Tag Archives: david mortman

HIPAA Changes Coming 2/2010

The American Recovery and Reinvestment Act includes changes to HIPAA, including:

  • Much higher civil penalties for violations.
  • Covered entities must disclose security breaches when client data is exposed.
  • Business associates will be subject to the same civil and criminal penalties as covered entities.

The changes are not effective until February 2010.

David Mortman of Searchsecurity.com provides an overview of the changes here.

For a more comprehensive list of changes, see Thomson Hine (PDF).


Leave a comment

Filed under Audit, Security

Attackers Don’t Help Companies, PCI Does

Is PCI still relevant? Some are proclaiming that PCI is irrelevant due to the recent, high-profile breaches. David Mortman disagrees, and I’m on his side.

Continue reading

Leave a comment

Filed under Audit, Security