<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>http://www.karmaspoon.com</title>
	<atom:link href="http://karmaspoon.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://karmaspoon.com</link>
	<description></description>
	<lastBuildDate>Wed, 20 Jan 2010 16:32:06 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Apple releases OS X security update</title>
		<link>http://karmaspoon.com/apple-releases-os-x-security-update/</link>
		<comments>http://karmaspoon.com/apple-releases-os-x-security-update/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 16:30:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[Secure Your Network]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security updates]]></category>

		<guid isPermaLink="false">http://karmaspoon.com/?p=127</guid>
		<description><![CDATA[Apple&#8217;s First 2010 OS X Security Update Not So Bad
SEVERITY: HIGH
19 January, 2010
SUMMARY:
These vulnerabilities affect: All current versions of OS X 10.5.x (Leopard) and OS X 10.6.x (Snow Leopard)
How an attacker exploits them: Multiple vectors of attack, including enticing one of your users into downloading and viewing various malicious media files
Impact: Various results; in the [...]]]></description>
			<content:encoded><![CDATA[<p>Apple&#8217;s First 2010 OS X Security Update Not So Bad</p>
<p><strong>SEVERITY</strong>: HIGH<br />
19 January, 2010</p>
<p><strong>SUMMARY</strong>:<br />
These vulnerabilities affect: All current versions of OS X 10.5.x (Leopard) and OS X 10.6.x (Snow Leopard)<br />
How an attacker exploits them: Multiple vectors of attack, including enticing one of your users into downloading and viewing various malicious media files<br />
Impact: Various results; in the worst case, an attacker executes code on your user&#8217;s computer, potentially gaining full control of it<br />
What to do: OS X administrators should download, test and install Security Update 2010-001<br />
<strong>EXPOSURE</strong>:<br />
Today, Apple released a security update to fix vulnerabilities in all current versions of OS X. The update fixes a dozen (number based on CVE-IDs) security issues in six of the components that ship as part of OS X, including CoreAudio, OpenSSL, and the Flash Player plug-in. Some of these vulnerabilities allow attackers to execute code on your OS X machines, so we rate this update Critical. Apply it as soon as you can. Three of the fixed vulnerabilities include:</p>
<p>CoreAudio Buffer Overflow Vulnerability. CoreAudio is an OS X component that helps the operating system play various audio files. It suffers from a buffer overflow vulnerability involving the way it handles specially malformed mp4 audio files.  If an attacker can get a victim to open a malicious mp4 file (perhaps hosted on a malicious web site), he could exploit this flaw to either crash the playing application or to execute attack code on the victim&#8217;s computer. By default, the attacker would only execute code with that user&#8217;s privileges.<br />
Multiple Adobe Flash Player Plug-in Vulnerabilities. OS X ships with Adobe&#8217;s Flash Player so that it can play Flash content found on many web sites today. Apple&#8217;s OS X update fixes seven unspecified security vulnerabilities in the OS X Flash Player plug-in. Apple&#8217;s alert does not describe these vulnerabilities in any technical detail. However, it does describe the impact of the worst flaws. By enticing you to a malicious web site, an attacker could potentially exploit one of these flaws to execute code on your computer, with your privileges. We suspect the updates to the OS X Flash Player plug-in are related to the ones Adobe fixed in their stand-alone player recently.<br />
Multiple Image-related Memory Corruption Vulnerabilities. ImageIO and Image RAW are both OS X components that help the operating system handle various types of image files. Both components suffer from memory-related vulnerabilities (specifically, a buffer overflow and a buffer underflow) involving the way they handle certain types of media files. Though the vulnerabilities differ technically, they share a very similar scope and impact. If an attacker can get a victim to view a specially crafted media file (perhaps hosted on a malicious web site), he could exploit these flaws to either crash the viewing application or to execute attack code on the victim&#8217;s computer. By default, the attacker would only execute code with that user&#8217;s privileges.<br />
