HIPAA Law



             


Saturday, May 17, 2008

Keeping Your Health Insurance Premiums Low


Health Savings Accounts offer tax deductions for medical expenses, and the opportunity to set up additional retirement accounts. But regardless of any other positive benefit of HSAs, lower premiums are the primary reason that thousands of Americans have chosen Health Savings Accounts as the best way to protect their family's health and assets. So I'd like to talk about some key suggestions on how to keep your premiums low.

1. Choose an HSA-qualified plan for lower rate increases.

Average group health insurance premiums rose by 9.6% last year and rose over 10% for each of the previous six years. Individual plans went up even more. Yet I expect most HSA plans to experience much lower rate increases. A very large study was recently published showing that rate increases over the past year for consumer driven health plans such as HSA plans was only 3.4%. Blue Cross of Minnesota has reported that its HSA customers spent 8% less than their traditional insurance clients. Humana has reported claims' costs of 4.9% for consumer-driven plans, versus a 19.2% increase in claims for other plans. In fact, average HSA premiums for individuals have actually dropped 19.5% during 2005.

The reason these plans will have lower rate increases is that people who have HSA-qualifying high deductible health insurance plans are likely to pay closer attention to costs, and take better care of their health. For instance, an HSA owner offered a statin drug to lower her cholesterol may be more likely to request a generic version, or ask her doctor if inexpensive nutritional supplements such as niacin or fish oil may be a solution. These actions save the insurance company money and should result in lower rate increases.

2. Raise your deductible as your Health Savings Account grows.

When you fund your account you build up a financial "cushion" which allows you to raise your deductible as your account grows. Every time you raise your deductible, your premium should go down.

By the way, don't forget that every time you fund your account you get an instant tax-deduction. When you offset the tax savings against your premiums, you'll find your net cost for an HSA plan can be very low.

The maximum allowable contribution goes up every year with the rise of the Consumer Price Index. Final numbers are not out yet, but in 2006 we expect the individual contribution limit to go up to $2,700, and the family limit to be $5,450. So each year you can deposit greater amounts into your HSA and continue to raise your deductible, if you choose.

3. Stay healthy, so you can switch plans.

All health insurance plans have rate increases, and we've even seen premiums jump on some HSA plans. If a rate increase happens to you, you can switch to a different insurance company - but only if you pass their underwriting requirements. If chronic disease develops, you may be stuck with your current plan, and its accompanying rate increases, for eternity. Or at least it may seem that long...

If you pay attention to the pharmaceutical commercials, you learn lifestyle really has nothing to do with disease, and it is natural and healthy to be on many medications for the rest of your life, which will then solve your health problems.

If you pay attention to the science, you know the truth is quite different. It appears lifestyle is probably 95% of the picture, and we know the occurrence of degenerative disease can be dramatically reduced and even prevented.

Fortunately, I've found many of our customers are interested in wellness, and disease prevention. After all, they're paying for their own doctor visits if they do get sick. I also believe it is because HSA owners are "forward thinking" people, and like to plan for their future - both financial and physical. You can improve your odds of excellent health with just a few key habits:

Eat very high quantities of fresh vegetables and fruits. Shoot for 35% of your calories. This will lower your risk for diabetes, high blood pressure, heart disease, cancer, and more.

Limit your intake of sugar and starchy carbohydrates like bread and pasta. The majority of health problems in the U.S. are related to metabolic diseases that involve insulin resistance.

Exercise and lift weights. Exercise guru Jack La Lanne just turned 92 on September 26, and he says if you have muscles you never feel old.

4. Compare your plan to other available plans at least once a year, or whenever you get a rate increase.

Often-times people keep their plan much longer than they should, and end up paying much more than they should. If your rates go up, you can compare a wide variety of plans at http://www.HSAforAmerica.com/instant-quote.htm. If you have your coverage through HSA for America, we automatically do this analysis of available plans for you any time we are notified of rate increases.

