October 10, 2017. HIPAA Integrity® commends to your attention the October 6, 2017, Health Data Management article by John Morrissey entitled: “Lack of security risk assessment could trim Medicare payments.”
August 16, 2017. On August 15, 2017, the National Institute of Standards and Technology (NIST) announced publication of the Draft Fifth Revision of NIST Special Publication (SP) 800-53 in a news release entitled: “NIST Crafts Next-Generation Safeguards for Information Systems and the Internet of Things.” NIST encourages public comment on Draft NIST SP 800-53-5 during the comment period of August 15-September 12, 2017, with comments sent via email by September 12, 2017, to: sec-cert@NIST.gov, with the subject line: “’Comments on Draft SP 800-53 Rev.5.’”
August 9, 2017. The September 2017 issue of Consumer Reports has an article in the Ask Our Experts section entitled: “How do ransomware attacks work? And if one happens to me, should I pay?” Here is part of the excellent answer:
August 8, 2017. The National Institute of Standards and Technology (NIST) has published with an August 2017 publication date NIST Special Publication (SP) 800-181: National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework. The Abstract for this publication follows:
July 27, 2017. The Office for Civil Rights (OCR) of the U.S. Department of Health and Human Services (HHS) has improved its breach portal for filing a Notice to the Secretary of HHS—Breach of Unsecured Protected Health Information, downloading a sample form showing Breach Portal Required Information for reporting a breach, listing Cases Currently Under Investigation that were reported in the past 24 months, and providing an archive of “all resolved breach reports and/or reports older than 24 months.” As of today, there are 350 cases under investigation and 1,659 cases in the archive that dates back to the required reporting date in September 2009.
June 27, 2017. The National Institute of Standards and Technology (NIST) released this month new Digital Identity Guidelines in a suite of four final documents in the Special Publication (SP) 800 series as SP 800-63-3. According to NIST, this suite of four documents covers “digital identity from initial risk assessment to deployment of federated identify solutions.” This suite is an outcome of a collaboration of stakeholders from government, industry, and academe, with the guidelines in the suite of documents describing “the risk management processes for selecting appropriate digital identity services and the details for implementing identity assurance, authenticator assurance, and federation assurance levels based on risk”.