<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Peritus Security</title>
	<atom:link href="http://peritussecurity.com/wordpress/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://peritussecurity.com/wordpress</link>
	<description>Building solid foundations in Information Assurance and Compliance.</description>
	<lastBuildDate>Fri, 19 Nov 2010 20:46:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>You think the Feds would know better&#8230;</title>
		<link>http://peritussecurity.com/wordpress/?p=118</link>
		<comments>http://peritussecurity.com/wordpress/?p=118#comments</comments>
		<pubDate>Fri, 19 Nov 2010 20:46:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=118</guid>
		<description><![CDATA[At least they caught the guy.
http://www.nbcnewyork.com/news/local-beat/Feds-Hacker-Exploits-Federal-Reserve-Bank-In-Cleveland-108985059.html
]]></description>
			<content:encoded><![CDATA[<p>At least they caught the guy.</p>
<p>http://www.nbcnewyork.com/news/local-beat/Feds-Hacker-Exploits-Federal-Reserve-Bank-In-Cleveland-108985059.html</p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=118</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>280,000 New Victims!</title>
		<link>http://peritussecurity.com/wordpress/?p=116</link>
		<comments>http://peritussecurity.com/wordpress/?p=116#comments</comments>
		<pubDate>Tue, 26 Oct 2010 12:15:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=116</guid>
		<description><![CDATA[&#8220;Two health insurers said a flash drive containing the personal health information of hundreds of thousands of Pennsylvania Medicaid recipients has gone missing&#8221; &#8211; whoops!  When will they start paying attention to HIPAA Laws?  I keep seeing the same things over and over again.  Does nobody learn from the mistakes of others?
Link:
http://www.scmagazineus.com/penn-medicaid-recipients-information-on-missing-flash-drive/article/181490/?DCMP=EMC-SCUS_Newswire
See you soon,
Kurt Baumgarten, [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Two health insurers said a flash drive containing the personal health information of hundreds of thousands of Pennsylvania Medicaid recipients has gone missing&#8221; &#8211; whoops!  When will they start paying attention to HIPAA Laws?  I keep seeing the same things over and over again.  Does nobody learn from the mistakes of others?</p>
<p>Link:</p>
<p><a href="http://www.scmagazineus.com/penn-medicaid-recipients-information-on-missing-flash-drive/article/181490/?DCMP=EMC-SCUS_Newswire">http://www.scmagazineus.com/penn-medicaid-recipients-information-on-missing-flash-drive/article/181490/?DCMP=EMC-SCUS_Newswire</a></p>
<p>See you soon,</p>
<p>Kurt Baumgarten, VP of Information Security</p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=116</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting article</title>
		<link>http://peritussecurity.com/wordpress/?p=114</link>
		<comments>http://peritussecurity.com/wordpress/?p=114#comments</comments>
		<pubDate>Sun, 19 Sep 2010 17:58:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=114</guid>
		<description><![CDATA[This article is about the doctor that went to jail for HIPAA violations.
http://www.compliancehelper.com/post/95319-you-can-go-to-jail-for
]]></description>
			<content:encoded><![CDATA[<p>This article is about the doctor that went to jail for HIPAA violations.</p>
<p><a href="http://www.compliancehelper.com/post/95319-you-can-go-to-jail-for">http://www.compliancehelper.com/post/95319-you-can-go-to-jail-for</a></p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=114</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cost of Cyber Crime</title>
		<link>http://peritussecurity.com/wordpress/?p=111</link>
		<comments>http://peritussecurity.com/wordpress/?p=111#comments</comments>
		<pubDate>Fri, 20 Aug 2010 14:00:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=111</guid>
		<description><![CDATA[I just ran across a study that has come out &#8211; enjoy:
http://go.techtarget.com/r/12243656/6276856/1
 
Thanks,
Kurt Baumgarten, CISA, CGEIT
VP of Information Security
]]></description>
			<content:encoded><![CDATA[<p>I just ran across a study that has come out &#8211; enjoy:</p>
<p><a href="http://go.techtarget.com/r/12243656/6276856/1">http://go.techtarget.com/r/12243656/6276856/1</a></p>
<p> </p>
<p>Thanks,</p>
<p>Kurt Baumgarten, CISA, CGEIT</p>
<p>VP of Information Security</p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=111</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yet another HIPAA fine</title>
		<link>http://peritussecurity.com/wordpress/?p=109</link>
		<comments>http://peritussecurity.com/wordpress/?p=109#comments</comments>
		<pubDate>Thu, 29 Jul 2010 15:55:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=109</guid>
		<description><![CDATA[I would have thought that Rite Aid would have learned a lesson from CVS &#8211; where CVS paid $2.25 million for doing pretty much the same thing about a year ago.  Article link below:
http://www.scmagazineus.com/rite-aid-to-pay-1-million-fine-for-hipaa-violation/article/175729/?DCMP=EMC-SCUS_Newswire
]]></description>
			<content:encoded><![CDATA[<p>I would have thought that Rite Aid would have learned a lesson from CVS &#8211; where CVS paid $2.25 million for doing pretty much the same thing about a year ago.  Article link below:</p>