Apple&#8217;s alert also describes a less risky Denial of Service (DoS) flaw and an information disclosure issue. Components patched by this security update include:</p>
<p>CoreAudio    CUPS<br />
Flash Player Plug-in<br />
ImageIO</p>
<p>Image RAW<br />
OpenSSL<br />
Please refer to Apple&#8217;s OS X 10.5.x and 10.6.x alert for more details</p>
<p><strong>SOLUTION PATH</strong>:<br />
Apple has released OS X Security Update 2010-001 to fix these security issues. OS X administrators should download, test, and deploy the corresponding update as soon as they can.</p>
<p><a href="http://support.apple.com/downloads/" target="_blank">Security Update 2010-001 (Leopard)<br />
Security Update 2010-001 (LeopardServer)<br />
Security Update 2010-001 (Snow Leopard )</a><br />
Note: If you have trouble figuring out which of these patches corresponds to your version of OS X, we recommend that you let OS X&#8217;s Software Update utility pick the correct updates for you automatically.</p>
<p>FOR ALL USERS:<br />
These flaws enable many diverse exploitation methods. Some of the exploits are local, meaning that your perimeter firewall never encounters the attack (unless you use firewalls internally between departments). Installing these updates, therefore, is the most secure course of action.</p>
<p>STATUS:<br />
Apple has released updates to fix these issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://karmaspoon.com/apple-releases-os-x-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Releases Firefox 3.5.6 and 3.0.16 to Fix 11 Vulnerabilities</title>
		<link>http://karmaspoon.com/mozilla-releases-firefox-3-5-6-and-3-0-16-to-fix-11-vulnerabilities/</link>
		<comments>http://karmaspoon.com/mozilla-releases-firefox-3-5-6-and-3-0-16-to-fix-11-vulnerabilities/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 15:20:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Secure Your Network]]></category>

		<guid isPermaLink="false">http://karmaspoon.com/?p=123</guid>
		<description><![CDATA[Summary:

This vulnerability affects: Firefox 3.5.5 (and previous versions) for Windows, Linux, and Macintosh
How an attacker exploits it: Multiple vectors of attack, including enticing one of your users to visit a malicious web page
Impact: Various results; in the worst case, an attacker executes code on your user&#8217;s computer, gaining complete control of it
What to do: Upgrade [...]]]></description>
			<content:encoded><![CDATA[<h3>Summary:</h3>
<ul>
<li><strong>This vulnerability affects:</strong> Firefox 3.5.5 (and previous versions) for Windows, Linux, and Macintosh</li>
<li><strong>How an attacker exploits it:</strong> Multiple vectors of attack, including enticing one of your users to visit a malicious web page</li>
<li><strong>Impact:</strong> Various results; in the worst case, an attacker executes code on your user&#8217;s computer, gaining complete control of it</li>
<li><strong>What to do:</strong> Upgrade to Firefox 3.5.6 (or legacy Firefox 3.0.16)</li>
</ul>
<h3>Exposure:</h3>
<p>The Mozilla Foundation released <a id="trk267262" href="http://www.tailorednews.com/r/AmQI912gkmsTOROpPO.htm" target="_blank">Firefox 3.5.6</a>, fixing at least 11 vulnerabilities (we typically base our count on <a id="trk267263" href="http://www.tailorednews.com/r/bBIH2sgZABYCRXRdOR.htm" target="_blank">CVE-ID</a>s) in their popular web browser. They also released <a id="trk267264" href="http://www.tailorednews.com/r/4tHUgYZTbtVPXQX5RX.htm" target="_blank">Firefox 3.0.16</a> to fix security vulnerabilities in the legacy version of Firefox. Three of the vulnerabilities have been rated as critical, which they define as a vulnerability that can be used to run attacker code and install software, requiring no user interaction beyond normal browsing. We summarize the most critical Firefox 3.5.x vulnerabilities below:</p>
<ul>
<li><span style="font-weight: bold;">Integer Overflow, Crash in Libtheora Video Library</span><strong> (<a id="trk267265" href="http://www.tailorednews.com/r/rLUmZVTC4LqOQIQ9XQ.html" target="_blank">2009-67</a>).</strong>  An attacker would first have to trick one of your users into visiting a malicious web page with a specially crafted video that writes data past the bounds of the buffer, causing a crash and potentially the ability to run arbitrary code on a victim&#8217;s computer. If your user took the bait, the attacker could execute malicious code on that user&#8217;s machine, with that user&#8217;s privileges. If the user happened to be a local administrator or had root privileges, the attacker would gain total control of the victim&#8217;s computer.<br />
<em>Mozilla Impact rating: <strong>Critical</strong></em></li>
</ul>
<ul>
<li><span style="font-weight: bold;">Memory Safety Fixes in Liboggplay Media Library</span><strong> (<a id="trk267266" href="http://www.tailorednews.com/r/WfmBTqCPrf3RIHI2QI.html" target="_blank">2009-066</a>).</strong> Again, the bugs which were fixed could potentially be used by an attacker to crash a victim&#8217;s browser and execute arbitrary code on their computer.<br />
<em>Mozilla Impact rating: <strong></strong></em><em><strong>Critical</strong></em></li>
</ul>
<ul>
<li><strong>Buffer Overflow Vulnerability in GIF Parser (<a id="trk267267" href="http://www.tailorednews.com/r/80BtC3POW0FXHUHgIH.html" target="_blank">2009-065</a>).</strong> This addresses several crashes in the brower engine used in Firefox and other Mozilla products.  Mozilla warns that with enough effort at least some of these could be exploited to run arbitrary code. As usual, if your user has local administrative privileges, the attacker gains complete control of the user&#8217;s machine.<br />
<em>Mozilla Impact rating:<strong> Critical</strong></em></li>
</ul>
<p>Mozilla&#8217;s alert describes several more vulnerabilities. Visit Mozilla&#8217;s <a id="trk267268" href="http://www.tailorednews.com/r/xztLPFOR8zkQUmUZHU.html" target="_blank">Known Vulnerabilities page</a> for a complete list of the vulnerabilities that the 3.5.6 update fixes. You can also visit the 3.0 <a id="trk267269" href="http://www.tailorednews.com/r/GnLfOkRXxnAImBmTUm.html" target="_blank">Known Vulnerabilities page</a>, to check out the fixes in 3.0.15.</p>
<h3>Solution Path:</h3>
<p>Mozilla has updated Firefox 3.5, correcting these security vulnerabilities. If you use Firefox in your network, we recommend that you download and deploy version 3.5.6 as soon as possible. They have also released updates for the 3.0.x line of Firefox, which you can find <a id="trk267270" href="http://www.tailorednews.com/r/jlf0RAXQGlbHBtBCmB.html" target="_blank">here</a>. However, we recommend 3.0.x users update to 3.5.x to keep current with the latest version of Firefox.</p>
<p><strong>Note:</strong> The latest version of Firefox 3.5 automatically informs you when a Firefox update is available. We highly recommend you keep this feature enabled so that Firefox receives its updates as soon as Mozilla releases them. To verify that you have Firefox configured to automatically check for updates, click <strong>Tools =&gt; Options =&gt; Advanced</strong> tab<strong> =&gt; Update</strong> tab. Make sure that &#8220;Firefox&#8221; is checked under &#8220;Automatically check for updates.&#8221; In this menu, you can configure Firefox to always download and install any update, or if you prefer, only to inform the user that an update exists.</p>
<h3>For All Users:</h3>
<p>Many of these attacks arrive as normal-looking HTTP traffic, which you must allow through your firewall if your network users need to access the World Wide Web. Therefore, the patches above are your best solution.</p>
<h3>Status:</h3>
<p>The Mozilla Foundation has released Firefox 3.5.6, fixing these security issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://karmaspoon.com/mozilla-releases-firefox-3-5-6-and-3-0-16-to-fix-11-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Urgent: Adobe Reader Vulnerability Affects 9.2 and Earlier</title>
		<link>http://karmaspoon.com/urgent-adobe-reader-vulnerability-affects-9-2-and-earlier/</link>
		<comments>http://karmaspoon.com/urgent-adobe-reader-vulnerability-affects-9-2-and-earlier/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 23:32:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Secure Your Network]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://karmaspoon.com/?p=116</guid>
		<description><![CDATA[ 

This vulnerability affects: Adobe Reader and Acrobat 9.2 and earlier, on Windows, Mac, and Unix computers
How an attacker exploits it: By enticing your users into viewing a maliciously crafted PDF document using javascript
Impact: An attacker can potentially gain control of  your system 
What to do: Implement the workarounds described in the Solution Path section of this alert

Exposure:
Adobe [...]]]></description>
			<content:encoded><![CDATA[<p><strong></strong> </p>
<ul>
<li><strong>This vulnerability affects</strong>: Adobe Reader and Acrobat 9.2 and earlier, on Windows, Mac, and Unix computers</li>
<li><strong>How an attacker exploits it</strong>: By enticing your users into viewing a maliciously crafted PDF document using javascript</li>
