{"id":14211,"date":"2019-01-02T04:30:02","date_gmt":"2019-01-02T12:30:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/01\/02\/news-7963\/"},"modified":"2019-01-02T04:30:02","modified_gmt":"2019-01-02T12:30:02","slug":"news-7963","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/01\/02\/news-7963\/","title":{"rendered":"If the CTO says it&#039;s OK, what could go wrong?"},"content":{"rendered":"<p><strong>Credit to Author: Sharky| Date: Wed, 02 Jan 2019 03:00:00 -0800<\/strong><\/p>\n<p>Medical rehab facility is facing a compliance deadline for <a href=\"https:\/\/en.wikipedia.org\/wiki\/Health_Insurance_Portability_and_Accountability_Act\" rel=\"noopener nofollow\" target=\"_blank\">HIPAA<\/a> privacy regulations, and that could be a problem, says a cybersecurity pilot fish working there.<\/p>\n<p>&#8220;The HIPAA regulations are strewn with potential issues,&#8221; fish says. &#8220;When some aspect isn&#8217;t followed and a patient&#8217;s data privacy is compromised, the fines can be substantial.&#8221;<\/p>\n<p>And that&#8217;s the headache fish faces because of his facility&#8217;s use of Gmail. As the site&#8217;s cybersecurity engineer, fish knows that ordinary Gmail isn&#8217;t HIPAA compliant.<\/p>\n<p>Fortunately, there&#8217;s a fix &#8212; one that involves additional paperwork and agreements, along with some added security verification. But that&#8217;s still easier and less complex than moving everyone off Gmail.<\/p>\n<p>So fish works to make sure all HIPAA requirements and industry standards are met. After a thorough search of available documentation, he creates a to-do list for the roadmap to ensure the facility has everything in order to comply with HIPAA.<\/p>\n<p>And fish has the CTO&#8217;s repeated assurances that all the necessary steps have been taken and followed per HIPAA.<\/p>\n<p>There&#8217;s just one problem: &#8220;After asking for required Document A four times and required Document B three times &#8212; and given past issues with the CTO &#8212; it became increasingly apparent that none of the work had actually been done,&#8221; sighs fish.<\/p>\n<p>&#8220;And without that documentation, if anything bad were to happen, everyone would be pointing at me&#8230;&#8221;<\/p>\n<p style=\"font-size: 0.875em;\"><strong>Document your true tale of IT life for Sharky.<\/strong> <i>Send your story to me at <a href=\"mailto:sharky@computerworld.com\" rel=\"nofollow\">sharky@computerworld.com<\/a>. You can also comment on today&#8217;s tale at <a href=\"https:\/\/plus.google.com\/u\/0\/communities\/113252326043973101081\" rel=\"nofollow\"><strong>Sharky&#8217;s Google+ community<\/strong><\/a>, and read thousands of great old tales in the <a href=\"http:\/\/www.computerworld.com\/search?query=+sharky&amp;s=d&amp;start=0\" title=\"Sharky's archives on easier-to-navigate pages\"><strong>Sharkives<\/strong><\/a>.<\/i><\/p>\n<p><em>Get Sharky&#8217;s outtakes from the IT Theater of the Absurd delivered directly to your Inbox. Subscribe now to the <a href=\"http:\/\/www.computerworld.com\/newsletters\/signup.html\" title=\"Daily Shark Newsletter subscription page\">Daily Shark Newsletter<\/a>.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3330562\/security\/if-the-cto-says-its-ok-what-could-go-wrong.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Sharky| Date: Wed, 02 Jan 2019 03:00:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Medical rehab facility is facing a compliance deadline for <a href=\"https:\/\/en.wikipedia.org\/wiki\/Health_Insurance_Portability_and_Accountability_Act\" rel=\"noopener nofollow\" target=\"_blank\">HIPAA<\/a> privacy regulations, and that could be a problem, says a cybersecurity pilot fish working there.<\/p>\n<p>&#8220;The HIPAA regulations are strewn with potential issues,&#8221; fish says. &#8220;When some aspect isn&#8217;t followed and a patient&#8217;s data privacy is compromised, the fines can be substantial.&#8221;<\/p>\n<p>And that&#8217;s the headache fish faces because of his facility&#8217;s use of Gmail. As the site&#8217;s cybersecurity engineer, fish knows that ordinary Gmail isn&#8217;t HIPAA compliant.<\/p>\n<p>Fortunately, there&#8217;s a fix &#8212; one that involves additional paperwork and agreements, along with some added security verification. But that&#8217;s still easier and less complex than moving everyone off Gmail.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3330562\/security\/if-the-cto-says-its-ok-what-could-go-wrong.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714],"class_list":["post-14211","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14211"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14211\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14211"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}