To your health and wealth,

Wiley Long President - HSA for America

Labels: , , ,

Saturday, May 10, 2008

Lack Of A Health Insurance Policy Invites Financial Disaster.


In 2003 health care spending rose four times the rate the inflation. The annual premium for an employer health plan covering a family of four averaged nearly $10,000. The cost of medical care continues to rise at the fastest rate in history.

Health insurance premiums will rise to an average of more than $14,500 for family coverage in 2006.

Surveys reveal that the number one reason many people have no coverage is because health insurance is too expensive. 23% percent of people who do have health insurance have had to drastically change their spending habits so that they could make the insurance payments.

You've read about the rise in the number of bankruptcies. A study shows that the average medical debt of those who filed for bankruptcy is $12,000... And 50% of bankruptcy filings were partly the result of medical expenses. Every minute two people in the U.S. file for bankruptcy because of serious medical problems.

Research shows that even when one member of a family is uninsured and requires a hospital stay, or costly medical treatment, the medical bills can effect the financial position of the entire family as they try to help with costs. Government officials agree that health care costs must be controlled, but they continue to argue about how to do it. Some say it must be done with price controls and by imposing strict budgets on health care spending. Others cry for free market competition as the solution to the high cost of medical care.

An important step in the right direction would have all of us adopting healthy eating habits and lifestyles. We all would require less medical care and those costs would drop.

For individuals and families is vital that you have at least some form of health insurance policy. It may be sensible to keep your health insurance cost as low as possible by having coverage for only a catastrophic illness. The expense of most medical treatment can be paid for over time. It is the unexpected major, life threatening injuries and diseases that can wipe you out financially.

One thing is certain. To protect your financial future you must have at least some type of health insurance policy.

Mark Walters presents an online guide to health insurance of kinds at http://www.HealthInsuranceMonster.com

Labels: , , , , ,

Wednesday, May 7, 2008

How to Find Affordable Health Insurance


Affordable health insurance - it seems, especially today, those words just don't belong together in the same sentence. Health insurance monthly premiums have become the biggest single expense in our lives - surpassing even mortgage payments. In fact, if you have any permanent health problems, such as diabetes, or have had cancer at one time in your family history, your monthly cost could easily be more than the house and car payment combined.

Shopping for affordable health insurance can certainly be an eye-opener. If you have always had a health insurance benefit where you work - especially a state or federal employee - and now have to buy your own, you may not be able to afford the level of health insurance coverage you have become used to.

Affordable health insurance, however, is definitely available -if you know how and where to look.

When you are looking for affordable health insurance, you want the lowest cost per year that will fit your budget, of course. But, even more importantly, you want a company that has a good record for paying without fighting with you on every detail. Just as there is a car for just about any budget, there is also affordable health insurance. You may not be able to afford a "Cadillac" policy - but then you probably don't need all the frills anyway.

Shopping for health insurance on the internet is the easiest and best way to find affordable health insurance. Here are five reasons why.

1. You don't need a local agent to help you submit the claims for health insurance. The medical provider does it for you. You save money because the health insurance company saves money by not paying the agent commission. This could amount to an 8% to 12% savings to you.

2. All the top health insurance companies are at your fingertips on the internet. Most local agents can only quote you from the few companies that they represent. They may not offer you what is best for you financially or health-wise but only what they happen to have available.

3. Health insurance companies have to be extremely competitive because it is so quick and easy to compare them with their competitors on the internet today. In the past you would have had to visit physically eight to ten agents to do a similar comparison. Most folks just didn't have the time or desire for that.

4. You can change your coverage, deductibles, and payment options with just a few clicks rather than going through the paperwork delay with a local agent (and then finding out he/she made a mistake - more delay).

5. Charging to a credit card means you aren't going to forget a payment and be without insurance. Also, it gives you another 30 days before you actually have to pay. Also, many companies today give an additional discount for "auto-pay".

The key, however, to finding affordable health insurance is realizing that the purpose of any health insurance is to protect you from a major financial loss - not to protect you from spending small money on clinic visits and sliver removal. These small expenses may be cumbersome but they generally will not hurt you. It's the $100,000 heart operation that will break you. That's the financial disaster health insurance was originally designed to prevent.

