HIPAA Law



             


Monday, March 3, 2008

Portable health care insurance gets rolling

Employees covered by group plans are often forced to remain at jobs only because they have suffered reversals in health. Were they to leave, they fear that they and their families might lose insurance benefits and new employers might be unwilling to
Once the Clinton Administration's massive health reform program was unceremoniously laid to rest, Congress began to nibble away at the social ills which prompted the ambitious initiative in the first place.

Among these is the sad fact that health insurance hasn't been "portable."

Employees covered by group plans are often forced to remain at jobs only because they have suffered reversals in health. Were they to leave, they fear that they and their families might lose insurance benefits and new employers might be unwilling to cover them.

Since 1985, when the Consolidated Omnibus Budget Reconciliation Act (COBRA) brought some relief, most employer-sponsored group health plans have been obliged to offer employees and their dependents the option of purchasing continued health coverage in case of termination or reduction in hours of employment, death, divorce or legal separation, enrollment in Medicare or the end of a child's dependency under a parent's health plan.

COBRA's maximum coverage period is 18 months. And, other than COBRA, no federal requirements apply to group health plans, insurers or health maintenance organizations (HMOs) fostering the portability of coverage.

But now all of that has changed. The Health Insurance Portability and Accountability Act of 1996 will impose portability requirements on group health plans in three ways.

It will prohibit excluding individuals from coverage based on health and related factors that have traditionally been taken into account. Thus, medical underwriting will be outlawed.

The new law will require that coverage offered by health insurers and HMOs generally be guaranteed renewable at the plan sponsor's option. Health insurers in the small-group market must also provide coverage to employees on a "guaranteed issue" basis.As a result, employers with two to 50 employees will be able to secure coverage without any underwriting at all.

The new will law place limits on exclusions of preexisting conditions. A preexisting condition is one for which medical advice, diagnosis, care or treatment was recommended or received within the past six months. When the laws take effect, health plans will be able to exclude coverage for such conditions for no more than 12 months (or 18 months for late enrollees). HMOs are permitted to substitute a two-month waiting period (three months for late enrollees) for a preexisting-condition limitation.

The new limits on preexisting-condition exclusions mean some administrative hassle. For one thing, the law mandates that health plans credit any prior group coverage toward preexisting-condition exclusion periods and a health plan will now need to provide a certificate of coverage to a former enrollee, documenting the length of coverage under the plan.

In addition, health plans must enroll individuals who initially decline health coverage because of other coverage if they seek to enroll within 30 days of losing their other coverage. And individuals who become dependents because of marriage, birth or adoption will also be entitled to special enrollment periods.

Not surprisingly, there is a price for all of this, and prudent employers will begin to assess the new law's impact on them and how best to control that impact before the portability rules take effect -- for plan years beginning after June 30.

They will need to consider whether the potential cost savings of applying a limited preexisting-condition exclusion outweigh the added administrative expense. They will need to assess whether market conditions still warrant providing extended health coverage until age 65 for early retirees, who may have an easier time securing affordable individual coverage in light of new "guaranteed issue" requirements benefiting individuals.

In addition, employers will need to review contractual arrangements with service providers. And they will need to see that health plan documents and disclosures are revised to reflect any changes before they take effect.

Marc Lane is a business and tax attorney, a Master Registered Financial Planner, a Registered Financial Consultant, and a Certified Investment Specialist. Marc is the author of 30 books on business organization, taxation, and personal finance. His newest book, "Advising Entrepreneurs: Dynamic Strategies for Financial Growth" draws from his experience working with those who have successfully built their businesses. Marc is an Adjunct Professor of Law at Northwestern University and an Adjunct Professor of Business at the University of Illinois. His practice areas include Individual Taxation, Corporate Tax Planning, Business Tax Planning, Estate Planning, Investments, Retirement Planning,Elder Law, International Trade, Business Law, and Wills, Trusts and Estates. Additional articles, case studies, and a free email newsletter are available at www.marcjlane.com.

Labels: , , , , ,

Thursday, January 31, 2008

HIPAA Compliance In A Technical World

The way people do business today relies more and more on internet connections and ?virtual? phone lines. This presents a problem for those in the medical industry and those required by the Department of Health and Human Services to follow the guidelines of The Health Insurance Portability and Accountability Act of 1996 (HIPAA). Those companies that deal with Personal Health Information (PHI) want to make sure that they are able to keep up with technology, and all the convenience and efficiency that it has to offer, yet at the same time ensure that the technology does not put their clients? confidential information at risk. One such technology that those in the medical industry are finding numerous benefits to is virtual fax.