<li><strong>Impact</strong>: An attacker can potentially gain control of  your system </li>
<li><strong>What to do</strong>: Implement the workarounds described in the Solution Path section of this alert</li>
</ul>
<h3>Exposure:</h3>
<p>Adobe has confirmed a critical zero day vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. This was first referenced by Adobe in a <a id="trk267236" href="http://karmaspoon.com/exchweb/bin/redir.asp?URL=http://www.tailorednews.com/r/zWAbNQwDL4I1VqviDv.html" target="_blank">blog posting</a> on Monday and they have since  issued a security bulletin. Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue. Users running Microsoft DEP (&#8221;Data Execution Prevention&#8221;) functionality available in more recent versions of Microsoft Windows are at reduced risk:</p>
<ul>
<li>All versions of Adobe Reader 9 running on Windows Vista SP1 or Windows 7</li>
<li>Acrobat 9.2 running on Windows Vista SP1 or Windows 7</li>
<li>Acrobat and Adobe Reader 9.2 running on Windows XP SP3</li>
<li>Acrobat and Adobe Reader 8.1.7 running on Windows XP SP3, Windows Vista SP1, or Windows 7</li>
</ul>
<p>With the DEP mitigation in place, the impact of this exploit has been reduced to a Denial of Service during Adobe&#8217;s testing.</p>
<p>Since attackers are actively exploiting this vulnerability in the wild and Adobe hasn&#8217;t had time to patch it yet, this flaw poses a serious risk to Adobe Reader users. Until a patch is available, we recommend you implement the workarounds described below to mitigate the risk of this attack.</p>
<h3>Solution Path</h3>
<p>Adobe has not had time to release a patch for this zero day vulnerability. However, the workarounds described below should mitigate the risk of attacks currently circulating in the wild.</p>
<ul>
<li><strong>Inform your users of this vulnerability. </strong>Advise them to remain wary of unsolicited PDF documents arriving via email. If they don&#8217;t absolutely need the document, and don&#8217;t trust the entity it came from, they should avoid opening it until you patch Adobe Reader.</li>
<li><strong>Disable JavaScript in Adobe Reader.</strong> According to Adobe, users can mitigate the issue by disabling JavaScript in Adobe Reader. To disable JavaScript in Adobe Reader, click <strong>Edit =&gt; Preferences =&gt; JavaScript </strong>and then uncheck<strong> Enable Acrobat JavaScript</strong>. Keep in mind, this prevents JavaScript from running in legitimate PDF documents as well.</li>
<li><strong>Use a gateway device, like your Firebox, to block PDF files. </strong>If your users can&#8217;t download PDF files, these exploits won&#8217;t affect them. Unfortunately, doing this blocks legitimate PDF files as well. Nonetheless, depending on your business needs, you may still want to block PDF files until a patch is available.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://karmaspoon.com/urgent-adobe-reader-vulnerability-affects-9-2-and-earlier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DIY Network Security</title>
		<link>http://karmaspoon.com/diy-network-security/</link>
		<comments>http://karmaspoon.com/diy-network-security/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 18:10:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[default password]]></category>
		<category><![CDATA[default SSID]]></category>
		<category><![CDATA[Disable SSID]]></category>
		<category><![CDATA[Enable MAC filtering]]></category>
		<category><![CDATA[Linksys]]></category>
		<category><![CDATA[Secure Your Network]]></category>
		<category><![CDATA[WPA Encryption]]></category>

		<guid isPermaLink="false">http://karmaspoon.com/?p=102</guid>
		<description><![CDATA[How to Secure Your Network
Networking makes it easy to share Internet access and data. But you don’t want to share your information with just anyone. With a wireless network, your information is traveling through the airwaves, not physical wires, so anyone within range can &#8220;listen in&#8221; on your network. There are five essential security measures [...]]]></description>
			<content:encoded><![CDATA[<h2>How to Secure Your Network</h2>
<p>Networking makes it easy to share Internet access and data. But you don’t want to share your information with just anyone. With a wireless network, your information is traveling through the airwaves, not physical wires, so anyone within range can &#8220;listen in&#8221; on your network. There are five essential security measures you should take to secure your wireless network.</p>