Also, keep this in mind. Health insurance, as with any insurance, is a gamble. You are gambling that you will draw out more than you pay in. Your health insurance company is gambling they will pay out less. The odds are in their favor for two reasons. They have all the facts for millions of families to average out, so they know the risk in advance. Also, they get to set the rules and the prices. The higher you set your deductible, the more risk you take. This is not a bad thing at all. You will most likely be the winner in the long run.

Yes, finding affordable health insurance is much easier than most people think.

Taking more of the risk with higher deductibles, spending a little time on the internet comparing eight to ten different companies, and deleting coverage that you will not likely need (such as maternity for many folks) will make it very possible to find your own affordable health insurance.

Dr. Deepak Dutta is the creator of SemanticBay.com - an interactive social network website based on user shared text and picture contents on any topics. Website creators, publishers, and maintainers can promote their website at SemanticBay.com using website articles. Users can join for free, invite friends, maintain buddy lists, rate contents, comment on contents and earn points.

Labels: , , , , , ,

Thursday, March 27, 2008

"How To Get Fit And Slash Your Health Insurance Costs"

"How To Get Fit And Slash Your Health Insurance Costs"

Okay, before we start, let me explain the purpose of this article. I want you to get so healthy, you'll never need to make a health insurance claim. You'll save money by increased fitness. You'll save money with a long no-claims insurance history. And you'll look and feel much better.

There's three sides to your maximum health and fitness. Diet, and Exercise. But that's only two ! Let me split Exercise into Aerobic exercise and Aneorobic exercise.

Get all three right. Get the right balance. And you'll get as fit and healthy as your body and genetics will allow.

Whole forests of paper have been filled with advice on each of these fitness factors. Just go into your local bookstore, and see shelves of diet advice. Shelves of exercise advice.

Funny how so much contradicts itself, especially for diet e.g right next to each other on the shelf, you'll find a book advocating low carbs & low fat; another saying high fat is okay if you keep the carbs low. Yet another focuses on high protein, and says carbs don't matter...

* Diet

Let me give you this simple diet advice. Stick to low fat, low carbs and high protein. Many medical and weight loss studies over the last 10-20 years prove this approach. Many other diet myths come from way back in time, and look just plain wrong when analyzed with modern methods.

* Aerobic Exercise

Couch potatoes don't realize how easily they can start feeling fit and healthy. Just walk somewhere 3-4 times per week, for around 20 minutes each time.

Ideally, do some more demanding aerobic exercise. I do a lot of cycling, because it's great low-impact exercise. And I get to see beautiful scenery while I ride.

Running provides even more intensive aerobic exercise, but careful of your joints. Maybe you prefer hiking, to see the local countryside ? Or take up a sport like rowing or tennis. You also get to meet new friends by taking up exercise as a sport.

* Anaerobic Exercise

Many people work on their diet. Many people take aerobic exercise. But many people ignore anaerobic exercise, or weight training.

What makes weight training so important ?

As you get older, muscle mass decreases. Muscle burns fat. So as you lose muscle, it gets harder to keep the fat off. Equally important, weight training can reshape your body.

No matter how much aerobic exercise you do, you'll still be a pear shape (a smaller pear shape) if you started out a pear shape.

Using weights you can flatten your stomach, tone your thighs, bulk up your chest and shoulders, and reshape your body any way you want.

Weight training is incredibly beneficial to your general skeleton strength and conditioning. Older women can reduce the effects of osteoporosis, and older men can maintain their strength and agility.

This short article can do nothing more than provide an introduction to the three keys to your health. Follow these and you shouldn't need to make a health insurance claim.

Slash your health insurance costs with a long no-claims bonus. Slash your health insurance costs with any insurer who rates your fitness.

Discover important health insurance facts and advice. Find out more about low carb foods, and how to lose weight quickly and easily. Go to ==> http://www.healthinsurance--quotes.com/ and ==> http://www.low-low-carb-foods.com/

Neil Stelling BSc, MBA

http://www.healthinsurance--quotes.com/

neil@healthinsurance--quotes.com

Labels: , , , , ,

Monday, February 11, 2008

How To Save Money On Health Insurance Premiums Using HSA's

Opening a health savings account (HSA) can save you hundreds on your health insurance premium and help pay for out of pocket expenses and deductibles. Anyone younger than age 65 who buys a qualified health insurance policy with a deductible of at least $1,000 for individuals, $2,000 for families, can open an HSA. An HSA lets you set aside pretax money up to the amount of the deductible (with an annual maximum of $2,600 for singles; $5,150 for families). You can use the money tax-free for medical expenses, and anything left over grows tax-deferred. You can use the money for anything after age 65 without penalty, but you will owe income taxes on any money that isn't used for medical expenses.

In many cases, the cost savings from buying a high-deductible policy make up for the higher out-of-pocket medical expenses you'll have to pay -- not to mention the tax benefits.

The HSA Insider Web site (http://www.hsainsider.com) has a comprehensive list of insurers offering HSA-eligible policies and financial institutions providing the investment accounts. You can also search for a quality high deductible health insurance plan to complement your HSA at Best Insurance Deals (http://www.Best-Insurance-Deals.net).

Charles White has authored several informational articles related to saving money on insurance. He is the owner of Best Insurance Deals, a website offering several sources of free insurance quotes saving you hundreds on Auto, Life, Health, Long Term Care and RV insurance. You can visit the website at http://www.best-insurance-deals.net and save money today.

Labels: , , ,

How to Get NPI - National Provider Number for HIPAA-Compliant Medical Billing in 7 Steps

The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) mandated the adoption of standard unique identifiers for health care providers, as well as the adoption of standard unique identifiers for health plans. They become mandatory on May 23, 2007.

The purpose of these provisions is to improve the efficiency and effectiveness of the electronic transmission of health information. The Centers for Medicare & Medicaid Services (CMS) has developed the National Plan and Provider Enumeration System (NPPES) to assign these unique identifiers.

CMS has contracted with Fox Systems, Inc. to serve as the NPI Enumerator. The NPI Enumerator is responsible for dealing with health plans and providers on issues relating to unique identification.

HCFA Timetable

Changes in the HCFA 1500 form to accommodate the NPI number took place January 1, 2007. Until March 30, 2007, using NPI number on the HCFA form is optional but as of April 2, 2007, using NPI becomes mandatory.

Getting an NPI is free - Not Having One Can Be Costly: If you delay applying for your NPI, you risk your cash flow.

  1. Enumerate: Enumeration is mandatory for both individual providers and organizations and subparts. When applying for your NPI, CMS urges you to include your legacy identifiers, not only for Medicare but for all payors. If reporting a Medicaid number, include the associated State name. This information is critical for payors in the development of crosswalks to aid in the transition to the NPI.
  2. Update: Make sure to upgrade your software, HIPAA Transactions, CMS1500, UB04, and/or Dental claim form changes.
  3. Communicate: Notify your payers once you have obtained your NPI number. As outlined in the Federal Regulation (The Health Insurance Portability and Accountability Act of 1996 (HIPAA)) you must also share your NPI with other providers, health plans, clearinghouses, and any entity that may need it for billing purposes -- including designation of ordering or referring physician.
  4. Collaborate: Check the readiness of your payment partners (such as health plans, TPAs, clearinghouses, etc...)? Not all payers are ready to accept the NPI number at this time. Use both your existing (legacy) number and the NPI number when submitting electronic claims.
  5. Test: Test transactions well before the deadline. Make sure to test HIPAA Transactions, e.g., 837 Claims, 835 Remittance Advice, and, if you submit paper claims, verify that the data is printed in the correct fields. The new HCFA form has new fields for identifier numbers on lines 17b, 32a and 33a.
  6. Educate: Focus on staff working on insurance verification of eligibility and claim denial or underpayment follow up.
  7. Implement: Once you obtain your NPI, it might take about 120 days to do the remaining work to use it. This includes working on your internal billing systems, coordinating with billing services, vendors, and clearinghouses, testing with payers.
  8. Yuval Lirov, PhD, author of "Mission Critical Systems Management" (Prentice Hall), inventor of patents in Artificial intelligence and Computer Security, and CEO of Vericle.net Billing Technologies and Services. Vericle? unites hundreds of billing services across the nation. Its electronic medical billing software tracks payer performance from a single point of control and shares compliance rules globally. Yuval invites you to register to the next webinar on audit risk at BillingPrecision.com

