<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Managed Data Center News</title>
	<atom:link href="http://resource.onlinetech.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://resource.onlinetech.com</link>
	<description>A Guide to Managed Hosting</description>
	<lastBuildDate>Wed, 16 May 2012 13:17:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Benefits of Outsourcing HIPAA Hosting</title>
		<link>http://resource.onlinetech.com/benefits-of-outsourcing-hipaa-hosting/</link>
		<comments>http://resource.onlinetech.com/benefits-of-outsourcing-hipaa-hosting/#comments</comments>
		<pubDate>Wed, 16 May 2012 13:17:21 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa white paper]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6941</guid>
		<description><![CDATA[Our HIPAA hosting and HIPAA compliant data center white paper provides a description of a HIPAA compliant data center IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria. Here&#8217;s an excerpt from section 4.1. on the benefits of outsourcing HIPAA hosting: Save &#8230; <a href="http://resource.onlinetech.com/benefits-of-outsourcing-hipaa-hosting/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Our <a href="http://www.onlinetech.com/hipaa">HIPAA hosting</a> and HIPAA compliant data center <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">white paper</a> provides a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria.</p>
<p>Here&#8217;s an excerpt from section 4.1. on the benefits of outsourcing HIPAA hosting:</p>
<h2>Save on Costs</h2>
<p>Why would a covered entity with sensitive data outsource their hosting solution to a third-party? A HIPAA compliant hosting provider that has already passed an independent HIPAA audit can save time and money by eliminating the need to audit your vendor in addition to your own business. While it does not release you of the obligation and responsibility of meeting compliance, it helps you more readily achieve compliance and mitigate risk.</p>
<p>Additionally, managed hosting allows your IT team to focus on the applications directly related to your business, not on the day-to-day details involved with server updates, data center infrastructure, network management and security which can more readily be outsourced to a trusted provider.</p>
<h2>Security</h2>
<p>A HIPAA compliant hosting provider can provide the latest tested and audited technology to help achieve compliance and secure your ePHI. With a variety of required and recommended security methods, you can trust experienced, certified professionals to maintain, monitor and accurately generate logs of activity on your servers.</p>
<p>Outsourcing allows you to benefit from the various levels of security that a quality hosting provider should have in place. These advantages include physical security, environmental controls, logged access and video surveillance, and multiple alarm systems to detect unauthorized access.</p>
<p>Network security includes protection of sensitive infrastructure, including managed servers, cloud, power and network infrastructure built with redundant routers, switches and paired universal threat management devices to protect sensitive information.</p>
<p>While the HITECH Act requires private accessibility on request by your patients, your outsourced hosting provider should never access PHI, but instead build, maintain and monitor the secure infrastructure that your sensitive information is stored and transmitted in.</p>
<h2>Availability</h2>
<p>The use of high-availability (HA) solutions in a fully redundant and compliant data center can allow clients to increase their uptime and PHI availability. Using an HA infrastructure can reduce the risk of business downtime due to a single point of failure. Outsourcing to a HIPAA hosting provider means your business can take advantage of your data center operator&#8217;s design of power connections, UPS (Uninterruptible Power Supplies) systems, generators, air conditioning and networks.</p>
<h2>Flexibility<strong><br />
</strong></h2>
<p>Outsourcing allows you to benefit from the latest virtualization technologies, such as fifth-generation VMware that dominates the market for applications that require a high degree of scalability. Choosing a high-performance managed cloud allows for the ability to scale servers up and down as needed to respond to the demands of end-users with fast deployment time.</p>
<p>To read about the Risks of Outsourcing, <a href="www.onlinetech.com/hipaawhitepaper">download our HIPAA white paper</a> today.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/benefits-of-outsourcing-hipaa-hosting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keep ePHI on Secure Networks, Not Mobile Devices, Recommends OCR</title>
		<link>http://resource.onlinetech.com/keep-ephi-on-secure-networks-not-mobile-devices-recommends-ocr/</link>
		<comments>http://resource.onlinetech.com/keep-ephi-on-secure-networks-not-mobile-devices-recommends-ocr/#comments</comments>
		<pubDate>Tue, 15 May 2012 14:36:45 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[covered entities]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[hipaa compliant data center]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6919</guid>
		<description><![CDATA[Of the 425 reported breach events to the OCR (Office of Civil Rights), two-thirds of all large breach cases involved loss or theft of information and more than half of these large breaches involved electronic devices. While a BAA (business &#8230; <a href="http://resource.onlinetech.com/keep-ephi-on-secure-networks-not-mobile-devices-recommends-ocr/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_6926" class="wp-caption alignleft" style="width: 410px"><img class="size-full wp-image-6926 " title="2012 Healthcare Data Breach Update" src="http://resource.onlinetech.com/wp-content/uploads/2012-BREACH.png" alt="2012 Healthcare Data Breach Update" width="400" height="550" /><p class="wp-caption-text">2012 Healthcare Data Breach Update</p></div>
<p>Of the 425 reported breach events to the OCR (Office of Civil Rights), two-thirds of all large breach cases involved loss or theft of information and more than half of these large breaches involved electronic devices.</p>
<p>While a BAA (business associate agreement) can help a healthcare organization maintain control and insight into privacy and security practices involved with handling their ePHI (electronic protected health information), risks of storing and transporting ePHI are also of concern, as exemplified by the reported 5 million individuals affected by a breach caused by backup tapes being stolen from an employee&#8217;s car.</p>
<p>About 1 million have been victims of lost backup tapes in office renovation situations, and 400,000 affected by theft of a laptop from an employee&#8217;s car. Desktop computer theft from offices has affected 943,000 more, and 63,000 have been affected by theft of a portable media device from an employee&#8217;s car.</p>
<p>What&#8217;s the solution to this seemingly prevalent problem with ePHI? Revert to paper records in a healthcare vault with multiple doors and lock combinations? Restrict ePHI to existing only on non-mobile electronics? Demand counter-reform in the face of federal reform with the advent of EHR system implementation?</p>
<p>The answer is fairly simple but often ignored &#8216;best practice&#8217; advice.</p>
<p>Aside from the common sense lesson of &#8216;don&#8217;t leave your electronics in your car,&#8217; David S. Holtzman from the OCR recommends storing data on a secure network, not a mobile device. Instead of losing data when you lose your phone or laptop, the data should be stored in a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> with standardized network security in place.</p>
<p>Sensitive infrastructure, such as servers, power and network should be protected by restricted access. Using an Intrusion Detection Service (IDS) and monitoring can help notify administrators of a potential breach, and give you the tools to resolve an issue, including times and user activity on a server and network.</p>
<p>As a second choice and additional layer of protection, Holtzman recommends encryption to protect the data, with the cost ranking up as minimal compared to breach fines. For detailed data on the minimum and maximum fines for breaches by type, visit <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">What is a HIPAA Violation?</a></p>
<hr />
<div><span style="line-height: 18px;"><a href="resources/white-papers/hipaa-compliant-data-centers"><img style="float: left;" src="http://resource.onlinetech.com/wp-content/uploads/hipaa-white-paper.gif" alt="HIPAA Compliant Data Centers" width="150" /></a>Looking for more information on HIPAA IT requirements, recommendations, and the foundation of a secure HIPAA compliant data center? </span></div>
<div><span style="line-height: 18px;"><br />
</span></div>
<div><span style="line-height: 18px;"><a href="resources/white-papers/hipaa-compliant-data-centers">Download our HIPAA Compliant Data Centers white paper</a> now for a complete guide to HIPAA hosting with IT vendors.</span></div>
<div><span style="line-height: 18px;"><br />
</span></div>
<div><span style="line-height: 18px;"><strong>Still have questions? </strong><a href="contact">Contact us</a> or <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">chat</a> with us now. Find out more about our fully compliant, <a href="secure-hosting/hipaa-compliant-hosting/packages">HIPAA hosting solutions</a>, or <a href="secure-hosting/hipaa-compliant-hosting/quote">submit a quote request</a> for your project today.</span></div>
<div>
<hr />
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/keep-ephi-on-secure-networks-not-mobile-devices-recommends-ocr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Liveblogging from Online Tech&#8217;s Spring into IT Seminar!</title>
		<link>http://resource.onlinetech.com/liveblogging-from-online-techs-spring-into-it-seminar/</link>
		<comments>http://resource.onlinetech.com/liveblogging-from-online-techs-spring-into-it-seminar/#comments</comments>
		<pubDate>Fri, 11 May 2012 12:29:50 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[online tech data center]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[spring into IT]]></category>
		<category><![CDATA[two-factor authentication]]></category>
		<category><![CDATA[vulnerability scanning]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6890</guid>
		<description><![CDATA[I&#8217;m liveblogging from Online Tech&#8217;s Ann Arbor data center &#8211; our Spring into IT seminar is underway! The first presentation of the day is You Are Vulnerable: How Not to be a Data Breach Statistic by Adam Goslin of High-Bit Security, &#8230; <a href="http://resource.onlinetech.com/liveblogging-from-online-techs-spring-into-it-seminar/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m liveblogging from Online Tech&#8217;s Ann Arbor data center &#8211; our Spring into IT seminar is underway! The first presentation of the day is <em>You Are Vulnerable: How Not to be a Data Breach Statistic </em>by Adam Goslin of High-Bit Security, at 8:30 A.M. There&#8217;s still time to join us for other sessions this morning until 1 P.M.</p>
<p>For the full schedule with times, speakers and location, check out <a href="http://www.onlinetech.com/resources/events/seminars/spring-into-it">Spring into IT</a>.</p>
<p>Stay tuned for live coverage of the presentations!</p>
<p><strong>8:30 A.M. &#8211; You Are Vulnerable: How Not to be a Data Breach Statistic</strong><br />
<em>Speaker: Adam Goslin</em></p>
<p>There&#8217;s been an increase of small-scale breaches involving small to medium-sized businesses. Recent breaches also involve lost or stolen devices (mobile phones or laptops). Encryption allows people a false sense of security &#8211; there are many other ways that security can be breached.</p>
<p>Mobile threats are also increasing with the use of mobile devices. Critical infrastructure attacks are also increasing &#8211; this includes malware that is designed to attack buildings. Breach costs are now averaged at $194 per record &#8211; this includes loss of business, remediation and more.</p>
<p>Only 10 percent of software developers and IT were documenting their security protocols.</p>
<p><strong>Vulnerability Scanning</strong></p>
<ul>
<li>Relatively inexpensive</li>
<li>Automated, pre-configured scan that will look for any configured, and known incompatibilities on your network</li>
</ul>
<p><strong>Penetration Testing</strong></p>
<ul>
<li>Significantly more expensive, but provides more coverage over networks, all devices, wireless systems and more</li>
<li>Detailed website and application testing</li>
<li>Performed and evaluated by a certified security engineer</li>
<li>A detailed report includes what was found, where it was found, and what the issue means, as well as specifics on how to resolve the issues</li>
</ul>
<p>A few ways to test the security of an organization include external hacking (ethical hacking) to find vulnerabilities of a system and social engineering &#8211; attempting to gain access to a system face-to-face.</p>
<p><strong>9:00 A.M. &#8211; Compliance Reporting and Remediation with VMware</strong><br />
<em>Speaker: Brian Foley</em></p>
<p><em>Introducing vCenter Configuration Manager</em></p>
<p>Customer concerns include: lacking visibility into their environment, dealing with change management issues, industry compliance standards, ensuring systems are patched.</p>
<p>VCM is cloud-ready, with quick-time-to-value to meet compliance requirements &#8211; compliance standards are built into the system.</p>
<p>Benefits include:</p>
<ul>
<li>Correlate performance to change with change management logs.</li>
<li>Allows you to create and customize your own compliance rules, as well as a number of predefined compliance standards that can check your current system against.</li>
<li>VCM also gives real-time and historical graphs of your degree of ongoing compliance, and allows for accelerated auditing with automated compliance.</li>
</ul>
<p><strong>9:30 A.M. &#8211; HIPAA at 16</strong><br />
<strong></strong><em>Speaker: Joe Dylewski</em></p>
<p>HITECH was created in order to enforce the implementation of EMR (electronic medical record) systems by providing incentives for healthcare organizations. Meaningful use was created for physicians to prove the systems were being used. The maximum breach penalty was increased to $1.5 million.</p>
<div id="attachment_6902" class="wp-caption alignnone" style="width: 504px"><img class="wp-image-6902 " title="Spring into IT Seminar Speaker Joe Dylewski" src="http://resource.onlinetech.com/wp-content/uploads/Spring-into-IT-Seminar-Speaker-Joe-Dylewski.jpg" alt="Spring into IT Seminar Speaker Joe Dylewski" width="494" height="370" /><p class="wp-caption-text">Spring into IT Seminar Speaker Joe Dylewski</p></div>
<p><strong>10:00 A.M. &#8211; Data Security in the Cloud</strong><br />
<strong></strong><em>Speaker: Steve Aiello, CISSP</em></p>
<p>Cloud computing security is a corporate strategy. Most of the vulnerabilities and threats have been around for a long time. Security concerns have risen due to the major attacks on Sony, PBS, CIA, FBI, PayPal and other large corporations. Just because you&#8217;re compliant, it does not mean you are secure.</p>
<p>What is Security? It&#8217;s the CIA Triad &#8211; includes the confidentiality, availability and integrity of the data.</p>
<ul>
<li><strong>Confidentiality</strong> &#8211; Keep information private. Determine what&#8217;s intellectual property to your company, and what needs to stay secure.</li>
<li><strong>Integrity</strong> &#8211; Keeping your data intact/accurate.</li>
<li><strong>Availability</strong> &#8211; Your data is there when you need it.</li>
</ul>
<p>Question to ask your company: Where can you reinvest cost-savings from using cloud technologies to improve overall security?</p>
<p>Something to consider: the introduction of external parties/providers shouldn&#8217;t lessen your security profile. Questions to ask about your vendor:</p>
<ul>
<li>Is your cloud provider audited regularly?</li>
<li>Will they share the results of their audit?</li>
<li>Do they have processes in place to pass on that tribal knowledge?</li>
</ul>
<p>Provider offerings that increase security:</p>
<ul>
<li>WAF</li>
<li>Encryption</li>
<li>Unique user IDs</li>
<li>Two-factor authentication</li>
<li>Applications</li>
<li>And more</li>
</ul>
<p>Cloud Options vs. Security</p>
<ul>
<li>The lower down the cloud stack the service providers tops, the more security you as a user absorbs</li>
</ul>
<p>Potential targeted technology:</p>
<ul>
<li>Hypervisors</li>
<li>Orchestration Tools</li>
<li>Administrative Machines</li>
<li>API Endpoints</li>
<li>Virtual Machines</li>
<li>Applications</li>
</ul>
<p><strong>10:30 A.M. &#8211; Two-Factor Authentication</strong><br />
<em>Speaker: Chris Schmitt</em></p>
<p>Factors of authentication include something you are (biometrics), something you own (card), and something you know (pin number). Two-factor is required for PCI compliance.</p>
<p>Ideal for protecting sensitive data &#8211; it&#8217;s important to have wide integration with the two-factor tool you choose. TFA solves the problem of a weak password &#8211; it provides an extra layer of security, and helps with access control. TFA doesn&#8217;t solve regulatory financial compliance.</p>
<p>When picking a TFA solution, focus on simplicity and management &#8211; the ability to sign up all users at one time and easily manage them is ideal. Online Tech uses Duo Security, an Ann Arbor-based tech company. Uptime availability is also important.</p>
<p><strong>11:00 A.M. - How to Properly Configure a High Availability Server Rack</strong><br />
<em>Speaker: Noah Wolff</em></p>
<p>[This will be video-taped and posted after the seminar concludes].</p>
<p>High availability is the percentage of time a system is available &#8211; do you need it? Consider the costs/consequences of downtime and your mission critical applications.</p>
<p>Common HA misconceptions &#8211; having a UPS is enough, having two firewalls is enough, power supplies on a server is enough, and collocating in a data center is enough (although a DC may provide HA, you may not be taking advantage of it).</p>
<p>Reasons to go HA &#8211; ease of maintenance, a single point of failure can affect your uptime and downtime can mean a loss of clients and business.</p>
<p>HA does not protect you from security breaches or human error. Backup is still important, even if you do have HA. DR assumes multiple points of failure. HA does cost more, and does not cover all possible sources of failure.</p>
<p>The most common mistake with configuring for HA is the failure to test it.</p>
<div id="attachment_6908" class="wp-caption alignnone" style="width: 504px"><img class="wp-image-6908 " title="Noah Configuring a HA Server Rack" src="http://resource.onlinetech.com/wp-content/uploads/Noah-Configuring-a-HA-Server-Rack.jpg" alt="Noah Configuring a HA Server Rack" width="494" height="370" /><p class="wp-caption-text">Noah Configuring a HA Server Rack</p></div>
<p><strong>12:00 -The Mobile Explosion: What Does it Mean for You, Your Business, and Michigan&#8217;s Economy</strong><br />
<em>Speaker: Linda Daichendt</em></p>
<p>Mobile is today&#8217;s primary consumer device &#8211; 5.3 billion have mobile devices of some kind, and 1.1 billion have tablets or laptops. We have 103.9% mobile subscriptions per capita, meaning more subscriptions than our entire population.</p>
<p>Consumption of the internet via mobile phones has increased over 1200% in the last few years. When it comes to marketing, the average response rate to a mobile offer is between 12-15%. Depending on the type of business (consumer-based), some markets have seen over 60% response rates.</p>
<div id="attachment_6912" class="wp-caption alignnone" style="width: 503px"><img class=" wp-image-6912    " title="Linda Daichendt's Keynote Speech on Mobile Trends" src="http://resource.onlinetech.com/wp-content/uploads/Linda-Daichendts-Keynote-Speech-on-Mobile-Trends.jpg" alt="Linda Daichendt's Keynote Speech on Mobile Trends" width="493" height="370" /><p class="wp-caption-text">Linda Daichendt&#39;s Keynote Speech on Mobile Trends</p></div>
<p>Check back to our blog in the next week for a full blog post on the mobile trends, statistics and latest technology presented by Linda.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/liveblogging-from-online-techs-spring-into-it-seminar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare Organizations: Seeking a Cloud Provider? BAAs Required</title>
		<link>http://resource.onlinetech.com/healthcare-organizations-seeking-a-cloud-provider-baas-required/</link>
		<comments>http://resource.onlinetech.com/healthcare-organizations-seeking-a-cloud-provider-baas-required/#comments</comments>
		<pubDate>Thu, 10 May 2012 13:15:00 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[private clouds]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6865</guid>
		<description><![CDATA[If you use a cloud service, it should be your business associate. If they refuse to sign a business associate agreement, don&#8217;t use the cloud service. - David S. Holtzman of the Health Information Privacy Division of OCR during a &#8230; <a href="http://resource.onlinetech.com/healthcare-organizations-seeking-a-cloud-provider-baas-required/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<blockquote>
<p dir="ltr"><strong>If you use a cloud service, it should be your business associate. If they refuse to sign a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#Business Associate Agreement">business associate agreement</a>, don&#8217;t use the cloud service.</strong></p>
<p dir="ltr"><em>- David S. Holtzman of the Health Information Privacy Division of OCR during a speech at the Health Care Compliance Association&#8217;s 16th Annual Compliance Institute.</em></p>
</blockquote>
<p>The OCR, Office of Civil Rights, is the federal enforcer of HIPAA/HITECH. This definitive statement straight from the governing body puts to rest the question about whether or not <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud providers</a> should be considered business associates for covered entities in the healthcare industry, as well as the question of whether a business associate agreement is required or not.</p>
<p>Holtzman’s speech included a specific example of a recent <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">HIPAA violation</a> involving the Phoenix Cardiac Surgery physician practice. Protected health information (PHI) was found posted on an Internet-based calendar, openly available to the public. The practice was using a public cloud-based application that did not have any privacy or security controls.</p>
<p>The lessons learned, according to Holtzman, include the physician’s lack of security and privacy controls, as well as the failure to consider cloud providers to be business associates and sign a business associate agreement (BAA).</p>
<p><strong>Why is it imperative to sign a BAA with a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages">HIPAA cloud provider</a>, as a healthcare organization concerned about PHI security and HIPAA compliance?</strong></p>
<p><strong>Ownership</strong><br />
Who has access to data and rights to your data should be clarified in the BAA with your cloud provider &#8211; some cloud providers may include provisions in your contract that give them ownership and control of your data while hosted in their environment. Loss of ownership and control may mean your PHI can be left vulnerable to a breach.</p>
<p><strong>Location</strong><br />
HIPAA security standards apply to covered entities within the United States; if your data is being hosted overseas, the same privacy and security laws may not apply. Know where your data lives and assess the physical, logical and network security of the data center or hosting facility. Read more about <a href="http://www.onlinetech.com/company/michigan-data-centers/features/data-center-security">Data Center Security</a> and <a href="http://www.onlinetech.com/secure-hosting/overview">Secure Hosting</a>.</p>
<p><strong>Breach Notification</strong><br />
A clause in your BAA should address breach notification in the event of a data leak &#8211; if your cloud provider is aware of a breach, they should have a plan in place that outlines a timeline of notifying the covered entity and their next steps. The OCR requires multiple documents within ten days of a breach &#8211; check that your cloud provider is aware of and has the information or ability to help you collect and/or create those documents.</p>
<p><strong>Security and Privacy Controls</strong><br />
Does your cloud provider have documented policies and procedures in place that include employee training on how to securely handle PHI? The obligations and responsibilities of the cloud provider should be outlined in your BAA clearly.</p>
<p><strong>Protocol After Termination</strong><br />
After contract termination with a cloud provider, the terms of data destruction and/or how to return the data to the covered entity should be addressed. Keeping copies of sensitive information within your organization is key to maintaining the data confidentiality and access limitation.</p>
<p>The OCR’s HIPAA audit pilot program launched late last year was intended to identify areas of improvement for covered entities when it comes to data security. With this field research, the OCR can provide more useful guidelines for other healthcare organizations, including the necessity of signing of a BAA with cloud vendors.</p>
<p><em><strong>Recommended Reading</strong></em><br />
<a href="http://resource.onlinetech.com/what%E2%80%99s-in-a-business-associate-agreement/"> What&#8217;s in a Business Associate Agreement?</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/five-questions-to-ask-your-business-associates/question-1-breach-notification/baa-breach-notification-clause"> Online Tech&#8217;s BAA Breach Notification Clause</a><br />
<a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider"> Five Questions to Ask Your HIPAA Hosting Provider</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/who-needs-to-be-hipaa-compliant"> Who Needs to Be HIPAA Compliant?</a></p>
<p>References:<br />
HIPAA Audits Wrapping Up at Year&#8217;s End as Federal Funding Winds Down &#8211; <a href="http://www.bna.com/health-law-resource-center-p6638/">Health Law Resource Center, Bloomberg BNA</a></p>
<hr />
<div><span style="line-height: 18px;"><a href="resources/white-papers/hipaa-compliant-data-centers"><img style="float: left;" src="http://resource.onlinetech.com/wp-content/uploads/hipaa-white-paper.gif" alt="HIPAA Compliant Data Centers" width="150" /></a>Looking for more information on HIPAA IT requirements, recommendations, and the foundation of a secure HIPAA compliant data center? </span></div>
<div><span style="line-height: 18px;"><br />
</span></div>
<div><span style="line-height: 18px;"><a href="resources/white-papers/hipaa-compliant-data-centers">Download our HIPAA Compliant Data Centers white paper</a> now for a complete guide to HIPAA hosting with IT vendors.</span></div>
<div><span style="line-height: 18px;"><br />
</span></div>
<div><span style="line-height: 18px;"><strong>Still have questions? </strong><a href="contact">Contact us</a> or <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">chat</a> with us now. Find out more about our fully compliant, <a href="secure-hosting/hipaa-compliant-hosting/packages">HIPAA hosting solutions</a>, or <a href="secure-hosting/hipaa-compliant-hosting/quote">submit a quote request</a> for your project today.</span></div>
<div>
<hr />
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/healthcare-organizations-seeking-a-cloud-provider-baas-required/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Security: Trying to Keep Up</title>
		<link>http://resource.onlinetech.com/mobile-security-trying-to-keep-up/</link>
		<comments>http://resource.onlinetech.com/mobile-security-trying-to-keep-up/#comments</comments>
		<pubDate>Tue, 08 May 2012 20:50:05 +0000</pubDate>
		<dc:creator>Aaron Riddle</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[two-factor authentication]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6855</guid>
		<description><![CDATA[There’s no question that our society is embracing the technology that is in front of us. You can go back almost 25 years and in 5 year gaps, see the massive innovation and technological impact that our society is seeing &#8230; <a href="http://resource.onlinetech.com/mobile-security-trying-to-keep-up/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_6858" class="wp-caption alignleft" style="width: 183px"><img class="size-full wp-image-6858" title="Mobile Security" src="http://resource.onlinetech.com/wp-content/uploads/Mobile-Security.png" alt="Mobile Security" width="173" height="260" /><p class="wp-caption-text">Mobile Security</p></div>
<p>There’s no question that our society is embracing the technology that is in front of us. You can go back almost 25 years and in 5 year gaps, see the massive innovation and technological impact that our society is seeing on an everyday basis. In the US today, more than 50% of cell phone purchases are now smartphones, up from 21% two years ago. With this massive increase in mobile computing, security has become the focal point. However, it has seemed that security is always on the tail end of the explosion in the mobile computing sphere.</p>
<p>This past January, a story broke out about a man who forgot his passport as he was entering customs to enter the United States from Canada. Realizing he had a scanned image of his passport on his iPad, he then proceeded to hand his iPad to the customs agent in hopes of it being enough to get him into the United States. After a few minutes of deliberation and some awkward looks, he was allowed into the United States with his scanned image of his passport in hand towards his destination. According to border officials, these types of situations are usually handled on an individual basis and can go many different ways, but this type of thinking by this man is a possible realization of things to come.</p>
<p>With the technology available, there is an opportunity to have documents with us at all times when we need them. Not only could this result in us having access to our music, videos and pictures at a moments notice, but personal documents as well. This could pose a huge security risk to ourselves.  There is always someone trying to manipulate systems in place for their own benefit. People have created fake passports, fake IDs, and have found many loopholes in systems. These types of malicious activity happen all the time and are a continuing and growing threat to our everyday life.</p>
<p>In an everchanging world, more and more of these types of cases will be coming up in the near future. There are already talks and technologies in place where your phone could become a personal wallet to make transactions with the flick of a wrist. It wouldn’t surprise me if there comes a day when we’ll have scans of all of our sensitive documents (SSN Cards, birth certificates, financial documents) all on our tablets for identification purposes and having a paper copy becomes obsolete. If this becomes the norm of mobile computing, there needs to be measures on all ends of the spectrum to better secure ourselves.</p>
<p>This first and foremost starts with the user. Whether that’s having some sort of <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">Disaster Recovery</a> plan to all of your files, or implementing a <a href="http://resource.onlinetech.com/two-factor-authentication-to-meet-hipaa-and-pci-compliance/">Two-Factor Authentication</a> solution to the mix, there are ways where you can keep yourself better protected. Until there are full security measures in place among everyone and is implemented by everyone, security will always be a huge factor to the future of mobile computing as it stands today.</p>
