Welcome!

Containers Expo Blog Authors: Yeshim Deniz, Liz McMillan, Elizabeth White, Zakia Bouachraoui, Pat Romanski

Blog Feed Post

Cloud Security Affected by HIPAA Business Associate Agreements

HIPAA Compliance Cloud Security  healthcare cloud security Cloud Security Affected by HIPAA Business Associate AgreementsMedCity Health IT: The HIPAA Omnibus Rule regulations encourage business associates to healthcare companies to share responsibility for data breaches. These new regulations involve signing “Business Associate Agreements” with providers, yet are likely to strengthen trust in cloud security, and allow more healthcare entities to enjoy the benefits of the cloud while ensuring that patient privacy is maintained.

In the recent past, organizations were hesitant to move sensitive healthcare information to the cloud. The cloud was unfamiliar and seemed to be less safe than crunching data on company hardware. But now that cloud service providers are taking on a big slice of responsibility for their clients’ data security, cloud computing is much more attractive. Not only is it perceived to be safer, but it transfers some of the responsibility for security from the healthcare company to the cloud provider, making it a safer choice than going it alone.

In fact,  a recent study (conducted in Aug 2013 by Imprivita) shows that the use of cloud-based applications and services in healthcare is up significantly from last year. A full 30 percent of respondents said they currently use cloud computing. In 2012, the number was only nine percent. And 40 percent of those respondents said they have moved their Private Health Information (PHI) into the cloud (also up from nine percent last year).

The new reality does bring with it some challenges. Business Associate Agreements (BAA’s) define the relationship between the provider and the healthcare organization. Some cloud providers set their own conditions which customers must meet in order to get a BAA. And the customers themselves , are asking questions such as how the provider will react to a security breach, or about the length of incident response time.

Although each BAA is a little different, the US Department of Health and Human Services provides a list of the necessary components of a BAA. The 10 crucial elements are:

  1. The contract must establish the permitted and required uses and disclosures of protected health information by the BA.
  2. It must provide that the BA will not disclose any other information other than what has been permitted in the agreement.
  3. The BA must implement safeguards to protect PHI, including electronic records.
  4. BA must disclose to the healthcare organization any use or disclosure of information not provided for in the contract, including security breaches.
  5. BA’s must disclose private health information to the healthcare provider when the patient requests it.
  6. The BA must follow all regulations set out in the Privacy Rule.
  7. The BA must make available to the healthcare organization its books, records and internal practices relating to use and disclosure of PHI.
  8. When the contract is terminated, the BA must return or destroy all PHI.
  9. Any subcontracters engaged by the BA are required to abide by the same regulations as the BA.
  10. If the BA violates any of the terms of the contract, the contract will be terminated.

These clear guidlines make it easier for healthcare organizations to venture into cloud computing.

HIPAA Compliant Organizations Turn to Data Encryption

Not only are more healthcare organizations looking to the cloud, but many businesses are now turning to data encryption as the most cost-effective and efficient method of data protection and breach notification. This is becoming the accepted best practice, and allows so-called “Safe Harbor” for a HIPAA compliant entity if a breach does occur.

Data encryption provides a kind of “mathematical wall” that replaces the old walls of the physical world.  As long as the owner of the data keeps the encryption keys to himself, this is actually quite effective. And “Safe Harbor” rules from the Health and Human Services administration (HHS) mean that – if you can prove that the data was encrypted and the encryption keys kept safe – you will avoid many of the fines and reporting requirements should something go wrong.

As healthcare providers and their business associates adjust to the new HIPAA regulations, it is expected that more of them will take advantage of data encryption and benefit from the efficiency of cloud computing.

The post Cloud Security Affected by HIPAA Business Associate Agreements appeared first on Porticor Cloud Security.

Read the original blog entry...

More Stories By Gilad Parann-Nissany

Gilad Parann-Nissany, Founder and CEO at Porticor is a pioneer of Cloud Computing. He has built SaaS Clouds for medium and small enterprises at SAP (CTO Small Business); contributing to several SAP products and reaching more than 8 million users. Recently he has created a consumer Cloud at G.ho.st - a cloud operating system that delighted hundreds of thousands of users while providing browser-based and mobile access to data, people and a variety of cloud-based applications. He is now CEO of Porticor, a leader in Virtual Privacy and Cloud Security.

IoT & Smart Cities Stories
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...
Charles Araujo is an industry analyst, internationally recognized authority on the Digital Enterprise and author of The Quantum Age of IT: Why Everything You Know About IT is About to Change. As Principal Analyst with Intellyx, he writes, speaks and advises organizations on how to navigate through this time of disruption. He is also the founder of The Institute for Digital Transformation and a sought after keynote speaker. He has been a regular contributor to both InformationWeek and CIO Insight...
CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018, in New York City and will bring together Cloud Computing, FinTech and Blockchain, Digital Transformation, Big Data, Internet of Things, DevOps, AI, Machine Learning and WebRTC to one location.
Bill Schmarzo, Tech Chair of "Big Data | Analytics" of upcoming CloudEXPO | DXWorldEXPO New York (November 12-13, 2018, New York City) today announced the outline and schedule of the track. "The track has been designed in experience/degree order," said Schmarzo. "So, that folks who attend the entire track can leave the conference with some of the skills necessary to get their work done when they get back to their offices. It actually ties back to some work that I'm doing at the University of San...
Andrew Keys is Co-Founder of ConsenSys Enterprise. He comes to ConsenSys Enterprise with capital markets, technology and entrepreneurial experience. Previously, he worked for UBS investment bank in equities analysis. Later, he was responsible for the creation and distribution of life settlement products to hedge funds and investment banks. After, he co-founded a revenue cycle management company where he learned about Bitcoin and eventually Ethereal. Andrew's role at ConsenSys Enterprise is a mul...
IoT is rapidly becoming mainstream as more and more investments are made into the platforms and technology. As this movement continues to expand and gain momentum it creates a massive wall of noise that can be difficult to sift through. Unfortunately, this inevitably makes IoT less approachable for people to get started with and can hamper efforts to integrate this key technology into your own portfolio. There are so many connected products already in place today with many hundreds more on the h...
DXWorldEXPO | CloudEXPO are the world's most influential, independent events where Cloud Computing was coined and where technology buyers and vendors meet to experience and discuss the big picture of Digital Transformation and all of the strategies, tactics, and tools they need to realize their goals. Sponsors of DXWorldEXPO | CloudEXPO benefit from unmatched branding, profile building and lead generation opportunities.
DXWorldEXPO LLC announced today that Telecom Reseller has been named "Media Sponsor" of CloudEXPO | DXWorldEXPO 2018 New York, which will take place on November 11-13, 2018 in New York City, NY. Telecom Reseller reports on Unified Communications, UCaaS, BPaaS for enterprise and SMBs. They report extensively on both customer premises based solutions such as IP-PBX as well as cloud based and hosted platforms.
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docker c...
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.