Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

July 2, 2009

Nevada's New Encryption Law; Made Moot By Its Own Data Breach Law?

On May 30, 2009, Nevada enacted a new law, SB 227, which will basically replace NRS 597.970 in January 2010.

In many ways the new law is an improvement over the much more vague, and brief, NRS 597.970. I want to focus here on an improvement, but something that still leaves much to interpretation; that is, what is meant by "encryption"?

 
Continue reading Nevada's New Encryption Law; Made Moot By Its Own Data Breach Law?...

June 29, 2009

South Carolina & Alaska Privacy Breach Notice Laws Go Into Effect July 1

This week two more U.S. breach notice laws go into effect...

 
Continue reading South Carolina & Alaska Privacy Breach Notice Laws Go Into Effect July 1...

June 16, 2009

FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations

Today the FTC issued a consent order against mortgage lender James B. Nutter & Company for GLBA Privacy Rule and Safeguards Rule violations resulting from having an inadequte information security program and safeguards. The requirements will result in, among other actions, 20 years of ongoing activities by James B. Nutter & Company; much more costly than it would have been to have established appropriate information security safeguards to begin with...

 
Continue reading FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations...

June 11, 2009

FTC's New Red Flags Rules FAQ

Today the US FTC released "Frequently Asked Questions: Identity Theft Red Flags and Address Discrepancies."

Here are a couple important things to take away from this FAQ...

 
Continue reading FTC's New Red Flags Rules FAQ...

May 18, 2009

HITECH Act does *NOT* make HIPAA, or HIPAA advice, "obsolete"!

A couple of weeks ago I was surprised and concerned by a statement made in one of my many listservs by a lawyer commenting on HIPAA books and past advice given for HIPAA compliance...

 
Continue reading HITECH Act does *NOT* make HIPAA, or HIPAA advice, "obsolete"!...

May 6, 2009

Podcast: HITECH Act adds new compliance requirements, penalties

Last week I had the pleasure of speaking with Alexander B. Howard at SearchCompliance.com for a 26 minute podcast...

 
Continue reading Podcast: HITECH Act adds new compliance requirements, penalties...

May 4, 2009

IP Addresses Are Considered PII By Some Countries No Matter If U.S. Orgs Like It Or Not

Today on Twitter, @clarinette02 posted a link to an interesting article, "IP Addresses Are Personal Data, E.U. Regulator Says," from a little over a year ago...

 
Continue reading IP Addresses Are Considered PII By Some Countries No Matter If U.S. Orgs Like It Or Not...

May 1, 2009

Red Flags Rule Enforcement Delayed to August 1, 2009; FTC Providing a Compliance "Template"

The FTC has once more announced a delayed enforcement of the Red Flags Rule to August 1, 2009...

 
Continue reading Red Flags Rule Enforcement Delayed to August 1, 2009; FTC Providing a Compliance "Template"...

April 29, 2009

Employee Rights to PII When You Leave Your Employer or Lose Your Job

I often get emails from my blog and Twitter readers, many of whom I have never met before; sometimes several in a day. Many often ask for help that really is a call for free consulting help. Others are quick, short and fast for me to answer. Others are just bizarre. I answer whatever I have time for. I recently got the following question (edited to protect identities), and I think so many folks may be involved in a similar situation with all the continuing job losses that it might be useful to several folks...

 
Continue reading Employee Rights to PII When You Leave Your Employer or Lose Your Job...

April 28, 2009

HIPAA & HITECH Act Sanctions & Penalties

Today I had the great pleasure and opportunity to do a podcast with Alexander Howard over at TechTarget discussing HIPAA and the HITECH Act...

 
Continue reading HIPAA & HITECH Act Sanctions & Penalties...

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.