Twitter
RSS

Posts Tagged ‘united-kingdom’


Laptop Thefts Again Lead Breach Roundup

“In this week's breach roundup, three organizations report breach incidents involving the theft of unencrypted laptops, a continuing problem in the healthcare arena. Stolen Laptop Affects 13,000 Home Care PatientsAn unencrypted laptop containing information on more than 13,000 clients of United HomeCare Services was stolen, compromising sensitive patient information. Although the Miami-based home health company's announcement didn't specify how many clients were affected, the U.S

Read More...

HIE Security Best Practices Get a Boost – Grants Support Secure Health Information Exchange Efforts

“Two organizations have received federal funding to support projects, including development of security best practices, designed to help pave the way for nationwide health information exchange. The Office of the National Coordinator for Health IT on April 4 announced it awarded $280,000 to DirectTrust, a non-profit trade association that created and maintains a security and trust framework for using the Direct Project protocol for secure e-mail between healthcare providers. DirectTrust will use the grant to support expanding security and trust best practices, standards and policies, says David Kibbe, the association's president and CEO….”

Read More...

FFIEC: Tackling New Online-Banking Risks – Bank Risk Assessment Reveals Need for Change

“Mike Wyffels, chief technology officer of QCR Holdings, a $2 billion company that owns and oversees four banking institutions, says recent risk assessments conducted as part of FFIEC guidance conformance proved QCR needed to make some shifts in its online-banking strategy.

Read More...

Federal Advisers Tackle Secure HIE – Committee Approves Data Sharing Proposals

“A federal advisory panel is outlining how to address privacy and security issues involved in the exchange of patient information among healthcare providers using the query and response method. The HIT Policy Committee on April 3 approved recommendations from its Privacy and Security Tiger Team.

Read More...

DDoS 'Cousin' Targets Emergency Call Centers – DHS, FBI Issue an Alert on Telephony-Denial-of-Service Attacks

“Extortionists employing telephony-denial-of-service attacks – a first cousin of DDoS attacks – are targeting emergency communications centers that dispatch first responders. According to an alert issued by the U.S. Department of Homeland Security and the FBI, dozens of TDoS attacks have taken aim at the communications centers known as public safety answering points.

Read More...

DDoS: What to Expect From Next Attacks – Phase 3 Incidents Offer Likely Glimpse into Future

“U.S.

Read More...

Webinar – ISACA's Guide to COBIT 5 for Information Security

“ISACA, the global IT association, recently released COBIT 5 for Information Security – new guidance aimed at helping security leaders use the COBIT framework to reduce their risk profile and add value to their organizations. Join two ISACA leaders for an insider's look at how to use COBIT 5 for Information Security to:Link information security with organizational strategic goals;Create the appropriate governance and management framework;Comply with the ever-growing number of relevant laws, regulations and contractual requirements….”

Read More...

CISO as Chief Privacy Officer – Why Intel Decided to Combine the Two Posts into One

“Intel has added privacy to the portfolio of its top information security executive, Malcolm Harkins, who says too many information security professionals are “color blind or tone deaf” to privacy, wrongly thinking strong data protection provides privacy safeguards. “Security organizations need to recognize that potential blind spot in their acumen, and they need to partner with and work very, very heavily with their privacy organization,” Harkins says in an interview with Information Security Media Group. Despite common ground, he says, too often security and privacy professionals don't work together, adding: “That is a disservice to both the privacy and the security teams, as well as a disservice to the organizations that they work for.”In the interview, Harkins:Explains why the chip and IT wares maker combined the roles of chief information security and chief privacy officers into a single position, which helps manage risk;Furnishes an example of how security and privacy needs could clash and how having a single organization address both helps resolve the conflict;…”

Read More...

What's Ahead for HIPAA Audits? – OCR's McAndrew Describes Timeline, Offers Insights

“The HIPAA compliance audit program will not resume until after the current federal fiscal year ends Sept. 30, says Susan McAndrew of the Department of Health and Human Services' Office for Civil Rights, which enforces HIPAA. A contractor is evaluating the results of last year's 115 HIPAA compliance audits conducted as part of a pilot project

Read More...

Mobile Software and User Privacy – FTC Puts Onus on Developers to Ensure Data Security

“One of my colleagues has a propensity for assigning code names to people and has given me the moniker “Mobile 1.” Not talking out of school here, but CK uses her iPhone for calls, texting and e-mails, and that's about all she can, or wants, to do. Late one afternoon, I received a call from my colleague, who's based in Dallas/Fort Worth. “Mobile 1, you know that I could care less about apps, other than the weather, but the other night I tried to get into my iTunes account and couldn't because some other person's information is in there.”You need to know that although CK is brilliant in certain areas, she admittedly terms herself an “idiot non-savant” when it comes to any form of technology – other than something really simple like an ATM (yes, iPhones and iPads still escape her comprehension)….”

Read More...