<p><a href="http://www.scmagazineus.com/rite-aid-to-pay-1-million-fine-for-hipaa-violation/article/175729/?DCMP=EMC-SCUS_Newswire">http://www.scmagazineus.com/rite-aid-to-pay-1-million-fine-for-hipaa-violation/article/175729/?DCMP=EMC-SCUS_Newswire</a></p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=109</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hmmmmm &#8230;. check this out</title>
		<link>http://peritussecurity.com/wordpress/?p=105</link>
		<comments>http://peritussecurity.com/wordpress/?p=105#comments</comments>
		<pubDate>Wed, 21 Jul 2010 01:54:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=105</guid>
		<description><![CDATA[Subject: [Dataloss] MA: Data Loss Affects Thousands Of Patients
http://www.thebostonchannel.com/mostpopular/24311150/detail.html
Data Loss Affects Thousands Of Patients
South Shore Hospital Incident Under Investigation
POSTED: 2:12 pm EDT July 19, 2010
UPDATED: 3:09 pm EDT July 19, 2010
BOSTON &#8212; Back-up computer files containing personal, health and financial
information of thousands affiliated with South Shore Hospital may have
been lost by a professional data management [...]]]></description>
			<content:encoded><![CDATA[<p><span>Subject: [Dataloss] MA: Data Loss Affects Thousands Of Patients</span></p>
<p><span><a href="http://www.thebostonchannel.com/mostpopular/24311150/detail.html">http://www.thebostonchannel.com/mostpopular/24311150/detail.html</a></span></p>
<p><span>Data Loss Affects Thousands Of Patients</span><br />
<span>South Shore Hospital Incident Under Investigation</span><br />
<span>POSTED: 2:12 pm EDT July 19, 2010</span><br />
<span>UPDATED: 3:09 pm EDT July 19, 2010</span></p>
<p><span>BOSTON &#8212; Back-up computer files containing personal, health and financial</span><br />
<span>information of thousands affiliated with South Shore Hospital may have</span><br />
<span>been lost by a professional data management company.</span></p>
<p><span>The backup computer files could contain personally identifiable</span><br />
<span>information for about 800,000 people, including patients who received</span><br />
<span>medical services at South Shore Hospital as well as employees, physicians,</span><br />
<span>volunteers, donors, vendors and other business partners associated with</span><br />
<span>the hospital between Jan. 1, 1996, and Jan. 6, 2010.</span></p>
<p><span>The information on the backup computer files may include individuals. full</span><br />
<span>names, addresses, phone numbers, dates of birth, Social Security numbers,</span><br />
<span>driver.s license numbers, medical record numbers, patient numbers, health</span><br />
<span>plan information, dates of service, protected health information including</span><br />
<span>diagnoses and treatments relating to certain hospital and home health care</span><br />
<span>visits, and other personal information. Bank account information and</span><br />
<span>credit card numbers for a very small subset of individuals also may have</span><br />
<span>been on the backup computer files.</span></p>
<p><span>WHOOPS!  &#8211; what  did I just say?</span></p>
<p><span>Kurt Baumgarten, VP of Information Security</span></p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=105</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Back to the Future &#8211; HIPAA and HITECH</title>
		<link>http://peritussecurity.com/wordpress/?p=103</link>
		<comments>http://peritussecurity.com/wordpress/?p=103#comments</comments>
		<pubDate>Tue, 20 Jul 2010 23:53:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=103</guid>
		<description><![CDATA[It’s been a while since the last update – we have been very very busy. To all of you that are following this blog … I am sorry for the delay of postings.  Anyway, what is new in the InfoSec space beyond the usual high profile breaches and “what-not”?  Well, if you have not been [...]]]></description>
			<content:encoded><![CDATA[<p>It’s been a while since the last update – we have been very very busy. To all of you that are following this blog … I am sorry for the delay of postings.  Anyway, what is new in the InfoSec space beyond the usual high profile breaches and “what-not”?  Well, if you have not been paying attention to the news, you might have missed a few incidents where the new iteration of HIPAA regulations (via the HITECH Act) have brought down the heavy hand of the Department of Health and Human Services on a few companies that up until February 17<sup>th</sup> 2010 (the date that HITECH went into effect).  Of course there were a few instances where some companies were fined HUGE amounts for non-compliance under HIPAA … but now, there is a whole new level of compliance required for those that are considered as “associated businesses” in the health care industry.  This means that if you have ANY part in the rendering care for a person – and “any” means: you’re and IT vendor, you manage benefits or you do billing, etc. – that you are now required by the HITECH Act to comply with the full effect of HIPAA.  Before HITECH, you needed to only worry about breaches if there was a financial component to the data you accessed or held.  Now, you need to worry about the laws if you have access in any way to any pertinent information that has anything to do with any treatment of any manifest disease or condition.  To make matters more difficult, if you have access to genetic testing data – you will also need to comply with the Genetic Information Non-discrimination Act (GINA).  We at Peritus have been dealing quite a bit with GINA lately.</p>