The benefits of virtual fax can be summed up in one word: efficiency. With a virtual fax there is no longer any need to go back and forth from the fax machine for sending or receiving faxes. All faxes can come into an email address or internet control panel and faxes can be sent right from the desktop as well. Since the faxes are digital, it is possible to clean up any paper trail and keep a digital file of all important correspondence. Another added benefit is the ability to rid the office of the bulky fax machine with all of the maintenance and upkeep that goes along with it. While it is easy to see how any office can benefit from the use of virtual fax, it may not be as obvious as to how they can do so and still stay HIPAA compliant.

There are four categories of security requirements under HIPAA and it is the consumer?s responsibility, according to the HIPAA regulations, to examine the technology employed by a virtual fax provider and determine how to use it in a compliant manner. Here are some things to look for in a virtual fax provider that help medical providers maintain compliance.

1.Administrative Procedures ? A virtual fax provider should have documented, formal practices to protect data and limit access to files. Most virtual fax providers will have policies that allow access to fax messages for the purpose of maintenance, customer service, repair, and backup, or in response to legal inquiries or warrants that legally force the disclosure of the messages or documents from courts or government agencies.

2.Physical Safeguards ? A virtual fax provider should be able to protect data from fire, other natural and environmental hazards and intrusion. A provider should have measures in place that include an industry standard fire safety system, off-site backups, and industry standard security systems to protect Personal Health Information from physical vulnerabilities.

3.Technical Security Services ? a virtual fax provider should have measures in place to protect information and control individual access to information. There are usually 3 ways to access documents in a virtual fax system and each one should have their own independent security measures.

?Access to a virtual fax system by phone should be restricted with PIN access.
?Email delivery of virtual fax messages should be sent using encryption technology. An added security feature is the ability to have the email delivery of fax documents configured for a ZIP format with password/encryption.
?Virtual fax access over the internet should also be PIN protected as well as be secured by industry standard protocols and encryption algorithms. An added security feature would be that the internet portal?s identity be verified by an SSL certificate.

4.Technical Security Mechanisms ? A virtual fax provider should be able to guard against unauthorized access or loss of data over the communications network. Data storage systems should implement industry standard fault tolerant measures to prevent data loss due to storage media failure. Databases and storage systems should be protected by battery backup technology to protect against potential data loss due to power failures. In addition, servers should use a measure comparable to FreeBSD UNIX to prevent unauthorized access and data security compromise.

For a medical provider in a technical world it can be difficult to keep up with all the current technology and still be sure to follow all the guidelines they are subject to. While ultimately it is the consumer?s responsibility to determine whether or not a virtual fax provider allows them to maintain HIPAA compliance, many providers already have security measures in place that can help them stay within the guidelines they are subject to.
Brandi Cummings, an expert in the field of virtual telecommunications, recommends checking out http://www.Fax800.com, a leading provider of internet fax technology for small businesses.

Labels: , , , ,

Wednesday, January 23, 2008

HIPAA legislation guide

The Health Insurance Portability and Accountability Act or HIPAA, which was enacted by the US Congress in 1996, has introduced to sweeping changes in health care administration and information systems. HIPAA is a federal law that has been amended to the Internal Revenue Code of 1986 which intends to improve portability and continuity of health insurance; combat waste, fraud and abuse in health insurance and health care delivery; promote the use of medical savings accounts and improve access to long-term health care services and coverage; and simplify the administration of health insurance.

HIPAA is designed to standardize the way all health care organizations electronically exchange sensitive patient data and to protect patients from unauthorized disclosure of their medical records (whether paper or electronic). Under HIPAA, there are specific standards that all health care organizations are required to adhere to. These standards include an Administrative Simplification Title that is aimed at preventing health care fraud and abuse. Within this title, there are several laws and proposed standards including Electronic Health Transactions Standards, Privacy & Confidentiality Standards, Unique Health Identifiers, and Security & Electronic Signature Standards.

