Average annual cost of #PCI compliance audit? $225k http://bit.ly/9o0PjU
#PCI DSS logging: A must for #compliance http://bit.ly/9Fom7k , it mandates logging of specific details and log-review procedures
Security Breach Notification Laws Reinforce Need for Cyber Insurance http://bit.ly/cSyqjK 40 states now enforcing privacy security laws
RT @mashable Hundreds of Twitter Accounts Hacked [WARNING]. http://bit.ly/dq5VCo #Twitter #Hacked #Hacking
#Westin Bonaventure Los Angeles latest victim of hotel #hackers, http://bit.ly/caEyC8 worldwide hotel hacking is on the uptrend
HIPAA Top 5
HIPAA Top 5 Protections
The Health Insurance Portability and Accountability Act (HIPAA) sets specific guidelines for any site that stores or transmits Personal Health Information (PHI). This can be in one location or between different locations. It can be internal or external and still require the same safeguards. The Security Rule and a Privacy Rule requires there to be technical and physical controls over the integrity and privacy of PHI. In addition, there has to be restrictions to the access of PHI to only authorized personnel.

1. Conduct a Risk Assessment
Section 164.308(a)(1) of HIPAA requires an organization to conduct the risk analysis before any solution is implemented. It is important to know your network’s vulnerabilities. Officials must understand what type of information might get exposed, who might expose it, and how where it could be exposed. The result of this analysis will facilitate creation of security policies & procedures.

2. Take a Multi-Layer Approach
A single technology cannot provide complete protection. Implementing firewalls, anti-virus software, anti-spam, and intrusion prevention are just some of the things needed to keep patient data completely secure. Your production environment should be protected from your development environment. You need to know what attacks are taking place at each layer of security.

3. Don’t Forget About Email

More patient data is breached through email than any other source. It is crucial to have secure email and full content filtering. You need both inbound and outbound filters for personal health information protection.

4. Implement Policies

Employees must be educated on the security policies of an organization, why the policies are important and how to protect confidential information. eSecurity training is the first step in this important process. Implement a security awareness and training program for all members of its workforce including management.

5. Backup Your Data Offsite (Securely)

Offsite data backup has become the easier and safer alternative to the out dated tape method. Offsite data backup offers multiple encryption methods, sophisticated file search availability, and complete automation. You can recover you data swiftly and test your backup information quickly for accuracy and completeness.


Contact your KRAA Security specialist for further information, devyn@kraasecurity.com
Generated with Mad4Joomla Mailforms Version 1.1.9.1
* Required information.
Name: *
Email: *
Company Name: *

Rapid Assessment Purchase


List All Products
Show Cart
Your Cart is currently empty.

pci-asv2

 

Contact Us: (Antispam Question- What is 1+1?)
Name
Phone
Email
Company
Interest

right_banner1