Labels: , , ,

Friday, January 18, 2008

HIPAA: Requirements For Intranet Collaboration Software

Sharing private health information over the internet can be a risky business. Unfortunately, as people become accustomed to doing most if not all of their personal business online, the demand for accessing this information online will grow to the point that health care providers will have no choice but to either provide access to this private health information or lose their customers.

The Health Insurance Portability and Accountability Act (HIPAA) was enacted to assure the confidentiality of patient information. This requires that health care providers employ stringent measures to assure that information shared on the internet is protected from unauthorized access.

The HIPAA Act requires health-providing entities to:

* Assign responsibility for security to a person or organization.

* Assess security risks and determine the major threats to the security and privacy of protected health information.

* Establish a program to address physical security, personnel security, technical security controls, and security incident response and disaster recovery.

* Certify the effectiveness of security controls.

* Develop policies, procedures and guidelines for use of personal computing devices (workstations, laptops, hand-held devices), and for ensuring mechanisms are in place that allow, restrict and terminate access (access control lists, user accounts, etc.) appropriate to an individual's status, change of status or termination.

* Implement access controls that may include encryption, context-based access, role-based access, or user-based access; audit control mechanisms, data authentication, and entity authentication

This law has serious implications for organizations that allow unauthorized access resulting in a breach in confidentiality.

Security is the key

Since the HIPAA law provides for both civil and criminal penalties for violations, data and access security is of the utmost importance. To assure HIPPA compliance, online document management on company intranets and extranets must include a number of security features:

* Secure web server - a server running secure socket layers is the minimum needed.

* Encrypted database - all data must be encrypted. Software is available that will encrypted all data sent between two computer over the internet.

* Secure access control -- in addition to a traditional user id and password, it may be a good idea to use a strong password or smart card as additional security.

* Session timeout - this assures that confidential data is not left on an unattended screen.

* Server monitoring - the secure web server needs to be strictly monitored to detect break-in attempts.

* Regular security audits - regular audits are required to make sure all security precautions are working properly.

* Personnel - system maintenance should be in the hands of qualified personnel familiar with HIPPA requirements

Laura Schweiker writes extensively on the use of technology by businesspeople and is an evangelist for online collaboration and intranet solutions.

Labels: , , , , ,

Tuesday, January 8, 2008

Alert: New HIPAA Rules Could Affect Your Organization

 Trust Failure to adhere to the new guidelines could cost your company
up to $250,000 per infraction!


On April 21, 2005 (just over three weeks from today), a new Health Insurance Portability and Accountability Act (HIPAA) security rule goes into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and availability of information.

The imminent HIPAA regulatory requirements encompass transmission, storage and discoverability of Protected Health Information (PHI). Given the widespread use and mission-critical nature of email, enforcement of HIPAA encryption policies and the growing demand for secure email solutions, email security has never been more important to the healthcare industry than it is right now.

Although many assume it applies only to health care providers, HIPAA affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 by former President Bill Clinton, with the intent of protecting employee health and insurance information when workers changed or lost their jobs. As Internet use became more widespread in the mid-to-late 1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information.

HIPAA in the Workplace
Collaboration between employers and healthcare professionals has grown increasingly digital, and email has played an ever-increasing role in this communication. However, emails increased importance can lead to severe consequences without proper security and privacy measures implemented.