These HIPAA laws and standards directly apply to the following groups of health care entities: health plans, public and private payers, health care insurers, HMOs, Medicare, Medicaid, group health plans, health care clearinghouses, any entity that facilitates the processing of non-standard formatted health information and must convert the non-standard data into standard transactions, or vice versa, Health Care Providers, providers who transmit health information electronically, providers who receive individual health information, and providers who electronically maintain health information used in electronic transmissions between entities.

Non-compliance with HIPAA regulations may cause disruptions in an organization's day-to-day business processes, resulting in both tangible and intangible costs. The most serious implications of HIPAA non-compliance for health care organizations include the inability to effectively conduct electronic business and the potential of losing significant segments of business. The government also imposes some sanctions on those who fail to comply with the regulations of HIPAA. The penalty for failure to comply with regulations goes up to $100 per violation per person up to a maximum of $25,000 per year. Penalty for knowingly and wrongfully disclosing individually identifiable health information is up to $50,000 per violation or one year imprisonment or both for simple offense; up to $100,000 per violation or five years imprisonment or both if the offense is "under false pretenses"; and up to $250,000 or ten years imprisonment or both if committed with intent to sell, transfer or use for commercial advantage, personal gain or malicious harm.

Thus, the ultimate objective of HIPAA is to increase the efficiency and effectiveness of health information systems through improvements in electronic health care transactions as well as to maintain the security and privacy of individually identifiable health information. It helps to promote the modernization of health information systems. Becoming HIPAA-compliant is a challenging task because of extensive cross-departmental compliance and training requirements but it is an ongoing administration, privacy and security challenge that must be constantly addressed.

Mansi gupta recommends that you visit HIPAA legislation for more information

Labels: , , , ,

Saturday, January 19, 2008

HIPAA and privacy guide 101

HIPAA has led to sweeping changes to health care administration and information systems as health care organizations struggle to achieve cost-effective compliance by 2003. The US Congress enacted the Health Insurance Portability and Accountability Act or HIPAA in 1996. The act covered a wide array of issues surrounding the health insurance industry but in particular it required administration simplification, which addressed the issue of security and privacy of health information.

HIPAA is designed to standardize the way all health care organizations electronically exchange sensitive patient data and to protect patients from unauthorized disclosure of their medical records (whether paper or electronic). HIPAA outlined standards to improve the nation's health care system by incorporating electronic data exchange between health care providers. The idea of course was to allow various health providers to access the records of a particular patient. So, when a patient visits a new hospital, the covering doctor can access that patients past record and in so doing provide him with better care. However, as one could envisage, this raised a great number of apprehensions with respect to the privacy and confidentiality of people's medical records. So the legislature created a fundamental list of rules and regulations with which health care providers must comply. And the creation of these rules and regulations gave birth to the industry that is called HIPAA Compliance.

To ensure HIPAA compliance, there are certain key provisions, which need to be followed. For instance, individuals should be able to access their records and request correction of errors. Also, they should be informed about how their personal information will be used. The 'protected health information' (PHI) indicates that the information cannot be used for marketing purposes without the clear consent of the patients in question. People should be able to ask their covered entities (which maintain PHI about them), to ensure that their communications with the patient are confidential. It should be possible for people to file formal privacy-related complaints to the Department of Health and Human Services (HHS) Office for Civil Rights. Covered entities should document their privacy procedures, however, they have discretion on what to include in their privacy procedure. They are required to designate a privacy officer and train their employees. Covered entities can use an individual's information without the individual's consent if the purpose is to provide treatment, obtain payment for services and to perform the non-treatment operational tasks of the provider's business. Some of the agencies, government bodies and individuals who can access the medical records of a person under HIPAA compliance rules are the insurance companies, employers, courts, hospitals, or individual physicians. This is also considered as a downside of the HIPAA Privacy rule because sponsors of a research study; makers of drugs for the particular study and the researchers involved in the study are included in this list.

However, the ultimate objective of HIPAA is to increase the efficiency and effectiveness of health information systems through improvements in electronic health care transactions as well as to maintain the security and privacy of individually identifiable health information.

Mansi gupta recommends that you visit HIPAA and privacy for more information.

Labels: , , , , , ,

Friday, January 11, 2008

HIPAA and Email - How Does Your Practice Deal with Compliance in a Digital Age

The internet has created a new business model for the smaller medical practice, specialty clinic and medical service (e.g. dermatologist, plastic surgeon, physical therapist, psychologist, et. al). More and more, patients are looking to communicate with their healthcare providers as they do in their personal and business lives - via email.

