span style="mso-spacerun: yes;"> </span></span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt; tab-stops: list .5in;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="color: #000000;"><span style="font-family: Calibri;">This type of assessment is a critical step and should be completed whether one is just starting a HIPAA Security Compliance program, rejuvenating an existing program and maintaining an existing program.<span style="mso-spacerun: yes;">  </span>The output of the evaluation establishes a baseline against which overall progress can be measured by the executive team, compliance or risk officer, audit committee or board.<span style="mso-spacerun: yes;">  </span><strong style="mso-bidi-font-weight: normal;">Think FOREST view.</strong> At the end of such an evaluation, one would have a Summary Compliance Indicator such as the one shown in the following Security Evaluation Compliance Summary:</span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 0pt;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri; color: #000000;"> </span></span></p>
<p class="MsoNormal" style="text-align: center; line-height: normal; margin: 0in 0in 10pt;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><span style="font-family: Calibri; color: #000000;"> <a href="http://www.datamountain.com/wp-content/uploads/SecurityEvalDashboard.jpg"><img class="aligncenter size-full wp-image-2085" title="SecurityEvalDashboard" src="http://www.datamountain.com/wp-content/uploads/SecurityEvalDashboard.jpg" alt="HIPAA Security Evaluation Dashboard" width="622" height="570" /></a><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-assessment-toolkit/" target="_blank"></a></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-layout-grid-align: none;"><span style="color: #000000;"><span style="font-family: Calibri;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">A <a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-risk-analysis-toolkit/"><strong style="mso-bidi-font-weight: normal;">HIPAA Security Risk Analysis</strong> </a>(§164.308(a)(1)(ii)(A)) <span style="mso-spacerun: yes;"> </span>is also required by law to be performed by every Covered Entity and Business </span><span style="font-size: 12pt;">Associate.<span style="mso-spacerun: yes;">  </span>Additionally, completion of the Risk Analysis is a core requirement to meet Meaningful Use objectives.<span style="mso-spacerun: yes;">  </span></span><span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">Section 164.308(a)(1)(ii)(A) of the <a href="http://www.datamountain.com/files/HIPAA_Security_Final_Rule.pdf">HIPAA Security Final Rule </a>states:</span></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt 0.5in; mso-layout-grid-align: none;"><em style="mso-bidi-font-style: normal;"><span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">RISK ANALYSIS (Required).</span></span></em></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt 0.5in; mso-layout-grid-align: none;"><span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;"><em>Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the [organization].</em></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">As required by The HITECH Act, the Office of Civil Rights, within the Department of Health and Human Services (HHS), has issued final “<a href="http://www.datamountain.com/wp-content/uploads/OCR_Risk-Analysis_Final_guidance.pdf" target="_blank">Guidance on Risk Analysis Requirements under the HIPAA Security Rule</a>”.<span style="mso-spacerun: yes;">  </span>This guidance was published on July 8, 2010.<span style="mso-spacerun: yes;">  </span>No specific methodology was indicated</span><span style="color: black; font-size: 12pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">.<span style="mso-spacerun: yes;">  </span>However, the guidance describes nine (9) essential</span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"> elements a Risk Analysis must incorporate, regardless of the risk analysis methodology employed.<span style="mso-spacerun: yes;">  </span>We have designed a Risk Analysis methodology and ToolKit around these elements while using industry best practices.</span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">As an example, upon evaluation of each information asset that creates, receives, maintains or transmits electronic Protected Health Information (ePHI), one would have an asset-by-asset evaluation of risk, along with mitigation actions involving new safeguards or controls:</span></span></p>
<p class="MsoNormal" style="text-align: center; line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-risk-analysis-toolkit/" target="_blank"><img class="aligncenter size-full wp-image-1800" title="RA_Step2.6_SummRiskLevel_600x311" src="http://hipaasecurityassessment.com/wp-content/uploads/2010/10/RA_Step2.6_SummRiskLevel_600x311.jpg" alt="HIPAA Security Risk Analysis Summary Risk Level" width="600" height="311" /></a></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">Upon completion of the Risk Analysis for all information assets, an overall Risk Analysis Project Tracking tool would be used to ensure ongoing project management of the implementation of safeguards:</span></span></p>
<p class="MsoNormal" style="text-align: center; line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-risk-analysis-toolkit/"><img class="aligncenter size-full wp-image-1802" title="RA_Step4.2.2_RiskAnalysisProjectTracking_550x252" src="http://hipaasecurityassessment.com/wp-content/uploads/2010/10/RA_Step4.2.2_RiskAnalysisProjectTracking_550x252.jpg" alt="HIPAA Security Risk Analysis Project Tracking" width="550" height="252" /></a></span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"> </span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">So, when it comes to </span><span style="color: #000000;"><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-assessment-toolkit/" target="_blank"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">HIPAA Security Compliance Evaluation</span></strong></a><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">, think:</span></span></span></p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l1 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Forest-level view</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l1 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Overall compliance with the HIPAA Security Final Rule</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l1 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Establishing baseline evaluation score for measuring progress</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l1 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Asking: Have we documented appropriate policies and procedures, etc?</span></span></p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-add-space: auto; mso-list: l1 level1 lfo2; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Asking: Are we performing against our policies and procedures?</span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">When it comes to <a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-risk-analysis-toolkit/"><strong style="mso-bidi-font-weight: normal;">HIPAA Security Risk Analysis</strong></a>, think:</span></span></p>
