<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Datamountain &#187; HIPAA Security Rule compliance</title>
	<atom:link href="http://www.datamountain.com/tag/hipaa-security-rule-compliance/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.datamountain.com</link>
	<description>Saving Your Assets. All Day. Everyday.</description>
	<lastBuildDate>Sat, 21 Jan 2012 21:45:31 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=650</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>HIPAA Business Associates and now Subcontractors – A Big Heads Up!</title>
		<link>http://www.datamountain.com/news/hipaa-business-associates-and-now-subcontractors-%e2%80%93-a-big-heads-up/</link>
		<comments>http://www.datamountain.com/news/hipaa-business-associates-and-now-subcontractors-%e2%80%93-a-big-heads-up/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 17:15:30 +0000</pubDate>
		<dc:creator>Bob</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Business Associates]]></category>
		<category><![CDATA[data protection services firm]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[HIPAA Security Rule compliance]]></category>
		<category><![CDATA[HIPAA-HITECH]]></category>

		<guid isPermaLink="false">http://www.datamountain.com/?p=1846</guid>
		<description><![CDATA[Whew! Nothing like a Notice of Proposed Rule Making (NPRM) from Health and Human Services (HHS) to send the HIPAA compliance blogosphere into a near “brown out “ and hatch a new crop of self-proclaimed HIPAA privacy and security experts!
More importantly, I hope the NPRM has some effect on the business leaders and managers of [...]]]></description>
			<content:encoded><![CDATA[<p>Whew! Nothing like a Notice of Proposed Rule Making (NPRM) from Health and Human Services (HHS) to send the HIPAA compliance blogosphere into a near “brown out “ and hatch a new crop of self-proclaimed HIPAA privacy and security experts!</p>
<p>More importantly, I hope the NPRM has some effect on the business leaders and managers of organizations (Covered Entities, Business Associates and, newly proposed, Business Associate “subcontractors”) that ought to be doing something about privacy and security!</p>
<p>This NPRM is a good one! <a href="http://hipaasecurityassessment.com/wp-content/uploads/2010/07/Modifications-to-the-HIPAA-Privacy-Security-and-Enforcement-Rules-under-HITECH.pdf" target="_blank">“Modifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act”</a>.</p>
<p>Some pundits are proclaiming they’ve studied the 234-page NPRM! No doubt, that will impress you about the blogger’s reading skills and chronic insomnia. I did read the official 58-page version published in the Federal Register, so there!</p>
<p>In announcing the NPRM, HHS Secretary Kathleen Sebelius said, <em>“To improve the health of individuals and communities, health information must be available to those making critical decisions, including individuals and their caregivers. While health information technology will help America move its health care system forward, the privacy and security of personal health data is at the core of all our work.”</em></p>
<p>There’s much to discuss, but my comments in this post focus on HIPAA Security and Business Associates. The HIPAA Security Rule is where the greatest amount of neglect, ignorance and non-compliance exists and from which the continued inexplicable and most egregious data breaches emanate. (As of this writing, since HHS started posting “data breachers” in February 2010 on the HHS data breach “wall of shame”, Covered Entities and their Business Associates have impermissibly disclosed the Protected Health Information of ~3.5 million fellow Americans – equivalent, almost, to the entire population of Los Angeles!)</p>
<ol>
<li>Let’s stick with data and facts for those seeking real information, not opinions:<br />
The official HHS Press Release on this NPRM: <a href="http://www.hhs.gov/news/press/2010pres/07/20100708c.html">http://www.hhs.gov/news/press/2010pres/07/20100708c.html</a></li>
<li>The official NPRM was issued on July 14, 2010: <a href="http://hipaasecurityassessment.com/wp-content/uploads/2010/07/Modifications-to-the-HIPAA-Privacy-Security-and-Enforcement-Rules-under-HITECH.pdf">http://hipaasecurityassessment.com/wp-content/uploads/2010/07/Modifications-to-the-HIPAA-Privacy-Security-and-Enforcement-Rules-under-HITECH.pdf</a><br />
A Notice of Public Rule Making is not the final regulation. It is a notice and an invitation for public comment.</li>
<li>Public comments are due in roughly 60-days; therefore, September 13, 2010.</li>
<li>Comments received will be considered and possibly incorporated into the Final Rule over a time period that could extend through the end of the year, December 2010.</li>
<li>While it’s important to get started (I’m a strong advocate), as stated in the NPRM, there is some time: <em>“In addition, we recognize that covered entities and business associates will need some time beyond the effective date of the final rule to come into compliance with the final rule’s provisions. In light of these considerations, we intend to provide covered entities and business associates with 180 days beyond the effective date of the final rule to come into compliance with most of the rule’s provisions.”</em></li>
