<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com &#187; National and State Privacy/Security Law</title>
	<atom:link href="http://paulmudgett.com/category/national-and-state-privacysecurity-law/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Thu, 05 Jan 2012 17:32:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>More Legislation?  Hmmm.</title>
		<link>http://paulmudgett.com/2011/09/13/more-legislation-hmmm/</link>
		<comments>http://paulmudgett.com/2011/09/13/more-legislation-hmmm/#comments</comments>
		<pubDate>Tue, 13 Sep 2011 20:44:05 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=376</guid>
		<description><![CDATA[Senator Richard Blumenthal, D-Conn, introduced new legislation aimed to prevent data breaches.   The proposed legislation includes federal requirements for customer notification in the event of a breach (something most States have been requiring for years) and requiring companies to provide two years of credit monitoring service.  There are fines and program requirements for regularly testing [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/09/13/more-legislation-hmmm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nevada&#8217;s step into electronic health information exchange</title>
		<link>http://paulmudgett.com/2011/06/29/nevadas-step-into-electronic-health-information-exchange/</link>
		<comments>http://paulmudgett.com/2011/06/29/nevadas-step-into-electronic-health-information-exchange/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 16:28:14 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=372</guid>
		<description><![CDATA[Governor Sandoval signed Senate Bill 43 to move forward with the State Health Information Technology Strategic and Operational Plan using federal stimulus funds.  This essentially gets the ball rolling for the development of a statewide system for the electronic exchange of health information.  The intent is to improve health care quality, prevent medical errors and [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/06/29/nevadas-step-into-electronic-health-information-exchange/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Do Not Track&#8221; &#8211; Will it really help?</title>
		<link>http://paulmudgett.com/2011/03/17/do-not-track-will-it-really-help/</link>
		<comments>http://paulmudgett.com/2011/03/17/do-not-track-will-it-really-help/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 16:27:15 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[information security]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=338</guid>
		<description><![CDATA[The FTC and White House are once again throwing their support behind a &#8220;Do Not Track&#8221; tool meant to protect user privacy on the Internet.   I think it&#8217;s easy to jump on board the good ship Privacy but anytime the federal government engages in such rule enforcement and legislation, you have to wonder what the [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/03/17/do-not-track-will-it-really-help/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cybersecurity Bill &#8211; DHS as Punisher</title>
		<link>http://paulmudgett.com/2010/11/23/cybersecurity-bill-dhs-as-punisher/</link>
		<comments>http://paulmudgett.com/2010/11/23/cybersecurity-bill-dhs-as-punisher/#comments</comments>
		<pubDate>Tue, 23 Nov 2010 21:35:35 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[security scotoma]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=267</guid>
		<description><![CDATA[In an effort to be a focal point of &#8220;cybersecurity&#8221;, legislation was introduced that would allow the DHS to levy fines and other civil penalties against any companies the government decides is &#8220;critical&#8221;.  I agree that the need to protect critical infrastructure is important, but this effort by legislators creates a slippery slope and a [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/11/23/cybersecurity-bill-dhs-as-punisher/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons Not Learned &#8211; Public-Private non-communication in CyberSecurity</title>
		<link>http://paulmudgett.com/2010/08/20/lessons-not-learned-public-private-non-communication-in-cybersecurity/</link>
		<comments>http://paulmudgett.com/2010/08/20/lessons-not-learned-public-private-non-communication-in-cybersecurity/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 23:46:13 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=242</guid>
		<description><![CDATA[One of the deficiencies that came to light in the aftermath of the 9/11 terrorist attacks was the communication failure between competing intelligence agencies.  A report released this past Monday from the Government Accountability Office shows that the same failure to communicate is happening in the cybersecurity arena.  The breakdown in this arena is between [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/08/20/lessons-not-learned-public-private-non-communication-in-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NJ Supreme Court impacts privacy expectation</title>
		<link>http://paulmudgett.com/2010/04/05/nj-supreme-court-impacts-privacy-expectation/</link>
		<comments>http://paulmudgett.com/2010/04/05/nj-supreme-court-impacts-privacy-expectation/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 17:58:22 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[disgruntled employee]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=191</guid>
		<description><![CDATA[The New Jersey Supreme Court recently ruled that a company shouldn&#8217;t have read an ex-staffer&#8217;s private e-mails even though they were sent from her employer&#8217;s computer.    NorthJersey.com article. Interesting ruling which will certainly change some thoughts as to personal use of work computers.  While I&#8217;m a proponent of privacy rights, I&#8217;m torn on this particular [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/04/05/nj-supreme-court-impacts-privacy-expectation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Shockwave &#8211; A Bust</title>
		<link>http://paulmudgett.com/2010/02/23/cyber-shockwave-a-bust/</link>
		<comments>http://paulmudgett.com/2010/02/23/cyber-shockwave-a-bust/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 01:11:03 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Awareness and Education]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[National InfoSec]]></category>
		<category><![CDATA[cyber czar]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=139</guid>
		<description><![CDATA[CNN recently broadcast a cyber-attack simulation meant to demonstrate the potential cascading effects of a widespread attack on our nation&#8217;s infrastructure.  The exercise included former federal officials who played the role of key positions in the executive branch to show how the government would respond to the escalating incident.  They even had a flashy headline: [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/02/23/cyber-shockwave-a-bust/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Lawsuit, breaches and bashing&#8230; oh my!</title>
		<link>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/</link>
		<comments>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 17:39:38 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=129</guid>
		<description><![CDATA[Though it seems obvious that corporations have an obligation to protect the sensitive information they use for business it still amazes me that corporate behavior in this regard is still quite dismissive.  Lawsuits and public embarrassment seem to be the only catalyst for action for many organizations.  That is kind of sad.  Not only is [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>House passes Data Breach legislation&#8230; jury still out</title>
		<link>http://paulmudgett.com/2009/12/14/house-passes-data-breach-legislation-jury-still-out/</link>
		<comments>http://paulmudgett.com/2009/12/14/house-passes-data-breach-legislation-jury-still-out/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 18:35:56 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[National Cyber Security]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=109</guid>
		<description><![CDATA[The U.S. House of Representatives has passed HR 2221, the Data Accountability and Trust Act.  This sets nationwide breach notification requirements that trump the patchwork of State laws that have been in effect with California leading the way in 2002.   The passage was written about in a Federal Computer Week article &#8220;House passes bill to [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/12/14/house-passes-data-breach-legislation-jury-still-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using a Framework to Navigate Regulatory Compliance</title>
		<link>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/</link>
		<comments>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 22:48:49 +0000</pubDate>
		<dc:creator>Paul</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=59</guid>
		<description><![CDATA[The regulatory environment overseeing the protection of sensitive information is incredibly crowded.  Sarbanes-Oxley (SOX), Graham-Leach-Bliley (GLB), the Health Insurance Portability and Accountability Act (HIPAA), HITECH, Red Flags, Payment Card Industry Data Security Standard (PCI-DSS), among a host of state laws and audit guidelines seems to provide the Fort Know of IT risk management if organizations [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/10/21/using-a-framework-to-navigate-regulatory-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

