<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Pointing out the obvious</title>
	<atom:link href="http://infoseclinks.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://infoseclinks.wordpress.com</link>
	<description>Think like you don't understand</description>
	<lastBuildDate>Thu, 20 Aug 2009 18:02:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='infoseclinks.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Pointing out the obvious</title>
		<link>http://infoseclinks.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://infoseclinks.wordpress.com/osd.xml" title="Pointing out the obvious" />
	<atom:link rel='hub' href='http://infoseclinks.wordpress.com/?pushpress=hub'/>
		<item>
		<title>New FTC Ruling on Protecting Personal Health Information for Non-HIPAA Entities</title>
		<link>http://infoseclinks.wordpress.com/2009/08/20/new-ftc-ruling-on-protecting-patient-data-for-non-hipaa-entities/</link>
		<comments>http://infoseclinks.wordpress.com/2009/08/20/new-ftc-ruling-on-protecting-patient-data-for-non-hipaa-entities/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 15:29:20 +0000</pubDate>
		<dc:creator>gonorato</dc:creator>
				<category><![CDATA[Security Rants]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PHR]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://infoseclinks.wordpress.com/2009/08/20/new-ftc-ruling-on-protecting-patient-data-for-non-hipaa-entities/</guid>
		<description><![CDATA[The American Recovery and Reinvestment Act of 2009 charged the Federal Trade Commission to issue rules for vendors of personal health records and related entities to notify individuals upon a breach, and as such, define a reportable breach. Well, it is finally here. I know.. I know..  now that it is here it feels like [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infoseclinks.wordpress.com&amp;blog=1991849&amp;post=21&amp;subd=infoseclinks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-size:small;">The American Recovery and Reinvestment Act of 2009 charged the Federal Trade Commission to issue rules for vendors of personal health records and related entities to notify individuals upon a breach, and as such, define a reportable breach. Well, it is finally here. </span></p>
<p><span style="font-size:small;">I know.. I know..  now that it is here it feels like summer is over, but don’t despair, I am sure something new will be mandated by someone, around something, very soon. As a matter of fact we have another ruling, the final report from HHS is due by February of next year… So we got that going for us.. which is good.</span></p>
<p><span style="font-size:small;">As we cover this a bit, remember, this is not a replacement for HIPAA but really meant to cover entities that were not anticipated in the HIPAA rules. We aren’t talking health care providers and insurance companies but other entities who work with health care records, such as web based businesses and those who support them.</span></p>
<p><span style="font-size:small;">From the FTC:</span></p>
<blockquote><p><em><span style="font-size:small;">“The rule applies to both vendors of personal health records – which provide online repositories that people can use to keep track of their health information – and entities that offer third-party applications for personal health records. These applications could include, for example, devices such as blood pressure cuffs or pedometers whose readings consumers can upload into their personal health records.</span></em></p>
<p><span style="font-size:small;">…</span></p>
<p><span style="font-size:small;">the FTC’s Rule does not apply to businesses or organizations covered by the Health Insurance Portability &amp; Accountability Act (HIPAA). In case of a security breach, entities covered by HIPAA must comply with HHS’ breach notification rule.”</span></p></blockquote>
<p><span style="font-size:small;"> </span></p>
<p><span style="font-size:small;">There are plenty of great bloggers putting together information on what this all means, but I want to bring out a few points to those who find this in any way interesting:</span></p>
<p><span style="font-size:small;">1) “limited data sets” are not excluded from the ruling. The FTC feels the risk of re-identification of limited data sets is too great for a blanket exclusion. There is some interesting research on the likelihood of re-identifying limited data sets, and it turns out it is easier than it seems (links below). De-identified data sets are excluded.</span></p>
<p><span style="font-size:small;">2) Unsecured data which is breached is subject to notification, “unsecured” is defined as information “not protected<br />
through the use of a technology or methodology specified by the Secretary of Health and Human Services in the guidance issued under section 13402(h)(2) of the American Recovery and Reinvestment Act of 2009.” So, we are talking: </span></p>
<ul>
<li><span style="font-size:small;">De-identification, </span></li>
<li><span style="font-size:small;">Destruction, or </span></li>
<li><span style="font-size:small;">Encryption</span></li>
</ul>
<p><span style="font-size:small;">3) If a breach occurs entities have three notification requirements:</span></p>
<ul>
<li><span style="font-size:small;">The individuals impacted must be notified within 60 calendar days. Law enforcement can supersede this. </span></li>