In addition to the usual concerns about privacy and security of email correspondence, even organizations that are not in the healthcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how email containing PHI should be treated in the corporate setting. HIPAA, as it relates to email security, is an enforcement of otherwise well-known best practices that include:


  • Ensuring that email messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that email systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting email servers and message stores where PHI may exist


Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

Privacy and Email Security
The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

The clock is ticking its time to get started
Bringing an enterprise into compliance with the rules set by HIPAA can seem like a very daunting task to even the most experienced executives. Nonetheless, the growing dependence on email as a mission-critical application requires that your organization implement comprehensive security and privacy policies and soon. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence.

Despite the immediacy of the new HIPAA security rule, your organization can still achieve compliance. Learn more about how IronMail helps organizations comply with HIPAA by downloading CipherTrusts free whitepaper, "IronMail Compliance Control: Contributing to Corporate Regulatory Compliance". Failure to adhere to the new guidelines could cost your company
up to $250,000 per infraction!


On April 21, 2005 (just over three weeks from today), a new Health Insurance Portability and Accountability Act (HIPAA) security rule goes into effect. The requirements of this rule, which are basically information security best practices, focus on the three cornerstones of a solid information security infrastructure: confidentiality, integrity and availability of information.

The imminent HIPAA regulatory requirements encompass transmission, storage and discoverability of Protected Health Information (PHI). Given the widespread use and mission-critical nature of email, enforcement of HIPAA encryption policies and the growing demand for secure email solutions, email security has never been more important to the healthcare industry than it is right now.

Although many assume it applies only to health care providers, HIPAA affects nearly all companies that regularly transmit or store employee health insurance information. HIPAA was signed into law in 1996 by former President Bill Clinton, with the intent of protecting employee health and insurance information when workers changed or lost their jobs. As Internet use became more widespread in the mid-to-late 1990s, HIPAA requirements overlapped with the digital revolution and offered direction to organizations needing to exchange healthcare information.

HIPAA in the Workplace
Collaboration between employers and healthcare professionals has grown increasingly digital, and email has played an ever-increasing role in this communication. However, emails increased importance can lead to severe consequences without proper security and privacy measures implemented.

In addition to the usual concerns about privacy and security of email correspondence, even organizations that are not in the healthcare industry must now consider the regulatory compliance requirements associated with HIPAA. The Administrative Simplification section of HIPAA, which, among other things, mandates privacy and security of Protected Health Information (PHI), has sparked concern about how email containing PHI should be treated in the corporate setting. HIPAA, as it relates to email security, is an enforcement of otherwise well-known best practices that include:

  • Ensuring that email messages containing PHI are kept secure when transmitted over an unprotected link
  • Ensuring that email systems and users are properly authenticated so that PHI does not get into the wrong hands
  • Protecting email servers and message stores where PHI may exist


Organizations regulated by HIPAA must comply and put these practices in place. However, the need to comply with regulations puts particular pressure on the healthcare industry to enhance their use of technology and catch up with other industries of similar size and scope.

Privacy and Email Security
The privacy protection provisions in HIPAA pose a major compliance challenge for the healthcare industry. These provisions are intended to protect patients from disclosure of any of their individually identifiable health information. Organizations that fail to protect this information face fines ranging from $10,000 to $25,000 for each instance of unauthorized disclosure. If the disclosure is found to be intentional, HIPAA provides for fines ranging from $100,000 to $250,000 and possible jail time for individuals involved in the violations.

The clock is ticking its time to get started
Bringing an enterprise into compliance with the rules set by HIPAA can seem like a very daunting task to even the most experienced executives. Nonetheless, the growing dependence on email as a mission-critical application requires that your organization implement comprehensive security and privacy policies and soon. A solid combination of security policies and the technologies to enforce those policies can ensure improved security as well as HIPAA readiness and ongoing adherence.

