<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Pondurance</title>
	<atom:link href="http://www.pondurance.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pondurance.com</link>
	<description>Security.Continuity.Compliance</description>
	<lastBuildDate>Tue, 21 Feb 2012 16:07:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on 2011 Data Breach Review by steve.lodin</title>
		<link>http://www.pondurance.com/blog/2011-data-breach-review/#comment-84</link>
		<dc:creator>steve.lodin</dc:creator>
		<pubDate>Tue, 21 Feb 2012 16:07:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.pondurance.com/?p=683#comment-84</guid>
		<description>Jeovan,

I completely agree with the small office comment you mention.  See my recent blog post on &quot;SMB Security Can No Longer Be Ignored&quot; http://www.pondurance.com/blog/smb-security-can-no-longer-be-ignored/

I do not think Meaningful Use fund awards will trigger random audits.  It appears that KPMG has a different set of criteria for selecting targets based on their initial process.

Yes, it will be interesting to see the auditing steady state.  Some organizations really only react in the security space when faced with fines or after they are breached.  I&#039;m not sure if the threat of audits and fines will move the needle.

Steve</description>
		<content:encoded><![CDATA[<p>Jeovan,</p>
<p>I completely agree with the small office comment you mention.  See my recent blog post on &#8220;SMB Security Can No Longer Be Ignored&#8221; <a href="http://www.pondurance.com/blog/smb-security-can-no-longer-be-ignored/" rel="nofollow">http://www.pondurance.com/blog/smb-security-can-no-longer-be-ignored/</a></p>
<p>I do not think Meaningful Use fund awards will trigger random audits.  It appears that KPMG has a different set of criteria for selecting targets based on their initial process.</p>
<p>Yes, it will be interesting to see the auditing steady state.  Some organizations really only react in the security space when faced with fines or after they are breached.  I&#8217;m not sure if the threat of audits and fines will move the needle.</p>
<p>Steve</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 2011 Data Breach Review by Jeovan</title>
		<link>http://www.pondurance.com/blog/2011-data-breach-review/#comment-78</link>
		<dc:creator>Jeovan</dc:creator>
		<pubDate>Sat, 18 Feb 2012 18:56:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.pondurance.com/?p=683#comment-78</guid>
		<description>Interesting suvery but what would the results be like if small provider practices (1-3 doctors per office) were polled?  Most small offices I have encountered do not have personnel with the knowledge, skills or experience to perform a security risk analysis- much less risk management.  A security assessment AND risk management are REQUIRED objectives for HITECH fund recipients.  Will HITECH fund awards trigger  random  OIG HIPAA security audits?  Only time will tell .</description>
		<content:encoded><![CDATA[<p>Interesting suvery but what would the results be like if small provider practices (1-3 doctors per office) were polled?  Most small offices I have encountered do not have personnel with the knowledge, skills or experience to perform a security risk analysis- much less risk management.  A security assessment AND risk management are REQUIRED objectives for HITECH fund recipients.  Will HITECH fund awards trigger  random  OIG HIPAA security audits?  Only time will tell .</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Healthcare Information Security Survey by Steve Lodin</title>
		<link>http://www.pondurance.com/blog/new-healthcare-information-security-survey/#comment-30</link>
		<dc:creator>Steve Lodin</dc:creator>
		<pubDate>Wed, 16 Nov 2011 19:49:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.pondurance.com/?p=571#comment-30</guid>
		<description>Thanks for the comment!  You are correct and that is now fixed in the post.

Steve</description>
		<content:encoded><![CDATA[<p>Thanks for the comment!  You are correct and that is now fixed in the post.</p>
<p>Steve</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Healthcare Information Security Survey by Kevin</title>
		<link>http://www.pondurance.com/blog/new-healthcare-information-security-survey/#comment-29</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Tue, 15 Nov 2011 15:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.pondurance.com/?p=571#comment-29</guid>
		<description>Your percentages are flipped per the data in the report.  Page 4 of the report states that 26% of respondents have yet to conduct the assessment not 74%.</description>
		<content:encoded><![CDATA[<p>Your percentages are flipped per the data in the report.  Page 4 of the report states that 26% of respondents have yet to conduct the assessment not 74%.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

