Showing posts with label 800-66. Show all posts
Showing posts with label 800-66. Show all posts

Monday, March 9, 2009

Hungry, Hungry, HIPAA

Over the last year we have seen a small surge in HIPAA assessments from our clients. The few years leading up to that were pretty darn quiet compared to the initial storm when the regulation first came out. So why is that? Well, it’s something we say over and over and that’s “no one does security unless they have to,” though there is some due diligence. But that’s all about to change.

With HIPAA, other than some initial work a long time ago, it wasn’t that scary until the audits started. And most of the work was done under some risk-based assessment that likely favored the business over security. Even so, statistically speaking, your organization isn’t likely to get ‘hit’ any time soon based on the number of audits being performed. In previous postings, we tried to make it easy for you and talked about using the NIST 800-66 framework.

Now despite all our efforts, the current administration – like them or not – realizes that HIPAA still needs more teeth. I don’t know about you, but the $100,000 HIPAA audit fine for an organization in Seattle was nearly laughable compared to the millions of dollars being levied for PCI. So of course your ‘risk assessment’ is going to say doing security isn’t worth it versus the costs given what we’ve seen to date. So we need to make it more painful, right? Make it so that you feel like you have to do it, right?

Buried within the American Recovery and Reinvestment Act of 2009 (ARRA) signed in February is the Health Information Technology for Economic and Clinical Health Act's (HITECH Act) – though this isn’t really high tech, go figure. This includes quite a few revisions to HIPAA such as increased coverage for non-entities. But the high impact area is mandatory breach notification and subsequent requirements. To enforce this, it is tied to increased penalties, fines and overall liability, and improved enforcement. Fines can reach $1.5M now. Civil lawsuits can now leverage HIPAA. And finally, there is an increase in audits.

So, do we have your attention now? It’s time for organizations to dust off their HIPAA compliance manuals from 5+ years ago and get some new, independent review on what the real risks are and using an accepted framework. It’s time for organizations to get risk assessments performed, like penetration tests that truly simulate breaches to see if it could really happen there. Failure to do some assessment/audit work prior to a CMS audit is likely going to result in fines and reactive security, or worse, a very expensive breach. It’s better that experts like SecureState find the problem than CMS or the hacker – and for a lot less.

Read more!

Tuesday, August 5, 2008

Preparing for HIPAA: Round Two - The Audit

The big buzz this year around security assessments and audits is all about HIPAA. This was #6 in SecureState's Top 8 of 08 and, to say the least, there’s quite a bit of tension in the air as organizations hold their breath. While PCI is still the most active, all of our clients with HIPAA concerns – which is many – are on constant watch to see what HIPAA is really going to mean. To date, HIPAA has been a little weak as organizations have been left to their own devices to operate around a risk-based approach for HIPAA. But that approach has time and time again proven to not be diligent enough and/or favors the business over security. But now, the audits are happening, HIPAA is getting some teeth, and most organizations are scrambling to figure out what ‘their’ interpretation is and if what they did is enough. Everyone knows that the first audit was done last year at a hospital and have seen the list of‘42 questions’ that were asked. But those hardly helped as they really didn’t indicate what the expectations were. Now other HIPAA organizations are being audited including retailers and insurers. The results are supposed to be posted on the CMS/HHS site, but so far nothing is out there. But hope is not lost as the details emerge from our clients and other information.

First of all, it is important to realize who is doing the audits. It is KPMG’s government practice and working for a government agency. As such, it should be expected that they would leveraging NIST standards. The second indicator is from NIST itself. The CMS/HHS first worked with NIST to develop the 800-66 publication for understanding and implementing the HIPAA Security Rule. But that proved to be fairly vague and mainly referencing a bunch of other NIST standards but not providing a lot of ‘how’. Based on that type of feedback, they have issued a draft version ( http://csrc.nist.gov/publications/drafts/800-66-Rev1/Draft_SP800-66-Rev1.pdf ) that has finally provided a solid understanding of how to implement the Security Rule – by mapping it to NIST 800-53 that outlines ‘recommended controls’, not unlike ISO 27002 (formerly 17799). Ultimately, this has been further confirmed in reviewing some of the HIPAA audit draft reports that NIST 800-53 is the core of the KPMG audit framework.

So now you know what they are looking for and what to expect. If you were looking for a solid ‘checklist’ for gapping your HIPAA program, look no further than NIST 800-53, or even better, the draft of NIST 800-66. The draft is great as it also has sample questions that the auditor might be asking as well – hint hint. The other referenced NIST standards can also be helpful, especially if your organization uses a particular technology extensively e.g. 800-124 draft on cell/PDA security. Regardless of what the checklist is, the bottom line is HIPAA has not had a strong enough impact for organizations, much like SOX. As a result, companies aren’t really getting secure as originally intended. Every hospital or insurance company we have reviewed has failed system audits and penetration testing - and we're the good guys. Getting compliant, even to a higher level, isn’t getting secure. And odds are, your organization has more than HIPAA data out there.

So do the right thing, do due diligence, do it soon, and get your organization to a defensible position before the audit. Base your decisions on the intent of the controls outlined in 800-53/66, not the wording or sample interpretation. Don't wait for the audit, findings and fines - or even worse - the breach. It's a lot more expensive to implement security after the fact than before.

Read more!