Section §164.308 of the Health Insurance Portability and Accountability Act (HIPAA) covers security management and assigning overall responsibility for security policies to an individual in the organization. This article focuses on the required HIPAA administrative safeguards covered in subsections §164.308(a)(1) and (a)(2) describing policies and responsibilities. Section (a)(2) is a simple requirement. The organization must identify an individual as the Security Official who is responsible for the policies and procedures that bring the organization into compliance with the law. The Security Official is responsible for communicating these policies effectively to all workforce members. These policies must also cover the workforce and training requirements discussed in section §164.308 which will be covered in a later article. In order to be HIPAA compliant,[…]

The new HIPAA Omnibus Rule from the Department of Health and Human Services (HHS) makes some changes to the Federal Code to account for the HITECH law as well as changes since then.  This summary will be discussing changes to the Breach Notification Rule; we will also have a summary for changes to the Privacy Rule. The major change to the Breach Notification Rule is that a breach requiring notification is assumed unless : the covered entity can show (through a risk assessment) that there is a low probability that the protected health information (PHI) has been compromised, or the compromise falls under one of three exceptions to the definition of “breach”. Previously, covered entities only had to notify affected individuals if a risk[…]

While reviewing the 2013 changes to HIPAA, we came upon this interesting bit of economic impact analysis early in the document. A table is presented called “Estimated Costs of the Final Rule”. Within this table, an estimated cost is presented for Security Rule Compliance by Business Associates, expected to apply to between 200,000 and 400,000 business associates of covered entities that were not previously directly liable for HIPAA compliance. The table lists this estimated cost as between $22.6 million and $113 million. I believe this cost is not remotely realistic. Let’s do a little math to figure out these costs per organization. How about a best case scenario, where we spend the least amount of money getting the largest number of[…]

In a press release issued last week, the U.S. Department of Health and Human Services (HHS) announced a long-awaited update to the Health Insurance Portability and Accountability Act of 1996 (HIPAA). HHS Secretary Kathleen Sebelius gave the understatement of the year in the announcement: “Much has changed in health care since HIPAA was enacted over fifteen years ago…” Some of the most significant changes in health care have been as a result of the original requirements of HIPAA. Now everyone who has been to a medical professional is familiar with signing a consent form indicating they have seen a Notice of Privacy Practices. This update to HIPAA, which will go into effect on March 26, 2013, and require compliance by September 23, 2013, has a number of[…]

By default, the installation of VMware’s vCenter and ESXi use self-signed certificates with hardcoded passwords to protect the private keys of their SSL web services. While it gets you services that work out of the box, it is really bad form and a poor security practice. If you install (or update to) version 5.1 of the VMware infrastructure components, you will be left with a bunch of warning windows like the ones on the left. If you’re lucky enough to have access to your own public key infrastructure, you can issue your own certificates to replace those provided by VMware so you don’t see constant warnings. However, if you undertake this effort be forewarned: VMWare’s guidance (Replacing Default vCenter 5.1[…]

Two weeks ago, I finally got a chance to try out a Windows 8 system. First, I have to give huge kudos to Dell, who makes the XPS 12 system I’m playing with. This system seems to be the ideal platform for a Windows 8 user. A thin and light notebook with plenty of power, with the ability to flip the screen around and make it into a touchscreen tablet. That said, during my initial installation of the system, alarm bells immediately rang in my head. “This system doesn’t comply with many password policies!” I found that as I joined my Windows 8 system to my company’s domain (which enforces a number of things through group policy), some configurations were allowed[…]