Entries from Realtime Community | IT Compliance tagged with 'PIA'
Sorry to be so tardy in getting a blog post out. As many of you know I've been working with the NIST Smart Grid Privacy Subgroup since late June. The work done for this group is through time volunteered by...
Posted by Rebecca Herold on November 28, 2009 6:42 PM
I've had about half a dozen folks ask me how things are going with the work I'm doing with the NIST Smart Grid privacy group, and if I could provide an update since my last couple of posts on the...
Posted by Rebecca Herold on November 9, 2009 5:12 PM
Over the years there have been many...too many...instances where doctors have performed the wrong types of surgeries on patients, and even the wrong surgeries on completely wrong patients......
Posted by Rebecca Herold on November 5, 2009 8:29 PM
The HHS released HITECH Act Enforcement Interim Final Rule today......
Posted by Rebecca Herold on October 29, 2009 8:05 PM
I was recently asked several questions about my work with the NIST Smart Grid privacy group and associated issues. Here are a couple of those questions, and my answers to them......
Posted by Rebecca Herold on October 21, 2009 12:07 PM
Late last month I posted, "HIPAA/HITECH Breach Notice Rule: Applies To PHI of Deceased Individuals + Training A Key Element" and since then I've had around half a dozen or so folks ask me to write about privacy for the...
Posted by Rebecca Herold on September 30, 2009 2:43 PM
I have had the great opportunity to participate in the NIST Smart Grid privacy standards group since July......
Posted by Rebecca Herold on September 25, 2009 10:55 AM
Last week I was very fortunate to be able to speak at the IAPP Privacy Academy in Boston......
Posted by Rebecca Herold on September 21, 2009 7:22 PM
Today Kevin Beaver posted a nice article, "Dumb things IT consultants do" that included more than one warning about making assumptions. Kevin's nice post made me think about all the dangerous assumptions consulants and practitioners often make when it comes...
Posted by Rebecca Herold on June 17, 2009 9:29 PM
A type of project I really love to do is a privacy impact assessment (PIA). For companies who collect or otherwise handle the personally identifiable information (PII) of individuals from multiple countries, typically doing a cross border data flow analysis...
Posted by Rebecca Herold on March 12, 2009 8:37 PM
I recently did a privacy impact assessment (PIA) for a marketing company and remembered that the U.S. Do Not Call list entries expire after 5 years! Most people do not realize this...did you know this?...
Posted by Rebecca Herold on September 6, 2007 7:17 AM
I am a huge proponent of privacy impact assessments (PIAs); basically risk assessments for privacy. PIAs can reveal gaps in privacy practices, along with the information security practices used to protect privacy. They are important and effective exercises for all...
Posted by Rebecca Herold on August 15, 2007 12:03 AM
Site tags used on this blog: