The SECURITY & PRIVACY NEWSLETTER is published monthly in support of the healthcare industry's efforts to work together towards compliance in security and privacy. Subscribers total over 3,000.
In this issue:
1. Monthly HIPAA Compliance Tip: Auditing and Monitoring
2. Wireless and Mobility for Hospitals Web cast, Hosted by Cisco
3. AT&T FOCUS 2007 National Conference – Register Today
4. Emergency Response Communication: Pitfalls and Resources
5. The Fall Collaborative Communications Summit: Transforming Healthcare through Health Information Technology
6. Solutions Exhibiting at MidwestRegional HIMSS Chapters Annual Fall Conference: 11/5-6
7. Grants Funding Analysis Provided by TANDBERG
8. Compliance Portal Delivers 1-Click Access to Regulations
9. HIPAA Academy Presents Security Exec Brief, Oct 30, 2007 in Sacramento, California
1. Monthly HIPAA Compliance Tip: Auditing and Monitoring
Brought to you by: Ali Pabrai, CISSP, CSCS, HIPAA Academy
Audit Controls (§ 164.312(b)) is a Standard defined under Technical Safeguards in the HIPAA Security Rule that requires that an organization:
Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information (EPHI).
Given that the U.S. Department Health and Human Services (HHS) Office of Inspector General (OIG) has started HIPAA Security compliance audits, it is a good time for organizations to review their compliance with the legislation as well as assess the state of their security practices. On March 5th the OIG initiated the first audit of a provider’s compliance with the HIPAA Security Rule. The organization audited was Piedmont Hospital in Atlanta, Georgia. Officials at Piedmont Hospital were presented with a list of 42 items the agency wanted information on (Computerworld, June 18, 2007).
Organizations should ensure that systems are monitored to detect deviation from access control policy and record monitor-able events to provide evidence in case of security incidents. The analysis of all such information will increase awareness of areas that need to be looked at closely to prevent security violations. The objective for conducting a security audit is as follows:
- Ensure the confidentiality, integrity and availability (CIA) of sensitive business information and resources-
- Investigate security violations and ensure compliance with security policies of the organization
- Monitor user or system activity where necessary
2. Wireless and Mobility for Hospitals Web cast , hosted by Cisco
When: Wednesday, October 24, 1–2:30 p.m. Eastern Time
In hospitals throughout the U.S. and Canada, wireless networks improve patient care and reduce stress levels by delivering vital information to the point of care on PDAs, Tablets, and computers
on wheels. Wireless networks also enable automated asset tracking and improve caregiver collaboration.
But, how do you choose the right wireless networking vendor? What applications provide the biggest payback? And, how do you implement them?
Featured Case Study: Learn how the North Broward Hospital District uses wireless technology to improve patient care and drive value in business processes.
Register today!
3. AT&T FOCUS 2007 National Conference – Register Today
When: October 29-31
Where: Chicago
Mark your calendar for October 29-31 in the Windy City for the 2007 National FOCUS Conference. The three-day event will be jam-packed with education, technology, and networking opportunities. The conference will center on the popular Technology Showcase demonstrations and is expected to feature:
- Keynotes by AT&T officers
- Industry Outlooks by national business leaders
- Technical deep dives by industry experts
- Whiteboard sessions and special interest group roundtables by IT/telecom specialists
- FOCUS member case studies on hot topics
- Q&A session with AT&T senior executives
- Professional development
For more details visit www.thefocus.org
4. Emergency Response Communication: Pitfalls and Resources, hosted by TANDBERG
Wednesday, October 24, 2007 2:00 PM - 3:00 PM EDT
FREE Web cast
Coordination of emergency response resources is increasingly capturing the focus of standards bodies, funding sources, and public safety agencies at all levels of government. Certainly, America has witnessed firsthand the impact of poor coordination and insufficient communication.
Join Grants Office CEO Michael Paddock and special guests Dr. Robert Chandler, Communication Division Chair and Blanche E. Seaver Professor of Communication at Pepperdine University, and Scott Feinberg, Public Sector Market Manager at TANDBERG, as we discuss:
Register for October 24 event.
5. The Fall Collaborative Communications Summit: Transforming Healthcare through Health Information Technology
When: November 5-6, 2007
Where: The Peninsula Beverly Hills, CA
The Collaborative Communications Summit is designed to help top-level executives, legislators, physicians, regulators and technologists come to grips with the swirling forces of health information technology change, policy development and changing business models. Join your colleagues and industry leaders for two days of panels, presentations, keynotes, and high level networking.
Topics Addressed include: The HIT Landscape, Convergence of the PHR and HER, A Comparison of HIE & RHIOs Across the USA and more!
Click here to register!
The HIT Landscape: Who Are The Major Players and How Can Your Organization Work With Them?
The evolution underway to a successful and widespread adoption of Health Information Technology is a massive undertaking that requires the collaboration of private, non-profit, and government organizations. This session will offer an overview and perspective from each group addressing how they are currently working together and what needs to be done in the future.
When: November 5-6
Location: Osthoff Resort located in Elkhart Lake, WI. Elkhart Lake
Theme: Technology for Tomorrow and Beyond: A Healthcare Information Technology Odyssey
The Fall Conference boasts the largest gathering in the area of professionals interested in the use of information technology and management systems to improve healthcare. The event includes nationally recognized keynote speakers, multiple breakout sessions and a large exhibit hall.
stop by our booth too!
Visit www.2007falltechnologyconference.com to learn more and to register.
7. Grants Funding Analysis Provided by TANDBERG
Need assistance in funding your distance learning, telemedicine or communications project? Request a complimentary funding analysis from TANDBERG's Grant Services Team.
Click here to begin the research.
8. Compliance Portal Delivers 1-Click Access to Regulations!
HIPAA Academy, the industry’s leading provider of HIPAA training, certification and consulting, has launched the industry’s most comprehensive compliance and security portal. Please visit www.HIPAAAcademy.Net and click on Compliance Portal. Compliance Portal provides one-click access to all major information security and associated compliance requirements including HIPAA, PCI DSS, ISO 17799:2005 (ISO 27002), FISMA and many others.
9. Pabrai Presents Security Exec Brief, Oct 30, 2007 in Sacramento, California
Join Ali Pabrai, CISSP, CSCS, as he delivers two executive briefs in Sacramento, California on Oct 30, 2007. The first brief is focused on “The 42 Questions HHS May Ask in a HIPAA Audit” and steps you through best practices to ensure HIPAA compliance. The second brief examines the new “ISO 27002 International Security Standard”. Learn about the scope of this new security standard and how to apply it in your organization to enhance policies and procedures.
To register or for more information, please visit www.HIPAAAcademy.Net or contact Lorna Waggoner, at 1.877.899.9974 x17.