<li>Fundamentally, the standards and the specifications in the HIPAA Security Final Rule stand as written – there are no sweeping, dramatic changes that make compliance any more or less difficult. Compliance is still a (large, non-trivial) business risk management project (not an IT project) and is still a journey, not a destination.</li>
<li>As it relates to the Security Rule and as we knew from the HITECH Act statutes, the single biggest changes for Security Rule compliance come in the form of a much, much larger net that is cast to now include not only Business Associates but also Business Associates Subcontractors. <em>“Therefore, consistent with Congress’ intent in sections 13401 and 13404 of the Act, as well as its overall concern that the HIPAA Rules extent beyond covered entities to those entities that create or receive protected health information, we propose that downstream entities that work at the direction of or on behalf of a business associate and handle protected health information would also be required to comply with the applicable Privacy and Security Rule provisions in the same manner as the primary business associate, and likewise would incur liability for acts of noncompliance.”</em></li>
</ol>
<p><strong>What Actions You Should Take Now:</strong></p>
<ol>
<li>Familiarize yourself with the proposed changes; discuss with your attorney and/or HIPAA Consultant</li>
<li>Don’t set your hair on fire yet!</li>
<li>If you’ve not already done so, start your HIPAA Security Compliance work by completing an honest self-assessment of where you stand (we may be able to assist you).</li>
<li>Sink your teeth into this Business Associate and subcontractor matter, whether you are a Covered Entity, Business Associate or Business Associate subcontractor. I predict that all parties in the “chain of trust” or “chain of custody” will be statutorily obligated to comply with the law AND be subject to the new Civil Monetary Penalty system:
<ol>
<li>Document your “ePHI data life cycle” for all ePHI that you create, receive, maintain or transmit to understand your “chain of custody”</li>
<li>Complete an exhaustive inventory of your upstream and downstream “chain of custody” relationships</li>
<li>Hold a Business Associate conference or webinar or workshop to take a more active role to ensure your Business Associates become compliant with the Privacy and Security requirements</li>
<li>Update your standard Business Associate Agreement to reflect the requirements of the HITECH Act</li>
<li>Start re-executing or executing Business Associate Agreements to get this critical area under control</li>
</ol>
</li>
</ol>
<p>If we may be of any assistance, please do not hesitate to call or write.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fhipaa-business-associates-and-now-subcontractors-%25e2%2580%2593-a-big-heads-up%2F&amp;linkname=HIPAA%20Business%20Associates%20and%20now%20Subcontractors%20%E2%80%93%20A%20Big%20Heads%20Up%21"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/hipaa-business-associates-and-now-subcontractors-%e2%80%93-a-big-heads-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March and April Data Protection Webinars &#8211; Open to Registration</title>
		<link>http://www.datamountain.com/news/march-and-april-data-protection-webinars-open-to-registration-2/</link>
		<comments>http://www.datamountain.com/news/march-and-april-data-protection-webinars-open-to-registration-2/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 03:14:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[HIPAA Security Rule compliance]]></category>
		<category><![CDATA[live webinars]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com.php5-16.websitetestlink.com/?p=170</guid>
		<description><![CDATA[Dear  Data-Diligent Readers,
With  all the &#8220;renewed&#8221; interest in HIPAA Security Rule compliance, driven by  The HITECH Act, we have designed several new webinars to help Covered  Entities (CEs) and Business Associates (BAs) restart their compliance  efforts.
In  March and April, our Complimentary live webinar offerings are listed  below with [...]]]></description>
			<content:encoded><![CDATA[<p>Dear  Data-Diligent Readers,</p>
<p>With  all the &#8220;renewed&#8221; interest in HIPAA Security Rule compliance, driven by  The HITECH Act, we have designed several new webinars to help Covered  Entities (CEs) and Business Associates (BAs) restart their compliance  efforts.</p>
<p>In  March and April, our Complimentary live webinar offerings are listed  below with direct links to see the overview and learning objectives of  each webinar:</p>
<ul>
<li><a href="https://www1.gotomeeting.com/register/285687248" target="_blank"><span style="color: #00a594;">HIPAA Security, The  HITECH Act and Contingency Planning – Wednesday, <strong>3/17/2010 </strong>–  4pm ET / 3pm CT / 1pm PT</span> </a></li>
<li><a href="https://www1.gotomeeting.com/register/161415816" target="_blank"><span style="color: #00a594;">How to Avoid the new Health &amp; Human Services &#8216;Wall  of Shame&#8221; – Friday, <strong>3/19/2010 </strong>– 2:30pm ET / 1:30pm CT /  11:30am PT</span></a> &#8211; (new!)</li>
<li><a href="https://www1.gotomeeting.com/register/803334728" target="_blank"><span style="color: #00a594;">The Truth About HIPAA Security, The HITECH Act and Data  Backup – Tuesday, 3/23/2010 – 2:30pm ET | 1:30pm CT | 11:30am PT</span></a> &#8211; (new!)</li>
