
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Savid Insight &#187; HIPAA</title>
	<atom:link href="http://www.savidtech.com/blog/category/hipaa/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.savidtech.com/blog</link>
	<description>Savid Technologies thoughts on technology, IT, information security, and business</description>
	<lastBuildDate>Sun, 08 Jan 2012 22:27:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<div id='fb-root'></div>
					<script type='text/javascript'>
						window.fbAsyncInit = function()
						{
							FB.init({appId: null, status: true, cookie: true, xfbml: true});
						};
						(function()
						{
							var e = document.createElement('script'); e.async = true;
							e.src = document.location.protocol + '//connect.facebook.net/en_US/all.js';
							document.getElementById('fb-root').appendChild(e);
						}());
					</script>	
						<item>
		<title>If You Cannot Prevent It, Detect It: Why Defense In Depth Works</title>
		<link>http://www.savidtech.com/blog/it-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/</link>
		<comments>http://www.savidtech.com/blog/it-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/#comments</comments>
		<pubDate>Sun, 08 Jan 2012 22:25:09 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[application security defense in depth]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[defense in depth]]></category>
		<category><![CDATA[ethical hackers]]></category>
		<category><![CDATA[ethical hacking]]></category>
		<category><![CDATA[GLBA]]></category>
		<category><![CDATA[honeytokens]]></category>
		<category><![CDATA[prevent breach]]></category>
		<category><![CDATA[Security controls]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.savidtech.com/blog/?p=759</guid>
		<description><![CDATA[As audit season is finally over, (over 65% of all our assessments and audits happen in Q4) we finally have a chance to grab a cup of coffee and look back at a couple trends in 2011 that we think separate the best security teams from the worst. First, we need to discuss how we [...]]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fif-you-cannot-prevent-it-detect-it-why-defense-in-depth-works%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fif-you-cannot-prevent-it-detect-it-why-defense-in-depth-works%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img class="alignleft size-thumbnail wp-image-760" style="text-decoration: line-through; padding: 0px 5px 5px 0px;" title="If You Cannot Prevent It, Detect It" src="http://www.savidtech.com/blog/wp-content/uploads/2012/01/prevention-150x150.jpg" alt="" width="150" height="150" /> As audit season is finally over, (over 65% of all our assessments and audits happen in Q4) we finally have a chance to grab a cup of coffee and look back at a couple trends in 2011 that we think separate the best <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> teams from the worst.</p>
<p>First, we need to discuss how we measure the quality of a security team. At Savid, <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> is pretty simple. Since we perform <a href="http://www.savidtech.com/blog/tag/ethical-hacking/" class="st_tag internal_tag" rel="tag" title="Posts tagged with ethical hacking">ethical hacking</a> to assess security programs at organizations, if we got access to something we shouldn’t have, it counts as an intrusion in our books.</p>
<p>Most reviews of <a href="http://www.savidtech.com/blog/tag/security-controls/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Security controls">security controls</a> look at what went wrong because it’s harder to learn from the successes. So let’s get the major failures of 2011 out of the way and then let’s talk about what our best clients did to prevent us from breaking in. Overall, most of the security programs we assessed had application security issues. However, 2011 was the worst we have ever seen in terms of the depth and breadth of application security issues &#8211; even though the majority of the security programs we tested were in compliance with regulations such as <a href="http://www.savidtech.com/blog/tag/hipaa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HIPAA">HIPAA</a>, <a href="http://www.savidtech.com/blog/tag/pci/" class="st_tag internal_tag" rel="tag" title="Posts tagged with PCI">PCI</a>, and <a href="http://www.savidtech.com/blog/tag/glba/" class="st_tag internal_tag" rel="tag" title="Posts tagged with GLBA">GLBA</a>.</p>
<p>Ok, so with that out of the way, what did the best security teams do to prevent our ethical <a href="http://www.savidtech.com/blog/tag/hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hackers">hackers</a> from breaking in?  One Thing: <a href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">Defense In Depth</a>. 2011 was the first year where we saw significant advancements in <a href="http://www.savidtech.com/blog/tag/defense-in-depth/" class="st_tag internal_tag" rel="tag" title="Posts tagged with defense in depth">defense in depth</a> deployments among our clients. For example, we saw a noticeable increase in proper system hardening (using standards such as CIS and NIST) and reduction of excessive permissions that stopped our attacks cold.</p>
<p>Properly deploying defense in depth can be the distinction between a <a href="http://www.savidtech.com/blog/tag/data-breach/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Data Breach">data breach</a> requiring notification or a simple documented incident. The difference between the two for some organizations could be millions of dollars. Oh, and it also has a side effect of making most malware non-functional by preventing the malware from creating temporary files, accessing DLLs, etc. Remember, an attacker can’t exfiltrate data if the exfiltration tools won’t run!</p>
<p>So, how did the defense in depth stop our hacking? Most of the time we were able to get entry into a server or application but because of defense in depth we weren’t able to leverage that entry for any gain (such as privilege escalation, intellectual property, or personally identifiable information). For example, if we got access to an application via <a href="http://www.savidtech.com/blog/tag/sql/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL">SQL</a> injection, we weren’t able to execute any commands on the server because the <a href="http://www.savidtech.com/blog/tag/sql/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL">SQL</a> server was hardened to prevent usage of xp_cmd and the <a href="http://www.savidtech.com/blog/tag/sql/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL">SQL</a> service account had no local permissions on the box to do anything other than access the database files and folders. Another example is when we got access to a Linux system running a custom PHP login system via an upload vulnerable and a PHP Shell script. The hardening of Apache and the file system prevented our low privileged web server service account from reading local files, creating files, etc. Essentially, the account we got control of was useless and the attack vector wasted our time and effort.</p>
<p>Wasting an attacker’s time and effort is exactly what you as the defender want to do. Every minute an attacker is stalled or delayed is more time for your detective controls such as IDS/IPS, Logging, or even Tripwire like defenses to detect an attack. We recommend that every <a href="http://www.savidtech.com/blog/tag/security-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security program">security program</a> have a simple theme: If You Cannot Prevent It, Detect It. Leveraging defense in depth provides additional detection points along the attack path. Every time a low privileged user attempts to access the Accounting Share – detect it. Every time a server in your DMZ attempts to connect to a server in the internal network (which should be blocked by the firewall) detect it and respond to it. These are all indicators that the server is doing something it shouldn’t.</p>
<p>Our number one recommendation when deploying defense in depth with proper detection controls is the use of fake records &#8211; commonly called “<a href="http://www.savidtech.com/blog/tag/honeytokens/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honeytokens">honeytokens</a>”. For example, if you have a public web application that has access to an internal database server through a firewall, place a fake record in the database using a randomly generated 30-64 character value. This record has no value and should never be accessed via normal web application use. If your firewall, web filter, or DLP system ever sees this traffic move across the network – something went wrong and you need to find out why.</p>