Despite the immediacy of the new HIPAA security rule, your organization can still achieve compliance. Learn more about how IronMail helps organizations comply with HIPAA by downloading CipherTrusts free whitepaper, "IronMail Compliance Control: Contributing to Corporate Regulatory Compliance".
CipherTrust is the leader in anti-spam and email security. Learn more by downloading our free whitepaper, IronMail Compliance Control: Contributing to Corporate Regulatory Compliance or by visiting www.ciphertrust.com.

Labels: , , , , , ,

Thursday, November 29, 2007

Deriving Due Care Practices from HIPAA and GLBA

Recent years have shown a trend in corporations being held responsible for information security negligence. In particular, the Federal Trade Commission (FTC) and the Attorney General of New York have been actively pursuing companies that fail to follow effective security practices. Many high-visibility cases illustrate how companies are being required to implement stronger security controls, the Guess case being a good example.

In June 2003, Guess, Incorporated agreed to settle FTC charges that it exposed consumers' personal information to commonly known attacks by hackers, contrary to the company's claims. "Consumers have every right to expect that a business that says it's keeping personal information secure is doing exactly that," said Howard Beales, Director of the FTC's Bureau of Consumer Protection. The settlement required that Guess implement a comprehensive information security program that would be certified as meeting or exceeding the standards in the consent order by an independent professional within a year.

The Problem

A key reason why corporations demonstrate poor or inconsistent information security controls is the lack of a widely accepted and comprehensive set of good security practices. Standards bodies such as the U.S. National Institute of Standards and Technology (NIST) and the International Organization for Standardization (ISO) publish security standards with varying degrees of corporate acceptance and use. The Information Systems Security Association (ISSA) has identified the need for a universally agreed-upon collection of essential security practices and is currently developing the Generally Accepted Information Security Principles (GAISP)--although how well accepted these principles will be upon publication remains to be seen.

The Health Insurance Portability and Accountability Act (HIPAA) Final Security Rule and the Gramm Leach Bliley Act (GLBA) Interagency Guidelines are customer privacy laws specifying the security rules that must be followed by the healthcare and financial services industries respectively. If entities covered by these laws fail to follow the required security practices they may not only be exposing their customers' private information but may also be subject to regulatory penalties and fines. These laws, in essence, define information security due care standards--the security practices that must be followed to avoid liability--for the healthcare and financial services industries. The entities covered by these laws, however, only represent approximately 25% of the U.S. Gross Domestic Product. Other industries must rely upon their best judgment to protect customer information--clearly not an effective approach as the cases mentioned earlier demonstrate.

Most companies certainly want to do the right thing and protect their customers' information, but avoiding legal liability and harm to their reputation are also factors that motivate them to implement appropriate information security controls. While most corporate information security professionals probably think they understand how to protect customer information, many wouldn't be comfortable attesting that their practices would protect their employer from liability. Lacking a commonly accepted set of security practices, many corporate information security professionals are uncertain how to secure customer information in a way that also limits their company's liability.

Proposed Solution

The best approach for companies that wish to protect their customer's information and potentially avoid liability is to implement the security practices required by both HIPAA and GLBA. There are 12 security practices in common between these two customer privacy laws. By following these 12 practices, companies will be practicing information security due care and can potentially avoid liability. Indeed, all of the security requirements mandated in the settlement of the cases mentioned earlier are among the 12 practices in common between HIPAA and GLBA.

What is Due Care?

Companies that handle the personal information of their customers may be breaking the law and not know it, as evidenced by the Guess case. This ignorance may partly stem from substantial gaps of prosecutable computer crimes that exist in federal criminal code and individual state criminal statutes. Federal and state criminal statutes are slow to evolve to adequately prosecute crimes based on the fast-changing technology of information systems. Companies and information security professionals may find little direction in criminal codes and statutes to help them avoid inadvertently breaking the law when it comes to protecting their customers' personal information.

Since there is little guidance for companies to follow when it comes to avoiding criminal or civil liability or harsh settlements from the FTC, they need to consider how legal standards are created in the first place. Legal standards are developed based on the concept of due care, which is the care that an ordinarily prudent person would have exercised under the same or similar circumstances. Failure to practice due care is equivalent to demonstrating negligence. Companies that demonstrate negligence relative to their information security practices are susceptible to lawsuits, fines, and other sanctions, whereas companies that practice due care should be largely protected from such punishments.

