PCI Compliance
5 of 9 HIPAA Network Considerations
Over the last several weeks, I’ve been posting a blog series around nine HIPAA network considerations. HIPAA Audits will continue The HIPAA Audit Protocol and NIST 800-66 are your best preparation Knowledge is a powerful weapon―know where your PHI is Ignorance is not bliss Risk Assessment drives yo…
Attend the 2013 PCI Community Meeting for the Latest Core PCI Standards
The Payment Card Industry (PCI) Security Standards Council (SSC) is an open global forum for the ongoing development, enhancement, storage, dissemination, and implementation of security standards for account data protection. The 2013 meeting will focus on the updates to core PCI standards: PCI DSS,…
4 of 9 HIPAA Network Considerations
The fourth consideration in this 9 HIPAA Network Considerations blog series, we look at whether ‘not knowing’ is a valid defense post-breach. Is Ignorance Bliss, or will that get you into trouble? Remember, the HIPAA Omnibus Rule was released January 23, 2013, became effective March 26, 2013 with co…
3 of 9 HIPAA Network Considerations
Next in this 9 HIPAA Network Considerations blog series, I cover the third network consideration focusing on knowing where your PHI is. Remember, the HIPAA Omnibus Rule was released January 23, 2013, became effective March 26, 2013 with compliance to the updates se for September 23, 2013. Audits w…
TMA? Get Some Relief from Acronym Overload
I see and hear a variety of acronyms being used on a daily basis. I recently heard one tossed around with good humor that makes a point: TMA or Too Many Acronyms. Every once in a while, when I think I’ve embedded the definition and use of an acronym into my long-term memory (anything beyond an…
2 of 9 HIPAA Network Considerations
Continuing the thread from the last blog where I discussed the first HIPAA network consideration, ‘HIPAA Audits will continue’, in this blog I’ll discuss the second network consideration on the list below. Remember, The HIPAA Omnibus Final Rule, released January 2013, introduced some significant ch…
1 of 9 HIPAA Network Considerations
The HIPAA Omnibus Final Rule, released January 2013, introduced some significant changes and updates. The 2012 HIPAA audits, performed by KPMG, concluded with some initial findings released by the Department of Health and Human Services (HHS) Office of Civil Rights, OCR. These two events may impac…
Question: Are you PCI Compliant? Are you Secure? Part 2 of 2
Last week, we sat down with Bart McGlothin and Christian Janoff from Cisco’s security team to discuss PCI Security for Retail to better understand “What is PCI Compliance?” and “How does that affect Retailers?” As a quick re-cap: PCI Compliance is a 12-step process to secure credit cards. Any retail…
Question: Are you PCI Compliant? Are you Secure? Part 1 of 2
A common perception is that there is a difference between being secure and being compliant. A Verizon analysis on cybercrime reported that cyber-attacks on Retailers are increasing and becoming streamlined and automated. According to the 2012 Verizon PCI compliance report, “97% of breaches were avo…