Email as a communication solution for the smaller clinic can be a time-saving resource. It can replace the many phone calls and postal mailings, adding a financial benefit to the smaller clinic.

Does email eliminate the office visit? No nothing can replace the personal face-to-face office visit, but email can be an additional tool clinicians can implement to streamline their practice.

Some healthcare practitioners do however feel that emailing their patients equates to working for free, but some clinics have already adopted charging for email consultations.

At some practices, patients pay a flat rate from $100 to several hundred dollars per year for this type of service. Harvard professor of medicine Dr. Daniel Z Sands, a proponent to a digital clinic, stated "I think it's reasonable to assume that if lawyers and accountants charge for time, then physicians should too. (1)"

Sustainability of Health Information Technology is also on the government's radar. As part of the President's mandate to move the medical field towards a digital clinical setting within the next ten years (2). The National Coordinator for Health IT, Dr. David Brailer, noted the value-added benefit of investing in Healthcare IT:

Information technology supports treatment choices for consumers and enables better and more cost-effective care... Health IT not only adds value to the way people lead their lives, but it gets more out of our investment in healthcare overall. (3)

It is possible for clinics to shift towards a digital medical office while remaining financially solid. Rights management software tools have become a reality for the small and medium business office (4). Small Business Rights Management (SBRM) reflects a shift Rights Management software tools.

SBRM solutions provide clinics and practices of a smaller scale an equal level of user rights management and encryption previously available to larger medical organizations (e.g. state hospitals, large research facilities, university medical networks, etc.).

With any medical advance, the side affects of a solution or cure, must also be considered. While email is beneficial time-wise and financially, there are also cons to using this tool - many HIPAA related. According to the Health Privacy Project's 2005 study, 70% of Americans are concerned that personal health information (PHI) could be disclosed as a result of weak data security (5)

Currently, healthcare organizations are required to provide a disclosure statement when communication is sent to their patients. A sample of a healthcare professional's email disclosure statement may read like this:

Client information gathered by [Clinic or Organization's Name] is protected by Federal Law. If this communication contains any client information, including information which would identify a client, you are prohibited from redisclosing it to any person or organization in any manner, and you are required to maintain it as confidential. Failure to do so is punishable by civil and criminal penalties. If such information has reached you in error, please contact [Clinic or Organization's Name] contact@emailaddress.com

With the advent of phishing, malware, and spyware, the unintended recipient could possibly spread a patients PHI like a virus; using or selling data to any number of damaging sites.

Protecting a patient's PHI is an ingrained concept within the medical profession. Laws and government mandates are take this notion a step further, medical facilities not compliant to protecting their patient's PHI face stiff penalties under HIPAA. PHI includes and is not limited to:

* Patient's address, phone number
* Treating Hospital/Clinic number assigned the patient
* Patient's date of birth/ SSN
* Patients legal next of kin/guardian and their telephone number
* Patient's insurance information (pre-certification/ DSHS/ Medicare)
* Anticipated Admission date and time<

While there are some drawbacks to email, patients want the option of emailing their doctor, pharmacist, therapist or clinic. "People are often more comfortable talking to a computer than they are to a doctor," said Dr. Delbanco, a professor of medicine at the Harvard Medical School and the lead author of an article on doctors and e-mail in the New England Journal of Medicine (6).

Dealing with HIPAA compliance issues can often be frustrating to the small clinical practice. SBRM solutions bridge the gap between staying current with healthcare industry regulations and keeping a small physician practice open. Patient/client information, private communiqu? regarding diagnosis/treatment, and medical billing can stay discreet, only the intended recipient will see this information.

With SBRM solutions; clinics don't have to worry that their email content breaks the Hippocratic Oath's creed of confidentiality by revealing patient's PHI. Healthcare providers can remain both respectful and compliant under HIPAA regarding the patient privacy.

