Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'PIA'


Smart Grid Privacy: Possible Privacy Standards To Address Concerns

Sorry to be so tardy in getting a blog post out. As many of you know I've been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by...

15 Smart Grid Privacy Concerns + Other Smart Grid Thoughts

I've had about half a dozen folks ask me how things are going with the work I'm doing with the NIST Smart Grid privacy group, and if I could provide an update since my last couple of posts on the...

HIPAA And Surveillance In Hospitals

Over the years there have been many...too many...instances where doctors have performed the wrong types of surgeries on patients, and even the wrong surgeries on completely wrong patients......

CEs and BAs: Be HIPAA/HITECH Compliant Or Pay A Hefty Penalty

The HHS released HITECH Act Enforcement Interim Final Rule today......

Smart Grid Privacy: Laws and Implications

I was recently asked several questions about my work with the NIST Smart Grid privacy group and associated issues. Here are a couple of those questions, and my answers to them......

Privacy For The Deceased

Late last month I posted, "HIPAA/HITECH Breach Notice Rule: Applies To PHI of Deceased Individuals + Training A Key Element" and since then I've had around half a dozen or so folks ask me to write about privacy for the...

10 Smart Grid Consumer-to-Utility Privacy Concerns; Are There More?

I have had the great opportunity to participate in the NIST Smart Grid privacy standards group since July......

How To Do Privacy Impact Assessments

Last week I was very fortunate to be able to speak at the IAPP Privacy Academy in Boston......

5 Common, Dumb and Dangerous Privacy Assumptions

Today Kevin Beaver posted a nice article, "Dumb things IT consultants do" that included more than one warning about making assumptions. Kevin's nice post made me think about all the dangerous assumptions consulants and practitioners often make when it comes...

1746 Organizations In The U.S.'s EU Safe Harbor Program

A type of project I really love to do is a privacy impact assessment (PIA). For companies who collect or otherwise handle the personally identifiable information (PII) of individuals from multiple countries, typically doing a cross border data flow analysis...

Your Name May Be Falling Off the Do Not Call List Soon!

I recently did a privacy impact assessment (PIA) for a marketing company and remembered that the U.S. Do Not Call list entries expire after 5 years! Most people do not realize this...did you know this?...

U.S. Dept. of Homeland Security Makes 14 Privacy Impact Assessments Available

I am a huge proponent of privacy impact assessments (PIAs); basically risk assessments for privacy. PIAs can reveal gaps in privacy practices, along with the information security practices used to protect privacy. They are important and effective exercises for all...

Site Tags

Site tags used on this blog: