Cyber insurance transfers risk but doesn’t replace due care

The ongoing series of high-profile data breaches reported by companies across multiple industry sectors – including major retailers (Target and Home Depot), health insurers (Anthem and Premera), online service vendors (Uber), hotels (Mandarin Oriental and Hilton HHonors),…

VA decision to allow iPad use without FIPS certification provides good example of risk-based decsion making

The decision by Department of Veterans Affairs CIO Roger Baker to allow users to connect mobile devices such as the Apple iPad and iPhone to the agency’s computing network provides a good example of the trade-off…

Consider risks, business impact when making tradeoffs between security and productivity

Reported findings from a recently released survey of federal government executives on Cybersecurity in the Federal Government suggest that the increased emphasis on information security and corresponding protective measures put in place by government agencies are…

Rewarding processing speed at the expense of accuracy is a failure of risk managment

In the wake of the decision by many leading financial institutions to suspend mortgage foreclosure proceedings due to the discovery of pervasive deficiencies in the way those processes were being carried out, the practices of the…

Despite emphasis on risk analysis, health IT security won’t change much under meaningful use

With all the talk about the need for effective security measures to protect personal health data stored in electronic health records and shared among organizations participating in health information exchanges, the decision of what actual security…

HHS publishes new guidance on conducting risk analysis

Under the administrative safeguard provisions of the HIPAA Security Rule, covered entities are required to perform a risk analysis, specifically to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality,…

Health care entities need clear guidance on analyzing risk for meaningful use

There is but a single measure related to security and privacy in the “meaningful use” rules that will be used to determine the eligibility of health care providers to qualify for incentive payments for the adoption…