EHR Authors and Value Added Resellers (VARs) will soon have their own HIPAA obligations. At present, EHR Authors and VARs are contractually obligated by the terms of any HIPAA Business Associate Agreements (BAAs) they have signed. Soon, EHR Authors and VARs (and all other types of Business Associates) will be directly regulated by HIPAA. This means that they will be subject to Civil Monetary Penalties up to $50,000 per incident and up to $1.5 million for identical violations in 1 year. Click to read the rest!
-

Categories
Surf Cloud
Access Control Backup Breach Notification Rule Business Associate CMP compliance audit DOJ EHR EMR Encryption Enforcement Facebook FERPA HIPAA HIPAA Complaint HIPAA Compliance Audit HIPAA Compliance Audits HIPAA Criminal Conviction HIPAA Security HIPAA Security Breach HITECH Hospitals JCAHO KPMG lifestyle modification malware Meaningful use mobile devices NIST 800-30 OCR Ohio OIG Policies & Procedures Policy Manual risk analysis risk assessment Security Vulnerabilities SMS social media State AG Texas HB 300 Texas House Bill 300 Texting Text messages Wireless SecurityArchives

Nonetheless, Eagle Consulting’s Beijing contacts have helped piece together the components of the remediation effort. Immediately after the incident, the front entrance was closed and a security perimeter was established for pedestrian safety. A protective canopy was constructed along the rear and employees and visitors were directed to use the rear entrance. Then, the inspection and correction of any problems on the front was conducted. Now that phase is complete, attention has turned to the rear of the building.
Common Wireless Feature, WPS, Readily Hacked
An industry-standard feature on wireless routers marketed to consumers and small businesses, Wi Fi Protected Setup (WPS), is vulnerable to a simple “brute force” attack. Free tools are already available to gain access to these routers. Making matters worse, it has been discovered that some router brands are unable to disable WPS, making it impossible to secure the routers at this time. Many healthcare providers use this low-cost, consumer-grade equipment with WPS in
their facilities.
WPS is a feature invented by the wireless industry to ease the setup process for people lacking technical expertise. The intent is to help people easily enable encryption features for greater security and protection. In an ironic twist, a feature to improve security has become a vulnerability. Click to read the rest!