<p>Every year <a href="http://www.savidtech.com/blog/tag/verizon/" class="st_tag internal_tag" rel="tag" title="Posts tagged with verizon">Verizon</a> releases their Data Breach investigations Report and year after year they mention the same problem: The time between a breach occurring and detection of the breach is too long, sometimes it takes years! So this year, add some more defense in depth controls to your security program and watch how quickly it helps reduce the impact of a <a href="http://www.savidtech.com/blog/tag/vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with vulnerability">vulnerability</a>.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/application-security-defense-in-depth/" title="application security defense in depth" rel="tag">application security defense in depth</a>, <a href="http://www.savidtech.com/blog/tag/data-breach/" title="Data Breach" rel="tag">Data Breach</a>, <a href="http://www.savidtech.com/blog/tag/defense-in-depth/" title="defense in depth" rel="tag">defense in depth</a>, <a href="http://www.savidtech.com/blog/tag/ethical-hackers/" title="ethical hackers" rel="tag">ethical hackers</a>, <a href="http://www.savidtech.com/blog/tag/ethical-hacking/" title="ethical hacking" rel="tag">ethical hacking</a>, <a href="http://www.savidtech.com/blog/tag/glba/" title="GLBA" rel="tag">GLBA</a>, <a href="http://www.savidtech.com/blog/tag/hipaa/" title="HIPAA" rel="tag">HIPAA</a>, <a href="http://www.savidtech.com/blog/tag/honeytokens/" title="honeytokens" rel="tag">honeytokens</a>, <a href="http://www.savidtech.com/blog/tag/pci/" title="PCI" rel="tag">PCI</a>, <a href="http://www.savidtech.com/blog/tag/prevent-breach/" title="prevent breach" rel="tag">prevent breach</a>, <a href="http://www.savidtech.com/blog/tag/security-controls/" title="Security controls" rel="tag">Security controls</a>, <a href="http://www.savidtech.com/blog/tag/sql/" title="SQL" rel="tag">SQL</a>, <a href="http://www.savidtech.com/blog/tag/sql-injection/" title="SQL injection" rel="tag">SQL injection</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-security/if-you-cannot-prevent-it-detect-it-why-defense-in-depth-works/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Management Can Work Across Multiple Enterprises</title>
		<link>http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/</link>
		<comments>http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 02:55:27 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Business process]]></category>
		<category><![CDATA[enterprise vulnerability]]></category>
		<category><![CDATA[legal contracts]]></category>
		<category><![CDATA[management program]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security processes]]></category>
		<category><![CDATA[supply chain]]></category>
		<category><![CDATA[Supply chain management]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=465</guid>
		<description><![CDATA[Security teams that manage security at single company think their job is hard (it is!) but imagine if you have 10 partners accessing your network all day everyday! Learn the 3 steps to implement multi-enterprise vulnerability management the right way.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fvulnerability-management-can-work-across-multiple-enterprises%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fvulnerability-management-can-work-across-multiple-enterprises%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>I just released a report for Dark Reading on how to build a multi-<a href="http://www.savidtech.com/blog/tag/enterprise-vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with enterprise vulnerability">enterprise vulnerability</a> <a href="http://www.savidtech.com/blog/tag/management-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with management program">management program</a>. If you are dealing with outsourced vendors, or an outsourced <a href="http://www.savidtech.com/blog/tag/supply-chain/" class="st_tag internal_tag" rel="tag" title="Posts tagged with supply chain">supply chain</a>, you should definitely <a href="http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=224300024">give the article a read</a>.</p>
<p>To summarize the article:</p>
<ol>
<li>Get your <a href="http://www.savidtech.com/blog/tag/legal-contracts/" class="st_tag internal_tag" rel="tag" title="Posts tagged with legal contracts">legal contracts</a> in order. So many firms don&#8217;t put what they need from their partners into a contract. How do you expect to get what you need then?</li>
<li>Establish Communication channels that work for everyone. If you don&#8217;t get the right people on the &#8220;phone&#8221;, nothing will get done &#8211; including your <a href="http://www.savidtech.com/blog/tag/security-processes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security processes">security processes</a></li>
<li>Find the person with authority at your partner and ensure they are involved, otherwise your efforts will be useless.</li>
</ol>
<p>I offer many more details and tips within the article but step #1 is so critical that an entire article should be dedicated to just that!</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/business-process/" title="Business process" rel="tag">Business process</a>, <a href="http://www.savidtech.com/blog/tag/enterprise-vulnerability/" title="enterprise vulnerability" rel="tag">enterprise vulnerability</a>, <a href="http://www.savidtech.com/blog/tag/legal-contracts/" title="legal contracts" rel="tag">legal contracts</a>, <a href="http://www.savidtech.com/blog/tag/management-program/" title="management program" rel="tag">management program</a>, <a href="http://www.savidtech.com/blog/tag/security/" title="security" rel="tag">security</a>, <a href="http://www.savidtech.com/blog/tag/security-processes/" title="security processes" rel="tag">security processes</a>, <a href="http://www.savidtech.com/blog/tag/supply-chain/" title="supply chain" rel="tag">supply chain</a>, <a href="http://www.savidtech.com/blog/tag/supply-chain-management/" title="Supply chain management" rel="tag">Supply chain management</a>, <a href="http://www.savidtech.com/blog/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a href="http://www.savidtech.com/blog/tag/vulnerability-management/" title="vulnerability management" rel="tag">vulnerability management</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/vulnerability-management-can-work-across-multiple-enterprises/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>7 consecutive errors equals a Security Breach</title>
		<link>http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/</link>
		<comments>http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 05:01:41 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Christian Moldes]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[gladwell]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[moldes]]></category>
		<category><![CDATA[plane crashes]]></category>
		<category><![CDATA[privileged account]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[security breaches]]></category>
		<category><![CDATA[security program]]></category>
		<category><![CDATA[verizon]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=450</guid>
		<description><![CDATA[Even with many controls in place you cannot always prevent a security breach. This is the exact reason why we recommend that incident response policies and processes (Which should be tested like you test your Disaster Recovery processes!) should be the FIRST THING you implement when building a security program at an organization followed by detective controls such as logging to detect a breach as soon as possible.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2F7-consecutive-errors-equals-a-security-breach%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2F7-consecutive-errors-equals-a-security-breach%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.savidtech.com/blog/tag/verizon/" class="st_tag internal_tag" rel="tag" title="Posts tagged with verizon">Verizon</a> Business <a href="http://www.savidtech.com/blog/tag/christian-moldes/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Christian Moldes">Christian Moldes</a> as a great post about <a href="http://securityblog.verizonbusiness.com/2010/03/11/plane-crashes-and-security-breaches">Plane Crashes and Security Breaches</a> and how they are very similar. He hits <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> right on the head! During our engagement wrap-up meetings where we explain the various potential scenarios an attacker can use to break into a client’s network we are always asked to put a specific ranking on a specific <a href="http://www.savidtech.com/blog/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a>. I argue that that almost doesn&#8217;t matter because normally the big <a href="http://www.savidtech.com/blog/tag/breaches/" class="st_tag internal_tag" rel="tag" title="Posts tagged with breaches">breaches</a> are not from a single <a href="http://www.savidtech.com/blog/tag/vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with vulnerability">vulnerability</a> but many chained together.</p>
