Raytheon|Websense Rebrands as Forcepoint
Raytheon|Websense has recently been rebranded. From January 14, 2016 the company will be known as Forcepoint. Forcepoint combines the cybersecurity products of Websense, which was acquired by Raytheon in May 2015, Raytheon – a major U.S. defense contractor, and the next generation firewall solutions of Stonesoft and Sidewinder, which were acquired from Intel Security this month. Forcepoint is a joint venture between Raytheon and Vista Equity Partners. The acquisitions which allow the company to provide a wide range of cybersecurity solutions to address the ever-evolving threat landscape through the transformative technologies of the cloud, mobility and IoT. The company is providing a cloud-centric platform that will safeguard data, networks, and end users. The combination of all services under the same brand will help the firm eliminate some of the inefficiencies of managing separate collections of cybersecurity products. The products of all companies will be combined into a platform solution that offers protection from internal and external threats, combining next generation...
Beware of Medical Device Ransomware in 2016 Warns Forrester Research
The spate of data breaches suffered by HIPAA-covered entities is set to continue in 2016 according to predictions by security experts. Malware and phishing attacks on healthcare providers are likely to continue to be used to obtain PHI from healthcare providers this year. While phishing and social engineering was used to gain access to data last year (Anthem, Premera), ransomware attacks have not plagued the healthcare industry, even though the use of the malicious software has grown. Hackers have preferred attacking healthcare providers for the data they hold rather than locking computers and demanding a ransom. Far greater rewards can be gained from obtaining millions of healthcare records than from locking a handful of computers. However, that does not mean that ransomware is not a problem, in fact, research and advisory company Forrester Research has predicted that ransomware attacks are going to be more of a problem in 2016, and the company believes that medical devices and wearables will be targeted. If the prediction turns out to be true, medical devices could be attacked...
Upgrade Internet Explorer to Remain HIPAA Compliant
On Wednesday January 12, 2016., Microsoft will be stopping support and security updates for Internet Explorer 8, 9 and 10. All users of Internet Explorer must therefore upgrade to Internet Explorer 11, or make the switch over to Microsoft Edge in order to continue receiving support, security updates, and patches. 18 months ago, Microsoft announced that its internet browser updates for IE8, IE9, and IE10 would be stopping. Any user who has not yet upgraded now has just two days left before their browser officially becomes obsolete. Whenever software is discontinued and support and security patches are stopped, that software becomes a security risk. Vulnerabilities are discovered that are not patched, and hackers are likely to be able to take advantage. Microsoft recently issued a warning saying continued use of IE 10, 9 and 8 would leave individuals “at risk of viruses and other malicious software that exploit security flaws and bugs in the browsers.” Figures from Netmarketshare.com and Duo Security put the number of Internet Explorer users with IE10 and below installed at between...
A Year of HIPAA Enforcement: OCR HIPAA Penalties Issued in 2015
In its capacity as enforcer of the Health Insurance Portability and Accountability Act (HIPAA) Rules, the Department of Health and Human Services’ Office for Civil Rights (OCR) can issue fines to HIPAA-covered entities that fail to implement sufficient safeguards to keep the Protected Health Information (PHI) of patients and health plan members secure. OCR has been criticized in recent years for an apparent lack of enforcement, specifically for failing to issue financial penalties for clear violations of the HIPAA Privacy, Security, and Breach Notification Rules by HIPAA-covered entities. Covered entities are required to self-report data breaches to OCR under the Breach Notification Rule of 2009, and all data breaches that expose the PHI of more than 500 patients are investigated. Sometimes, those data breaches occur even when covered entities have implemented all of the administrative, technical, and physical controls that are required by the HIPAA Security Rule. However, in many cases, data breaches are suffered as a result of HIPAA failures. In such cases, action is taken by OCR...
OCR Issues New Guidance on Patient Data Access
Healthcare providers should be aware that patients are permitted access to their medical records under HIPAA rules; however, not all patients are aware of their legal rights. Not only are patient data access rights under HIPAA not well understood, many patients who have attempted to access their medical records have faced problems. There is also a misconception that HIPAA – specifically the HIPAA Privacy Rule – prevents healthcare providers from disclosing medical records. While it is true when it comes to disclosing Protected Health Information (PHI) of patients to individuals unauthorized to view that information, HIPAA does allow patients to access their own records. In fact, any healthcare provider who fails to allow patients to access their medical records could be fined. OCR Issues Guidance on Patient Data Access Rights Under HIPAA The Department of Health and Human Services’ Office for Civil Rights has started the year with the launch of a brand new website interface, and has now followed up on previous promises by issuing new guidance on HIPAA. This is the first in...



