Alleged health data disclosure via Facebook raises legal and policy issues

Reports of potential breaches of patient privacy at Tri-City Medical Center in Oceanside, California have garnered the HIPAA-related attention you would expect, but are also raising questions about the availability and use of social networking sites…

NIST answers to questions on continuous monitoring suggest no drastic change in approach

In the wake of the release of its updated Special Publication 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, which among other things calls for federal agencies to continuously monitor the security…

Issues raised about no-fly list checks provide a nice lesson in disparate impact of false positives and false negatives

The last-minute apprehension of the would-be Times Square bomber, who had already boarded an international flight despite being placed on the government’s no-fly list, provides one of the rare instances where real-time integration or data propagation…

Federal agencies have a window of opportunity to move on continuous monitoring

The call now seems to coming from all sides that federal government agencies need to fully embrace risk-based approaches to information security and move towards continuous monitoring and enterprise situational awareness. OMB, in coordination with the…

NSF cybersecurity research focuses on 3 “game-changing” themes

In a notice published this week in the Federal Register, the National Science Foundation’s National Coordination Office for Networking and Information Technology Research and Development (NCO/NITRD) announced three new federal cybersecurity research themes that represent a…

Change in European Commission, UK government likely to bring action on privacy

While there appears to no shortage of consideration in the current administration or Congress for addressing privacy practices in some contexts in the United States, efforts to strengthen personal privacy protections seem to be gaining momentum…

State laws complicate navigation of health data disclosure rules

As noted this week in a blog posting from Hunton & Williams, a ruling issued in February from a federal district court in Ohio highlights some of the legal complexities in navigating both state and federal…