<p>Christian quotes Malcom <a href="http://www.savidtech.com/blog/tag/gladwell/" class="st_tag internal_tag" rel="tag" title="Posts tagged with gladwell">Gladwell</a>, and says:</p>
<blockquote><p>The typical [plane] accident involves seven consecutive human errors.</p></blockquote>
<p>When we work with clients we normally see that breaches are caused by a chaining of at least three errors: <a href="http://www.savidtech.com/blog/tag/exploitation/" class="st_tag internal_tag" rel="tag" title="Posts tagged with exploitation">exploitation</a> of a vulnerability, then a mis-configuration is used to find a <a href="http://www.savidtech.com/blog/tag/privileged-account/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privileged account">privileged account</a> user name and password, and then data is found on the network somewhere it wasn&#8217;t supposed to be that the <a href="http://www.savidtech.com/blog/tag/privileged-account/" class="st_tag internal_tag" rel="tag" title="Posts tagged with privileged account">privileged account</a> has access too.</p>
<p>Even with many controls in place you cannot always prevent a <a href="http://www.savidtech.com/blog/tag/security-breach/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security breach">security breach</a>. This is the exact reason why we recommend that <a href="http://www.savidtech.com/blog/tag/incident-response/" class="st_tag internal_tag" rel="tag" title="Posts tagged with incident response">incident response</a> policies and processes (Which should be tested like you test your Disaster Recovery processes!) should be the FIRST THING you implement when building a <a href="http://www.savidtech.com/blog/tag/security-program/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security program">security program</a> at an organization followed by detective controls such as logging to detect a breach as soon as possible.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/christian-moldes/" title="Christian Moldes" rel="tag">Christian Moldes</a>, <a href="http://www.savidtech.com/blog/tag/exploitation/" title="exploitation" rel="tag">exploitation</a>, <a href="http://www.savidtech.com/blog/tag/gladwell/" title="gladwell" rel="tag">gladwell</a>, <a href="http://www.savidtech.com/blog/tag/incident-response/" title="incident response" rel="tag">incident response</a>, <a href="http://www.savidtech.com/blog/tag/moldes/" title="moldes" rel="tag">moldes</a>, <a href="http://www.savidtech.com/blog/tag/plane-crashes/" title="plane crashes" rel="tag">plane crashes</a>, <a href="http://www.savidtech.com/blog/tag/privileged-account/" title="privileged account" rel="tag">privileged account</a>, <a href="http://www.savidtech.com/blog/tag/security-breach/" title="security breach" rel="tag">security breach</a>, <a href="http://www.savidtech.com/blog/tag/security-breaches/" title="security breaches" rel="tag">security breaches</a>, <a href="http://www.savidtech.com/blog/tag/security-program/" title="security program" rel="tag">security program</a>, <a href="http://www.savidtech.com/blog/tag/verizon/" title="verizon" rel="tag">verizon</a>, <a href="http://www.savidtech.com/blog/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/7-consecutive-errors-equals-a-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare Reform Bill Spells Regular HIPAA Changes</title>
		<link>http://www.savidtech.com/blog/it-security/healthcare-reform-bill-spells-regular-hipaa-changes/</link>
		<comments>http://www.savidtech.com/blog/it-security/healthcare-reform-bill-spells-regular-hipaa-changes/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 01:48:09 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=375</guid>
		<description><![CDATA[The bill proposes four additional HIPAA transactions for healthcare industries where their data and information must comply with the most current standards and operating rules – health claims, enrollment/disenrollment in plans, health plan premium payments, and referral certification and authorization.  The bill would give healthcare industries until 2015 to get compliant in these areas.  There is also a list of proposed penalties for those who fail to comply to the HIPAA requirements.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-security/healthcare-reform-bill-spells-regular-hipaa-changes/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fhealthcare-reform-bill-spells-regular-hipaa-changes%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fhealthcare-reform-bill-spells-regular-hipaa-changes%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>If you are annoyed by the constant updating, amending, and general tinkering of <a href="http://www.savidtech.com/blog/tag/hipaa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HIPAA">HIPAA</a> compliance regulations, then you may have to get used to <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>.  The proposed healthcare reform bill not only contains additional HIPAA provisions but a proposal for periodic updates.</p>
<p>At this moment, the healthcare reform bill has just passed a key Senate committee.  Within the 1,000 page document are proposals for regular HIPAA renewals that would allow for biannual reviews of existing HIPAA standards and operation rules, and the ability to make recommendations and updates.</p>
<p>The bill proposes four additional HIPAA transactions for healthcare industries where their data and information must comply with the most current standards and operating rules – health claims, enrollment/disenrollment in plans, health plan premium payments, and referral certification and authorization.  The bill would give healthcare industries until 2015 to get compliant in these areas.  There is also a list of proposed penalties for those who fail to comply to the HIPAA requirements.</p>
<p>The healthcare industry already had to adjust to HIPAA amendments that were caveats to accepting money in Obama’s <a href="http://www.savidtech.com/blog/tag/economic-stimulus-bill/" class="st_tag internal_tag" rel="tag" title="Posts tagged with economic stimulus bill">economic stimulus bill</a> earlier this year.  Those amendments manifested in the Health <a href="http://www.savidtech.com/blog/tag/information-technology/" class="st_tag internal_tag" rel="tag" title="Posts tagged with information technology">Information Technology</a> for Economic and Clinical Health (<a href="http://www.savidtech.com/blog/tag/hitech/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HITECH">HITECH</a>) Act extended HIPAA regulations to business associates and required notification to patients in the event of <a href="http://www.savidtech.com/blog/tag/security-breaches/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security breaches">security breaches</a>.  While HITECH provided $31.2 billion for healthcare infrastructure and adoption of <a href="http://www.savidtech.com/blog/tag/electronic-health-records/" class="st_tag internal_tag" rel="tag" title="Posts tagged with electronic health records">electronic health records</a>, it also increased compliance obligations and strengthened enforcement penalties.</p>
<p>The bill basically makes <a href="http://www.savidtech.com/blog/tag/government/" class="st_tag internal_tag" rel="tag" title="Posts tagged with government">government</a> regulation of healthcare IT regulatory with biannual updates to HIPAA.  I’m not sure if more <a href="http://www.savidtech.com/blog/tag/government/" class="st_tag internal_tag" rel="tag" title="Posts tagged with government">government</a> regulation and compliance is going to improve the quality of healthcare <a href="http://www.savidtech.com/blog/tag/privacy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Privacy">privacy</a> for individuals, but I am sure that many will oppose these changes.</p>
