Indiana Security & Privacy Network
News

Feb 24, 2010

Breach Notification reports due by March 1, 2010

For breaches of less than 500 that occurred between Sept 29 - Dec 31, 2009 are due to be reported by March 1 See link (more) for details

More

Feb 24, 2010

HHS announces breaches over 500 in 2009 - see details on link

36 events were reported by healthcare providers - these occurred between Sept 29- Dec 31, 2009. A substantial number involved laptops and portable devices. Go to the link (more) for details.

More

Feb 15, 2010

InSPN Newsletter

Welcome to the Indiana Security & Privacy Network (InSPN) newsletter. The purpose of this newsletter is to keep you informed about security and privacy concerns that affects your organization. We invite you to participate by sharing information, knowledge and best practices on security, privacy and regulatory compliance that affect all Indiana industries.

More

Dec 17, 2009

InSPN Newsletter

See link for review of November 2009 meeting presentation by Dr Marc Rogers, InSPN 2010 dates & Board of Directors and recent privacy and security news

More

Oct 31, 2009

HITECH Act Enforcement Interim Final Rule

The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as part of the American Recovery and Reinvestment Act of 2009, was signed into law on February 17, 2009, to promote the adoption and meaningful use of health information technology. Subtitle D of the HITECH Act addresses the privacy and security concerns associated with the electronic transmission of health information, in part, through several provisions that strengthen the civil and criminal enforcement of the HIPAA rules. Section 13410(d) of the HITECH Act, which became effective on February 18, 2009, revised section 1176(a) of the Social Security Act (the Act) by establishing: Four categories of violations that reflect increasing levels of culpability; Four corresponding tiers of penalty amounts that significantly increase the minimum penalty amount for each violation; and A maximum penalty amount of $1.5 million for all violations of an identical provision. It also amended section 1176(b) of the Act by: Striking the previous bar on the imposition of penalties if the covered entity did not know and with the exercise of reasonable diligence would not have known of the violation (such violations are now punishable under the lowest tier of penalties); and Providing a prohibition on the imposition of penalties for any violation that is corrected within a 30-day time period, as long as the violation was not due to willful neglect. This interim final rule conforms HIPAA’s enforcement regulations to these statutory revisions that are currently effective under section 13410(d) of the HITECH Act. This interim final rule does not make amendments with respect to those enforcement provisions of the HITECH Act that are not yet effective under the applicable statutory provisions. This interim final rule will become effective on November 30, 2009. HHS has invited public comments on the interim final rule, which will be considered if received by December 29, 2009. see MORE to - View the Enforcement Interim Final Rule View the Press Release.

More