<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; health insurance portability and accountability act</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/health-insurance-portability-and-accountability-act/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>HIPAA Compliance for Data Centers &#124; The How and Why</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/hipaa-compliance-for-data-centers-the-how-and-why/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/hipaa-compliance-for-data-centers-the-how-and-why/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 13:49:14 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[co-location]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[health insurance portability and accountability act]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[managed services]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SAS 70]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/hipaa-compliance-for-data-centers-the-how-and-why/</guid>
		<description><![CDATA[HIPAA compliance for data centers is fast becoming a hot topic in regulatory compliance. It first started with Statement on Auditing Standards No. 70 (SAS 70), it is now moving onto the Payment Card Industry Data Security Standards (PCI DSS) provisions, and how the Health Information Portability and Accountability Act (HIPAA) mandates may very well [...]]]></description>
				<content:encoded><![CDATA[<p><strong><a href="http://www.sas70.us.com/industries/hipaa-and-sas70.php">HIPAA compliance</a></strong> for data centers is fast becoming a hot topic in regulatory compliance. It first started with Statement on Auditing Standards No. 70 (SAS 70), it is now moving onto the Payment Card Industry Data Security Standards (PCI DSS) provisions, and how the Health Information Portability and Accountability Act (HIPAA) mandates may very well be next on the horizon.</p>
<p>In short, it is a string of compliance requirements that has and will continue to be had for data centers, co-location, and managed service entities. And why?  Because these types of businesses are at the forefront of virtualization, cloud computing, hybrid clouds, software as a service (SaaS) platforms</p>
<p>So, if a data center undertakes a HIPAA assessment or audit, are they HIPAA compliant, do they get a HIPAA certificate, etc? The best way to answer that is an accounting firm would undertake an Agreed Upon Procedure (AUP) audit an the audit itself would test the requirements as stated in the HIPAA  provisions. You would then end up with a data center that is compliant with these very provisions.</p>
<p>In subsequent blogs, i&#8217;ll discuss the scope of a HIPAA assessment/audit for a data center.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/hipaa-compliance-for-data-centers-the-how-and-why/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Will HIPAA compliance ever have any Teeth like SAS 70 and PCI DSS?</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/will-hipaa-compliance-ever-have-any-teeth-like-sas-70-and-pci/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/will-hipaa-compliance-ever-have-any-teeth-like-sas-70-and-pci/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 20:47:26 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[162]]></category>
		<category><![CDATA[45 CFR Parts 160]]></category>
		<category><![CDATA[and 164]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[health insurance portability and accountability act]]></category>
		<category><![CDATA[Health Insurance Reform: Security Standards]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[payment card industry data security standards]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[The Department of Health and Human Services]]></category>
		<category><![CDATA[type II]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/will-hipaa-compliance-ever-have-any-teeth-like-sas-70-and-pci/</guid>
		<description><![CDATA[HIPAA, The Health Insurance Portability and Accountability Act, has been with us for years now. Upon reading through the vast and cumbersome documentation, one quickly realizes that HIPAA has many moving parts, enough to make you truly gaze at amazement as to what the actual explicit intent is for compliance. In regards to the security [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.sas70.us.com/industries/hipaa-and-sas70.php">HIPAA</a>, The Health Insurance Portability and Accountability Act, has been with us for years now.  Upon reading through the vast and cumbersome documentation, one quickly realizes that HIPAA has many moving parts, enough to make you truly gaze at amazement as to what the actual explicit intent is for compliance.  In regards to the security provisions of HIPAA, The Department of Health and Human Services, 45 CFR Parts 160, 162, and 164, Health Insurance Reform: Security Standards; Final Rule, there are a number of broad based requirements for ensuring HIPAA compliance. </p>
<p>But that’s really where it ends, because unlike a <a href="http://www.sas70.us.com">SAS 70 </a>Type II audit and a Payment Card Industry Data Security Standards (PCI DSS) assessment, compliance is, for the most part, not actively overseen. What does it really mean to be HIPAA compliant? What part of HIPAA do organizations need to be compliant with? What are the true penalties for non-compliance, if any?  </p>
<p>HIPAA needs to take a more aggressive approach, possibly a revision of the law along with explicit rules for what compliance is and for what part of the HIPAA legislation. Only then will HIPAA really have the bite like SAS 70 or <a href="http://www.pciassessment.org">PCI DSS</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/will-hipaa-compliance-ever-have-any-teeth-like-sas-70-and-pci/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