<p>Of course there’s no guarantee the bill will not change drastically as it goes through the House of Representatives on the next leg of its journey.  And, even then, it may or may not be passed by Congress and signed by Obama.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-security/healthcare-reform-bill-spells-regular-hipaa-changes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber-warfare is overrated, Cyber-Crime is the real issue we need to address</title>
		<link>http://www.savidtech.com/blog/network-security/cyber-warefare-is-overrated-cyber-crime-is-the-real-issue-we-need-to-address/</link>
		<comments>http://www.savidtech.com/blog/network-security/cyber-warefare-is-overrated-cyber-crime-is-the-real-issue-we-need-to-address/#comments</comments>
		<pubDate>Wed, 02 Sep 2009 14:18:02 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[cyber security]]></category>
		<category><![CDATA[cyber terrorism]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[fraud detection]]></category>
		<category><![CDATA[fraud issues]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[scheiner]]></category>
		<category><![CDATA[security companies]]></category>
		<category><![CDATA[small businesses]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=329</guid>
		<description><![CDATA[So why is there so much concern about “cyber-terrorism”? Answering a question with a question: who frames the debate? Much of the data are gathered by ultra-secretive government agencies—which need to justify their own existence—and cyber-security companies—which derive commercial benefits from popular anxiety.]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/cyber-warefare-is-overrated-cyber-crime-is-the-real-issue-we-need-to-address/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fcyber-warefare-is-overrated-cyber-crime-is-the-real-issue-we-need-to-address%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fcyber-warefare-is-overrated-cyber-crime-is-the-real-issue-we-need-to-address%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.schneier.com/blog/archives/2009/09/the_exaggerated.html">Bruce Scheiner</a> is talking about a great post at the Boston Review about <a href="http://bostonreview.net/BR34.4/morozov.php">the new age of cyber-warfare</a>, and how cyber-warfare is greatly exaggerated. I couldn&#8217;t agree more. Granted, the US <a href="http://www.savidtech.com/blog/tag/government/" class="st_tag internal_tag" rel="tag" title="Posts tagged with government">government</a> has a cyber-warfare problem. All governments do, however, the bigger problem that is more real today is cyber-crime. I spoke at the Federal Reserve last week on this exact topic.</p>
<p><a href="http://www.savidtech.com/blog/tag/small-businesses/" class="st_tag internal_tag" rel="tag" title="Posts tagged with small businesses">Small businesses</a> are now being targeted because they have more money in their accounts and <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> is easier to transfer larger sums of money out of their accounts without <a href="http://www.savidtech.com/blog/tag/fraud-detection/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fraud detection">fraud detection</a> going off at banks.</p>
<p>A quote from the review sums it all up:</p>
<blockquote><p>So why is there so much concern about “cyber-terrorism”? Answering a question with a question: who frames the debate? Much of the data are gathered by ultra-secretive government agencies—which need to justify their own existence—and cyber-<a href="http://www.savidtech.com/blog/tag/security-companies/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security companies">security companies</a>—which derive commercial benefits from popular anxiety. Journalists do not help. Gloomy scenarios and speculations about cyber-Armaggedon draw attention, even if they are relatively short on facts.</p></blockquote>
<p>I try very hard not to do what they describe when I speak but it can be difficult especially to those that are not familiar with the problem.Cyber-crime is the death by a thousands cuts type of problem. $3,000 here, $5,000 there, but it all adds up pretty quickly. Cyber-warfare is much bigger and easier to point at than these small little <a href="http://www.savidtech.com/blog/tag/fraud-issues/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fraud issues">fraud issues</a>.</p>
<p>If you have 10 minutes of time, read the<a href="http://bostonreview.net/BR34.4/morozov.php"> Boston Review article</a> and give me some feedback. Are we in a situation where we as citizens have to be concerned about cyber-warfare like we were concerned about nukes in years past?</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/cyber-security/" title="cyber security" rel="tag">cyber security</a>, <a href="http://www.savidtech.com/blog/tag/cyber-terrorism/" title="cyber terrorism" rel="tag">cyber terrorism</a>, <a href="http://www.savidtech.com/blog/tag/cyber-warfare/" title="cyber warfare" rel="tag">cyber warfare</a>, <a href="http://www.savidtech.com/blog/tag/fraud/" title="fraud" rel="tag">fraud</a>, <a href="http://www.savidtech.com/blog/tag/fraud-detection/" title="fraud detection" rel="tag">fraud detection</a>, <a href="http://www.savidtech.com/blog/tag/fraud-issues/" title="fraud issues" rel="tag">fraud issues</a>, <a href="http://www.savidtech.com/blog/tag/government/" title="government" rel="tag">government</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/scheiner/" title="scheiner" rel="tag">scheiner</a>, <a href="http://www.savidtech.com/blog/tag/security-companies/" title="security companies" rel="tag">security companies</a>, <a href="http://www.savidtech.com/blog/tag/small-businesses/" title="small businesses" rel="tag">small businesses</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/cyber-warefare-is-overrated-cyber-crime-is-the-real-issue-we-need-to-address/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>3 Reasons Against Patch Tuesday</title>
		<link>http://www.savidtech.com/blog/network-security/3-reasons-against-patch-tuesday/</link>
		<comments>http://www.savidtech.com/blog/network-security/3-reasons-against-patch-tuesday/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 19:18:05 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=196</guid>
		<description><![CDATA[Ultimately, whether you participate in Patch Tuesday or not depends on the nature of your unique enterprise.  Some organizations cannot afford the risks of waiting to patch and require more vigilant updating to protect their systems.  Other organizations may value the fluidity of operations over security and prefer a monthly scheduled time for patching.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/3-reasons-against-patch-tuesday/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2F3-reasons-against-patch-tuesday%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2F3-reasons-against-patch-tuesday%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Patch Tuesday is kind of like a monthly holiday for many businesses I work with.  <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">It</a> gives employees a chance to kick back while their computers and systems do all the work of updating (Yes, I am joking).  But is Patch Tuesday really a good idea?  Many have expressed concerns about creating a consistent trend to patching that informs attackers about the update patterns of their targets.</p>
<p>Here are the three main disadvantages to the system of Patch Tuesday:</p>
<p>1. Patch Tuesday, by its very nature, makes exploits public.  So while Patch Tuesday may make things easier for those who take the time to patch, it severely damages those who do not.  Not only are exploits announced but <a href="http://www.savidtech.com/blog/tag/hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hackers">hackers</a> can analyze the patch to figure out exactly how to take advantage of unpatched systems.  For this reason, the existence of Patch Tuesday actually makes the need to patch that much greater.</p>
<p>2.  By having so many patches downloaded at the same time by so many systems, there is a definite toll on the bandwidth.  This could tie up the bandwidth on your corporate network.  But it is a much greater problem on a vendor’s servers who must contend with downloads from everyone who uses their products.</p>
<p>3. If you wait until a set time before patching, then you allow for your software to remain vulnerable until then.  It’s not a big problem when the <a href="http://www.savidtech.com/blog/tag/vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with vulnerability">vulnerability</a> is not widely known, but there have been cases where the vulnerabilities were made publicly known for months before patches were available.  Either way, hackers have a fair amount of time to take advantage of the exploit before it is corrected with the patch.</p>