- - - - - - - - - -

End Notes:

1.) Dr. Daniel Z. Sands as quoted in Liz Kowalczyk's article "Is E-Mailing the Future of Doctor-Patient Relations?" The Boston Globe, D2, April 27, 2004, Lexis Nexus - http://www.lexisnexus.com

2.) United States Department of Health and Human Services, "Secretary Leavitt Takes New Steps to Advance Health IT," Press Release on HHS website, June 6, 2005, http://www.os.dhhs.gov/

3.) "Remarks by David Brailer, MD PhD National Coordinator for Health Information Technology HIMSS 2005" February 17, 2005, http://www.himss.org

4.) SBRM on Wikipedia - http://en.wikipedia.org/wiki/Small_Business_Rights_Management

5.) "Majority of Americans Have Privacy Concerns about Electronic Medical Record System," Health Privacy Project (www.heathprivacy.org): http://www.healthprivacy.org/info-url_nocat2303/info-url_nocat_show.htm?doc_id=263085

6.) Anahad O'Connor, "Take Two Aspirin, E-Mail Me Tomorrow," The New York Times, Section F; Column 5; Health & Fitness; 7., 30 September 2005, Lexis Nexis - http://www.lexisnexus.comMs. Veniegas is an alumni of the University of Washington Marilee joined the Marketing team at Essential Security Software, Inc. in 2005. She also serves as one of the ESS site editors for "I Want My ESS!

Labels: , , , ,

Wednesday, December 12, 2007

Deriving Due Care Practices from HIPAA and GLBA

Recent years have shown a trend in corporations being held responsible for information security negligence. In particular, the Federal Trade Commission (FTC) and the Attorney General of New York have been actively pursuing companies that fail to follow effective security practices. Many high-visibility cases illustrate how companies are being required to implement stronger security controls, the Guess case being a good example.

In June 2003, Guess, Incorporated agreed to settle FTC charges that it exposed consumers' personal information to commonly known attacks by hackers, contrary to the company's claims. "Consumers have every right to expect that a business that says it's keeping personal information secure is doing exactly that," said Howard Beales, Director of the FTC's Bureau of Consumer Protection. The settlement required that Guess implement a comprehensive information security program that would be certified as meeting or exceeding the standards in the consent order by an independent professional within a year.

The Problem

A key reason why corporations demonstrate poor or inconsistent information security controls is the lack of a widely accepted and comprehensive set of good security practices. Standards bodies such as the U.S. National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) publish security standards with varying degrees of corporate acceptance and use. The Information Systems Security Association (ISSA) has identified the need for a universally agreed-upon collection of essential security practices and is currently developing the Generally Accepted Information Security Principles (GAISP)--although how well accepted these principles will be upon publication remains to be seen.

The Health Insurance Portability and Accountability Act (HIPAA) Final Security Rule and the Gramm Leach Bliley Act (GLBA) Interagency Guidelines are customer privacy laws specifying the security rules that must be followed by the healthcare and financial services industries respectively. If entities covered by these laws fail to follow the required security practices they may not only be exposing their customers' private information but may also be subject to regulatory penalties and fines. These laws, in essence, define information security due care standards--the security practices that must be followed to avoid liability--for the healthcare and financial services industries. The entities covered by these laws, however, only represent approximately 25% of the U.S. Gross Domestic Product. Other industries must rely upon their best judgment to protect customer information--clearly not an effective approach as the cases mentioned earlier demonstrate.

Most companies certainly want to do the right thing and protect their customers' information, but avoiding legal liability and harm to their reputation are also factors that motivate them to implement appropriate information security controls. While most corporate information security professionals probably think they understand how to protect customer information, many wouldn't be comfortable attesting that their practices would protect their employer from liability. Lacking a commonly accepted set of security practices, many corporate information security professionals are uncertain how to secure customer information in a way that also limits their company's liability.

Proposed Solution

The best approach for companies that wish to protect their customer's information and potentially avoid liability is to implement the security practices required by both HIPAA and GLBA. There are 12 security practices in common between these two customer privacy laws. By following these 12 practices, companies will be practicing information security due care and can potentially avoid liability. Indeed, all of the security requirements mandated in the settlement of the cases mentioned earlier are among the 12 practices in common between HIPAA and GLBA.

What is Due Care?

Companies that handle the personal information of their customers may be breaking the law and not know it, as evidenced by the Guess case. This ignorance may partly stem from substantial gaps of prosecutable computer crimes that exist in federal criminal code and individual state criminal statutes. Federal and state criminal statutes are slow to evolve to adequately prosecute crimes based on the fast-changing technology of information systems. Companies and information security professionals may find little direction in criminal codes and statutes to help them avoid inadvertently breaking the law when it comes to protecting their customers' personal information.

