<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>M. Scott Koller</title>
	<atom:link href="http://www.koller-law.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.koller-law.com</link>
	<description>Attorney at Law</description>
	<lastBuildDate>Mon, 20 May 2013 19:45:03 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<item>
		<title>NIST releases 4th version of security control catalog SP 800-53</title>
		<link>http://www.koller-law.com/2013/05/20/nist-releases-4th-version-of-security-control-catalog-sp-800-53/</link>
		<comments>http://www.koller-law.com/2013/05/20/nist-releases-4th-version-of-security-control-catalog-sp-800-53/#comments</comments>
		<pubDate>Mon, 20 May 2013 19:45:03 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=475</guid>
		<description><![CDATA[The National Institute of Standards and Technology released April 30 a revised version of its security control catalog for federal systems, SP 800-53. The revision (.pdf), the fourth version of the security controls catalog, also includes for the first time an appendix of privacy controls. Changes to the security controls include a new emphasis on secure software [...]]]></description>
			<content:encoded><![CDATA[<p>The National Institute of Standards and Technology released April 30 a revised version of its security control catalog for federal systems, SP 800-53.<a href="http://www.reasonableexpectation.com/wp-content/uploads/2013/05/NIST-Logo_5.jpg"><img class="alignright  wp-image-307" alt="NIST-Logo_5" src="http://www.reasonableexpectation.com/wp-content/uploads/2013/05/NIST-Logo_5.jpg" width="229" height="102" /></a></p>
<p>The <a href="http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf">revision</a> (.pdf), the fourth version of the security controls catalog, also includes for the first time an appendix of privacy controls.</p>
<p>Changes to the security controls include a new emphasis on secure software development in an effort to shift security away from the focus of the past few years, during which it&#8217;s targeted matters such as configuration management or continuous monitoring.</p>
<p>&nbsp;</p>
<p>Download: <a href="http://csrc.nist.gov/publications/drafts/800-53-rev4/sp800-53-rev4-ipd.pdf">SP 800-53 rev. 4</a><br />
Source: <a href="http://www.fiercegovernmentit.com/story/nist-releases-4th-version-security-control-catalog-sp-800-53/2013-05-01#ixzz2Tfw6pdQC">NIST releases 4th version of security control catalog SP 800-53 &#8211; FierceGovernmentIT</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2013/05/20/nist-releases-4th-version-of-security-control-catalog-sp-800-53/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>California AG’s Mobile App Case Against Delta Dismissed</title>
		<link>http://www.koller-law.com/2013/05/14/california-ags-mobile-app-case-against-delta-dismissed/</link>
		<comments>http://www.koller-law.com/2013/05/14/california-ags-mobile-app-case-against-delta-dismissed/#comments</comments>
		<pubDate>Tue, 14 May 2013 20:50:25 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=468</guid>
		<description><![CDATA[A state court has dismissed the California Attorney General’s claims that Delta Air Lines Inc. (“Delta”) violated the California Online Privacy Protection Act by failing to have an appropriately posted privacy policy for its mobile application, Bloomberg reports. The California AG sued Delta in December as part of an enforcement campaign that began with the issuance of warning letters to approximately 100 operators [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.reasonableexpectation.com/wp-content/uploads/2013/05/dl.gif"><img class="alignright  wp-image-300" alt="dl" src="http://www.reasonableexpectation.com/wp-content/uploads/2013/05/dl-300x199.gif" width="210" height="139" /></a>A state court has dismissed the California Attorney General’s claims that Delta Air Lines Inc. (“Delta”) violated the <a href="http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc&amp;group=22001-23000&amp;file=22575-22579" target="_blank">California Online Privacy Protection Act</a> by failing to have an appropriately posted privacy policy for its mobile application, <a href="http://www.bloomberg.com/news/2013-05-09/delta-wins-dismissal-of-california-app-privacy-lawsuit.html?cmpid=yhoo" target="_blank"><em>Bloomberg</em> reports</a>. The California AG <a href="http://www.huntonprivacyblog.com/2012/12/articles/california-ag-sues-delta-for-failure-to-post-a-privacy-policy-on-its-mobile-app/" target="_blank">sued Delta in December</a> as part of an enforcement campaign that began with the issuance of <a href="http://www.huntonprivacyblog.com/2012/11/articles/time-running-out-for-mobile-app-operators-targeted-by-california-attorney-general/" target="_blank">warning letters</a> to approximately 100 operators of mobile apps, including Delta. According to the <em>Bloomberg</em> report, a basis for the dismissal was the federal Airline Deregulation Act, under which a state “may not enact or enforce a law, regulation, or other provision having the force and effect of law related to a price, route, or service of an air carrier that may provide air transportation under this subpart.” <em>49 U.S.C. § 41713</em>.</p>
