PRIVACY + SECURITY BLOG

News, Developments, and Insights

HIPAA Turns 10: Analyzing the Past, Present, and Future Impact

by Daniel J. Solove In the April issue of the Journal of AHIMA, I authored two short pieces about HIPAA: HIPAA Turns 10: Analyzing the Past, Present, and Future Impact 84 Journal of AHIMA 22 (April 2013) HIPAA Mighty and Flawed: Regulation has Wide-Reaching Impact on the Healthcare Industry 84 Journal of AHIMA 30 (April […]

The HIPAA-HITECH Regulation, the Cloud, and Beyond

by Daniel J. Solove The new HIPAA-HITECH regulation is here. Officially titled “Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules,” this new regulation modifies HIPAA in accordance with the changes mandated by the HITECH Act of 2009. After years of waiting and many false alarms that the regulation was going to be […]

Final HIPAA-HITECH Regulation

posted by Daniel J. Solove The final HIPAA-HITECH regulation is finally out!  Clocking in at 563 pages long, the regulation, which is entitled “Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules” will be published in the Federal Register on January 25, 2013.  You can download the PDF of the pre-publication version here.

New Privacy by Design Training Video

I recently created this 2-minute comical cartoon vignette to teach about the importance of privacy and apps.  Far too often, apps are not designed with privacy in mind, and people install apps without considering the privacy implications. [Video no longer available online – please contact us if you’d like to see it] More About Apps and […]

Educational Institutions and Cloud Computing: A Roadmap of Responsibilities

by Daniel J. Solove Increasingly, educational institutions and state entities handling student data are hiring outside companies to perform cloud computing functions related to managing personal information. The benefits of cloud computing are that outside entities might be more sophisticated at managing personal data. These entities may be able to manage data more inexpensively and […]

Employer Social Media Policies: A Brave New World

Posted by Daniel J. Solove The frequent use of social media by employees has created a new domain of risk for employers – employees who reveal confidential or sensitive information or who otherwise say things that damage their institution’s reputation or create strife with their colleagues. For example, in the healthcare context, in a number […]

Data Security and the Human Factor: Training and Its Challenges

Posted by Daniel J. Solove According to a stat in SC Magazine, 90% of malware requires a human interaction to infect.  One of the biggest data security threats isn’t technical – it’s the human factor.  People click when they shouldn’t click, put data on portable devices when they shouldn’t, email sensitive information, and engage in […]