<div><img src="http://downloads.linksysbycisco.com/images/dynamic/Home%20Networking17.png" border="0" alt="" align="middle" /></div>
<h4><strong>1. Change the default password</strong></h4>
<p>Access points and routers have a default password set by the factory. You will be asked for a password when you want to change their settings. (The Linksys by Cisco default password is <em>admin</em>). Hackers know these defaults and will try them to access your wireless device and change your network settings. To thwart any unauthorized changes, change the password so it will be hard to guess.</p>
<h4><strong>2. Change the default SSID</strong></h4>
<p>Your wireless devices have a default SSID (Service Set Identifier) set by the factory. The SSID is the name of your wireless network, and can be up to 32 characters. Linksys by Cisco wireless products use <em>linksys</em> as the default SSID. Hackers know these defaults and can use them to join your network. Change your network&#8217;s SSID to something unique, and make sure it doesn&#8217;t refer to the networking products you use. As an added precaution, be sure to change the SSID on a regular basis, so any hacker who may have figured out your network&#8217;s SSID in the past will have to figure out the SSID again and again. This will deter future intrusion attempts.</p>
<h4><strong>3. Enable WPA Encryption</strong></h4>
<p>Encryption allows protection for data that is transmitted over a wireless network. Wired Equivalency Privacy (WEP) and Wi-Fi Protected Access (WPA) offer different levels of security for wireless communication. WPA is considered to be more secure than WEP, because it uses dynamic key encryption. To protect the information as it passes over the airwaves, you should enable the highest level of encryption that is supported by your network equipment.</p>
<h4><strong>4. Disable SSID broadcast</strong></h4>
<p>By default, most wireless networking devices are set to broadcast the SSID, so anyone can easily join the wireless network with just this information. But hackers will also be able to connect, so unless you&#8217;re running a public hotspot, it&#8217;s best to disable SSID broadcast. You may think it is more convenient to broadcast your SSID so that you can click on it to join your network, but you can configure the devices on your network to automatically connect to a specific SSID without broadcasting the SSID from your router.</p>
<p>You might ask &#8220;If it&#8217;s easier for hackers, why broadcast SSID in the first place?&#8221; The reason is because setup is easier if you can see it. After setup you should disable SSID Broadcast.</p>
<h4><strong>5. Enable MAC address filtering</strong></h4>
<p>Linksys by Cisco routers give you the ability to enable MAC (Media Access Control) address filtering.</p>
<p>Some routers give you the ability to enable MAC address filtering. This is not MAC like Mac computers. With MAC address filtering, you specify which computers can access your network. It would be very difficult for a hacker to access your network using a random MAC address.</p>
<p>The MAC address is a unique series of numbers and letters assigned to every networking device. With MAC address filtering enabled, wireless network access is provided solely for wireless devices with specific MAC addresses. For example, you can specify only the computers in your house to access your wireless network. It would be very difficult for a hacker to access your network using a random MAC address. </p>
<h4><strong>Purchase a new Linksys by Cisco device</strong></h4>
<p>If you do not already have a quality, easy to use wireless network security device, you can get great deals direct through Linksys. <br />
<a onmouseover="window.status='http://www.shoplinksys.com/';return true;" onmouseout="window.status=' ';return true;" href="http://www.dpbolvw.net/click-3740024-10707970" target="_blank">Linksys by Cisco</a><img src="http://www.awltovhc.com/image-3740024-10707970" border="0" alt="" width="1" height="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://karmaspoon.com/diy-network-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is HIPAA</title>
		<link>http://karmaspoon.com/what-is-hipaa/</link>
		<comments>http://karmaspoon.com/what-is-hipaa/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 17:52:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://karmaspoon.com/?p=50</guid>
		<description><![CDATA[Health Insurance Portability and Accountability Act of 1996 (HIPAA)
HIPAA mandates the privacy and security of protected health information (PHI).