<p>Source: <a href="http://www.huntonprivacyblog.com/2013/05/articles/california-ags-mobile-app-case-against-delta-dismissed/">Privacy and Information Security Law Blog</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2013/05/14/california-ags-mobile-app-case-against-delta-dismissed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Omnibus Final Rule Released</title>
		<link>http://www.koller-law.com/2013/01/17/hipaa-omnibus-final-rule-released/</link>
		<comments>http://www.koller-law.com/2013/01/17/hipaa-omnibus-final-rule-released/#comments</comments>
		<pubDate>Thu, 17 Jan 2013 22:10:23 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=466</guid>
		<description><![CDATA[This afternoon, HHS released the attached omnibus final rule modifying the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules as required the Health Information Technology Economic and Clinical Health (HITECH) Act and the Genetic Information Nondiscrimination Act (GINA). Notably, the final rule makes business associates of covered entities directly liable for certain HIPAA Privacy and [...]]]></description>
			<content:encoded><![CDATA[<p>This afternoon, HHS released the attached omnibus final rule modifying the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules as required the Health Information Technology Economic and Clinical Health (HITECH) Act and the Genetic Information Nondiscrimination Act (GINA).</p>
<p>Notably, the final rule makes business associates of covered entities directly liable for certain HIPAA Privacy and Security rule requirements; expands individuals’ right to receive electronic copies of their health information; incorporates an increased tiered and civil money penalty structure as provided by the HITECH Act; changes to the “harm” definition included in the HIPAA Breach Notification interim final rule; and modifies the HIPAA Privacy Rule as required by GINA.</p>
<p>Link: <a href="http://www.reasonableexpectation.com/wp-content/uploads/2013/01/HIPAA-Final-Rule.pdf">HIPAA Final Rule</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2013/01/17/hipaa-omnibus-final-rule-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OCR Issues Guidance on the Use of De-Identified Health Information</title>
		<link>http://www.koller-law.com/2012/11/28/ocr-issues-guidance-on-the-use-of-de-identified-health-information/</link>
		<comments>http://www.koller-law.com/2012/11/28/ocr-issues-guidance-on-the-use-of-de-identified-health-information/#comments</comments>
		<pubDate>Wed, 28 Nov 2012 19:34:20 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=461</guid>
		<description><![CDATA[Covered Entities and HIPAA practitioners should be aware that the Office of Civil Rights (OCR) has issued guidance about methods and approaches to achieve de-identification in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. The full text is available here: http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/De-identification/guidance.html]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.reasonableexpectation.com/wp-content/uploads/2012/05/MP900422620.jpg"><img class="alignright size-medium wp-image-198" title="Shelves of Medical Records" src="http://www.reasonableexpectation.com/wp-content/uploads/2012/05/MP900422620-300x202.jpg" alt="" width="300" height="202" /></a><br />Covered Entities and HIPAA practitioners should be aware that the Office of Civil Rights (OCR) has issued guidance about methods and approaches to achieve de-identification in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. The full text is available here:</p>
<p><a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/De-identification/guidance.html">http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/De-identification/guidance.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/11/28/ocr-issues-guidance-on-the-use-of-de-identified-health-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>California Issues App Developer Noncompliance Notice</title>
		<link>http://www.koller-law.com/2012/11/08/california-issues-app-developer-noncompliance-notice/</link>
		<comments>http://www.koller-law.com/2012/11/08/california-issues-app-developer-noncompliance-notice/#comments</comments>
		<pubDate>Thu, 08 Nov 2012 17:36:58 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=453</guid>
