<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>Realtime Community | IT Compliance</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/" />
   <link rel="self" type="application/atom+xml" href="http://www.realtime-itcompliance.com/atom.xml" />
   <id>tag:www.realtime-itcompliance.com,2010://1</id>
   <updated>2009-11-29T00:41:38Z</updated>
   <subtitle>The Realtime IT Compliance Community is an objective source for information related to IT Compliance, regulations, information security, and data protection.  The community provides a wide range of resources including blogs, articles, white papers, forums and podcast as well as links to external resources.</subtitle>
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.1</generator>


<entry>
   <title>Smart Grid Privacy: Possible Privacy Standards To Address Concerns</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/11/smart_grid_privacy_possible_pr.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1054</id>
   
   <published>2009-11-28T23:42:04Z</published>
   <updated>2009-11-29T00:41:38Z</updated>
   
   <summary>Sorry to be so tardy in getting a blog post out. As many of you know I&apos;ve been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by all involved. As a quick recap, I led the privacy impact assessment (PIA) for the consumer-to-utility portion of the planned smart grid during the late June to late August/early September time frame. On Friday, 11/20, I provided an update on our NIST groups activities during the Gridwise Alliance phone conference; perhaps some of you were on that call? Here are...</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="446" label="NIST" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="23" label="privacy law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2299" label="Smart Grid" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2329" label="Smart Meter" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2300" label="SmartGrid" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Sorry to be so tardy in getting a blog post out. As many of you know I've been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by all involved. As a quick recap, I led the privacy impact assessment (PIA) for the consumer-to-utility portion of the planned smart grid during the late June to late August/early September time frame. On Friday, 11/20, I provided an update on our NIST groups activities during the Gridwise Alliance phone conference; perhaps some of you were on that call? Here are...
   </content>
</entry>

<entry>
   <title>15 Smart Grid Privacy Concerns + Other Smart Grid Thoughts</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/11/15_smart_grid_privacy_concerns.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1053</id>
   
   <published>2009-11-09T22:12:48Z</published>
   <updated>2009-11-10T16:20:17Z</updated>
   
   <summary>I&apos;ve had about half a dozen folks ask me how things are going with the work I&apos;m doing with the NIST Smart Grid privacy group, and if I could provide an update since my last couple of posts on the topic here and here. The time is going by much too quickly, and I am getting a bit nervous as we get closer to when we need to have the next draft of the NISTIR ready, tentatively set for December 31; there is so much more to do in this VOLUNTEER group effort......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="446" label="NIST" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="23" label="privacy law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2299" label="Smart Grid" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2329" label="Smart Meter" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2300" label="SmartGrid" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
I've had about half a dozen folks ask me how things are going with the work I'm doing with the NIST Smart Grid privacy group, and if I could provide an update since my last couple of posts on the topic here and here. The time is going by much too quickly, and I am getting a bit nervous as we get closer to when we need to have the next draft of the NISTIR ready, tentatively set for December 31; there is so much more to do in this VOLUNTEER group effort......
   </content>
</entry>

<entry>
   <title>HIPAA And Surveillance In Hospitals</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/laws_regulations/2009/11/hipaa_and_surveillance_in_hosp.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1052</id>
   
   <published>2009-11-06T01:29:30Z</published>
   <updated>2009-11-06T01:45:34Z</updated>
   
   <summary>Over the years there have been many...too many...instances where doctors have performed the wrong types of surgeries on patients, and even the wrong surgeries on completely wrong patients......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="168" label="patient privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="23" label="privacy law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2327" label="Rhode Island Hospital" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Over the years there have been many...too many...instances where doctors have performed the wrong types of surgeries on patients, and even the wrong surgeries on completely wrong patients......
   </content>
</entry>

<entry>
   <title>CEs and BAs: Be HIPAA/HITECH Compliant Or Pay A Hefty Penalty</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/10/ces_and_bas_be_hipaahitech_com.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1051</id>
   
   <published>2009-10-30T00:05:48Z</published>
   <updated>2009-10-30T13:55:16Z</updated>
   
   <summary>The HHS released HITECH Act Enforcement Interim Final Rule today......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="168" label="patient privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2325" label="patient privacyimpact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="23" label="privacy law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
The HHS released HITECH Act Enforcement Interim Final Rule today......
   </content>
</entry>

<entry>
   <title>Smart Grid Privacy: Laws and Implications</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/10/smart_grid_privacy_laws_and_im.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1050</id>
   
   <published>2009-10-21T16:07:10Z</published>
   <updated>2009-10-21T16:20:22Z</updated>
   
   <summary>I was recently asked several questions about my work with the NIST Smart Grid privacy group and associated issues. Here are a couple of those questions, and my answers to them......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="446" label="NIST" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2310" label="NISTIR 7628" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="23" label="privacy law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2299" label="Smart Grid" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
I was recently asked several questions about my work with the NIST Smart Grid privacy group and associated issues. Here are a couple of those questions, and my answers to them......
   </content>
</entry>