Where to Find Due Care Information Security Practices

Companies that wish to find due care information security practices need look no further than to two major federal laws that regulate the protection of customer information: HIPAA and GLBA. While both HIPAA and GLBA enacted a lot more than just customer privacy requirements, they both have spawned substantial regulatory guidance on security controls for protecting customer information. The regulations for HIPAA are called the Final Security Rule and those for GLBA are referred to as the Interagency Guidelines.

While some of the requirements in these regulations are industry-specific, there is a lot of commonality between the two. In particular, 12 security practices were found in both the HIPAA Final Security Rule and the GLBA Interagency Guidelines. The fact that these two sets of regulations intersect in 12 places is no coincidence. This is a clear signal from the federal government of the level of due care it expects the country's health care providers and financial institutions to practice. If these are the standards of due care that must be practiced by industries that represent about a quarter of the country's GDP, it stands to reason that other industries will be expected to follow these same practices.

HIPAA & GLBA Security Due Care Practices in Common

The 12 security practices in common between HIPAA and GLBA are all "high-level" practices. There are no specific technology controls. Some practices are required while others are required only if a risk assessment conducted by the entity determines that the practice is appropriate.

The HIPAA Final Security Rule and the GLBA Interagency Guidelines were designed to provide guidance to senior management. How the practices are implemented is left largely up to the companies to determine.

Following is the list of the 12 security practices in common between HIPAA and GLBA (please refer to the HIPAA/GLBA Due Care Practice Matrix in the Laws and Regulations section of the OpenCSOProject for detailed analysis and references):

 

  1. Assess and Control Risk
  2. Assign Security Responsibility
  3. Appropriate Access and Authorization
  4. Security Awareness and Training
  5. Incident Response and Reporting
  6. Disaster Recovery
  7. Security Evaluation
  8. Vendor Contracts
  9. Facility Access Controls
  10. Data Integrity Controls
  11. Encryption
  12. Security Monitoring Procedures

 

Validation from Recent Enforcement Actions

If the companies in the FTC settlement cases mentioned earlier had faithfully implemented these 12 practices, they would not have suffered any penalties and their customers’ information would have been protected. For instance, in the Guess case, the FTC ordered Guess to:

 

  • Designate an employee or employees to coordinate and be accountable for the information security program (HIPAA/GLBA Due Care Practice #2: Assign Security Responsibility);
  • Identify material internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment must include consideration of risks in each area of relevant operation. (HIPAA/GLBA Due Care Practice #1: Assess and Control Risk);
  • Design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards' key controls, systems, and procedures. (HIPAA/GLBA Due Care Practice #7: Security Evaluation);
  • Evaluate and adjust its information security program in light of the results of testing and monitoring, any material changes to its operations or business arrangements, or any other circumstances that Guess knows or has reason to know may have a material impact on its information security program. (HIPAA/GLBA Due Care Practice #7: Security Evaluation)

 

These four requirements would have been fulfilled by following just three of the 12 HIPAA/GLBA Due Care Practices: Assess and Control Risk, Assign Security Responsibility, and Security Evaluation. The other settlement cases had similar requirements, also covered by the HIPAA/GLBA Due Care Practices. It is clear that the security practices required by both HIPAA and GLBA establish a basis of due care.

Conclusion

Companies are finding that they will pay the price for not maintaining strong security controls and protecting their customers' information. They must proactively implement and maintain prudent security processes to demonstrate that they are practicing due care. Until a universally accepted set of information security practices is produced, the best approach for companies is to implement the security practices required by both HIPAA and GLBA.

Marc R. Menninger is a Certified Information Systems Security Professional (CISSP) and is the founder and site administrator for the OpenCSOProject, a knowledge base for security professionals. To download security policies, articles and presentations, click here: Security Officer Forums.

Labels: , , , , , , ,