		<description><![CDATA[California Attorney General Kamala Harris has reportedly sent out notices warning as many as 100 mobile app developers that they must conspicuously post privacy policies within the next 30 days to be in compliance with the California Online Privacy Protection Act, Bloomberg reports. The new state protocol requires mobile applications that collect personal data within the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright  wp-image-239" title="clip_art_cell_phone" src="http://www.reasonableexpectation.com/wp-content/uploads/2012/11/clip_art_cell_phone-300x300.png" alt="" width="168" height="168" /> California Attorney General Kamala Harris has reportedly sent out notices warning as many as 100 mobile app developers that they must conspicuously post privacy policies within the next 30 days to be in compliance with the California Online Privacy Protection Act, Bloomberg reports. The new state protocol requires mobile applications that collect personal data within the state to post a privacy policy stating what data is collected and how it will be used. Harris said, “We have worked hard to ensure that app developers are aware of their legal obligations to respect the privacy of Californians, but it is critical that we take all necessary steps to enforce California’s privacy laws.”</p>
<p>Source: IAPP <a href="http://www.businessweek.com/news/2012-10-30/delta-united-warned-by-california-over-mobile-privacy" target="_blank"><strong>Full Story</strong></a></p>
<div>
<p>&nbsp;</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/11/08/california-issues-app-developer-noncompliance-notice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fan Sites for Pop Stars Settle Children’s Privacy Charges</title>
		<link>http://www.koller-law.com/2012/10/03/fan-sites-for-pop-stars-settle-childrens-privacy-charges/</link>
		<comments>http://www.koller-law.com/2012/10/03/fan-sites-for-pop-stars-settle-childrens-privacy-charges/#comments</comments>
		<pubDate>Wed, 03 Oct 2012 16:16:06 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=446</guid>
		<description><![CDATA[The operator of fan Web sites for pop stars Justin Bieber, Selena Gomez, Rihanna and Demi Lovato agreed to pay a $1 million civil penalty to settle federal charges that the sites had illegally collected personal information about thousands of children, the Federal Trade Commission said Wednesday. Artist Arena, a company that operates fan web [...]]]></description>
			<content:encoded><![CDATA[<p>The operator of fan Web sites for pop stars Justin Bieber, Selena Gomez, Rihanna and Demi Lovato agreed to pay a $1 million civil penalty to settle federal charges that the</p>
<div id="attachment_233" class="wp-caption alignright" style="width: 307px"><a href="http://www.reasonableexpectation.com/wp-content/uploads/2012/10/04kids-popup.jpg"><img class="size-medium wp-image-233" title="04kids-popup" src="http://www.reasonableexpectation.com/wp-content/uploads/2012/10/04kids-popup-297x300.jpg" alt="" width="297" height="300" /></a><p class="wp-caption-text">Artist Arena, a company that operates fan web sites for pop stars like Justin Bieber and Selena Gomez, agreed to settle federal charges that the sites had violated a children&#8217;s privacy protection law. Source: New York Times</p></div>
<p>sites had illegally collected personal information about thousands of children, the Federal Trade Commission said Wednesday.</p>
<p>Artist Arena, a company that operates fan web sites for pop stars like Justin Bieber and Selena Gomez, agreed to settle federal charges that the sites had violated a children&#8217;s privacy protection law.</p>
<p>In a complaint, the Federal Trade Commission alleged that Artist Arena, the operator of the sites, had violated a children’s online privacy rule by collecting personal details — like the names, e-mail addresses, street addresses and cellphone numbers — of about 101,000 children aged 12 or younger without their parents’ permission.</p>
<p>The law, called the Children’s Online Privacy Protection Act, or COPPA for short, requires operators of Web sites to notify parents and obtain verifiable parental consent before collecting, using or disclosing personal information about children younger than 13.</p>
<p>Source: <a title="New York Times" href="http://www.nytimes.com/2012/10/04/technology/fan-sites-for-pop-stars-settle-childrens-privacy-charges.html?partner=rss&amp;emc=rss">New York Times</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/10/03/fan-sites-for-pop-stars-settle-childrens-privacy-charges/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why passwords have never been weaker—and crackers have never been stronger</title>
		<link>http://www.koller-law.com/2012/08/21/why-passwords-have-never-been-weaker-and-crackers-have-never-been-stronger/</link>
		<comments>http://www.koller-law.com/2012/08/21/why-passwords-have-never-been-weaker-and-crackers-have-never-been-stronger/#comments</comments>
		<pubDate>Tue, 21 Aug 2012 17:24:15 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=441</guid>