The HIPAA security rule was published in May 2003 and subject to enforcement for all covered entities starting in April 2005. Given the productivity gains for healthcare professionals to communicate with patients and other doctors and health [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Health Insurance Portability and Accountability Act of 1996 (HIPAA)</strong></h3>
<p>HIPAA mandates the privacy and security<img class="alignright size-full wp-image-51" title="HIPAA" src="http://karmaspoon.com/wp-content/uploads/2009/12/HIPAA.jpg" alt="HIPAA" width="383" height="210" /> of protected health information (PHI).<br />
The HIPAA security rule was published in May 2003 and subject to enforcement for all covered entities starting in April 2005. Given the productivity gains for healthcare professionals to communicate with patients and other doctors and health professionals via email, healthcare organizations need to leverage real-time electronic communications, but do so securely.<br />
HIPAA places a number of requirements on the health care industry’s information handling practices, and has direct impact on the operation of messaging systems.</p>
<p><strong>Who is impacted by HIPAA? </strong><br />
Covered entities consist of healthcare providers, health plans (insurance, etc.) and healthcare<br />
clearinghouses (claims and transaction processors). Service personnel (accountants, lawyers, etc.) working on behalf of the covered entities are also subject to HIPAA requirements.</p>
<h3><strong>HIPAA IT Security Requirements</strong></h3>
<p><strong>HIPAA dictates that organizations must ensure that</strong>:<br />
Email messages containing protected health information are secured, even when transmitted via<br />
unencrypted links.<br />
Senders and recipients are properly verified via person or entity authentication<br />
Email servers and the messages they contain are protected.</p>
<p><strong>NIST</strong> (National Institute of Science and Technology) has published an information security guide that many believe will meet the requirements of HIPAA. This guide (An Introduction to Computer Security: The NIST Handbook) provides the specifics an organization needs to understand the scope of their compliance efforts.<br />
<a href="http://csrc.nist.gov/publications/nistpubs/800‐12/handbook.pdf" target="_blank">http://csrc.nist.gov/publications/nistpubs/800‐12/handbook.pdf</a></p>
<p><strong>To better understand at a high level the outcomes that HIPAA requires, covered entities must</strong>:<br />
Have a documented process to protect PHI and detect/correct security violations<br />
Allow only authorized personnel have access to PHI<br />
Develop a process to respond in the event of a security breach<br />
Periodically evaluate the organization’s ability to protect PHI<br />
From a technology standpoint, strong cases can be made for organizations to implement:<br />
Access controls: to ensure the wrong people do not get access to information<br />
Detailed auditing of mail traffic: to track who is accessing data (and more importantly, prove it to the examiners)<br />
Encryption: to authenticate sender and recipient, provide protection of the message contents and<br />
ensure a message hasn’t been tampered with.<br />
While HIPAA does not specify particular technologies that should be used to implement these rules, the regulation can be seen as an attempt to mandate best practices for information security, and, for the purposes of this paper, messaging security.</p>
<p><strong>Penalties Associated With Non-Compliance to HIPAA </strong><br />
The general penalty for failure to comply with HIPAA regulations is:<br />
Each violation: $100<br />
Maximum penalty for all violations of an identical requirement: may not exceed $25,000<br />
Penalties for Wrongful Disclosure of INDIVIDUALLY Identifiable Health Information include:<br />
Wrongful disclosure offense: $50,000, imprisonment of not more than one year or both<br />
Offense under false pretenses: $100,000, imprisonment of not more than five years, or both<br />
Offense with intent to sell information: $250,000, imprisonment of not more than ten years, or both.</p>
<h4><strong><span style="color: #ff6600;">If you need help with your HIPAA needs, please contact us. We have years of experience in getting people HIPAA compliant.</span></strong></h4>
]]></content:encoded>
			<wfw:commentRss>http://karmaspoon.com/what-is-hipaa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