<p>Ultimately, whether you participate in Patch Tuesday or not depends on the nature of your unique enterprise.  Some organizations cannot afford the risks of waiting to patch and require more vigilant updating to protect their systems.  Other organizations may value the fluidity of operations over <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> and prefer a monthly scheduled time for patching.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/3-reasons-against-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>HackersBlog – White or Black Hat?</title>
		<link>http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/</link>
		<comments>http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/#comments</comments>
		<pubDate>Mon, 29 Jun 2009 16:28:40 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[anonymous hackers]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[bitdefender]]></category>
		<category><![CDATA[breaches]]></category>
		<category><![CDATA[customer data]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[kapersky]]></category>
		<category><![CDATA[private customer]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[security vulnerability]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=103</guid>
		<description><![CDATA[This is the controversy surrounding “HackersBlog.org” – a blog where anonymous hackers alert the public about security vulnerabilities.  Each blog entry lists the site hacked, how the data was captured, and what private information is accessible.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhackersblog-%25e2%2580%2593-white-or-black-hat%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Fhackersblog-%25e2%2580%2593-white-or-black-hat%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Consider this:  A hacker finds a <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> hole on your website that exposes hundreds of thousands private <a href="http://www.savidtech.com/blog/tag/customer-data/" class="st_tag internal_tag" rel="tag" title="Posts tagged with customer data">customer data</a> including names, emails, and even passwords.  The hacker does not steal this information.  Instead, he quietly alerts you via email; but at the same time he makes the security <a href="http://www.savidtech.com/blog/tag/vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with vulnerability">vulnerability</a> public information on his blog.</p>
<p>Do you: A) Thank the hacker for bringing the <a href="http://www.savidtech.com/blog/tag/security-vulnerability/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security vulnerability">security vulnerability</a> to your attention?  Or, B) seek legal action against the hacker who damaged your company’s reputation by alerting the public about your sloppy security?</p>
<p>This is the controversy surrounding “<a href="http://www.HackersBlog.org">HackersBlog.org</a>” – a blog where anonymous <a href="http://www.savidtech.com/blog/tag/hackers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Hackers">hackers</a> alert the public about <a href="http://www.savidtech.com/blog/tag/security-vulnerabilities/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security vulnerabilities">security vulnerabilities</a>.  Each blog entry lists the site hacked, how the data was captured, and what private information is accessible.</p>
<p>The site made its first splash when a Romanian hacker named “Unu” hacked the databases of <a href="http://www.savidtech.com/blog/tag/kapersky/" class="st_tag internal_tag" rel="tag" title="Posts tagged with kapersky">Kapersky</a> – ironically, one of the leading companies in the security and <a href="http://www.savidtech.com/blog/tag/antivirus/" class="st_tag internal_tag" rel="tag" title="Posts tagged with antivirus">antivirus</a> market.  “Seems incredible but unfortunately, its true,” writes Unu, “Alter one of the parameters and you have access to EVERYTHING: users, activation codes, lists of bugs, admins, shop, etc.”</p>
<p>The next target, which occurred the very next day, was <a href="http://www.savidtech.com/blog/tag/bitdefender/" class="st_tag internal_tag" rel="tag" title="Posts tagged with bitdefender">BitDefender</a> – another antivirus software company.  Unu used an <a href="http://www.savidtech.com/blog/tag/sql-injection/" class="st_tag internal_tag" rel="tag" title="Posts tagged with SQL injection">SQL injection</a> to show how data could be easily extracted.</p>
<p>In an official statement, Kapersky denied the attack was successful.  BitDefender called the hack an attack and portrayed <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> negatively even though “the action did not intend to steal information but simply show a vulnerability.”  Usually when sites are hacked, the companies are left scrambling to put out the public relations fires.</p>
<p>So, alerting the website via email about the found vulnerability?  That sounds white hat enough.  So why expose the flaw to everyone publicly on the Internet and wreck the reputation of that company?  “If we just send an email, without making it public they would fix only that parameter that we announced,” says Unu, “and it is possible [for there] to be others too.”</p>
<p>It seems that HackersBlog owes its allegiance to the public and not to the companies who allow for these <a href="http://www.savidtech.com/blog/tag/breaches/" class="st_tag internal_tag" rel="tag" title="Posts tagged with breaches">breaches</a> in security.  &#8220;I&#8217;m not a criminal, I [am] not a burglar,” says Unu, “You do the work of a [pentesting firm] that could test the security of the site or [sic] server at the request of the owner. The difference is that the firm makes this for a big sum of money, a very big sum of money, and we do it as a hobby, for pleasure, free, and most of the times we do that much better, but we don’t even get a simple ‘Thank you.’”</p>
<p>Leave me a comment and let me know what you think about this Hacker Blog site!</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/anonymous-hackers/" title="anonymous hackers" rel="tag">anonymous hackers</a>, <a href="http://www.savidtech.com/blog/tag/antivirus/" title="antivirus" rel="tag">antivirus</a>, <a href="http://www.savidtech.com/blog/tag/bitdefender/" title="bitdefender" rel="tag">bitdefender</a>, <a href="http://www.savidtech.com/blog/tag/breaches/" title="breaches" rel="tag">breaches</a>, <a href="http://www.savidtech.com/blog/tag/customer-data/" title="customer data" rel="tag">customer data</a>, <a href="http://www.savidtech.com/blog/tag/hackers/" title="Hackers" rel="tag">Hackers</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/kapersky/" title="kapersky" rel="tag">kapersky</a>, <a href="http://www.savidtech.com/blog/tag/private-customer/" title="private customer" rel="tag">private customer</a>, <a href="http://www.savidtech.com/blog/tag/security-vulnerabilities/" title="security vulnerabilities" rel="tag">security vulnerabilities</a>, <a href="http://www.savidtech.com/blog/tag/security-vulnerability/" title="security vulnerability" rel="tag">security vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/hackersblog-%e2%80%93-white-or-black-hat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding Your Attackers with a Honeypot</title>
		<link>http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/</link>
		<comments>http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 20:28:45 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Consulting]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Network security]]></category>
		<category><![CDATA[corporate managers]]></category>
		<category><![CDATA[decoy systems]]></category>
		<category><![CDATA[honey pot]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[honeypots]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security budget]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=110</guid>
		<description><![CDATA[Honeypot data is a great way to loosen the purse strings of corporate managers who are hesitant to dip into the company budget.  You can make a case for a larger IT security budget by showing them the attack data on the honey pot – who is attacking, how they are attacking, how often, and, most importantly, what damage they could potentially do to the enterprise if the proper defenses are not built.  Actual data speaks louder than any verbal argument.