<p>On the topic of Mobile Security, Linda Daichendt from the Mobile Technology Association of Michigan will be the keynote speaker at our <a href="http://www.onlinetech.com/resources/events/seminars/spring-into-it">Spring into IT</a> event on May 11th discussing: “The Mobile Explosion: What Does it Mean for You, Your Business, and Michigan’s Economy”.</p>
<p>For more information on mobile security, check out <a href="http://resource.onlinetech.com/mobile-security-how-safe-is-your-data/">Mobile Security: How Safe Is Your Data?</a> and <a href="http://resource.onlinetech.com/mobile-security-are-most-apps-safe/">Mobile Security: Are Your Apps Safe?</a></p>
<p>Sources:<br />
<a href="http://blog.nielsen.com/nielsenwire/online_mobile/smartphones-account-for-half-of-all-mobile-phones-dominate-new-phone-purchases-in-the-us/">http://blog.nielsen.com/nielsenwire/online_mobile/smartphones-account-for-half-of-all-mobile-phones-dominate-new-phone-purchases-in-the-us/</a><br />
<a href="http://www.theglobeandmail.com/news/national/flash-of-an-ipad-gets-man-past-border-security/article2290029/">http://www.theglobeandmail.com/news/national/flash-of-an-ipad-gets-man-past-border-security/article2290029/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/mobile-security-trying-to-keep-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech On The Michigan Business Network</title>
		<link>http://resource.onlinetech.com/online-tech-on-the-michigan-business-network/</link>
		<comments>http://resource.onlinetech.com/online-tech-on-the-michigan-business-network/#comments</comments>
		<pubDate>Tue, 08 May 2012 19:34:48 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6844</guid>
		<description><![CDATA[Yan Ness, CEO of Online Tech, will be on the Michigan Business Network, 10 A.M. ET tomorrow morning. Be sure to tune in and listen online! If you happen to miss a show, you can always listen to podcasts of &#8230; <a href="http://resource.onlinetech.com/online-tech-on-the-michigan-business-network/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_6846" class="wp-caption alignleft" style="width: 178px"><img class="wp-image-6846  " title="Michigan Business Network" src="http://resource.onlinetech.com/wp-content/uploads/Michigan-Business-Network.jpg" alt="Michigan Business Network" width="168" height="168" /><p class="wp-caption-text">Michigan Business Network</p></div>
<p>Yan Ness, CEO of Online Tech, will be on the Michigan Business Network, 10 A.M. ET tomorrow morning. Be sure to tune in and <a href="http://michiganbusinessnetwork.com/">listen online</a>!</p>
<p>If you happen to miss a show, you can always listen to podcasts of previous programs by using the Michigan Business Network&#8217;s <a href="http://michiganbusinessnetwork.com/radio/">Broadcast Schedule</a>. We&#8217;ll post a link to the podcast after it airs.</p>
<p>Yan will discuss our upcoming <a href="http://www.onlinetech.com/resources/events/seminars/spring-into-it">Spring into IT</a> seminar scheduled for this Friday morning, with seminar sessions running from 8 A.M. to 1 P.M. ET at our newest <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor data center</a>.</p>
<p>It&#8217;s free to attend, and online registration is still open. Please join us for just one session or stay for the special noon keynote on mobile technology.  <a href="http://www.onlinetech.com/resources/events/seminars/spring-into-it">Register online</a> today.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-on-the-michigan-business-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Raising the Bar on Security, Reliability and Compliance</title>
		<link>http://resource.onlinetech.com/raising-the-bar-on-security-reliability-and-compliance/</link>
		<comments>http://resource.onlinetech.com/raising-the-bar-on-security-reliability-and-compliance/#comments</comments>
		<pubDate>Tue, 08 May 2012 14:42:29 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[energy star]]></category>
		<category><![CDATA[michigan data center]]></category>
		<category><![CDATA[pci audit]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[two-factor authentication]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6834</guid>
		<description><![CDATA[An update from Online Tech&#8217;s President: As we roll into spring, Online Tech continues to raise the bar on the security, reliability and compliance of our data centers and services.  Here is a brief list of some of the capabilities &#8230; <a href="http://resource.onlinetech.com/raising-the-bar-on-security-reliability-and-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>An update from Online Tech&#8217;s President:</p>
<p>As we roll into spring, Online Tech continues to raise the bar on the security, reliability and compliance of our data centers and services.  Here is a brief list of some of the capabilities we’ve added over the first four months of this year:</p>
<p><strong>Audits and Compliance:</strong><br />
As you may know, we continue to invest heavily to ensure we meet the top tier of data center standards.  In the recent months, we’ve successfully completed three new audits:</p>
<ul>
<li><strong>SOC 2 &amp; SOC 3 Audits</strong> – Online Tech was the first multi-tenant data center in the country to complete this much more stringent AICPA audit. SOC 2 is a more objective standard for high quality data center operators and we passed the audit with flying colors.  You can read more on this audit at: <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=763f533348&amp;e=a9fb62ad83">http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting</a></li>
<li><strong>PCI Audit</strong> – In February we completed one of the most technically demanding audits for security in the Payment Card Industry (PCI).  <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=0f9c4cd8d4&amp;e=a9fb62ad83">PCI compliance</a> is required for any company that receives, processes or stores credit card information on their servers.</li>
<li><strong>Energy Star Certification</strong> – With our investments last year in our Mid-Michigan data center, we achieved the <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=65abb02f1f&amp;e=a9fb62ad83">EPA’s Energy Star Certification</a> for energy efficiency.  The Mid-Michigan data center performs in the top 25 percent of data centers nationwide for energy efficiency and meets strict performance levels set by the EPA.</li>
</ul>
<p><strong>Data Center Infrastructure:</strong></p>
<ul>
<li><strong>New Fiber into Mid-Michigan</strong> – We’ve added another optic path to our Internet providers in Mid-Michigan – increasing the redundancy and resiliency of our Internet connections.</li>
<li><strong>Comcast Fiber in Mid-Michigan</strong> – Comcast has also installed fiber into Mid-Michigan. Comcast Business Class is an additional connection option for our clients that need high speed direct connection to our data centers.</li>
<li>We also added a redundant dark fiber circuit between our Ann Arbor data centers.  This second path takes an entirely different route through the Avis Farms office park &#8211; providing a more resilient connection between the two data centers.</li>
</ul>
<p><strong>New Network Security Services:</strong><br />
In the next 90 days, we will be rolling out an enhanced set of network services to meet PCI security requirements. The first of these services is two-factor VPN authentication.</p>
<ul>
<li><a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=f06722cd2b&amp;e=a9fb62ad83">Two-factor VPN Authentication</a>– We teamed up with Duo Security to provide a simple, mobile phone-based authentication method that is much more convenient and easier to use traditional two-factor systems. The security measure adds an extra layer of protection to critical VPN connections by requiring a secondary authentication method to achieve network access.  If you have critical data such as financial or healthcare information on your servers, we recommend you take a look at two-factor VPN authentication.</li>
</ul>
<p><strong>Website &amp; Seminars:</strong></p>
<ul>
<li><a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=89bd42533b&amp;e=a9fb62ad83">Spring into IT Seminar</a>- This Friday, May 11<sup>th</sup>, we’re bringing in the experts on Mobile Computing, Cloud Security, HIPAA, PCI Compliance, and Network Security for a morning of technical seminars at our Ann Arbor 2 data center.  We’d love to have you join us.  You can register at: <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=ebc62549dd&amp;e=a9fb62ad83">http://www.onlinetech.com/resources/events/seminars/spring-into-it</a></li>
<li>New Web Site &amp; Blog – We launched our new website at the beginning of this year and we’d love your feedback.  Something confusing?  Something you love?  Let us know.  We appreciate your feedback because it helps us continue to better serve you.</li>
</ul>
<p><strong>Net Promoter Score:</strong></p>
<ul>
<li>We started using the Net Promoter System (NPS) from the book “The Ultimate Question 2.0” by Fred Reichheld to track and measure client satisfaction. We want to consistently deliver excellent client service through our metrics, accountability and visibility.</li>
</ul>
<p>As you can see, we’re working hard to earn our reputation as one of the top mission-critical data center operators in the country.  We look forward to continuing to serve your hosting needs.</p>
<p>Best Regards,</p>
<p>Mike Klein<br />
President &amp; Chief Operating Officer<br />
Online Tech Inc.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/raising-the-bar-on-security-reliability-and-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Update: Tech Seminar, White Paper and Scholarships</title>
		<link>http://resource.onlinetech.com/online-tech-update-tech-seminar-white-paper-and-scholarships/</link>
		<comments>http://resource.onlinetech.com/online-tech-update-tech-seminar-white-paper-and-scholarships/#comments</comments>
		<pubDate>Mon, 07 May 2012 16:19:42 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[cloud computing event]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa hosting requirements]]></category>
		<category><![CDATA[michigan scholarships]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[tech scholarships]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6812</guid>
		<description><![CDATA[Here&#8217;s a brief roundup of what&#8217;s new with Online Tech in May: Spring into IT This Friday, we&#8217;re bringing in the experts to launch technical discussions and provide tactical knowledge around topics like cloud computing security, HIPAA compliance, how to &#8230; <a href="http://resource.onlinetech.com/online-tech-update-tech-seminar-white-paper-and-scholarships/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a brief roundup of what&#8217;s new with Online Tech in May:</p>
<h2>Spring into IT</h2>
<div id="attachment_6817" class="wp-caption alignleft" style="width: 376px"><img class=" wp-image-6817   " title="Spring into IT May 2012" src="http://resource.onlinetech.com/wp-content/uploads/Spring-into-IT-May-2012.png" alt="Spring into IT May 2012" width="366" height="144" /><p class="wp-caption-text">Spring into IT May 2012</p></div>
<p>This Friday, we&#8217;re bringing in the experts to launch technical discussions and provide tactical knowledge around topics like <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> security, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a>, how to properly configure server racks, how to comply with <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/what-is-pci-compliance">PCI DSS standards</a>, and more.</p>
<p>Don&#8217;t miss our special noon keynote speaker, Linda Daichendt, Executive Director of the Mobile Technology Association of Michigan, and her presentation on &#8220;The Mobile Explosion: What Does it Mean for You, Your Business, and Michigan&#8217;s Economy.&#8221;</p>
<p>Stay for a few sessions, breakfast or lunch, or join us for the morning for great networking opportunities. Sign up online and view the seminar schedule and location <a href="http://www.onlinetech.com/resources/events/seminars/spring-into-it">here</a>.</p>
<h2>HIPAA Compliant Data Centers White Paper</h2>
<p>CIO&#8217;s, CEO&#8217;s, physicians, healthcare SaaS (Software-as-a-Service providers) and any other IT decision-maker or influencer should download and read this paper.</p>
<p><img class="alignleft" title="HIPAA Compliant Data Centers" src="http://resource.onlinetech.com/wp-content/uploads/hipaa-white-paper.gif" alt="HIPAA Compliant Data Centers" width="181" height="132" />This is a comprehensive, detailed document for anyone seeking more information about the implications of HIPAA/HITECH on data centers, the role of business associates, specific technology requirements and recommendations, and more.</p>
<p>We consulted with a Certified HIPAA Security Specialist (CHSS) and internal engineers to create a diagram comparing each HIPAA standard to our applied technology to create a secure and private hosting environment. We&#8217;re serious about compliance, and we want to share our research and knowledge to educate the industry to make more informed hosting decisions. <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">Download the white paper</a> today.</p>
<h2>Data Security Scholarships</h2>
<p>Stay tuned for more about this great opportunity for tech-minded students interested in health IT, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a>, data security, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a>, <a href="http://www.onlinetech.com/colocation/overview">colocation </a>and a variety of other topics. We&#8217;ll post a detailed blog tomorrow about how to sign up and what you&#8217;ll need to enter the scholarship program.</p>
<h2>IMN Data Center Forum in NYC</h2>
<p><img class="alignleft" title="IMN Data Center Forum" src="http://resource.onlinetech.com/wp-content/uploads/IMN-Data-Center-Forum-May-2012.jpg" alt="IMN Data Center Forum" width="286" height="124" /></p>
<p>Online Tech will be attending the <a href="http://www.imn.org/Conference/Financing-Investing--Real-Estate-Development-for-Data-Centers/Event_Description.html">Second Annual Spring Forum on Financing, Investing and Real Estate Development for Data Centers</a> at the end of May, in New York City, New York.</p>
<p>Online Tech CEO and President Mike Klein will be leading a session on <em><strong>Evaluating Data Center Business Models</strong></em>, May 24 at 8:30 A.M. Find out more about session and panel <a href="http://www.onlinetech.com/resources/events/seminars/online-tech-to-speak-at-imn-data-center-forum-in-nyc">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-update-tech-seminar-white-paper-and-scholarships/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Data: What It Means for Science, Healthcare and Social Media</title>
		<link>http://resource.onlinetech.com/big-data-what-it-means-for-science-healthcare-and-social-media/</link>
		<comments>http://resource.onlinetech.com/big-data-what-it-means-for-science-healthcare-and-social-media/#comments</comments>
		<pubDate>Fri, 04 May 2012 12:49:30 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[big data]]></category>
		<category><![CDATA[big data healthcare]]></category>
		<category><![CDATA[big data science]]></category>
		<category><![CDATA[big data social media]]></category>
		<category><![CDATA[high-capacity cloud]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6789</guid>
		<description><![CDATA[It is just what it sounds like &#8211; an immense amount of data.  From social networks to genomics to medical records, big data is everywhere and rapidly growing. Technology must adapt and advance in the management of big data &#8211; &#8230; <a href="http://resource.onlinetech.com/big-data-what-it-means-for-science-healthcare-and-social-media/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>It is just what it sounds like &#8211; an immense amount of data.  From social networks to genomics to medical records, big data is everywhere and rapidly growing. Technology must adapt and advance in the management of big data &#8211; otherwise these large data sets would be rendered useless without the capability to efficiently analyze and produce results. Federal agencies have announced $200 million in research and development investments that will allow them to mine, process and store big data.</p>
<h2>Science</h2>
<div id="attachment_6795" class="wp-caption aligncenter" style="width: 579px"><img class=" wp-image-6795  " title="Cancer Genomics Hub" src="http://resource.onlinetech.com/wp-content/uploads/Cancer-Genomics-Hub.png" alt="Cancer Genomics Hub" width="569" height="163" /><p class="wp-caption-text">Cancer Genomics Hub</p></div>
<p>The National Cancer Institute is funding a $10.5 million project managed by UC Santa Cruz for a supercomputer that will store the genetic codes of malignancies from 10,000 patients with the intent of revealing mutations that trigger uncontrolled cell growth. The Cancer Genomics Hub (CGHub), said to be the world&#8217;s largest repository for cancer genomes, will sift through the large amount of data attempting to find gene mutations that cause tumors and make it easier to make cross-dataset comparisons &#8211; significantly accelerating the time it takes to analyze and produce results from data sets.</p>
<p>To get an idea of why big data is so big &#8211; according to the Oakland Tribune, each tumor’s DNA record is 300 billion bytes (1 gigabyte), which has to be compared to a normal genome (billions of bytes), plus the sequence data from RNA &#8211; all adding up to nearly a terabyte for each case.</p>
<h2>Healthcare</h2>
<p>Not only does big data have major implications for scientific breakthroughs, the aggregate and analysis of healthcare data sets can improve patient care. Digital records stored in electronic medical record or electronic health record systems (EMR/EHRs) can be mined to detect patterns in care. These patterns can help advance the healthcare industry by assisting in the automation of processes in the workflow of patient care, and get the industry up-to-speed with the technological advancement of other industries.</p>
<p>Hospitals and healthcare software companies also need storage-intensive hosting solutions for systems such as <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/pacs-hosting">PACS</a> (Picture Archiving and Communications Systems) that store and process medical imaging, including X-rays, MRIs, CAT/CT scans and others. A <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting/high-capacity-hipaa-cloud">high-capacity HIPAA cloud</a> with a managed SAN (Storage Area Network) can offer a scalable solution to healthcare’s big data needs.</p>
<h2>Social Media</h2>
<p>Social media involves the countless amount of user-generated data collected from various sources, including mobile phones &#8211; demanding an intelligent way to manage and analyze the content. DataSift is a U.K.-based startup launched to handle the vast amount of social media data by analyzing feed data based on pairing related quantifiers and keyphrases.</p>
<p>The company intends to take monitoring and data analysis to measure the level of intent-to-buy to help sales teams and companies build financial models based around customer conversations. The last week of April was even declared <a href="http://bigdataweek.com/">Big Data Week</a> by the Head of Client Services at DataSift and sponsored by Oracle and EMC, with meetups and communities in three countries to discuss big data innovations and startups.</p>
<p>While brands have been long tracking social media for mentions and support-related issues, entrepreneurs are taking it a step further by developing new and more meaningful ways to analyze big data in social media to shape and influence business decisions.</p>
<p>Twitter recently announced its plan to team up with UC Berkeley School of Information to develop and teach a class entirely about analyzing big data, aptly named, Analyzing Big Data with Twitter. The <a href="http://www.ischool.berkeley.edu/courses/290-abdt">course description</a> details the topics, including applied natural language processing algorithms such as sentiment analysis, large scale anomaly detection, real-time search and more. Students will get advising from Twitter engineers on programming-intensive projects that include building apps and social media data analysis.</p>
<p>Beyond the hype, big data has the potential to put hard facts and real figures behind scientific research, business development and healthcare management.</p>
<p>References:<br />
<a href="http://www.insidebayarea.com/news/ci_20521677/national-data-center-cancer-genomes-built-at-ucsc">Cancer Genome Data Center Raises Hope for Cures</a><br />
<a href="http://blogs.wsj.com/tech-europe/2012/05/03/datasift-offers-new-insights-into-customers/">DataSift Exploits Big Data for New Insights Into Customers</a><br />
<a href="http://thenextweb.com/socialmedia/2012/05/02/twitter-teams-up-with-uc-berkeley-to-teach-students-about-big-data/?awesm=tnw.to_1EGJK&amp;utm_campaign=social%20media&amp;utm_medium=Spreadus&amp;utm_source=Twitter&amp;utm_content=Twitter%20teams%20up%20with%20UC%20Berkeley%20to%20teach%20students%20about%20big%20data">Twitter Teams Up with UC Berkeley to Teach Students About Big Data</a><br />
<a href="http://www.nextgov.com/big-data/2012/03/white-house-launches-governmentwide-investment-in-big-data/50929/">White House Launches Government-Wide Investment in Big Data</a><br />
<a href="http://news.sciencemag.org/scienceinsider/2012/05/worlds-largest-hub-for-cancer.html?ref=hp">World&#8217;s Largest Hub for Cancer Genomes Opens</a><br />
<a href="https://cghub.ucsc.edu/index.html"> Cancer Genomics Hub &#8211; UC Santa Cruz</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/big-data-what-it-means-for-science-healthcare-and-social-media/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NIST Recommendations for Security in the Outsourced Cloud</title>
		<link>http://resource.onlinetech.com/nist-recommendations-for-security-in-the-outsourced-cloud/</link>
		<comments>http://resource.onlinetech.com/nist-recommendations-for-security-in-the-outsourced-cloud/#comments</comments>
		<pubDate>Wed, 02 May 2012 20:13:22 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6764</guid>
		<description><![CDATA[NIST (The National Institute of Standards and Technology) provides a number of recommendations addressing security and privacy issues with outsourcing cloud hosting services in its Guidelines on Security and Privacy in Public Cloud Computing published last December: Governance NIST refers &#8230; <a href="http://resource.onlinetech.com/nist-recommendations-for-security-in-the-outsourced-cloud/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>NIST (The National Institute of Standards and Technology) provides a number of recommendations addressing security and privacy issues with outsourcing <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> services in its <a href="http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf">Guidelines on Security and Privacy in Public Cloud Computing</a> published last December:</p>
<p><strong>Governance</strong><br />
NIST refers to the organizational controls over policies, procedures, standards of development, and the design, implementation, testing, use and monitoring of deployed services. In short, they explain that while the cloud requires less capital investment, it still requires a high level of employee training and administrative oversight to maintain security.</p>
<p>Governance also refers to proactive risk management in the form of deploying audit tools to determine how data is stored, protected and used. Securing an audit trail of user/system activity  is also a <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI DSS requirement</a> (10.5), and recommended for <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a>. The use of file integrity monitoring and log monitoring can provide continuous records of activity and alert you to any abnormal use to help prevent a breach.</p>
<p><strong>Compliance</strong><br />
While NIST recognizes the complexity and breadth of compliance regulations varying by industry, region and governing body, the take-home message is that organizations are ultimately held accountable for the security and privacy of data that is held by a cloud provider on their behalf.</p>
<p>NIST doesn’t come out and say cloud providers need to abide by the same standards that, for example, covered entities or health organizations in the healthcare industry need to follow. They also recognize that “the degree to which they will accept liability in their service agreements, for exposure of content under their control, remains to be seen.” This statement is more a reflection of current industry trends in compliance, instead of endorsing a standard that cloud providers should follow.</p>
<p>But if the organization is responsible for the security and privacy of data held by a cloud provider, then it’s up to the organization to do a thorough assessment of their cloud provider’s security controls and knowledge of industry standards.</p>
<p>Another aspect of compliance is data location &#8211; if outsourcing, be sure to tour their <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> facilities to know exactly where your data will live, and what kind of security is in place to protect it. Download our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA compliant data centers white paper</a> for a complete guide to HIPAA hosting.</p>
<p><strong>Trust</strong><br />
Direct control over security and privacy is transferred to the cloud provider, obviously demanding a fair amount of trust between the organization and provider. NIST recommends ensuring visibility into a cloud provider’s security and privacy controls and their performance over a period of time. NIST also recommends establishing cohesive and exclusive ownership rights over data.</p>
<p>Insider access can also lead to threats such as fraud and theft &#8211; ask your cloud provider if they do background checks on employees, and if they are properly trained on how to handle sensitive data.</p>
<p>Establishing data ownership and access, gaining visibility into security controls and conducting a risk analysis or assessment is fundamental to risk management. Prior to undergoing a third-party audit, a cloud provider should conduct a risk assessment of any potential vulnerabilities, whether alone or with the help of a security consultant. Find out what&#8217;s in a <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/whats-in-a-hipaa-risk-analysis">HIPAA risk analysis</a> (helpful for healthcare organizations and anyone concerned with security).</p>
<p>Stay tuned for future blog posts on other cloud security recommendations, including <em><strong>Architecture, Identity and Access Management, Software Isolation, Data Protection, Availability</strong></em> and <em><strong>Incident Response</strong></em>.</p>
<p>References:<br />
<a href="http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf">Guidelines on Security and Privacy in Public Cloud Computing</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/nist-recommendations-for-security-in-the-outsourced-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spring into IT: Online Tech Hosts Tech Seminar</title>
		<link>http://resource.onlinetech.com/spring-into-it-online-tech-hosts-tech-seminar/</link>
		<comments>http://resource.onlinetech.com/spring-into-it-online-tech-hosts-tech-seminar/#comments</comments>
		<pubDate>Tue, 01 May 2012 13:35:00 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[cloud computing event]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[data center events]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[michigan data center]]></category>
		<category><![CDATA[mobile technology]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6720</guid>
		<description><![CDATA[Online Tech will host a spring tech seminar next Friday, May 11 from 8 A.M.-1 P.M. at our Ann Arbor 2 data center location. Presentations by tech, security and compliance professionals include topics such as mobile technology, cloud security, and &#8230; <a href="http://resource.onlinetech.com/spring-into-it-online-tech-hosts-tech-seminar/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_6727" class="wp-caption alignleft" style="width: 618px"><img class=" wp-image-6727   " title="Spring Into IT 2012" src="http://resource.onlinetech.com/wp-content/uploads/Spring-Into-IT-2012.png" alt="Spring Into IT 2012" width="608" height="252" /><p class="wp-caption-text">Spring Into IT 2012</p></div>
<p>Online Tech will host a spring tech seminar next Friday, May 11 from 8 A.M.-1 P.M. at our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor 2 data center location</a>. Presentations by tech, security and compliance professionals include topics such as mobile technology, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud security</a>, and the implications of meaningful use on <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA</a> for healthcare IT.</p>
<p>Attend for one session or the entire morning to take advantage of networking opportunities and knowledge-sharing presentations. Sessions and speakers include:</p>
<p><strong>Seminar Schedule</strong><br />
8:00am- Registration, Networking and Breakfast</p>
<p><em><strong>Seminar Track 1</strong><br />
</em></p>
<ul>
<li>8:30am &#8211; Adam Goslin, High Bit Security, <em>You Are Vulnerable: How Not to be a Data Breach Statistic</em></li>
<li>9:30am &#8211; Joe Dylewski, Health Care Management, <em>HIPAA at 16</em></li>
<li>10:30am &#8211; Chris Schmitt, Online Tech, <em><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/two-factor-authentication-for-vpn-login-faq">Two-Factor Authentication</a> to Protect Sensitive Data</em></li>
<li>11:00am &#8211; Noah Wolff, Online Tech, <em>How to Properly Configure a High Availability Server Rack</em></li>
</ul>
<p><strong><em>Seminar Track 2</em> </strong></p>
<ul>
<li>9:00am &#8211; Brian Foley, <em>VMware, Compliance Reporting and Remediation with VMware</em></li>
<li>10:00am &#8211; Steve Aiello, Online Tech, <em>Data Security in the Cloud</em></li>
<li>11:00am &#8211; Adam Goslin, High Bit Security, <em>Payment Card Compliance- What Does it Mean and How to Comply Effectively</em></li>
</ul>
<p>12:00pm &#8211; Linda Daichendt, Mobile Technology Association of Michigan, <em>The Mobile Explosion: What Does it Mean for You, Your Business, and Michigan&#8217;s Economy</em></p>
<p>1:00pm &#8211; Lunch</p>
<p>Registration will begin at 8:00 A.M. with presentations starting at 9:00 A.M and a noon keynote on Mobile Technology Trends to conclude our seminar. Coffee and a continental breakfast will be served in the morning and gourmet pizza for lunch.</p>
<p>Seating is limited, so please be sure to reserve your seat for topics of interest by completing our <a href="http://www.onlinetech.com/resources/events/seminars/spring-into-it">online form</a>.</p>
<div class="wp-caption alignnone" style="width: 446px"><img class="   " title="Ann Arbor Data Center Tours" src="http://resource.onlinetech.com/wp-content/uploads/Ann-Arbor-Data-Center-Tours1.png" alt="Ann Arbor Data Center Tours" width="436" height="324" /><p class="wp-caption-text">Ann Arbor Data Center Tours</p></div>
<p><strong>About Our Ann Arbor Data Center</strong></p>
<p><img class="alignnone" title="Online Tech's Ann Arbor 2 Data Center" src="http://resource.onlinetech.com/wp-content/uploads/Ann-Arbor-2-Data-Center.jpg" alt="" width="484" height="199" /></p>
<p>Our newest Ann Arbor data center is a 19,500 square foot facility with 10,000 square feet of 12″ raised floor and high availability Internet connectivity. With diversified utility and network feeds, our data center is perfect for production and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> projects.</p>
<div id="attachment_6752" class="wp-caption alignleft" style="width: 271px"><img class="wp-image-6752  " title="Open House 2011" src="http://resource.onlinetech.com/wp-content/uploads/Open-House-20111.png" alt="Open House 2011" width="261" height="302" /><p class="wp-caption-text">Open House 2011</p></div>
<p>Like our other data centers, our Ann Arbor, <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> is independently audited and found to be <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/sas-70-data-centers">SAS 70</a>, <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/ssae-16-data-centers">SSAE 16</a>, <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/soc-2-data-centers">SOC 2 &amp; SOC 3</a> and <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant</a>. Visit <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor Data Center</a> for detailed specifications on the power, network infrastructure, security, and cooling capacity.</p>
<p>Previous events at our Ann Arbor data center location include a <a href="http://resource.onlinetech.com/u-of-m-ross-school-of-business-alumni-cloud-computing-seminar-recap/">UM Ross School of Business cloud computing seminar</a> and our <a href="http://resource.onlinetech.com/2011-ann-arbor-data-center-open-house/">data center open house</a> &#8211; view photo slideshows of both on our <a href="http://www.flickr.com/photos/onlinetech">OT Flickr</a>.</p>
<p>If you&#8217;d like to host your next event at our data center, contact us by emailing <a href="mailto:contactus@onlinetech.com">contactus@onlinetech.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/spring-into-it-online-tech-hosts-tech-seminar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech to Speak at IMN Data Center Forum in NYC</title>
		<link>http://resource.onlinetech.com/online-tech-to-speak-at-imn-data-center-forum-in-nyc/</link>
		<comments>http://resource.onlinetech.com/online-tech-to-speak-at-imn-data-center-forum-in-nyc/#comments</comments>
		<pubDate>Mon, 30 Apr 2012 15:09:57 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[data center events]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6700</guid>
		<description><![CDATA[Online Tech will be attending the Second Annual Spring Forum on Financing, Investing and Real Estate Development for Data Centers at the end of May, in New York City, New York. The event is hosted by the Information Management Network &#8230; <a href="http://resource.onlinetech.com/online-tech-to-speak-at-imn-data-center-forum-in-nyc/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_6707" class="wp-caption aligncenter" style="width: 486px"><img class="size-full wp-image-6707" title="IMN Data Center Forum May 2012" src="http://resource.onlinetech.com/wp-content/uploads/IMN-Data-Center-Forum-May-2012.jpg" alt="IMN Data Center Forum May 2012" width="476" height="207" /><p class="wp-caption-text">IMN Data Center Forum May 2012</p></div>
<p>Online Tech will be attending the <a href="http://www.imn.org/Conference/Financing-Investing--Real-Estate-Development-for-Data-Centers/Event_Description.html">Second Annual Spring Forum on Financing, Investing and Real Estate Development for Data Centers</a> at the end of May, in New York City, New York. The event is hosted by the Information Management Network (IMN), global organizers of institutional finance and investment conferences.</p>
<p>The forum will include panel discussions on the Macroeconomy &amp; Data Centers, the President/CEO panels and Mergers, Private Equity &amp; IPOs.</p>
<p>Online Tech CEO and President Mike Klein will be leading a session on <em><strong>Evaluating Data Center Business Models</strong></em>, May 24 at 8:30 A.M. The session will cover the following industry topics and emerging trends:</p>
<ul>
<li>As colo players expand &amp; wholesale players come down market and sell racks what is the distinction?</li>
<li>Can new players enter the wholesale market? What is the price tag?</li>
<li>Comparing power pricing &amp; lease pricing models and methodologies</li>
<li>Impact of the <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud</a></li>
<li>Building a shell vs. providing power and cooling vs. providing <a href="http://www.onlinetech.com/colocation/overview">colocation</a>/<a href="http://www.onlinetech.com/managed-services/overview">managed services</a></li>
<li>Customer target and employee skill sets of different approaches</li>
<li>Revenues and expenses of different approaches</li>
<li>Transitioning to managed services: How much does it cost? How much revenue will it pull in?</li>
</ul>
<p>Panel participants include C.J. Brucato III, Partner of Abry Partners, LLC; Carl Strang III, Managing Member of the 6/10 Corp.; Phil Horstmann, CEO of Ascent, LLC; Jonathan A. Schildkraut, Managing Director, Equity Research-Telecom Services &amp; Data Center Services of Evercore Partners; and Drew Leonard of Savvis.</p>
<p>Available panel participant biographies:</p>
<hr />
<p><strong>Mike Klein, President, Online Tech</strong></p>
<p><img class="alignleft" src="http://www.onlinetech.com/images/stories/people/mike-klein-100.jpg" alt="Mike Klein of Online Tech" width="65" /></p>
<p>Mike is a serial entrepreneur with more than 30 years of high tech business leadership, technology, and startup experience including CEO of Interlink Networks, Managing Partner of CompanyCrafters, and CEO /Founder of Steeplechase Software, an INC 500 Company which he sold to Schneider Electric. Prior to becoming an entrepreneur, Mike spent the first decade of his career working in sales, strategic marketing, product development at Motorola Semiconductor and Rockwell International.</p>
<hr />
<p><img class="alignleft" title="Jonathan Schildkraut" src="http://www.imn.org/images/speakers/jonathan_schildkraut.gif" alt="" width="65" height="80" /></p>
<p><strong>Jonathan A. Schildkraut, Managing Director, Equity Research-Telecom Services &amp; Data Center Services of Evercore Partners</strong></p>
<p>Jonathan Schildkraut is a Managing Director in the Equity Research group, leading the equities coverage of Telecom Services companies, including data center operators, RBOCs, CLECs, alternative backbone providers, and tower operators. In 2010, Mr. Schildkraut was recognized in FT Starmine&#8217;s annual Best Brokerage Analysts awards, where he ranked #1 in earnings estimates for Wireless (includes Towers), and #3 in earnings estimates for Diversified Telecom. In 2009, he ranked #1 in earnings estimates for Diversified Telecom, and #3 in earnings estimates for Wireless (includes Towers). In 2008, Mr. Schildkraut was recognized in Forbes&#8217;s Best of the Brokerage Analysts awards, where he ranked #3 in Telecommunications. Mr. Schildkraut has been in the telecommunications industry since 1997.</p>
<hr />
<p><strong>Drew Leonard of Savvis</strong></p>
<p>Drew Leonard has over 16 years in the Telecom and Data Center industry. As Vice President of Colocation Product Management for Savvis, Drew is responsible for enhancing colocation services, growing the business through new client and market opportunities, and ensuring that customers receive the most current and cost effective solutions. Prior to joining Savvis, Drew was Director of Product Marketing at Switch and Data Facilities, and Director of Marketing at PAIX. As a seasoned marketing professional for these Data center and internet exchange providers, Drew’s primary focus was developing detailed strategic marketing plans leveraging market and revenue opportunity through market sizing. Drew has continued to specialize in market sizing, market share analysis, strategic planning, market-based pricing, product development, channel marketing, and sales development. Drew has a Bachelor of Science degree from the University of California.</p>
<hr />
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-to-speak-at-imn-data-center-forum-in-nyc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliant Data Center Architecture</title>
		<link>http://resource.onlinetech.com/hipaa-compliant-data-center-architecture/</link>
		<comments>http://resource.onlinetech.com/hipaa-compliant-data-center-architecture/#comments</comments>
		<pubDate>Fri, 27 Apr 2012 14:48:38 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[hipaa compliant data center architecture]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa white papers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6675</guid>
		<description><![CDATA[Here&#8217;s an exclusive preview of our HIPAA Compliant Data Centers white paper &#8211; the 36 page document provides a detailed description of a HIPAA compliant data center IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria. The diagram &#8230; <a href="http://resource.onlinetech.com/hipaa-compliant-data-center-architecture/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s an exclusive preview of our HIPAA Compliant Data Centers white paper &#8211; the 36 page document provides a detailed description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria.</p>
<p>The diagram below shows elements of a HIPAA compliant hosting architecture.</p>
<p>To create this, we worked with Certified HIPAA Security Specialists and Certified HIPAA Professionals who matched each HITECH standard, specification, and implementation with a common technology application to meet Security Rule compliance.</p>
<p>Each element is described further in our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Data Centers white paper</a>.</p>
<div id="attachment_6676" class="wp-caption aligncenter" style="width: 570px"><img class=" wp-image-6676  " title="HIPAA Compliant Data Center Architecture" src="http://resource.onlinetech.com/wp-content/uploads/hipaa-compliant-data-center-architecture.png" alt="HIPAA Compliant Data Center Architecture" width="560" height="552" /><p class="wp-caption-text">HIPAA Compliant Data Center Architecture</p></div>
<p><strong>Get access to our HIPAA Compliant Data Centers white paper today! <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">Download now</a>.</strong><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><br />
</a></p>
<table border="0">
<tbody>
<tr>
<th><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignnone" title="HIPAA White Paper" src="http://resource.onlinetech.com/wp-content/uploads/hipaa-white-paper.gif" alt="" width="239" height="175" /></a></th>
<th><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignleft" title="HIPAA Compliant Data Centers White Paper" src="http://www.onlinetech.com/images/stories/misc/hipaa_wp_module.png" alt="" width="209" height="171" /></a></th>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-compliant-data-center-architecture/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Impact of HITECH &amp; HIPAA on Data Centers</title>
		<link>http://resource.onlinetech.com/the-impact-of-hitech-hipaa-on-data-centers/</link>
		<comments>http://resource.onlinetech.com/the-impact-of-hitech-hipaa-on-data-centers/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 20:10:46 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[health it white paper]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa white paper]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6635</guid>
		<description><![CDATA[Our HIPAA hosting and HIPAA compliant data center white paper provides a description of a HIPAA compliant data center IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria. Section 2.0 discusses the impact of HITECH and HIPAA on &#8230; <a href="http://resource.onlinetech.com/the-impact-of-hitech-hipaa-on-data-centers/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignright" title="HIPAA Compliant Data Centers White Paper" src="http://resource.onlinetech.com/wp-content/uploads/hipaa-white-paper.gif" alt="HIPAA Compliant Data Centers White Paper" width="294" height="216" /></a>Our <a href="http://www.onlinetech.com/hipaa">HIPAA hosting</a> and HIPAA compliant data center <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">white paper</a> provides a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria. <strong>Section 2.0</strong> discusses the impact of HITECH and HIPAA on data centers:</p>
<p>Protecting the confidentiality, integrity, and availability of electronic protected health information (ePHI) is the essence of the HIPAA Security Rule1. Since <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> typically store, transmit, or process ePHI, they must comply with the HITECH standards and citations to meet HIPAA compliance. The same risk analysis, administrative safeguards, physical safeguards, technical safeguards, and ongoing due diligence apply just as much in the data center as in a provider’s facility.</p>
<p>While there is some debate about the responsibilities of business associates for the protection of ePHI, all indications point toward business associates being held as responsible as covered entities. Consider the latest notice of proposed rulemaking that speaks to the extension of responsibilities from covered entities to business associates:</p>
<blockquote><p>As with the Privacy Rule, the Security Rule requires covered entities to have contracts or other arrangements in place with their business associates that provide satisfactory assurances that the business associates will appropriately safeguard the electronic protected health information they receive, create, maintain, or transmit on behalf of the covered entities.</p></blockquote>
<p>Moreover, both covered entities and business associates should bear in mind that prosecution by the Office of Civil Rights (OCR) under HITECH is not the only legal concern. The last year has witnessed an increase in state and consumer lawsuits against both covered entities and business associates. In January 2012, Minnesota Attorney General filed a lawsuit against Accretive Health, for failing to protect the confidentiality of over 23,000 patient healthcare records.</p>
<p><img class="aligncenter" title="HIPAA Compliant Data Centers White Paper" src="http://resource.onlinetech.com/wp-content/uploads/Business-Associates-Why-Invest-in-a-HIPAA-Audit.jpg" alt="HIPAA Compliant Data Centers White Paper" width="494" height="410" /></p>
<p>The safest and most diligent practice to protect ePHI is to ensure that the same policies, risk management, safeguards, and ongoing compliance governance standards are followed no matter where ePHI resides. This means that data centers, whether in-house or outsourced, need to fully embrace complete responsibility for ePHI.</p>
<p>In the areas of administrative safeguards, such as ongoing HIPAA awareness and training for all employees, healthcare providers tend to be stronger. In the areas of technical safeguards and PHI availability, professional data center companies that invest extensively in redundant facility infrastructure and security may be the safer bet.</p>
<p>Ideally, either a healthcare provider would have infinite resources to build and maintain multiple, high-availability data centers or a data center hosting business associate would have a thorough understanding of HIPAA compliance including a HIPAA security risk analysis and management, policies, training of all employees, and ongoing HIPAA compliance audits. While both ideals exist, they are in the minority.</p>
<p>In these cases, the weighing of the pros and cons falls back to the risk analysis and management to choose the best option that will maintain ePHI confidentiality, integrity, and availability.</p>
<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class=" alignleft" title="HIPAA White Paper Download" src="http://www.onlinetech.com/images/stories/misc/hipaa_wp_module.png" alt="HIPAA White Paper Download" width="322" height="263" /></a></p>
<p><strong>Read more in our free <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Data Centers white paper</a> - download it today!</strong></p>
<p>References:<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/riskassessment.pdf">HIPAA Security Series: Basics of Risk Analysis and Risk Management</a> (PDF)<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/nprmhitech.pdf">U.S. Dept. of Health and Human Services, Federal Register Part II</a><br />