<p class="MsoListParagraphCxSpFirst" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l2 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Trees/Weeds-level view of each information asset with PHI</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l2 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Meeting a specific step in the overall compliance process</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l2 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Understanding current safeguards and controls in place</span></span></p>
<p class="MsoListParagraphCxSpMiddle" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-add-space: auto; mso-list: l2 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Asking: What are our specific risks and exposures to information assets?</span></span></p>
<p class="MsoListParagraphCxSpLast" style="line-height: normal; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in; mso-add-space: auto; mso-list: l2 level1 lfo3; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: symbol; color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;"><span style="mso-list: ignore;">·<span style="font: 7pt 'times new roman';">         </span></span></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Asking: What do we need to do to mitigate these risks?</span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="font-family: Calibri;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">Both the </span><span style="color: #000000;"><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-assessment-toolkit/"><strong style="mso-bidi-font-weight: normal;"><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;">HIPAA Security Compliance Evaluation</span></strong></a><span style="font-size: 12pt; mso-bidi-font-size: 11.0pt;"><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-assessment-toolkit/"> </a>and the </span><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-risk-analysis-toolkit/"><strong style="mso-bidi-font-weight: normal;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;">HIPAA Security Risk Analysis</span></strong></a></span><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><a href="http://hipaasecurityassessment.com/estore/hipaa-hitech-security-risk-analysis-toolkit/"> </a>are, required by law and important and necessary steps on your HIPAA HITECH Security compliance journey.</span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="color: black; font-size: 12pt; mso-bidi-font-size: 10.0pt; mso-bidi-font-family: calibri; mso-bidi-theme-font: minor-latin;"><span style="font-family: Calibri;">Please feel free to contact us to benefit from our expertise and help you jump-start your program.</span></span><span style="line-height: 115%; font-size: 14pt; mso-bidi-font-size: 12.0pt;"><span style="font-family: Calibri; color: #000000;"> </span></span></p>
<p class="MsoNormal" style="line-height: normal; margin: 0in 0in 10pt; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto;"><span style="line-height: 115%; font-size: 14pt; mso-bidi-font-size: 12.0pt;"><span style="font-family: Calibri; color: #000000;"><a href="mailto:bob.chaput@H3CA.com">bob.chaput@H3CA.com</a> or call 615-496-4891</span></span></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fhipaa-compliance-assessment-hipaa-risk-analysis-explained%2F&amp;title=HIPAA%20Security%20Evaluation%20%E2%80%93%20HIPAA%20Risk%20Analysis%20%E2%80%93%20Explained" id="wpa2a_18"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/hipaa-compliance-assessment-hipaa-risk-analysis-explained/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing:  Here Come the Lawyers</title>
		<link>http://www.datamountain.com/news/cloud-computing-here-come-the-lawyers/</link>
		<comments>http://www.datamountain.com/news/cloud-computing-here-come-the-lawyers/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 15:05:11 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[data protection services]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[HIPAA Security Law]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1609</guid>
		<description><![CDATA[Dear Data-Diligent Reader, Like moths to a porch light, many lawyers are finding the uncertain legal and regulatory terrain of cloud computing to be fertile ground for new legal analysis&#8211;and new legal business.  They may have a point.  What should you do to reduce the risks when implementing cloud computing? Cloud computing, which can be [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Dear Data-Diligent Reader,</strong></p>
<p>Like moths to a porch light, many lawyers are finding the uncertain legal and regulatory terrain of cloud computing to be fertile ground for new legal analysis&#8211;and new legal business.  They may have a point.  What should you do to reduce the risks when implementing cloud computing?</p>
<p>Cloud computing, which can be a truly dynamic, multi-party compute environment, challenges laws that assume that electronic assets behave the same as their paper or celluloid brethren—being static, not easily duplicated and stored on the owner&#8217;s premises.</p>
<p>The gap between the cloud and the current state of legislation is considerable. Legal experts who have looked at cloud computing from the user’s perspective have identified several issues, including:</p>
<p>1.    The ability of cloud computing service providers to change terms of service with little or no notice to users of the service</p>
<p>2.    The attraction to hackers to &#8220;high value&#8221; targets.  The breach of Twitter data on the Google infrastructure was a wake-up call.</p>
<p>3.    The possible centralization of user data with a few cloud computing firms</p>
<p>4.    Exposure of data to seizure by foreign government and data subpoenas</p>
<p>5.    The ability to put a litigation hold on your data if data is carried in the “cloud.”</p>
<p>Until these issues are addressed, corporations will hesitate before jumping into cloud computing and cloud storage.  The legal debates that are happening now will hopefully lead to legislation that will make external clouds as safe a choice as leasing office space.  But until then, buyer beware.  </p>
<p>You should evaluate any cloud computing outsourcing relationship based upon the vendor’s track record and its ability to document service levels very specific contracts.  </p>
<p>Our advice is to work with a cloud storage vendor who truly understands your enterprise storage requirements. </p>
<p><strong><em>We would love to hear your thoughts. Please comment below!</em></strong></p>
<div>
<div>
<div>
<div>
<div>Benefit from our expertise&#8230; DOWNLOAD FREE ARTICLE: <a href="/resources/hipaa-hitech-compliance/truth-about-hipaa-backup/" target="_blank">&#8220;The Truth About the HIPAA Security Rule, The HITECH Act and Data Backup&#8221;</a> . Attend our Complimentary Live Webinars on data protection, online data backup and recovery and data security. <a href="/resources/data-protection-webinars/" target="_blank">Register today!</a> Or, view one of our <a href="/resources/pre-recorded-webinars/" target="_blank">Pre-Recorded Webinars</a></div>
</div>
</div>
</div>
</div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fcloud-computing-here-come-the-lawyers%2F&amp;title=Cloud%20Computing%3A%20%20Here%20Come%20the%20Lawyers" id="wpa2a_20"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/cloud-computing-here-come-the-lawyers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

