HHS Issues Guidance for Securing PHI
The Guidance distinguishes among four categories or states in which PHI is vulnerable:
-- Data in motion (e.g., network, wireless transmission)
-- Data at rest (e.g., databases, file systems, other storage)
-- Data in use (e.g., being created, retrieved, updated)
-- Data disposed (e.g., discarded paper records and electronic media)
– Standards described in NIST Special Publications 800-52, Guidelines for the Selection and Use of Transport Layer Security (TLS) Implementations,
– 800-77, Guide to IPsec VPNs,
– 800-113, Guide to SSL VPNs, and-- May include others which are FIPS 140-2 validated
– Paper, film, or other hard copy media have been shredded or destroyed such that the PHI cannot be read or otherwise cannot be reconstructed
– Electronic media have been cleared, purged, or destroyed consistent with NIST Special Publication 800-88, Guidelines for Media Sanitization, such that the PHI cannot be retrieved
Reduce Email Archives up to 60%
Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.
Aberdeen Report: To Patch, or Not to Patch? (Not If, But How)
The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.
Recent Comments
- The CISO's Survival Guide to Securing Data
- Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- FireEye Advanced Threat Protection KnowledgeVault
- Five Tips to Consider in a Data Security Strategy for Smartphones and Tablets
- Moving Your Email to the Trusted Cloud
- Comprehensive Server Protection

