<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>paulmudgett.com&#187; PHI</title>
	<atom:link href="http://paulmudgett.com/tag/phi/feed/" rel="self" type="application/rss+xml" />
	<link>http://paulmudgett.com</link>
	<description>Information Security &#38; Business Leadership</description>
	<lastBuildDate>Fri, 11 May 2012 16:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Checkbox Security Fails Again</title>
		<link>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/</link>
		<comments>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 16:41:31 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[federal legislation]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[ISO 27001/27002]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=453</guid>
		<description><![CDATA[Regulatory compliance is often a confusing mess.  Rattling off the alphabet of compliance can often result in dizziness, headaches, and for some, a bad case of nausea.   PCI-DSS, HIPAA, HITECH, GLB, SOX, and heck, might as well throw in some state data breach notification laws as well.  Congress doesn&#8217;t want to stop there as [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2012/04/04/checkbox-security-fails-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nevada&#8217;s step into electronic health information exchange</title>
		<link>http://paulmudgett.com/2011/06/29/nevadas-step-into-electronic-health-information-exchange/</link>
		<comments>http://paulmudgett.com/2011/06/29/nevadas-step-into-electronic-health-information-exchange/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 16:28:14 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=372</guid>
		<description><![CDATA[Governor Sandoval signed Senate Bill 43 to move forward with the State Health Information Technology Strategic and Operational Plan using federal stimulus funds.  This essentially gets the ball rolling for the development of a statewide system for the electronic exchange of health information.  The intent is to improve health care quality, prevent medical errors and [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2011/06/29/nevadas-step-into-electronic-health-information-exchange/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lawsuit, breaches and bashing&#8230; oh my!</title>
		<link>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/</link>
		<comments>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 17:39:38 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[National and State Privacy/Security Law]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[security awareness]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=129</guid>
		<description><![CDATA[Though it seems obvious that corporations have an obligation to protect the sensitive information they use for business it still amazes me that corporate behavior in this regard is still quite dismissive.  Lawsuits and public embarrassment seem to be the only catalyst for action for many organizations.  That is kind of sad.  Not only is [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2010/01/19/lawsuit-breaches-and-bashing-oh-my/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Failures in Leadership, Ethics, and Security</title>
		<link>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/</link>
		<comments>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 18:25:19 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Ethics]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=103</guid>
		<description><![CDATA[A breach of patient personal information at University Medical Center has all the makings of a made for TV movie or at least provides an opportunity to examine issues in security, leadership, ethics, and even the knee-jerk reaction of ignorant politicians trying to use the opportunity to score some free publicity.  The story &#8220;FBI looking [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/25/failures-in-leadership-ethics-and-security/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Learning From Someone Else&#8217;s Breach</title>
		<link>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/</link>
		<comments>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 19:37:07 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[security mistakes]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/?p=100</guid>
		<description><![CDATA[A subsidiary of manged health care provider Health Net Inc, just reported the loss of personal information for 1.5 million customers that occurred six months ago according to a ComputerWorld article.  Without knowing all the details of the situation, I can only speculate as to some of the security controls and thoughts of the Health [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/11/20/learning-from-someone-elses-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ex-Lover Busted, But Not Totally to Blame</title>
		<link>http://paulmudgett.com/2009/09/21/ex-lover-busted-but-not-totally-to-blame/</link>
		<comments>http://paulmudgett.com/2009/09/21/ex-lover-busted-but-not-totally-to-blame/#comments</comments>
		<pubDate>Mon, 21 Sep 2009 16:48:35 +0000</pubDate>
		<dc:creator>Paul Mudgett</dc:creator>
				<category><![CDATA[Business and Security]]></category>
		<category><![CDATA[Should Have Known Better]]></category>
		<category><![CDATA[Workstation Security]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://paulmudgett.com/blog/?p=37</guid>
		<description><![CDATA[A 38-year-old Avon Lake, Ohio man is set to plead guilty to federal charges after spyware he allegedly meant to install on the computer of a woman he&#8217;d had a relationship with ended up infecting computers at Akron Children&#8217;s Hospital.   (Misdirected spyware infects Ohio hospital.  McMillan, Robert. 17 September 2009. ComputerWorld.) Graham certainly gets what [...]]]></description>
		<wfw:commentRss>http://paulmudgett.com/2009/09/21/ex-lover-busted-but-not-totally-to-blame/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