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Funderstanding-your-attackers-with-a-honeypot%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fnetwork-security%2Funderstanding-your-attackers-with-a-honeypot%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The reality of the situation is that there is no such thing as a 100% secure place on Earth.  <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">IT</a> <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> professionals can only do what they can to make things as secure as possible.  There is no computer <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> defense that will succeed every time, forever, or as I say when presenting at conferences &#8220;You cannot buy your <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> at the local best Buy&#8221;. (NOTE: If you have an indepth udnerstanding of heypots, you can skip this post)</p>
<p>Because of my interaction and association with the <a href="http://www.honeynet.org">Honeynet Project</a> I am frequently asked what benefits honeynets can provide to the normal everyday <a href="http://www.savidtech.com/blog/tag/it-security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT Security">IT security</a> engineer. Simply put, <a href="http://www.savidtech.com/blog/tag/honeypots/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honeypots">honeypots</a> provide us with early warning so we can be vigilant and prepare our defenses accordingly. </p>
<p>Additionally, <a href="http://www.savidtech.com/blog/tag/honeypot/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honeypot">honeypot</a> data is a great way to loosen the purse strings of <a href="http://www.savidtech.com/blog/tag/corporate-managers/" class="st_tag internal_tag" rel="tag" title="Posts tagged with corporate managers">corporate managers</a> who are hesitant to dip into the company budget.  You can make a case for a larger IT <a href="http://www.savidtech.com/blog/tag/security-budget/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security budget">security budget</a> by showing them the attack data on the <a href="http://www.savidtech.com/blog/tag/honey-pot/" class="st_tag internal_tag" rel="tag" title="Posts tagged with honey pot">honey pot</a> – who is attacking, how they are attacking, how often, and, most importantly, what damage they could potentially do to the enterprise if the proper defenses are not built.  Actual data speaks louder than any verbal argument.</p>
<p>Here’s an analogy to help you understand the importance of honeypots. </p>
<p>Imagine you are tasked with defending your king’s castle from an impending enemy attack.  But you don’t know who the enemy is, where they are coming from, how many there are, or what kind of attacks they will use.  They may use spears, rifles, or just sharp rocks.  They may attack on horseback, with catapults, or maybe with tanks.</p>
<p>So what kind of defenses should you build?  A 30 foot tall wall surrounding the castle or a moat?  Should you put archers in the towers or build turrets?  Maybe you should just pile up a few sandbags and hope for the best. Maybe the real problem is the village idiot on the inside&#8230; =)</p>
<p>Without knowing anything about the impending attack, you do not know what an appropriate defense would be.  You may dig a futile trench around your castle while the enemy attacks with stealth bombers.  Or you may encapsulate your entire castle in an impenetrable crystalline dome while your five attackers sling rocks at it.  The latter defense may work, but your king might not be too happy with you for wasting his whole treasury on an unnecessarily robust defense.</p>
<p>A Honeypot is perhaps like a decoy paper version of your castle set up a mile before your actual king’s castle.  The paper castle has no value, but you can see what attacks your enemy uses when they attack it, and thus prepare accordingly.</p>
<p>Honeypots allow you to understand what kind of attacks you can expect.  With this knowledge you can allocate resources to defenses appropriately, without under or overspending. Now, with all that said not everyone can run out and install a honeypot and solve their problems. Honeypots require a lot of maintenance, watching, and i fnot properly installed you can actually decrease the security of your network.</p>
<p>If you don&#8217;t want to take the chance of hurting your own security posture, there are services that will configure and run honeypots for you and provide you with their data. <a href="http://www.savidtech.com/blog/tag/symantec/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Symantec">Symantec</a> and <a href="http://www.savidtech.com/blog/tag/mcafee/" class="st_tag internal_tag" rel="tag" title="Posts tagged with McAfee">McAfee</a> offer such services.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/corporate-managers/" title="corporate managers" rel="tag">corporate managers</a>, <a href="http://www.savidtech.com/blog/tag/decoy-systems/" title="decoy systems" rel="tag">decoy systems</a>, <a href="http://www.savidtech.com/blog/tag/honey-pot/" title="honey pot" rel="tag">honey pot</a>, <a href="http://www.savidtech.com/blog/tag/honeypot/" title="honeypot" rel="tag">honeypot</a>, <a href="http://www.savidtech.com/blog/tag/honeypots/" title="honeypots" rel="tag">honeypots</a>, <a href="http://www.savidtech.com/blog/tag/information-technology/" title="information technology" rel="tag">information technology</a>, <a href="http://www.savidtech.com/blog/tag/it/" title="IT" rel="tag">IT</a>, <a href="http://www.savidtech.com/blog/tag/it-security/" title="IT Security" rel="tag">IT Security</a>, <a href="http://www.savidtech.com/blog/tag/mcafee/" title="McAfee" rel="tag">McAfee</a>, <a href="http://www.savidtech.com/blog/tag/security/" title="security" rel="tag">security</a>, <a href="http://www.savidtech.com/blog/tag/security-budget/" title="security budget" rel="tag">security budget</a>, <a href="http://www.savidtech.com/blog/tag/symantec/" title="Symantec" rel="tag">Symantec</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/network-security/understanding-your-attackers-with-a-honeypot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Health Industry Should Beware HITECH</title>
		<link>http://www.savidtech.com/blog/it-security/health-industry-should-beware-hitech/</link>
		<comments>http://www.savidtech.com/blog/it-security/health-industry-should-beware-hitech/#comments</comments>
		<pubDate>Mon, 15 Jun 2009 15:02:41 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[economic stimulus bill]]></category>
		<category><![CDATA[EHR]]></category>
		<category><![CDATA[electronic health record]]></category>
		<category><![CDATA[electronic health records]]></category>
		<category><![CDATA[electronic health records ehr]]></category>
		<category><![CDATA[health care operations]]></category>
		<category><![CDATA[health information exchange]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[information disclosure]]></category>
		<category><![CDATA[personal health record]]></category>
		<category><![CDATA[President Obama]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[public notification]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security breaches]]></category>
		<category><![CDATA[violation]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=86</guid>
		<description><![CDATA[While HIPAA has mostly been a toothless tiger up to this point, we can expect the OCR to act much more aggressively and prosecute violators further now that they get to keep whatever they can collect.  