<entry>
   <title>6 Critical Factors for Effective Information Security &amp; Privacy Policies</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/information_security/2009/10/6_critical_factors_for_effecti.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1049</id>
   
   <published>2009-10-14T13:49:45Z</published>
   <updated>2009-10-14T14:02:27Z</updated>
   
   <summary>I&apos;ve been feeling bad about not posting to my blog as often as I have historically......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1992" label="privacy policies" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2323" label="security policies" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
I've been feeling bad about not posting to my blog as often as I have historically......
   </content>
</entry>

<entry>
   <title>Who Are Your Business Associates?</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/10/who_are_your_business_associat.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1048</id>
   
   <published>2009-10-09T00:33:00Z</published>
   <updated>2009-10-09T00:42:23Z</updated>
   
   <summary>Since just before HIPAA went actively into effect I&apos;ve done a lot of HIPAA compliance work for covered entities (CEs). In the past few years I&apos;ve done around 200 business associate (BA) information security and program reviews for just one CE, and these don&apos;t even scratch the surface for how many BAs each CE has......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Since just before HIPAA went actively into effect I've done a lot of HIPAA compliance work for covered entities (CEs). In the past few years I've done around 200 business associate (BA) information security and program reviews for just one CE, and these don't even scratch the surface for how many BAs each CE has......
   </content>
</entry>

<entry>
   <title>HIPAA/HITECH Etc. Retention: Does Your Reality = Your Requirements?</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/laws_regulations/2009/10/hipaahitech_etc_retention_does.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1047</id>
   
   <published>2009-10-07T00:14:16Z</published>
   <updated>2009-10-07T00:26:34Z</updated>
   
   <summary>Last month I had the great pleasure of being a guest on Scott Draughon and Anyck Turgeon&apos;s MyTechnologyLawyer.com radio show for a segment entitled, &quot;Is encryption enough to achieve privacy?&quot; I was pleasantly surprised to see a large number of great follow-up questions following the show! I covered one of them in my post, &quot;Don&apos;t Throw Your Privacy Out The Window; Know How Your PII Is Used&quot; Here are a couple more of those many questions I want to answer in this post......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="2319" label="21 CFR Part 11" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2321" label="ADA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="83" label="data retention" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="908" label="SSA" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Last month I had the great pleasure of being a guest on Scott Draughon and Anyck Turgeon's MyTechnologyLawyer.com radio show for a segment entitled, "Is encryption enough to achieve privacy?" I was pleasantly surprised to see a large number of great follow-up questions following the show! I covered one of them in my post, "Don't Throw Your Privacy Out The Window; Know How Your PII Is Used" Here are a couple more of those many questions I want to answer in this post......
   </content>
</entry>

<entry>
   <title>Proposed HIPAA Privacy Rule Change Explicitly Makes Genetic Info PHI</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/laws_regulations/2009/10/proposed_hipaa_privacy_rule_ch.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1046</id>
   
   <published>2009-10-02T20:00:39Z</published>
   <updated>2009-10-02T20:17:58Z</updated>
   
   <summary>An important element of data protection compliance is knowing, identifying and inventorying the applicable information......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="586" label="breach notice" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="210" label="breach response" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2317" label="genetic data" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2315" label="GINA Law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
An important element of data protection compliance is knowing, identifying and inventorying the applicable information......
   </content>
</entry>

<entry>
   <title>Privacy For The Deceased</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/09/privacy_for_the_deceased.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1045</id>
   
   <published>2009-09-30T18:43:02Z</published>
   <updated>2009-09-30T18:58:17Z</updated>
   
   <summary>Late last month I posted, &quot;HIPAA/HITECH Breach Notice Rule: Applies To PHI of Deceased Individuals + Training A Key Element&quot; and since then I&apos;ve had around half a dozen or so folks ask me to write about privacy for the deceased......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="586" label="breach notice" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="210" label="breach response" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2313" label="deceased" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2312" label="HITECH" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="77" label="privacy breach" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Late last month I posted, "HIPAA/HITECH Breach Notice Rule: Applies To PHI of Deceased Individuals + Training A Key Element" and since then I've had around half a dozen or so folks ask me to write about privacy for the deceased......
   </content>
</entry>

<entry>
   <title>10 Smart Grid Consumer-to-Utility Privacy Concerns; Are There More?</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/09/10_smart_grid_consumertoutilit.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1044</id>
   
   <published>2009-09-25T14:55:54Z</published>
   <updated>2009-09-25T15:33:45Z</updated>
   
   <summary>I have had the great opportunity to participate in the NIST Smart Grid privacy standards group since July......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2306" label="Christophe Veltsos" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2308" label="Gal Shpantzer" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1130" label="IAPP" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="446" label="NIST" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2310" label="NISTIR 7628" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2299" label="Smart Grid" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2300" label="SmartGrid" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
I have had the great opportunity to participate in the NIST Smart Grid privacy standards group since July......
   </content>
</entry>