		<description><![CDATA[In late 2010, Sean Brooks received three e-mails over a span of 30 hours warning that his accounts on LinkedIn, Battle.net, and other popular websites were at risk. He was tempted to dismiss them as hoaxes—until he noticed they included specifics that weren&#8217;t typical of mass-produced phishing scams. The e-mails said that his login credentials [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.reasonableexpectation.com/wp-content/uploads/2012/08/password-kingdom.jpg"><img class="alignright size-medium wp-image-226" title="Aurich Lawson / Thinkstock" src="http://www.reasonableexpectation.com/wp-content/uploads/2012/08/password-kingdom-300x168.jpg" alt="Aurich Lawson / Thinkstock" width="300" height="168" /></a>In late 2010, Sean Brooks received three e-mails over a span of 30 hours warning that his accounts on LinkedIn, Battle.net, and other popular websites were at risk. He was tempted to dismiss them as hoaxes—until he noticed they included specifics that weren&#8217;t typical of mass-produced phishing scams. The e-mails said that his login credentials for various Gawker websites had been exposed by hackers who rooted the sites&#8217; servers, then bragged about it online; if Brooks used the same e-mail and password for other accounts, they would be compromised too.</p>
<p>The warnings Brooks and millions of other people received that December weren&#8217;t fabrications. Within hours of anonymous hackers penetrating Gawker servers and <a href="http://www.theregister.co.uk/2010/12/13/gawker_hacked/">exposing cryptographically protected passwords for 1.3 million of its users</a>, botnets were cracking the passwords and using them to commandeer Twitter accounts and send spam. Over the next few days, the sites advising or requiring their users to change passwords expanded to include Twitter, Amazon, and Yahoo.</p>
<p>&#8220;The danger of weak password habits is becoming increasingly well-recognized,&#8221; said Brooks, who at the time <a href="https://www.cdt.org/blogs/sean-brooks/gawker-breach-victims-aided-unexpected-allies">blogged about the warnings</a> as the Program Associate for the Center for Democracy and Technology. The warnings, he told me, &#8220;show [that] these companies understand how a security breach outside their systems can create a vulnerability within their networks.&#8221;</p>
<p>The ancient art of password cracking has advanced further in the past five years than it did in the previous several decades combined. At the same time, the dangerous practice of password reuse has surged. The result: security provided by the average password in 2012 has never been weaker.</p>
<p>Read the full article <a href="http://arstechnica.com/security/2012/08/passwords-under-assault/">here</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/08/21/why-passwords-have-never-been-weaker-and-crackers-have-never-been-stronger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Beth Israel suffers large data breach</title>
		<link>http://www.koller-law.com/2012/07/31/beth-israel-suffers-large-data-breach/</link>
		<comments>http://www.koller-law.com/2012/07/31/beth-israel-suffers-large-data-breach/#comments</comments>
		<pubDate>Wed, 01 Aug 2012 04:19:06 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=438</guid>
		<description><![CDATA[Beth Israel Deaconess Medical Center (BIDMC) in Boston is in the process of notifying approximately 3,900 patients of a potential breach of protected health information (PHI) as a result of a physician&#8217;s stolen personal laptop computer. The computer was stolen from the office of a BIDMC physician on May 22. The computer, which contained a [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://www.cmio.net/images/assets/images/laptoplock_1343074019.jpg" alt="" width="240" height="180" />Beth Israel Deaconess Medical Center (BIDMC) in Boston is in the process of notifying approximately 3,900 patients of a potential breach of protected health information (PHI) as a result of a physician&#8217;s stolen personal laptop computer.</p>
<p>The computer was stolen from the office of a BIDMC physician on May 22. The computer, which contained a tracking device, has not been recovered nor has the tracking device been activated.</p>
<p>In addition to notifying law enforcement, which arrested a suspect in the theft, BIDMC engaged a national forensic firm to investigate whether data were compromised.</p>
<p>Source: <a href="http://www.cmio.net/index.php?option=com_articles&amp;view=article&amp;id=34638:beth-israel-suffers-large-data-breach">CMIO</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/07/31/beth-israel-suffers-large-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>California Starts Up a Privacy Enforcement Unit</title>
		<link>http://www.koller-law.com/2012/07/19/california-starts-up-a-privacy-enforcement-un/</link>
		<comments>http://www.koller-law.com/2012/07/19/california-starts-up-a-privacy-enforcement-un/#comments</comments>
		<pubDate>Fri, 20 Jul 2012 01:46:05 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=435</guid>