<li><span style="font-size:small;">The FTC must be notified, </span><a href="http://www.ftc.gov/os/2009/08/R911002hbnform.pdf"><span style="font-size:small;">via this form</span></a><span style="font-size:small;">, with 10 business days for breaches over 500 records or 60 calendar days after the end of the year for beaches of less than 500 records.</span></li>
<li><span style="font-size:small;">For breaches of over 500 individuals of a particular state or jurisdiction (think smaller than a state), the media in that jurisdiction must be notified, so if 1000 records are lost but only 200 from each state, no media notification is needed (big sigh, until someone shows their cousin the news producer your letter).</span></li>
</ul>
<p><span style="font-size:small;">4) Looking at the notification form, the first type of breach they ask about is “Lost or stolen laptop, computer, flash drive, disk, etc.”. This is a strong argument for encryption, or minimally DLP so that data can be tracked.</span></p>
<p><span style="font-size:small;">5) Interesting little side note (and this is not entered here as a “WOW LOOK ANOTHER JURISDICTIONAL LAND GRAB”… if you want to yell that feel free but I think it is a good idea to apply this more broadly rather than less) just because an entity was not under the jurisdiction of the FTC before, does not mean they are not held to there requirements. From the doc:</span></p>
<blockquote><p><span style="font-size:small;">“In its NPRM, the Commission noted that the proposed rule applied to entities<br />
beyond the FTC’s traditional jurisdiction under section 5 of the FTC Act, such as nonprofits<br />
(e.g., educational institutions, charities, and 501(c)(3) organizations), because the<br />
Recovery Act does not limit the FTC’s enforcement authority to its enforcement”</span></p></blockquote>
<p><span style="font-size:small;">Links:</span></p>
<p><span style="font-size:small;">FTC Publications and Guidance</span></p>
<p><a href="http://www.ftc.gov/healthbreach"><span style="font-size:small;">http://www.ftc.gov/healthbreach</span></a></p>
<p><a title="http://www.ftc.gov/opa/2009/08/hbn.shtm" href="http://www.ftc.gov/opa/2009/08/hbn.shtm"><span style="font-size:small;">http://www.ftc.gov/opa/2009/08/hbn.shtm</span></a></p>
<p><a title="http://www.ftc.gov/os/2009/08/R911002hbn.pdf" href="http://www.ftc.gov/os/2009/08/R911002hbn.pdf"><span style="font-size:small;">http://www.ftc.gov/os/2009/08/R911002hbn.pdf</span></a></p>
<p><span style="font-size:small;">Re-identifying data (and some other interesting stuff)</span></p>
<p><a title="http://privacy.cs.cmu.edu/people/sweeney/cv.html#publications" href="http://privacy.cs.cmu.edu/people/sweeney/cv.html#publications"><span style="font-size:small;">http://privacy.cs.cmu.edu/people/sweeney/cv.html#publications</span></a></p>
<p><span style="font-size:small;"> </span></p>
<p><span style="font-size:small;"> </span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infoseclinks.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infoseclinks.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infoseclinks.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infoseclinks.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infoseclinks.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infoseclinks.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infoseclinks.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infoseclinks.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infoseclinks.wordpress.com&amp;blog=1991849&amp;post=21&amp;subd=infoseclinks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infoseclinks.wordpress.com/2009/08/20/new-ftc-ruling-on-protecting-patient-data-for-non-hipaa-entities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfc10fd99e8b807a1384b16b9c39db7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Gerard</media:title>
		</media:content>
	</item>
		<item>
		<title>IP Header Illustrations</title>
		<link>http://infoseclinks.wordpress.com/2009/08/11/ip-header-illustrations/</link>
		<comments>http://infoseclinks.wordpress.com/2009/08/11/ip-header-illustrations/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 02:02:53 +0000</pubDate>
		<dc:creator>gonorato</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[Diagrams]]></category>
		<category><![CDATA[IP Headers]]></category>

		<guid isPermaLink="false">http://infoseclinks.wordpress.com/2009/08/11/ip-header-illustrations/</guid>
		<description><![CDATA[Hexis (who I do not know personally), did a great job with these IP header illustrations.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infoseclinks.wordpress.com&amp;blog=1991849&amp;post=17&amp;subd=infoseclinks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hexis (who I do not know personally), did a great job with these <a href="http://freebie.fatpipe.org/~mjb/Drawings/">IP header illustrations</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infoseclinks.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infoseclinks.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infoseclinks.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infoseclinks.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infoseclinks.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infoseclinks.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infoseclinks.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infoseclinks.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infoseclinks.wordpress.com&amp;blog=1991849&amp;post=17&amp;subd=infoseclinks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infoseclinks.wordpress.com/2009/08/11/ip-header-illustrations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfc10fd99e8b807a1384b16b9c39db7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Gerard</media:title>
		</media:content>
	</item>
		<item>
		<title>Enterprise Encryption on the Rise &#8211; Enterprise Key Management Lags</title>
		<link>http://infoseclinks.wordpress.com/2009/07/15/enterprise-encryption-on-the-rise-enterprise-key-management-lags/</link>
		<comments>http://infoseclinks.wordpress.com/2009/07/15/enterprise-encryption-on-the-rise-enterprise-key-management-lags/#comments</comments>
		<pubDate>Wed, 15 Jul 2009 20:03:00 +0000</pubDate>
		<dc:creator>gonorato</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Key Management]]></category>

		<guid isPermaLink="false">http://infoseclinks.wordpress.com/2009/07/15/enterprise-encryption-on-the-rise-enterprise-key-management-lags/</guid>
		<description><![CDATA[This story indicates that the use of ad-hoc encryption solutions is on the decline as companies take a more enterprise aware approach to encryption management. Okay, the survey was sponsored by an encryption product company…&#160; okay there seems to be some extrapolation which could be argued but my experience with clients leads me to believe [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infoseclinks.wordpress.com&amp;blog=1991849&amp;post=14&amp;subd=infoseclinks&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://tinyurl.com/l9akol">This story</a> indicates that the use of ad-hoc encryption solutions is on the decline as companies take a more enterprise aware approach to encryption management. Okay, the survey was sponsored by an encryption product company…&#160; okay there seems to be some extrapolation which could be argued but my experience with clients leads me to believe this is pretty accurate. </p>
<p>Companies are wise to adopt centralized encryption technologies to ensure compliance, simplify management and offer attainable services to internal users but please don’t confuse integrated key management of an enterprise product with enterprise key management. </p>
<p>In my experience, large enterprises are falling short when it comes to enterprise key management strategies both in policy and execution. Companies still lack strategy and comprehensive EKM policy. It simply isn’t enough to take the NIST KM doc and attach your name to it. I can’t tell you how many otherwise excellent policy (functional or otherwise) and standards libraries I have seen that have unenforceable and unsuitable statements in KM documents.</p>
<p>Vendors are claiming to have EKM solutions but wide spread integration with third-party products just isn’t there. Until there is a more interoperability there will be no true EKM unless the `E` decides to do some serious, and potentially limiting, standardization. OASIS is considering KMIP, which seems as good as others. </p>
<p>For now, think strategically, speak to vendors about roadmaps and consider the enterprise not the vendor’s marketing tag. </p>
<p><em>and remember….</em></p>
<p>&quot;Key management is the hardest part of cryptography and often the Achilles&#8217; heel of an otherwise secure system.&quot; — <b>Bruce Schneier</b>,&#160; <a href="http://www.schneier.com/book-applied-2preface.html">Preface</a> to <cite>Applied Cryptography</cite>, Second Edition</p>
<p>Good links to explore: </p>
<p>Some good links: <a title="http://xml.coverpages.org/keyManagement.html" href="http://xml.coverpages.org/keyManagement.html">http://xml.coverpages.org/keyManagement.html</a></p>
<p>Oasis: <a title="http://www.oasis-open.org/home/index.php" href="http://www.oasis-open.org/home/index.php">http://www.oasis-open.org/home/index.php</a></p>
<p>The story: <a href="http://tinyurl.com/l9akol">http://tinyurl.com/l9akol</a></p>
<div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:bba9749c-8230-4915-bd94-5076da731a10" style="display:inline;float:none;margin:0;padding:0;">Technorati Tags: <a href="http://technorati.com/tags/Encryption" rel="tag">Encryption</a>,<a href="http://technorati.com/tags/Key+Managment" rel="tag">Key Managment</a>,<a href="http://technorati.com/tags/EKM" rel="tag">EKM</a>,<a href="http://technorati.com/tags/Data+Protection" rel="tag">Data Protection</a></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/infoseclinks.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/infoseclinks.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/infoseclinks.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/infoseclinks.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/infoseclinks.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/infoseclinks.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/infoseclinks.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/infoseclinks.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=infoseclinks.wordpress.com&amp;blog=1991849&amp;post=14&amp;subd=infoseclinks&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://infoseclinks.wordpress.com/2009/07/15/enterprise-encryption-on-the-rise-enterprise-key-management-lags/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfc10fd99e8b807a1384b16b9c39db7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Gerard</media:title>
		</media:content>
	</item>
	</channel>
</rss>
