Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

May 13, 2008

Addressing the Insider Threat

My May issue of "IT Compliance in Realtime" is now available!

The first article I have within this issue is, "Addressing the Insider Threat."

Here is the unformatted text of the article; download the PDF to get the much nicer, prettier, formatted version...

 
Continue reading Addressing the Insider Threat...

May 8, 2008

A Couple Of Little Known HIPAA Facts

Last week I was contacted by Corey Goodman, a reporter for HCPro, about a story he is doing that sounds like it will be quite interesting! He is collecting examples and anecdotes about "little know HIPAA facts" and asked me to contribute some for his article.

I anticipate that he will be cutting the couple of little known facts I provided to him down quite a bit, so I wanted to provide them here not only as a future reference for myself, but also for those of you who may be interested!

 
Continue reading A Couple Of Little Known HIPAA Facts...

March 25, 2008

Yet Another Stolen Laptop With Clear Text Patient PII

Yet another in a long procession of laptop thefs, "Stolen laptop contains personal info of 2,500 patients".

Here are the first few paragraphs...

 
Continue reading Yet Another Stolen Laptop With Clear Text Patient PII...

March 23, 2008

Passport Breach: Poor Security Practices Lead To Privacy Breaches

The breach of the presidential candidates' passport files were widely reported over the past few days, such as here and here, not to mention the many postings referencing it as "passport-gate" throughout the blogosphere and the political implications. However, based upon what I've been reading it looks more like the result of a poor, inadequate and vulnerable information security program.

There are many information security and privacy issues involved with this incident. It would make a great case study to use at a joint meeting with your information security, privacy and compliance folks. Some of the questions to include in your discussion could include...

 
Continue reading Passport Breach: Poor Security Practices Lead To Privacy Breaches ...

March 13, 2008

What Business Leaders Need to Know About Privacy Breach Notifications

The third article in my March e-journal issue of "IT Compliance in Realtime" is "What Business Leaders Need to Know About Privacy Breach Notifications."

Here it is, unformatted:

 
Continue reading What Business Leaders Need to Know About Privacy Breach Notifications...

March 12, 2008

The "Reasonable Belief" of a Privacy Breach

The second article in my March e-journal issue of "IT Compliance in Realtime" is "The "Reasonable Belief" of a Privacy Breach."

Here it is, unformatted:

 
Continue reading The "Reasonable Belief" of a Privacy Breach...

March 1, 2008

Will Bad News Come in 3's For Health Net?

In the past several days Health Net made the news...in ways they would rather not have...

First this on 2/22:

 
Continue reading Will Bad News Come in 3's For Health Net?...

February 24, 2008

Example privacy breach response plan

Too few organizations are prepared to respond to a privacy breach when it happens. Too many naively believe a privacy breach will not happen to them.

It is helpful to look at existing privacy breach notice plans when creating your own. The U.S. government agencies actually provide some good plans you can use as examples.

 
Continue reading Example privacy breach response plan...

February 18, 2008

Have You Looked In Your Trash Bins Lately?

It shouldn't still amaze me, but it does, how often so many organizations just dump huge amounts of printed paper containing tons of personally identifiable information (PII) right into their dumpster sitting behind their building, in the alley, or some other easily reachable public location.

Here's yet another example of a business throwing away people's privacy in their trash dumpster...

 
Continue reading Have You Looked In Your Trash Bins Lately?...

February 13, 2008

Phisherthieves Like Banks Best

Here's a pretty good mainstream news story from CNN to give to your business leaders to raise their awareness and understanding about phishing...

 
Continue reading Phisherthieves Like Banks Best...

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.