<entry>
   <title>Don&apos;t Throw Your Privacy Out The Window; Know How Your PII Is Used</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/09/dont_throw_your_privacy_out_th.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1043</id>
   
   <published>2009-09-23T13:38:53Z</published>
   <updated>2009-09-23T16:37:24Z</updated>
   
   <summary>A couple of week&apos;s ago I had the great opportunity and pleasure to speak with the both equally delightful and brilliant Anyck Turgeon and Scott Draughon on MyTechnologyLawyer.com about &quot;Is encryption enough to achieve privacy?&quot; The feedback and followup to that show was spectacular! I got a ton of questions as a result. I will answer some of them here in the coming days. Here is the first......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="2302" label="Anyck Turgeon" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="7" label="encryption" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2304" label="Scott Draughon" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
A couple of week's ago I had the great opportunity and pleasure to speak with the both equally delightful and brilliant Anyck Turgeon and Scott Draughon on MyTechnologyLawyer.com about "Is encryption enough to achieve privacy?" The feedback and followup to that show was spectacular! I got a ton of questions as a result. I will answer some of them here in the coming days. Here is the first......
   </content>
</entry>

<entry>
   <title>How To Do Privacy Impact Assessments</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/09/how_to_do_privacy_impact_asses.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1042</id>
   
   <published>2009-09-21T23:22:27Z</published>
   <updated>2009-09-21T23:41:45Z</updated>
   
   <summary>Last week I was very fortunate to be able to speak at the IAPP Privacy Academy in Boston......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="531" label="CSI" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="446" label="NIST" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2297" label="NISTIR" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="893" label="PIA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="891" label="privacy impact assessment" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2299" label="Smart Grid" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2300" label="SmartGrid" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Last week I was very fortunate to be able to speak at the IAPP Privacy Academy in Boston......
   </content>
</entry>

<entry>
   <title>What Happens To Privacy During Pandemics?</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/privacy_and_compliance/2009/09/what_happens_to_privacy_during.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1041</id>
   
   <published>2009-09-14T23:45:11Z</published>
   <updated>2009-09-14T23:53:09Z</updated>
   
   <summary>I am talking to increasing numbers of privacy and information security pros who are concerned about not only getting their pandemic plans in place, but also wanting to know what kinds of privacy issues need to be addressed within the plans....</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy and Compliance" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2290" label="breach law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1591" label="breach notification" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="210" label="breach response" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="561" label="employee privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2188" label="HITECH Act" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="626" label="pandemic" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="168" label="patient privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
I am talking to increasing numbers of privacy and information security pros who are concerned about not only getting their pandemic plans in place, but also wanting to know what kinds of privacy issues need to be addressed within the plans....
   </content>
</entry>

<entry>
   <title>Is Encryption Enough to Achieve Privacy?</title>
   <link rel="alternate" type="text/html" href="http://www.realtime-itcompliance.com/laws_regulations/2009/09/is_encryption_enough_to_achiev.htm" />
   <id>tag:www.realtime-itcompliance.com,2009://1.1040</id>
   
   <published>2009-09-10T12:58:58Z</published>
   <updated>2009-09-10T13:02:14Z</updated>
   
   <summary>Of course the answer is no. But there are many reasons! Tune in this afternoon at 4:00pm Pacific time to hear Anyck Turgeon, Scott Draughon and me discuss this topic and talk about encryption laws and the impacts to privacy. Here is the information about the event......</summary>
   <author>
      <name>Rebecca Herold</name>
      <uri>http://www.realtime-itcompliance.com</uri>
   </author>
   
      <category term="Information Security" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Laws &amp; Regulations" scheme="http://www.sixapart.com/ns/types#category" />
   
      <category term="Privacy Incidents" scheme="http://www.sixapart.com/ns/types#category" />
   
   <category term="18" label="awareness and training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2290" label="breach law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1591" label="breach notification" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="210" label="breach response" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="7" label="encryption" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="39" label="HIPAA" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="2188" label="HITECH Act" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="10" label="information security" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="14" label="IT compliance" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1856" label="IT training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="822" label="law" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="168" label="patient privacy" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="869" label="personally identifiable information" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="145" label="PII" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="37" label="policies and procedures" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1119" label="privacy training" scheme="http://www.sixapart.com/ns/types#tag" />
   <category term="1056" label="security training" scheme="http://www.sixapart.com/ns/types#tag" />
   
   <content type="html" xml:lang="en" xml:base="http://www.realtime-itcompliance.com/">
Of course the answer is no. But there are many reasons! Tune in this afternoon at 4:00pm Pacific time to hear Anyck Turgeon, Scott Draughon and me discuss this topic and talk about encryption laws and the impacts to privacy. Here is the information about the event......
   </content>
</entry>

</feed>