		<description><![CDATA[Watch out, Silicon Valley, there’s a new startup in town and its gunning for you. California Attorney General Kamala Harris announced Thursday she’s created a unit intended to actually enforce federal and state privacy laws. “The Privacy Unit will police the privacy practices of individuals and organizations to hold accountable those who misuse technology to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.reasonableexpectation.com/wp-content/uploads/2012/07/seal.jpg"><img class="alignright size-medium wp-image-217" title="seal" src="http://www.reasonableexpectation.com/wp-content/uploads/2012/07/seal-273x300.jpg" alt="" width="273" height="300" /></a>Watch out, Silicon Valley, there’s a new startup in town and its gunning for you. California Attorney General Kamala Harris announced Thursday she’s created a unit intended to actually enforce federal and state privacy laws.</p>
<p>“The Privacy Unit will police the privacy practices of individuals and organizations to hold accountable those who misuse technology to invade the privacy of others,” California’s top attorney <a href="http://oag.ca.gov/news/press-releases/attorney-general-kamala-d-harris-announces-privacy-enforcement-and-protection">said</a> in a statement.</p>
<p>The announcement of the unit, comprised of six attorneys, comes just months after Harris inked a <a href="http://oag.ca.gov/news/press-releases/attorney-general-kamala-d-harris-secures-global-agreement-strengthen-privacy">February agreement</a> with Amazon, Apple, Google, Hewlett-Packard, Microsoft and Research in Motion to demand that mobile apps on their platforms contain privacy policies. Facebook <a href="http://oag.ca.gov/news/press-releases/attorney-general-kamala-d-harris-announces-expansion-california%E2%80%99s-consumer">signed on</a> last month.</p>
<p>Source: <a href="http://www.wired.com/threatlevel/2012/07/california-privacy-unit/">Wired Threat Level</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/07/19/california-starts-up-a-privacy-enforcement-un/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OCR Director Leon Rodriguez Says Tolerance for HIPAA Non-Compliance Is Low</title>
		<link>http://www.koller-law.com/2012/07/05/ocr-director-leon-rodriguez-says-tolerance-for-hipaa-non-compliance-is-low/</link>
		<comments>http://www.koller-law.com/2012/07/05/ocr-director-leon-rodriguez-says-tolerance-for-hipaa-non-compliance-is-low/#comments</comments>
		<pubDate>Thu, 05 Jul 2012 23:53:04 +0000</pubDate>
		<dc:creator>Scott Koller</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.koller-law.com/?p=427</guid>
		<description><![CDATA[On June 7, 2012, at the annual Safeguarding Health Information: Building Assurance through HIPAA Security Conference hosted in Washington, D.C. by the Department of Health and Human Services Office for Civil Rights (“OCR”) and the National Institute of Standards and Technology (“NIST”), OCR Director Leon Rodriguez said that, given HIPAA’s 15-year history and the substantial technical assistance OCR [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" src="http://www.hhs.gov/ocr/office/OCR%20images/leonrodriguez.jpg" alt="" width="168" height="235" />On June 7, 2012, at the annual <a href="http://www.nist.gov/itl/csd/hipaasec.cfm" target="_blank">Safeguarding Health Information: Building Assurance through HIPAA Security Conference</a> hosted in Washington, D.C. by the Department of Health and Human Services Office for Civil Rights (“OCR”) and the National Institute of Standards and Technology (“NIST”), OCR Director Leon Rodriguez said that, given HIPAA’s 15-year history and the substantial technical assistance OCR and NIST have provided covered entities, tolerance for HIPAA non-compliance is “much, much lower” than it has been in the past.</p>
<p>In his remarks, Director Rodriguez indicated that the <a href="http://www.huntonprivacyblog.com/2012/04/articles/hhs-finalizes-omnibus-hipaa-rule-for-omb-review-settles-with-phoenix-cardiac-surgery-following-ocr-investigation/" target="_blank">final omnibus rule</a> modifying the HIPAA Privacy, Security and Enforcement Rules is “very close.” Director Rodriguez reiterated that the modifications will include extending HIPAA liability to business associates, but emphasized that business associates should not wait for the final rule to be enacted to focus on compliance. This is particularly true, according to Director Rodriguez, in light of the ability of state Attorneys General to enforce the Health Information Technology for Economic and Clinical Health Act (the “HITECH” Act), as evidenced by Minnesota Attorney General Lori Swanson’s <a href="http://www.huntonprivacyblog.com/2012/01/articles/minnesota-ag-sues-debt-collection-agency-for-health-privacy-violations/" target="_blank">recent lawsuit</a>against Accretive Health, a business associate that suffered a security breach compromising patient data. Director Rodriguez stated that he would not be surprised if other state Attorneys General began enforcing the HITECH Act in the business associate context.</p>
<p>&nbsp;</p>
<p><a href="http://www.huntonprivacyblog.com/2012/06/articles/ocr-director-leon-rodriguez-says-tolerance-for-hipaa-non-compliance-is-low/">Full Story</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.koller-law.com/2012/07/05/ocr-director-leon-rodriguez-says-tolerance-for-hipaa-non-compliance-is-low/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