<a href="http://www.ag.state.mn.us/Consumer/PressRelease/120119AccretiveHealth.asp">Attorney General Swanson Sues Accretive Health for Patient Privacy Violations</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/the-impact-of-hitech-hipaa-on-data-centers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Two-Factor Authentication to Meet HIPAA and PCI Compliance</title>
		<link>http://resource.onlinetech.com/two-factor-authentication-to-meet-hipaa-and-pci-compliance/</link>
		<comments>http://resource.onlinetech.com/two-factor-authentication-to-meet-hipaa-and-pci-compliance/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 12:51:55 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[two-factor authentication]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6420</guid>
		<description><![CDATA[What is Two-Factor Authentication? The simplest example may be the use of an ATM/debit card &#8211; this combines two factors; one is something you own (the card) and the other is something you know (the PIN number). Employees and other &#8230; <a href="http://resource.onlinetech.com/two-factor-authentication-to-meet-hipaa-and-pci-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>What is <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/two-factor-authentication-for-vpn-login-faq">Two-Factor Authentication?</a></strong></p>
<p>The simplest example may be the use of an ATM/debit card &#8211; this combines two factors; one is <em>something you own</em> (the card) and the other is <em>something you know</em> (the PIN number).</p>
<p>Employees and other users may need to log into a private network to access data from a remote location, a VPN (virtual private network). In this scenario, one authentication factor includes logging into a web-based system with a username and password. The second authentication factor may include the use of a cell phone &#8211; with a smartphone, you can register your phone number with the system and receive a request to approve.</p>
<p>Or, by using a passcode via text message, you can log into the system with the randomized numbers sent to your phone. You can even answer a phone call and press a key in order to authenticate you are the authorized account holder.</p>
<p>There are other authentication factors that can be used &#8211; for example, biometrics requires something specific to you, from a fingerprint to voice recognition. Or, you can use something physical you own, like a keyfob.</p>
<p><strong>Who&#8217;s Using Two-Factor Authentication?</strong></p>
<p>One example of a company using two-factor is Google &#8211; they&#8217;ve implemented their version called &#8220;2-step verification&#8221; for Google account holders. After signing into your account with your email address and password, Google requires you to enter a verification code sent to you via text message or generated by your smartphone.</p>
<div class="wp-caption aligncenter" style="width: 510px"><img title="Google's 2-Step Verification" src="http://1.bp.blogspot.com/-z1MrzrMJMxQ/Tt_YbIKoMFI/AAAAAAAAIxs/1OVcbqkNZ_o/s500/step1and2.png" alt="Google's 2-Step Verification" width="500" height="176" /><p class="wp-caption-text">Google&#39;s 2-Step Verification</p></div>
<p>Any organization concerned about security should consider implementing two-factor authentication for their VPN (virtual private network), regardless of their compliance requirements. Two-factor authentication lowers your risk of a data breach caused by unauthorized remote access to sensitive data.</p>
<p><strong>PCI DSS Compliance Requirements</strong></p>
<p>Two-factor is required by <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI compliance</a>. The Payment Card Industry Data Security Standards (PCI DSS) mandate that organizations who &#8220;hold, process, or pass cardholder information&#8221; meet a minimum level of security. Part of this security is protecting remote access logins with strong authentication. PCI requirement 8.0 states organizations must assign a unique ID to each person with computer access.</p>
<p>Specifically, section 8.3 requires organizations to implement two-factor authentication for remote access to the network by employees, administrators, and third parties. To achieve compliance with this requirement, you should use technologies such as remote authentication and dial-in service (RADIUS) or terminal access controller access control system (TACACS) with tokens; or other technologies that facilitate two-factor authentication.</p>
<p><strong>Two-Factor Authentication for HIPAA Compliance</strong></p>
<p>Two-factor authentication is also recommended in order to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a>, as it adds an extra layer of security that can prevent unauthorized access.</p>
<p>A recent article from ModernHealthcare.com demonstrates the need for strong authentication in the healthcare industry. The Privacy and Security Tiger Team of the Health IT Policy Committee is proposing rules for Stage 2 meaningful use that will govern security recommendations to authenticate the identity of patients as they log into their patient portals to download or view their personal health records.</p>
<p>While the policy committee intends to propose a rule requiring at least single-factor authentication while accessing records via a patient portal, two-factor authentication can offer significantly more security with minimal effort and cost.</p>
<p><strong>Related Resources</strong></p>
<div id="attachment_6605" class="wp-caption alignleft" style="width: 318px"><a href="http://resource.onlinetech.com/two-factor-authentication-to-meet-hipaa-and-pci-compliance/two-factor-screenshot/" rel="attachment wp-att-6605"><img class=" wp-image-6605     " title="Two-Factor Authentication FAQ" src="http://resource.onlinetech.com/wp-content/uploads/two-factor-screenshot.png" alt="Two-Factor Authentication FAQ" width="308" height="348" /></a><p class="wp-caption-text">Two-Factor Authentication FAQ</p></div>
<p>Read our <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/two-factor-authentication-for-vpn-login-faq">Two-Factor Authentication for VPN Login FAQ</a> for further information.</p>
<p>Find other PCI compliant resources <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources">here</a>. And watch this webinar or read the transcript, <a href="/resources/events/webinars/pci-webinar-series/pci-compliance-detailed-requirements">PCI Compliance: Detailed Requirements</a>, for a comprehensive overview of the required technology to achieve PCI DSS compliance.</p>
<p>References:<br />
<a href="https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf">PCI DSS Quick Reference Guide: Understanding the Payment Card Industry Data Security Standard Version 2.0</a> (PDF)<br />
<a href="http://www.informationweek.com/whitepaper/Infrastructure/Network-Systems-Management/the-right-way-to-prove-identity-establish-trust-wp1330538585?articleID=191704303&amp;itc=SBX_iwk_fture_wp_default">Defender 5: The Right Way to Prove, Identify and Establish Trust from Quest Software</a><br />
<a href="http://www.modernhealthcare.com/article/20120424/NEWS/304249988?AllowView=VW8xUmo5Q21TcWJOb1gzb0tNN3RLZ0h0MWg5SVgra3NZRzROR3l0WWRMVGJVUDhGRWxiNUtpQzMyWmV2NVhnWUpiU3A=&amp;utm_source=link-20120424-NEWS-304249988&amp;utm_medium=email&amp;utm_campaign=hits"> Federal Privacy Work Group Wants EHRs to Verify Patient ID</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/two-factor-authentication-to-meet-hipaa-and-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2012 Cloud Computing: Private Clouds Dominate</title>
		<link>http://resource.onlinetech.com/2012-cloud-computing-private-clouds-dominate/</link>
		<comments>http://resource.onlinetech.com/2012-cloud-computing-private-clouds-dominate/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 14:54:30 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[2012 cloud computing]]></category>
		<category><![CDATA[cloud computing infographic]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud hosting infographic]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[private cloud hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6568</guid>
		<description><![CDATA[Over 34 percent of IT budgets are spent on cloud computing solutions, according to a recent article by Forbes.com and the IDG Enterprise Cloud Computing study conducted in January 2012. More specifically, the majority of the budgets are allocated for &#8230; <a href="http://resource.onlinetech.com/2012-cloud-computing-private-clouds-dominate/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Over 34 percent of IT budgets are spent on <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> solutions, according to a recent article by Forbes.com and the IDG Enterprise Cloud Computing study conducted in January 2012.</p>
<p>More specifically, the majority of the budgets are allocated for <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">private cloud hosting</a> solutions, at 24 percent, as deduced from the survey of 1,682 IT and business executives.</p>
<div id="attachment_6572" class="wp-caption aligncenter" style="width: 532px"><a href="http://resource.onlinetech.com/2012-cloud-computing-private-clouds-dominate/2012-cloud-computing/" rel="attachment wp-att-6572"><img class="size-full wp-image-6572 " title="2012 Cloud Computing" src="http://resource.onlinetech.com/wp-content/uploads/2012-Cloud-Computing.jpg" alt="2012 Cloud Computing" width="522" height="735" /></a><p class="wp-caption-text">2012 Cloud Computing</p></div>
<p>When it came to what type of cloud activity the respondents expected to conduct over the next five years, 27 percent planned to perform the majority of their IT operations in the cloud. Thirty-five percent stated only a few selected IT operations would be performed in the cloud, while 21 percent plan to limit their cloud activity to private clouds. Additionally, 63 percent agree or strongly agree there will be long-term cost savings realized after adopting the cloud, despite higher short-term costs for implementation.</p>
<p>Again, security comes into play when it comes to hurdles to adopting the cloud (70 percent). Access to information is next at 40 percent, while concerns about information governance is third at 37 percent.</p>
<p>What can help ease security concerns for companies looking to outsource their private cloud? Check their audit history for dates and scope of compliance &#8211; from a <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2 </a>report that measures the security, availability, confidentiality and other attributes of a data center operator/cloud provider to any number of industry-specific compliance audit reports, including <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI compliance</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a> to ensure a provider is following national standards for security. Read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">white paper</a>; a comprehensive guide to HIPAA compliant data centers for more about how to secure ePHI (electronic protected health information) in the cloud.</p>
<p>As for concerns about information governance, your cloud contract should outline who actually has access, rights, and the right to grant access to your data. Knowing where your data lives is also important &#8211; the compliance standards of the audit reports previously discussed do not need apply if the data is transferred out of the country, meaning security may not be guaranteed if your data is overseas.</p>
<p>Security concerns may be a motivator for the deployment of private clouds, and the expected continuing trend in the next 18 months, at 33 percent.</p>
<p>References:<br />
<a href="http://marketing.idgenterprise.com/pdf/IDGE_Cloud_preso_2012_sample.pdf">2012 Cloud Computing Key Trends and Future Effects</a> (PDF)<br />
<a href="http://www.forbes.com/sites/joemckendrick/2012/04/11/more-than-one-third-of-it-budgets-now-spent-on-cloud-survey/?sf3825602=1">More Than One-Third of IT Budgets Now Spent on Cloud: Survey</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2012-cloud-computing-private-clouds-dominate/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U of M Ross School of Business Alumni: Cloud Computing Seminar Recap</title>
		<link>http://resource.onlinetech.com/u-of-m-ross-school-of-business-alumni-cloud-computing-seminar-recap/</link>
		<comments>http://resource.onlinetech.com/u-of-m-ross-school-of-business-alumni-cloud-computing-seminar-recap/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 14:33:08 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[cloud computing events]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[mid-michigan data center]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6541</guid>
		<description><![CDATA[Online Tech hosted a cloud computing seminar for University of Michigan alumni by the Ross School of Business Alumni Club of Southeast Michigan at our Ann Arbor 2 data center location last night. Thank you to everyone that attended! View photos &#8230; <a href="http://resource.onlinetech.com/u-of-m-ross-school-of-business-alumni-cloud-computing-seminar-recap/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech hosted a <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> seminar for University of Michigan alumni by the Ross School of Business Alumni Club of Southeast Michigan at our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor 2 data center</a> location last night. Thank you to everyone that attended! View photos from the event below in our slideshow:</p>
<p><object width="600" height="500" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="flashvars" value="offsite=true&amp;lang=en-us&amp;page_show_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629497255998%2Fshow%2F&amp;page_show_back_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629497255998%2F&amp;set_id=72157629497255998&amp;jump_to=" /><param name="allowFullScreen" value="true" /><param name="src" value="http://www.flickr.com/apps/slideshow/show.swf?v=109615" /><param name="allowfullscreen" value="true" /><embed width="600" height="500" type="application/x-shockwave-flash" src="http://www.flickr.com/apps/slideshow/show.swf?v=109615" flashvars="offsite=true&amp;lang=en-us&amp;page_show_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629497255998%2Fshow%2F&amp;page_show_back_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629497255998%2F&amp;set_id=72157629497255998&amp;jump_to=" allowFullScreen="true" allowfullscreen="true" /></object></p>
<p><em>Cloud Computing: Approach Innovatively and Understand Trends</em> featured speaker presentations, networking and data center tours. Speakers included:</p>
<ul>
<li>Mike Klein, COO &amp; President of Online Tech</li>
<li>M.S. Krishnan, PhD., Joseph Handleman Professor of Information Systems and Innovation at the Ross School of Business, University of Michigan; Faculty Director of India Initiatives; Professor of Business Information Technology</li>
<li>Gary Baker, CIO at Society of Manufacturing Engineers &amp; Co-host of Internet Advisor Radio Program at WJR</li>
</ul>
<p>Download Online Tech&#8217;s <a title="A Brief Overview of Cloud Computing - Online Tech" href="http://resource.onlinetech.com/wp-content/uploads/a-brief-overview-of-cloud-computing.pdf" target="_blank">A Brief Overview of Cloud Computing</a> (PDF).</p>
<p>Our Ann Arbor 2 data center is located south of Ann Arbor, Michigan in Avis Park. With close proximity to major highways and the University of Michigan, this facility offers an ideal location for <a href="http://www.onlinetech.com/company/michigan-data-centers/features/high-availability-server-hosting">high availability production</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a>.</p>