<li><a href="https://www1.gotomeeting.com/register/933372377" target="_blank"><span style="color: #00a594;">A Buyer’s Guide &#8211; What to Look For in Online Backup and  Recovery Services &#8211; Thursday, <strong>3/25/2010</strong> &#8211; 2:30pm ET |  1:30pm CT | 11:30am PT</span></a> &#8211; (new!)</li>
<li><a href="https://www1.gotomeeting.com/register/899156552" target="_blank"><span style="color: #00a594;">How The HITECH Act Raises the Ante on HIPAA Security  Rule Compliance -  Tuesday, March 30, 2010 &#8211; </span><span style="color: #0066cc;">2:30pm ET | 1:30pm CT | 11:30am PT</span></a> &#8211; (new!)</li>
</ul>
<p><span style="color: #000000;">If there is a data protection topic you would like us  to cover and do not see it listed, please contact us using the  information below.</span></p>
<h2><a href="/resources/data-protection-webinars/" target="_blank">Attend  one of our HIPAA-HITECH Data Protection Webinars&#8230; Register Today!</a></h2>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fmarch-and-april-data-protection-webinars-open-to-registration-2%2F&amp;linkname=March%20and%20April%20Data%20Protection%20Webinars%20%26%238211%3B%20Open%20to%20Registration"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/march-and-april-data-protection-webinars-open-to-registration-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March and April Data Protection Webinars &#8211; Open to Registration</title>
		<link>http://www.datamountain.com/news/march-and-april-data-protection-webinars-open-to-registration-3/</link>
		<comments>http://www.datamountain.com/news/march-and-april-data-protection-webinars-open-to-registration-3/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 21:24:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[HIPAA Security Rule compliance]]></category>
		<category><![CDATA[live webinars]]></category>
		<category><![CDATA[The HITECH Act]]></category>

		<guid isPermaLink="false">http://www.datamountain.com.php5-16.websitetestlink.com/news/march-and-april-data-protection-webinars-open-to-registration-3/</guid>
		<description><![CDATA[Dear  Data-Diligent Readers,
With  all the &#8220;renewed&#8221; interest in HIPAA Security Rule compliance, driven by  The HITECH Act, we have designed several new webinars to help Covered  Entities (CEs) and Business Associates (BAs) restart their compliance  efforts.
In  March and April, our Complimentary live webinar offerings are listed  below with [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/files/BobChaput_DSF8338_cropped.jpg" border="2" alt="Bob Chaput | President | Data  Mountain Online Data Backup and Recovery Services" hspace="3" vspace="2" width="129" height="136" align="left" />Dear  Data-Diligent Readers,</p>
<p>With  all the &#8220;renewed&#8221; interest in HIPAA Security Rule compliance, driven by  The HITECH Act, we have designed several new webinars to help Covered  Entities (CEs) and Business Associates (BAs) restart their compliance  efforts.</p>
<p>In  March and April, our Complimentary live webinar offerings are listed  below with direct links to see the overview and learning objectives of  each webinar:</p>
<ul>
<li><a href="https://www1.gotomeeting.com/register/755375384" target="_blank"><strong><span style="color: #00a594;">PC Encryption Regulatory Compliance &#8211; Tuesday, 3/9/2010 &#8211;  2:30pm ET | 1:30pm CT | 11:30am PT</span></strong></a></li>
<li><span style="color: #00a594;">HIPAA  Security, The HITECH Act and Contingency Planning – Wednesday, <strong>3/17/2010 </strong>– 4pm ET / 3pm CT / 1pm PT</span></li>
<li><a href="https://www1.gotomeeting.com/register/161415816" target="_blank"><span style="color: #00a594;">How to Avoid the new Health &amp; Human Services &#8216;Wall  of Shame&#8221; – Friday, <strong>3/19/2010 </strong>– 2:30pm ET / 1:30pm CT /  11:30am PT</span></a> &#8211; (new!)</li>
<li><a href="https://www1.gotomeeting.com/register/803334728" target="_blank"><span style="color: #00a594;">The Truth About HIPAA Security, The HITECH Act and Data  Backup – Tuesday, 3/23/2010 – 2:30pm ET | 1:30pm CT | 11:30am PT</span></a> &#8211; (new!)</li>
<li><a href="https://www1.gotomeeting.com/register/933372377" target="_blank"><span style="color: #00a594;">A Buyer’s Guide &#8211; What to Look For in Online Backup and  Recovery Services &#8211; Thursday, <strong>3/25/2010</strong> &#8211; 2:30pm ET |  1:30pm CT | 11:30am PT</span></a> &#8211; (new!)</li>
<li><a href="https://www1.gotomeeting.com/register/899156552" target="_blank"><span style="color: #00a594;">How The HITECH Act Raises the Ante on HIPAA Security  Rule Compliance -  Tuesday, March 30, 2010 &#8211; </span><span style="color: #0066cc;">2:30pm ET | 1:30pm CT | 11:30am PT</span></a> &#8211; (new!)</li>
</ul>
<p><span style="color: #000000;">If there is a data protection topic you would like us  to cover and do not see it listed, please contact us using the  information below.</span></p>
<h2><a href="/resources/data-protection-webinars/" target="_blank">Attend  one of our HIPAA-HITECH Data Protection Webinars&#8230; Register Today!</a></h2>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.datamountain.com%2Fnews%2Fmarch-and-april-data-protection-webinars-open-to-registration-3%2F&amp;linkname=March%20and%20April%20Data%20Protection%20Webinars%20%26%238211%3B%20Open%20to%20Registration"><img src="http://www.datamountain.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.datamountain.com/news/march-and-april-data-protection-webinars-open-to-registration-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