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-security/health-industry-should-beware-hitech/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fhealth-industry-should-beware-hitech%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fhealth-industry-should-beware-hitech%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>If you work in the health industry then you might be really thankful for that $31.2 billion provided in <a href="http://www.savidtech.com/blog/tag/president-obama/" class="st_tag internal_tag" rel="tag" title="Posts tagged with President Obama">President Obama</a>’s <a href="http://www.savidtech.com/blog/tag/economic-stimulus-bill/" class="st_tag internal_tag" rel="tag" title="Posts tagged with economic stimulus bill">Economic Stimulus Bill</a>.  The Health <a href="http://www.savidtech.com/blog/tag/information-technology/" class="st_tag internal_tag" rel="tag" title="Posts tagged with information technology">Information Technology</a> for Economic and Clinical Health (<a href="http://www.savidtech.com/blog/tag/hitech/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HITECH">HITECH</a>) Act will provide the funds for the healthcare infrastructure to adopt <a href="http://www.savidtech.com/blog/tag/electronic-health-records/" class="st_tag internal_tag" rel="tag" title="Posts tagged with electronic health records">electronic health records</a> (<a href="http://www.savidtech.com/blog/tag/ehr/" class="st_tag internal_tag" rel="tag" title="Posts tagged with EHR">EHR</a>).  But be warned, this isn’t a free lunch from the <a href="http://www.savidtech.com/blog/tag/government/" class="st_tag internal_tag" rel="tag" title="Posts tagged with government">government</a>.  That HITECH money comes with a steep price tag.</p>
<p>HITECH expands the scope of <a href="http://www.savidtech.com/blog/tag/hipaa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HIPAA">HIPAA</a> adding some new <a href="http://www.savidtech.com/blog/tag/privacy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Privacy">privacy</a> and <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> requirements.  These include <a href="http://www.savidtech.com/blog/tag/public-notification/" class="st_tag internal_tag" rel="tag" title="Posts tagged with public notification">public notification</a> of security <a href="http://www.savidtech.com/blog/tag/breaches/" class="st_tag internal_tag" rel="tag" title="Posts tagged with breaches">breaches</a>, complying with individual requests regarding PHI (Personal Health Information) disclosure, and giving electronic PHI to those individuals that request <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a>.  But sure to be one of the more annoying requirements is accounting for PHI disclosures.  Every time a patient’s PHI is disclosed in the form of treatment, payment, or other <a href="http://www.savidtech.com/blog/tag/health-care-operations/" class="st_tag internal_tag" rel="tag" title="Posts tagged with health care operations">health care operations</a>, a record must keep account of each and every disclosure.</p>
<p>Also, now business associates of healthcare providers will fall under the growing canopy of HIPAA.  Any business that contracts with a HIPAA covered entity and routinely accesses PHI must now also be HIPAA compliant.  This will include <a href="http://www.savidtech.com/blog/tag/health-information-exchange/" class="st_tag internal_tag" rel="tag" title="Posts tagged with health information exchange">Health Information Exchange</a> Organizations, Regional Health Information Organizations, or any other vendor that contracts that with a covered entity to allow that covered entity to offer a <a href="http://www.savidtech.com/blog/tag/personal-health-record/" class="st_tag internal_tag" rel="tag" title="Posts tagged with personal health record">personal health record</a> to patients as part of its <a href="http://www.savidtech.com/blog/tag/electronic-health-record/" class="st_tag internal_tag" rel="tag" title="Posts tagged with electronic health record">electronic health record</a>.</p>
<p>But these changes are not what worry me.  What worries me is the shift from the Office of Civil Right’s compliant-driven approach to enforcing HIPAA to the new <a href="http://www.savidtech.com/blog/tag/ocr/" class="st_tag internal_tag" rel="tag" title="Posts tagged with OCR">OCR</a>-funded approach.  Effective immediately, collected civil moneys from HIPAA neglectors goes directly to the <a href="http://www.savidtech.com/blog/tag/ocr/" class="st_tag internal_tag" rel="tag" title="Posts tagged with OCR">OCR</a>.  That’s right; the <a href="http://www.savidtech.com/blog/tag/ocr/" class="st_tag internal_tag" rel="tag" title="Posts tagged with OCR">OCR</a> is now driven by a cash incentive to find HIPAA violators, as opposed to just waiting until someone complains about it. </p>
<p>While HIPAA has mostly been a toothless tiger up to this point, we can expect the OCR to act much more aggressively and prosecute violators further now that they get to keep whatever they can collect. </p>
<p>The cash penalties are steeper now with HITECH.  “Did not know” or “reasonable cause” violations will be fined $100 to $50,000 for each incident.  Entities that show “willful neglect” will be given a minimum <a href="http://www.savidtech.com/blog/tag/fine/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fine">fine</a> of $10,000.</p>
<p>Because of HITECH, ignoring HIPAA compliance just became a bigger gamble than ever.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/economic-stimulus-bill/" title="economic stimulus bill" rel="tag">economic stimulus bill</a>, <a href="http://www.savidtech.com/blog/tag/ehr/" title="EHR" rel="tag">EHR</a>, <a href="http://www.savidtech.com/blog/tag/electronic-health-record/" title="electronic health record" rel="tag">electronic health record</a>, <a href="http://www.savidtech.com/blog/tag/electronic-health-records/" title="electronic health records" rel="tag">electronic health records</a>, <a href="http://www.savidtech.com/blog/tag/electronic-health-records-ehr/" title="electronic health records ehr" rel="tag">electronic health records ehr</a>, <a href="http://www.savidtech.com/blog/tag/health-care-operations/" title="health care operations" rel="tag">health care operations</a>, <a href="http://www.savidtech.com/blog/tag/health-information-exchange/" title="health information exchange" rel="tag">health information exchange</a>, <a href="http://www.savidtech.com/blog/tag/hitech/" title="HITECH" rel="tag">HITECH</a>, <a href="http://www.savidtech.com/blog/tag/information-disclosure/" title="information disclosure" rel="tag">information disclosure</a>, <a href="http://www.savidtech.com/blog/tag/personal-health-record/" title="personal health record" rel="tag">personal health record</a>, <a href="http://www.savidtech.com/blog/tag/president-obama/" title="President Obama" rel="tag">President Obama</a>, <a href="http://www.savidtech.com/blog/tag/privacy/" title="Privacy" rel="tag">Privacy</a>, <a href="http://www.savidtech.com/blog/tag/public-notification/" title="public notification" rel="tag">public notification</a>, <a href="http://www.savidtech.com/blog/tag/security/" title="security" rel="tag">security</a>, <a href="http://www.savidtech.com/blog/tag/security-breaches/" title="security breaches" rel="tag">security breaches</a>, <a href="http://www.savidtech.com/blog/tag/violation/" title="violation" rel="tag">violation</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-security/health-industry-should-beware-hitech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Finally Shows Its Teeth</title>
		<link>http://www.savidtech.com/blog/it-security/hipaa-finally-shows-its-teeth/</link>
		<comments>http://www.savidtech.com/blog/it-security/hipaa-finally-shows-its-teeth/#comments</comments>
		<pubDate>Fri, 29 May 2009 15:08:50 +0000</pubDate>
		<dc:creator>Michael A. Davis</dc:creator>
				<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[caremark]]></category>
		<category><![CDATA[fine]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[hipaa violations]]></category>
		<category><![CDATA[medical industry]]></category>
		<category><![CDATA[OCR]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[privacy rule]]></category>
		<category><![CDATA[prosecutions]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security practices]]></category>
		<category><![CDATA[U.S. Department]]></category>

		<guid isPermaLink="false">http://www.whatevercompliance.com/?p=39</guid>
		<description><![CDATA[The HHS Office for Civil Rights (OCR) and the Federal Trade Commission caught the pharmacy chain red-handed disposing of empty pill bottles that contained patient data into dumpsters and trash containers outside select stores.  Among other issues, CVS “failed to implement adequate policies and procedures to appropriately safeguard patient information during the disposal process; and failed to adequately train employees on how to dispose of such information properly.”