<p>The 19,500 square feet facility includes 10,000 square feet of 18” raised floor and offers high availability fiber Internet connectivity, and high availability heating and cooling systems. It also offers geographic separation from our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a>, providing diversified utility and network feeds, perfect for production and disaster recovery projects.</p>
<p>Read more about our data center, including <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">detailed specifications</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/u-of-m-ross-school-of-business-alumni-cloud-computing-seminar-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech to Attend Chicago HIMSS Event on Health IT</title>
		<link>http://resource.onlinetech.com/online-tech-to-attend-chicago-himss-event-on-health-it/</link>
		<comments>http://resource.onlinetech.com/online-tech-to-attend-chicago-himss-event-on-health-it/#comments</comments>
		<pubDate>Fri, 20 Apr 2012 18:22:15 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[hipaa colocation]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa managed servers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6518</guid>
		<description><![CDATA[Online Tech will be attending the Greater Chicago HIMSS event next week, April 26, on health IT innovations. HIMSS, the Healthcare Information and Management Systems Society, is one of the nation’s known leaders in facilitating discussions about information technology (IT) &#8230; <a href="http://resource.onlinetech.com/online-tech-to-attend-chicago-himss-event-on-health-it/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech will be attending the Greater Chicago HIMSS event next week, April 26, on health IT innovations. HIMSS, the Healthcare Information and Management Systems Society, is one of the nation’s known leaders in facilitating discussions about information technology (IT) and management systems for healthcare improvement. With a chapter in every state, the organization is at the forefront of the latest developments in health IT.</p>
<div id="attachment_6521" class="wp-caption aligncenter" style="width: 527px"><a href="http://resource.onlinetech.com/online-tech-to-attend-chicago-himss-event-on-health-it/himss-greater-chicago-chapter/" rel="attachment wp-att-6521"><img class="size-full wp-image-6521 " title="HIMSS Greater Chicago Chapter" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-Greater-Chicago-Chapter.png" alt="HIMSS Greater Chicago Chapter" width="517" height="180" /></a><p class="wp-caption-text">HIMSS Greater Chicago Chapter</p></div>
<p>The event, <em>Health IT:</em> <em>What’s Next in Digital Health?</em>, will feature speaker Kareem Saad from Dell to present on key health IT innovations changing the healthcare landscape, as well as Steve Lieber from HIMSS to provide insight on the widespread national adoption of health IT, and related topics from HIMSS ‘12.</p>
<p>GCCHIMSS.net describes the event topics:</p>
<blockquote>
<p dir="ltr">Health IT is transforming our healthcare system. Healthcare reform, industry consolidation, and demographic changes have spurred a significant increase in the U.S. healthcare industry’s use of technology to improve health and enhance the patient experience while trying to help control the ever-increasing cost of care. <strong>New players are emerging and cloud computing, social media, and mobile technology solutions targeting patients and healthcare providers are creating new opportunities.</strong></p>
</blockquote>
<p>We’re one of those <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> providers, continuously improving and developing our solutions to achieve optimal security delivered with responsive management and client service. Online Tech provides fully compliant <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solutions for healthcare organizations, healthcare SaaS (Software-as-a-Service) providers, and other related organizations in our <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a>.</p>
<p>We invested in and passed a third-party audit designed to test everything &#8211;  including our technology, policies, procedures, employee training, security measures, access controls and more, in order to ensure we can offer fully compliant <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a>, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/colocation">colocation</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/managed-servers">managed servers</a>. And, we’ll sign the business associate agreement (BAA) with every healthcare client. For a comprehensive guide to HIPAA compliant data centers for covered entities and business associates, read our recently published <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Data Centers White Paper</a>.</p>
<p>The meeting will be held at the Tripp Lite World Headquarters at 1111 W. 35th Street, Chicago, Illinois. <a href="https://secure100.telusys.net/tcsc-bin/sregdisplay?&amp;ctid=5023916737697829&amp;rtid=4626948774496085">Register online</a> and view directions to the headquarters <a href="http://www.gcchimss.net/programs/TrippLiteMap.pdf">here</a>.</p>
<p><strong>About GCC HIMSS</strong><br />
We are a diverse group of experienced healthcare professionals working in the greater Chicagoland area. We work at hospitals, corporate health systems, consulting firms, vendor organizations, universities, and a wide variety of other organizations. Many of us are the decision makers in our organization. Our members range from CEOs, CIOs, and other senior executives to analysts and students. We have technical members and clinical members. The majority of GCC’s members have well over ten years of experience in the healthcare field.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-to-attend-chicago-himss-event-on-health-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Implements Net Promoter System</title>
		<link>http://resource.onlinetech.com/online-tech-implements-net-promoter-system/</link>
		<comments>http://resource.onlinetech.com/online-tech-implements-net-promoter-system/#comments</comments>
		<pubDate>Thu, 19 Apr 2012 20:40:29 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[net promoter score]]></category>
		<category><![CDATA[net promoter system]]></category>
		<category><![CDATA[nps]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6501</guid>
		<description><![CDATA[At the beginning of this year, Online Tech started using the Net Promoter System (NPS) from the book “The Ultimate Question 2.0” by Fred Reichheld. The Net Promoter Score (part of the Net Promoter System) allows us to track and &#8230; <a href="http://resource.onlinetech.com/online-tech-implements-net-promoter-system/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>At the beginning of this year, Online Tech started using the Net Promoter System (NPS) from the book “The Ultimate Question 2.0” by Fred Reichheld. The Net Promoter Score (part of the Net Promoter System) allows us to track and measure client satisfaction, as well as the likelihood of client referrals as a result of their experience with our company. At Online Tech, we want to  consistently deliver excellent client service through our metrics, accountability and visibility.</p>
<div id="attachment_6503" class="wp-caption alignleft" style="width: 177px"><a href="http://resource.onlinetech.com/online-tech-implements-net-promoter-system/the-ultimate-question-2/" rel="attachment wp-att-6503"><img class=" wp-image-6503  " title="The Ultimate Question" src="http://resource.onlinetech.com/wp-content/uploads/The-Ultimate-Question1.png" alt="The Ultimate Question" width="167" height="236" /></a><p class="wp-caption-text">The Ultimate Question</p></div>
<p>We hope to implement the Net Promoter System over the course of the next year. In order to do so, we’ll be collecting data bimonthly with the help of our clients.</p>
<p>It’s all based on a simple question:</p>
<p><strong>“On a scale of 0 to 10, would you recommend Online Tech to a friend or colleague?”</strong></p>
<p><strong>0 </strong>= You wouldn’t recommend Online Tech<br />
<strong>10</strong> = You would definitely recommend Online Tech</p>
<p>By asking this question, Online Tech will be able to gather information and pinpoint areas in our company where we can improve the entire customer experience.</p>
<p>Every morning, our company holds a huddle to discuss client-related metrics and help resolve any client issues. We want to gather feedback from our clients at any point in time, good or bad.</p>
<p>If you’ve had a positive experience with us recently, tell us about it. If you’ve had a less than stellar experience with us, we want to know about those, too! Send us an email at <a href="mailto:feedback@onlinetech.com">feedback@onlinetech.com</a> with your score based on the scale mentioned earlier and any other comments you would like to share with us. We want to hear from you during this process &#8211;  without your feedback, it wouldn’t be possible.</p>
<p>Online Tech will provide more information about the Net Promoter Score as we fully implement the system this year. If you are interested in learning more about the Net Promoter System and about other companies that have implemented the system, visit <a href="http://www.netpromoter.com/">www.netpromoter.com</a>. Be sure to check back here frequently over the next few months to read more about our efforts in using the Net Promoter System to continuously improve our business practice.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-implements-net-promoter-system/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliant Data Centers &amp; HIPAA Hosting White Paper</title>
		<link>http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/</link>
		<comments>http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/#comments</comments>
		<pubDate>Thu, 19 Apr 2012 13:20:29 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[hipaa hosting white paper]]></category>
		<category><![CDATA[hipaa white paper]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6433</guid>
		<description><![CDATA[Our HIPAA compliant data center white paper is finally released! Here&#8217;s an overview of what you&#8217;ll find in the 36-page document: Executive Summary The increasing pressure to implement meaningful use, reduce healthcare costs, and improve care outcomes while still protecting &#8230; <a href="http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<div id="attachment_6436" class="wp-caption alignright" style="width: 204px"><a href="http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/hwp-cover/" rel="attachment wp-att-6436"><img class=" wp-image-6436  " title="HIPAA Compliant Data Centers Cover" src="http://resource.onlinetech.com/wp-content/uploads/HWP-Cover.png" alt="HIPAA Compliant Data Centers Cover" width="194" height="250" /></a><p class="wp-caption-text">HIPAA Compliant Data Centers Cover</p></div>
<p>Our HIPAA compliant data center white paper is finally released! Here&#8217;s an overview of what you&#8217;ll find in the 36-page document:</p>
<p><strong>Executive Summary</strong></p>
<div>
<p>The increasing pressure to implement meaningful use, reduce healthcare costs, and improve care outcomes while still protecting patient interests has led to strategic review and overhaul by many healthcare providers and vendors.</p>
</div>
<div>
<p>Evaluating outsourcing options to allow industry experts to manage parts of the healthcare IT components is an obvious part of the equation, and the intensive capital expense, human resource, security, and maintenance demands specific to data centers make these prime candidates for cost savings.</p>
<p>However, balancing the resource benefits of outsourcing data center and hosting services with the risks of engaging an off-premise business associate is daunting in the wake of increasing PHI (protected health information) breaches and penalties. Ultimately, finding the best blend of resources that can fulfill the availability, integrity, and confidentiality requirements to protect ePHI (electronic protected health information) &#8211; and thereby protecting the patients, covered entities, and business associates &#8211; is the challenge at hand.</p>
<p>This white paper explores the impact of HITECH and HIPAA on data centers. It includes a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of data center outsourcing, and vendor selection criteria.</p>
<div id="attachment_6443" class="wp-caption alignleft" style="width: 191px"><a href="http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/hwp-table-of-contents/" rel="attachment wp-att-6443"><img class="wp-image-6443 " title="HIPAA Compliant Data Centers Table of Contents" src="http://resource.onlinetech.com/wp-content/uploads/HWP-Table-of-Contents.png" alt="HIPAA Compliant Data Centers Table of Contents" width="181" height="236" /></a><p class="wp-caption-text">HIPAA Compliant Data Centers Table of Contents</p></div>
<p><strong>Main topics include:</strong></p>
<ul>
<li>Impact of HITECH/HIPAA on data centers &#8211; why compliance is more important than ever for business associates and covered entities</li>
<li>What is a HIPAA compliant data center? &#8211; what documents to look for to do your due diligence as a covered entity</li>
<li>Administrative safeguards</li>
<li>Physical safeguards</li>
<li>Technical safeguards</li>
<li>Business associate agreements &#8211; the extensive documentation OCR requires in the event of a data breach; what to look for in a business associate contract</li>
<li>Outsourcing vs. in-house hosting</li>
<li>Benefits of outsourcing hosting</li>
<li>Risks of outsourcing &#8211; comprehensive guide on HIPAA violations and associated penalties</li>
<li>Vendor selection criteria</li>
<li>HIPAA compliant business associates</li>
<li>And more!</li>
</ul>
<div id="attachment_6458" class="wp-caption alignright" style="width: 146px"><a href="http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/hwp-diagram/" rel="attachment wp-att-6458"><img class="wp-image-6458 " title="HIPAA Compliant Data Center Architecture" src="http://resource.onlinetech.com/wp-content/uploads/HWP-Diagram.png" alt="HIPAA Compliant Data Center Architecture" width="136" height="180" /></a><p class="wp-caption-text">HIPAA Compliant Data Center Architecture</p></div>
<p>The white paper also includes a comprehensive diagram depicting the essential elements of a HIPAA compliant data center architecture, complete with everything you need to have a fully compliant <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solution, including detailed descriptions of each requirement and recommended technology.</p>
<p>Each standard was matched with a common technology application to meet the HIPAA Security Rule. Use this diagram to help you make IT decisions when it comes to selecting a vendor and compliant technology.</p>
<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">View the full white paper content and download the PDF.</a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-compliant-data-centers-hipaa-hosting-white-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Due Diligence with Business Associates</title>
		<link>http://resource.onlinetech.com/due-diligence-with-business-associates/</link>
		<comments>http://resource.onlinetech.com/due-diligence-with-business-associates/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 12:16:29 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[due diligence]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6396</guid>
		<description><![CDATA[The latest 2012 HIMSS Analytics Report: Security of Patient Data released in April outlines survey statistics related to data breaches, including preventative measures taken and degree of due diligence with third-party vendors. Commissioned by Kroll Advisory Solutions, the study includes &#8230; <a href="http://resource.onlinetech.com/due-diligence-with-business-associates/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The latest 2012 HIMSS Analytics Report: Security of Patient Data released in April outlines survey statistics related to data breaches, including preventative measures taken and degree of due diligence with third-party vendors. Commissioned by Kroll Advisory Solutions, the study includes respondents who identify as Chief Security Officers, Senior Information Technology executives, Compliance Officers and Privacy Officers.</p>