<p>Anyway, I felt that I should post an update as it has been a while to let you know what we have been up to.  HIPAA, HITECH, 201CMR17, GLBA, SAS-70, and the other usual suspects are still our bread and butter so to speak.  However, there seems to be an new trend in developing what would be considered “new” standards that impact very specific industries.  Is this a good thing?  Getting away from standardization?  I am still up in the air about that waiting to see how things shake out … after all, the creation of new industry compliance standards will inherently be for the benefit of those that develop them.  I guess as long as the underlying “basis” of those new standards comes from a recognized framework, I don’t have much an issue with it.</p>
<p>Also, please note that we have disabled “comments” in this blog due to the incredible amount of potential SPAM comments.  After sifting through the 20 to 30 bogus comments a day about handbags, T-shirts, and other “performance enhancing” drugs, I just decided to disable comments for a while.  If you want to leave some feedback, you can leave it via the contact info on the main part of the website.</p>
<p>One last thing, if you have not seen the recent article on social networking and how to control company leakage, it is located here: <a href="http://searchcio.techtarget.com/news/article/0,289142,sid182_gci1510466_mem1,00.html">http://searchcio.techtarget.com/news/article/0,289142,sid182_gci1510466_mem1,00.html</a></p>
<p>Yours truly is quoted in this article as I think it is an important part of any businesses security plan given the proliferation of social networking sites and the threats that they pose (don’t get me started).</p>
<p>Thanks for reading – see you soon…</p>
<p>Kurt Baumgarten, VP of Information Security, Peritus Security Partners.</p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=103</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kurt Baumgarten Quoted in Search CIO Magazine</title>
		<link>http://peritussecurity.com/wordpress/?p=71</link>
		<comments>http://peritussecurity.com/wordpress/?p=71#comments</comments>
		<pubDate>Mon, 10 May 2010 12:04:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=71</guid>
		<description><![CDATA[Kurt Baumgarten was recently quoted in CIO about the use of social media in the work place and how to control the risks associated with that use.  The article can be found at the link below:
http://searchcio.techtarget.com/news/article/0,289142,sid182_gci1510466,00.html
]]></description>
			<content:encoded><![CDATA[<p>Kurt Baumgarten was recently quoted in CIO about the use of social media in the work place and how to control the risks associated with that use.  The article can be found at the link below:</p>
<p><a href="http://searchcio.techtarget.com/news/article/0,289142,sid182_gci1510466,00.html">http://searchcio.techtarget.com/news/article/0,289142,sid182_gci1510466,00.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=71</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA2 / HITECH Act</title>
		<link>http://peritussecurity.com/wordpress/?p=69</link>
		<comments>http://peritussecurity.com/wordpress/?p=69#comments</comments>
		<pubDate>Sun, 18 Apr 2010 13:53:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=69</guid>
		<description><![CDATA[Peritus is working on a new product for the creation and managment of programs that need to comply with the new HIPAA regulations.  One of the main concerns is again vendor management &#8211; now referrred to as &#8220;associated businesses&#8221; under the HITECH Act.  What you need to think about is what your vendors are doing [...]]]></description>
			<content:encoded><![CDATA[<p>Peritus is working on a new product for the creation and managment of programs that need to comply with the new HIPAA regulations.  One of the main concerns is again vendor management &#8211; now referrred to as &#8220;associated businesses&#8221; under the HITECH Act.  What you need to think about is what your vendors are doing with Private Healthcare Information (PHI) if they have any type of access to it as provided by you through the course of doing business.  Thus, the same requirments that apply to you will now apply to your vendors &#8211; and if they cannot or will not comply and prove the level of their care over the PHI, then you had better think about getting a new vendor.  Keep an eye out for our new product to help you manage these realtionships &#8211; it should be available in a few weeks.</p>
<p>Kurt Baumgarten, VP of Information Security</p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=69</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Humor</title>
		<link>http://peritussecurity.com/wordpress/?p=64</link>
		<comments>http://peritussecurity.com/wordpress/?p=64#comments</comments>
		<pubDate>Sat, 20 Mar 2010 15:39:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peritussecurity.com/wordpress/?p=64</guid>
		<description><![CDATA[Generally I will not post links from youtube on here &#8211; however, I thought that this ad from Symantec was pretty good at pointing out the prevalence of identity theft.  Enjoy.
http://www.youtube.com/watch?v=lMnfziDd9FQ
]]></description>
			<content:encoded><![CDATA[<p>Generally I will not post links from youtube on here &#8211; however, I thought that this ad from Symantec was pretty good at pointing out the prevalence of identity theft.  Enjoy.</p>
<p><a href="http://www.youtube.com/watch?v=lMnfziDd9FQ">http://www.youtube.com/watch?v=lMnfziDd9FQ</a></p>
]]></content:encoded>
			<wfw:commentRss>http://peritussecurity.com/wordpress/?feed=rss2&amp;p=64</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