]]></description>
			<content:encoded><![CDATA[<div class='wpfblike' style='height: 40px;'><fb:like href='http://www.savidtech.com/blog/it-security/hipaa-finally-shows-its-teeth/' layout='default' show_faces='true' width='400' action='like' colorscheme='light' send='false' /></div><p></p><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fhipaa-finally-shows-its-teeth%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.savidtech.com%2Fblog%2Fit-security%2Fhipaa-finally-shows-its-teeth%2F&amp;source=savidtech&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>When <a href="http://www.savidtech.com/blog/tag/hipaa/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HIPAA">HIPAA</a> was passed and made federal law by the Clinton administration in 1996, the fear of fines and even jail time sent the <a href="http://www.savidtech.com/blog/tag/medical-industry/" class="st_tag internal_tag" rel="tag" title="Posts tagged with medical industry">medical industry</a> scrambling to beef up their <a href="http://www.savidtech.com/blog/tag/patient-data/" class="st_tag internal_tag" rel="tag" title="Posts tagged with patient data">patient data</a> <a href="http://www.savidtech.com/blog/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> by the 2003 deadline.  However, for years afterwards, HIPAA remained a toothless tiger.  Occasionally, <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> growled and violators were threatened to clean up their act.  But <a href="http://www.savidtech.com/blog/tag/it/" class="st_tag internal_tag" rel="tag" title="Posts tagged with IT">it</a> usually did not bite, as <a href="http://www.savidtech.com/blog/tag/prosecutions/" class="st_tag internal_tag" rel="tag" title="Posts tagged with prosecutions">prosecutions</a> were rare and usually mild.</p>
<p>Since no serious prosecutions have taken place since HIPAA went into effect in 2003, I and the medical industry have wondered if HIPAA is just a made-up boogeyman meant to frighten them into compliance. </p>
<p>All this changed on February 18 when the <a href="http://www.savidtech.com/blog/tag/us-department/" class="st_tag internal_tag" rel="tag" title="Posts tagged with U.S. Department">U.S. Department</a> of Health and Human Services and the Federal Trade Commission issued a press release stating CVS had to pay $2.25 million to the U.S. <a href="http://www.savidtech.com/blog/tag/government/" class="st_tag internal_tag" rel="tag" title="Posts tagged with government">government</a> for <a href="http://www.savidtech.com/blog/tag/hipaa-violations/" class="st_tag internal_tag" rel="tag" title="Posts tagged with hipaa violations">HIPAA violations</a>.</p>
<p>The <a href="http://www.savidtech.com/blog/tag/hhs/" class="st_tag internal_tag" rel="tag" title="Posts tagged with HHS">HHS</a> Office for Civil Rights (<a href="http://www.savidtech.com/blog/tag/ocr/" class="st_tag internal_tag" rel="tag" title="Posts tagged with OCR">OCR</a>) and the Federal Trade Commission caught the pharmacy chain red-handed disposing of empty pill bottles that contained patient data into dumpsters and trash containers outside select stores.  Among other issues, CVS “failed to implement adequate policies and procedures to appropriately safeguard patient information during the disposal process; and failed to adequately train employees on how to dispose of such information properly.”</p>
<p>CVS <a href="http://www.savidtech.com/blog/tag/caremark/" class="st_tag internal_tag" rel="tag" title="Posts tagged with caremark">Caremark</a> Corp., the parent company of the 6,000 store pharmacy chain, must implement a robust corrective action plan that requires <a href="http://www.savidtech.com/blog/tag/privacy/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Privacy">Privacy</a> Rule compliant policies and procedures for safeguarding patient information in addition to its <a href="http://www.savidtech.com/blog/tag/fine/" class="st_tag internal_tag" rel="tag" title="Posts tagged with fine">fine</a>.  CVS must also submit to a biennial audit by a third party to show their compliance.</p>
<p>Is HHS trying to set an example with the steep penalty?  Is CVS the sacrificial lamb intended to inspire other delinquent HIPAA violators to clean up their act? </p>
<p>While many medical industry companies may have gambling with HIPAA violations, at least CVS learned it isn’t worth the <a href="http://www.savidtech.com/blog/tag/risk/" class="st_tag internal_tag" rel="tag" title="Posts tagged with risk">risk</a>.  Besides the possible penalties, compromising personal patient data is a strike against the reputation of a company.  And this can be more costly than any fine by the HHS.</p>

	Tags: <a href="http://www.savidtech.com/blog/tag/caremark/" title="caremark" rel="tag">caremark</a>, <a href="http://www.savidtech.com/blog/tag/fine/" title="fine" rel="tag">fine</a>, <a href="http://www.savidtech.com/blog/tag/hhs/" title="HHS" rel="tag">HHS</a>, <a href="http://www.savidtech.com/blog/tag/hipaa/" title="HIPAA" rel="tag">HIPAA</a>, <a href="http://www.savidtech.com/blog/tag/hipaa-violations/" title="hipaa violations" rel="tag">hipaa violations</a>, <a href="http://www.savidtech.com/blog/tag/it-security/" title="IT Security" rel="tag">IT Security</a>, <a href="http://www.savidtech.com/blog/tag/medical-industry/" title="medical industry" rel="tag">medical industry</a>, <a href="http://www.savidtech.com/blog/tag/ocr/" title="OCR" rel="tag">OCR</a>, <a href="http://www.savidtech.com/blog/tag/patient-data/" title="patient data" rel="tag">patient data</a>, <a href="http://www.savidtech.com/blog/tag/privacy/" title="Privacy" rel="tag">Privacy</a>, <a href="http://www.savidtech.com/blog/tag/privacy-rule/" title="privacy rule" rel="tag">privacy rule</a>, <a href="http://www.savidtech.com/blog/tag/prosecutions/" title="prosecutions" rel="tag">prosecutions</a>, <a href="http://www.savidtech.com/blog/tag/risk/" title="risk" rel="tag">risk</a>, <a href="http://www.savidtech.com/blog/tag/security-practices/" title="security practices" rel="tag">security practices</a>, <a href="http://www.savidtech.com/blog/tag/us-department/" title="U.S. Department" rel="tag">U.S. Department</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.savidtech.com/blog/it-security/hipaa-finally-shows-its-teeth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