Since there is little guidance for companies to follow when it comes to avoiding criminal or civil liability or harsh settlements from the FTC, they need to consider how legal standards are created in the first place. Legal standards are developed based on the concept of due care, which is the care that an ordinarily prudent person would have exercised under the same or similar circumstances. Failure to practice due care is equivalent to demonstrating negligence. Companies that demonstrate negligence relative to their information security practices are susceptible to lawsuits, fines, and other sanctions, whereas companies that practice due care should be largely protected from such punishments.

Where to Find Due Care Information Security Practices

Companies that wish to find due care information security practices need look no further than to two major federal laws that regulate the protection of customer information: HIPAA and GLBA. While both HIPAA and GLBA enacted a lot more than just customer privacy requirements, they both have spawned substantial regulatory guidance on security controls for protecting customer information. The regulations for HIPAA are called the Final Security Rule and those for GLBA are referred to as the Interagency Guidelines.

While some of the requirements in these regulations are industry-specific, there is a lot of commonality between the two. In particular, 12 security practices were found in both the HIPAA Final Security Rule and the GLBA Interagency Guidelines. The fact that these two sets of regulations intersect in 12 places is no coincidence. This is a clear signal from the federal government of the level of due care it expects the country's health care providers and financial institutions to practice. If these are the standards of due care that must be practiced by industries that represent about a quarter of the country's GDP, it stands to reason that other industries will be expected to follow these same practices.

HIPAA & GLBA Security Due Care Practices in Common

The 12 security practices in common between HIPAA and GLBA are all "high-level" practices. There are no specific technology controls. Some practices are required while others are required only if a risk assessment conducted by the entity determines that the practice is appropriate.

The HIPAA Final Security Rule and the GLBA Interagency Guidelines were designed to provide guidance to senior management. How the practices are implemented is left largely up to the companies to determine.

Following is the list of the 12 security practices in common between HIPAA and GLBA (please refer to the HIPAA/GLBA Due Care Practice Matrix in the Laws and Regulations section of the OpenCSOProject for detailed analysis and references):

 

  1. Assess and Control Risk
  2. Assign Security Responsibility
  3. Appropriate Access and Authorization
  4. Security Awareness and Training
  5. Incident Response and Reporting
  6. Disaster Recovery
  7. Security Evaluation
  8. Vendor Contracts
  9. Facility Access Controls
  10. Data Integrity Controls
  11. Encryption
  12. Security Monitoring Procedures

 

Validation from Recent Enforcement Actions

If the companies in the FTC settlement cases mentioned earlier had faithfully implemented these 12 practices, they would not have suffered any penalties and their customers’ information would have been protected. For instance, in the Guess case, the FTC ordered Guess to:

 

  • Designate an employee or employees to coordinate and be accountable for the information security program (HIPAA/GLBA Due Care Practice #2: Assign Security Responsibility);
  • Identify material internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment must include consideration of risks in each area of relevant operation. (HIPAA/GLBA Due Care Practice #1: Assess and Control Risk);
  • Design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards' key controls, systems, and procedures. (HIPAA/GLBA Due Care Practice #7: Security Evaluation);
  • Evaluate and adjust its information security program in light of the results of testing and monitoring, any material changes to its operations or business arrangements, or any other circumstances that Guess knows or has reason to know may have a material impact on its information security program. (HIPAA/GLBA Due Care Practice #7: Security Evaluation)

 

These four requirements would have been fulfilled by following just three of the 12 HIPAA/GLBA Due Care Practices: Assess and Control Risk, Assign Security Responsibility, and Security Evaluation. The other settlement cases had similar requirements, also covered by the HIPAA/GLBA Due Care Practices. It is clear that the security practices required by both HIPAA and GLBA establish a basis of due care.

Conclusion

Companies are finding that they will pay the price for not maintaining strong security controls and protecting their customers' information. They must proactively implement and maintain prudent security processes to demonstrate that they are practicing due care. Until a universally accepted set of information security practices is produced, the best approach for companies is to implement the security practices required by both HIPAA and GLBA.

Marc R. Menninger is a Certified Information Systems Security Professional (CISSP) and is the founder and site administrator for the OpenCSOProject, a knowledge base for security professionals. To download security policies, articles and presentations, click here: Security Officer Forums.

Labels: , , , , ,