<div id="attachment_6397" class="wp-caption aligncenter" style="width: 571px"><a href="http://resource.onlinetech.com/due-diligence-with-business-associates/duediligence/" rel="attachment wp-att-6397"><img class=" wp-image-6397 " title="HIMSS Analytics: Due Diligence with Business Associates" src="http://resource.onlinetech.com/wp-content/uploads/duediligence.png" alt="HIMSS Analytics: Due Diligence with Business Associates" width="561" height="397" /></a><p class="wp-caption-text">HIMSS Analytics: Due Diligence with Business Associates</p></div>
<p>While 98 percent of respondents require third-party vendors to sign a BAA (<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#Business%20Associate%20Agreement">business associate agreement</a>), only 50 percent require their business associates to show proof of employee training in HIPAA/security policies. The second most commonly practiced method of due diligence is ensuring <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#business%20associates">business associates</a> have a formal breach notification plan in place.</p>
<p>When it comes to <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/five-questions-to-ask-your-business-associates/question-1-breach-notification">breach notification</a> plans, it is essential to have a clause in place that specifically details the timeline by which the business associate will notify the covered entity when a breach is suspected. Online Tech’s <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/five-questions-to-ask-your-business-associates/question-1-breach-notification/baa-breach-notification-clause">breach notification clause</a> states:</p>
<blockquote>
<p dir="ltr">2.5. Business Associate shall notify Client in writing of any Breach involving Unsecured PHI within five (5) business days of becoming aware of such Breach. All reports of Breaches of Unsecured PHI shall be made in compliance with HITECH Act § 13402 and the regulations issued thereunder.</p>
<p dir="ltr">A Breach will be treated as discovered as of the first day that such Breach is known or reasonably should have been known by Business Associate. Business Associate shall notify Client within seventy-two (72) hours of any suspected or actual Security Incident or breach of security, intrusion or unauthorized use or disclosure of PHI and/or any actual or suspected use or disclosure of data in violation of any applicable federal or state laws or regulations.</p>
</blockquote>
<p>The third most commonly used method is ensuring business associates “use tools to secure patient information.” While the report doesn’t offer any additional details around what “tools” they’re referring to, it may vary from one <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> provider to another, as the HIPAA rules do not require any one method of achieving the same security standards.</p>
<p>Seventy-six percent checked to ensure their third-party vendor had a plan to identify breaches, different from the 82 percent that sought out business associates with a breach notification plan. Identifying breaches can be achieved with comprehensive monitoring systems that generate logs of activity on servers, as well as Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) that can help pinpoint any attempts at unauthorized access to servers that contain ePHI (electronic protected health information).</p>
<p>Checking for proof of employee background checks and periodic risk analyses both ranked at 56 percent in covered entities’ due diligence of business associates. While low on the list, employee background checks are key when it comes to data breach cases.</p>
<p>According to the HIMSS Analytics Report, the most common perpetrators of security breach incidents are employees (79 percent). Although down from 2010’s 94 percent, this still accounts for the majority of PHI breaches within an organization. While this may be attributed to other factors such as lack of employee training, background checks should be implemented regardless for optimal PHI security.</p>
<p>The U.S. Department of Health and Human Services requires covered entities to conduct periodic risk analyses (read <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/whats-in-a-hipaa-risk-analysis">What’s in a HIPAA Risk Analysis?</a>). An emphasis on ‘periodic’ is in order, since, like any audit or analysis, a one-time report only measures the security of an organization during a certain snapshot of time. For assurance of ongoing compliance, check their analysis and the scope of their analysis to do your due diligence.</p>
<p>To get educated on what you need to know about third-party vendors to stay compliant, read our E-Tip, <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider">Five Questions to Ask Your HIPAA Hosting Provider</a>. Read our other <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance">HIPAA-related E-Tips</a> too.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/due-diligence-with-business-associates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIT 2012 Recap</title>
		<link>http://resource.onlinetech.com/hit-2012-recap/</link>
		<comments>http://resource.onlinetech.com/hit-2012-recap/#comments</comments>
		<pubDate>Mon, 16 Apr 2012 14:41:37 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hit 12]]></category>
		<category><![CDATA[hit 2012]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6389</guid>
		<description><![CDATA[The Healthcare Information Transformation, or HIT ‘12, conference was held in Jacksonville, Florida last week with 2 days packed with case studies, panel presentation, and a great variety of topics and presenters from across the country. The theme was Leveraging &#8230; <a href="http://resource.onlinetech.com/hit-2012-recap/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The Healthcare Information Transformation, or HIT ‘12, conference was held in Jacksonville, Florida last week with 2 days packed with case studies, panel presentation, and a great variety of topics and presenters from across the country. The theme was <em>Leveraging IT to Improve Healthcare Delivery</em>.</p>
<p>The first morning kicked off with a panel discussion of the <em>Consumerization of IT: Mobile Infrastructure, Support, and Security</em>. Chris Seper, CEO of MedCity Media, started us off with a 30,000 foot view of the healthcare IT landscape of tablets, smartphones, and BYOD being used to access applications daily. The great news is the PHI is readily at hand. The challenge is managing the security and privacy that mobile devices add to the responsibility of providers and vendors in the industry to protect us.</p>
<p>Dr. Marie-Michelle Strah of Applied Information Sciences emphasized the need for enterprise information management as the key framework for managing security. Securing the device is not the point. There&#8217;s no technical silver bullet for security, and being able to step back and see the forest is critical. Every mobile device adds another endpoint that needs to be addressed: the more endpoints, the greater the risk.</p>
<p>Kirk Larson, VP &amp; COP of Children&#8217;s Hospital Central California shared his successful implementation of a BYOD policy leveraging VMware&#8217;s VDI to ensure no PHI is stored on devices.</p>
<p>Larson takes a pragmatic approach to BYOD in the healthcare space by recognizing that relinquishing a sense of control in what types of devices are used in the hospital is realistic for the digital world, but he still manages to secure PHI with the VDI paradigm with relative ease since there is only a single image security profile to manage despite the wide variety of devices used in the hospital.</p>
<p>His big eye-opener during various device implementations? Most care providers returned their iPads within 24-48 hours of receiving one. Turns out they are great for reading static content, but if you actually want to use it to interact and input information, something with a separate keyboard is widely preferred.</p>
<p>After a lunch for the morning workshop participants, conference chair Tom Gomez welcomed attendees back for the keynote panel, <em>Prioritizing HIT Issues and Challenges in 2012 and Beyond</em> with:</p>
<ul>
<li>Andy Crowder, CEO of JC Solutions Group</li>
<li>Brian Comp, CTO of Orlando Health</li>
<li>Kirk Larson, VP &amp; CIO of Children&#8217;s Hospital Central California</li>
<li>Elizabeth Lindsay-Wood, Tampa General Hospital</li>
<li>Joanne Rohde, CEO of Axial Exchange</li>
</ul>
<p>The panel discussed what keeps CIOs up at night and how to reduce stress while innovating and still meeting compliance. All easier said than done!</p>
<p>Tushar Hazra from EpitomeOne discussed interoperability and the key criteria for big data to help make decisions before the afternoon break.</p>
<p>Rick Moore, CIO &amp; CISO of the National Committee for Quality Assurance; Terrel Herzig, UAB Health System; Deborah Lafky Center for Strategic Health Innovation; and Chad Peterson Sinaiko of Altegra Health discussed<em> Security Integration into Each IT Business Decision</em>. The critical need for a risk assessment as the fundamental cornerstone of healthcare IT security was emphasized, as well as leveraging existing security models and standards as a good starting point (i.e. NIST). Deborah Lafky pointed out efforts by the ONC Tiger Team to get a preliminary sense of the degree of overlap between the HITECH standards and citations that make up the HIPAA Security Rule and other standards, such as NIST, and found a roughly 66% overlap.</p>
<p>Next, Shahid Shah, a.k.a. the Healthcare IT Guy and blogger of <a href="about:blank">www.healthcareguy.com,</a> moderated a panel with Ron Cowan, VP Information Management &amp; CIO of Lewistown Hospital; Edith Dees, VP &amp; CIO of the Holy Spirit Health System; and myself as we discussed PHI in the Cloud. We discussed the importance of contract elements, policy documentation, audit standards, and other key aspects to consider when thinking of putting PHI in the cloud. Ron and Edith pointed out how the cloud allows them to implement the same technologies and standards as the largest hospitals, even without the benefit of local HIT resources. They shared lessons learned the hard way in vendor selection. I illuminated some of the lesser known variations of <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> audits and key questions to ask business associates in the cloud space.</p>
<p>Bob Havasy rounded out the afternoon with a compelling presentation about the quantifiable self as it relates to motivating and tracking healthcare outside the walls of the hospitals with the ubiquitous mobile devices every person seems personally attached to. He shared examples of how leveraging these technologies can have a powerful impact on a person’s health awareness and success in making healthy lifestyle changes, as well as the importance of being agile and failing quickly in the development of new technologies.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hit-2012-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Sponsors iHT2 Health IT Summit</title>
		<link>http://resource.onlinetech.com/online-tech-sponsors-iht2-health-it-summit/</link>
		<comments>http://resource.onlinetech.com/online-tech-sponsors-iht2-health-it-summit/#comments</comments>
		<pubDate>Mon, 16 Apr 2012 13:15:29 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[health IT conference]]></category>
		<category><![CDATA[health it summit]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6331</guid>
		<description><![CDATA[Online Tech will be sponsoring and exhibiting HIPAA hosting solutions at the iHT2 Health IT Summit conference in Fort Lauderdale from June 12-13. The conference will be attended by C-level physican, practice management and IT executives to learn the latest &#8230; <a href="http://resource.onlinetech.com/online-tech-sponsors-iht2-health-it-summit/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech will be sponsoring and exhibiting <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solutions at the iHT2 Health IT Summit conference in Fort Lauderdale from June 12-13. The conference will be attended by C-level physican, practice management and IT executives to learn the latest solutions for practice management, mobility, telemedicine, outsourcing, IT infrastructure, next-generation EMR systems (electronic medical record), disease management and more, according to iHealthTran.com.</p>
<p>The conference focuses on healthcare IT as the industry evolves, including the latest implications of ARRA (American Recovery and Reinvestment Act of 2009) and meaningful use changes and how it affects practices and hospitals. Other presentations will focus on electronic protected health information (ePHI) security, using EHR systems for health information exchange (HIE), healthcare delivery reform and other topics on improving patient care with data technology.</p>
<p>Online Tech’s Director of Healthcare Vertical, April Sage, CPHIMS, will be speaking on the panel <em>The hCloud at 30,000 Feet: Cloud Computing Solutions for Mobile Healthcare</em>. The panel will discuss how <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a> can offer a way for mobile devices to capture, store and process healthcare information securely, supporting a range of healthcare applications. The panel will also discuss how mobile devices will have the ability to extend to previously inaccessible communities in order to help patients in remote locations.</p>
<p>Moderated by Judy Hanover, the Research Director at IDC Health Insights, other healthcare <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> panel speakers include:</p>
<ul>
<li>Jayne Bassler, VP &amp; Associate CIO of the Florida Hospital</li>
<li>Ari Entin, Director of IT at the Miami-Dade County Health Department</li>
<li>Mary Carroll Ford, VP &amp; Chief Information Officer of the Lakeland Regional Medical Center</li>
</ul>
<p>The conference’s keynote speakers include:</p>
<ul>
<li>C. Martin Harris, MD, CIO &amp; Chairman IT Division of the Cleveland Clinic will present Clinical Transformation: Experience of One System</li>
<li>Jonathan Perlin, MD, PhD, President of Clinical &amp; Physician Services and CMO of the Hospital Corporation of America</li>
</ul>
<p><strong><a href="http://resource.onlinetech.com/online-tech-sponsors-iht2-health-it-summit/iht-health-it-summit/" rel="attachment wp-att-6352"><img class="wp-image-6352 alignright" title="iHT Health IT Summit" src="http://resource.onlinetech.com/wp-content/uploads/iHT-Health-IT-Summit.png" alt="" width="162" height="173" /></a>Location</strong>:<br />
Hyatt Regency Pier Sixty Six<br />
2301 SE 17 Street Causeway<br />
Ft. Lauderdale FL 33316<br />
954-525-6666</p>
<p>Find more information about the conference, including agenda, venue, sponsors, whitepapers and more <a href="http://ihealthtran.com/fortlauderdalehome.html">here</a>.</p>
<hr />
<p><strong>About the Institute for Health Technology Transformation</strong></p>
<p><a href="http://resource.onlinetech.com/online-tech-sponsors-iht2-health-it-summit/institute-for-health-technology-transformation/" rel="attachment wp-att-6343"><img class="alignleft  wp-image-6343" title="Institute for Health Technology Transformation" src="http://resource.onlinetech.com/wp-content/uploads/Institute-for-Health-Technology-Transformation.png" alt="" width="159" height="104" /></a>The Institute for Health Technology Transformation is the leading organization committed to bringing together private and public sector leaders fostering the growth and effective use of technology across the healthcare industry. Through collaborative efforts the Institute provides programs that drive innovation, education, and provide a critical understanding of how technology applications, solutions and devices can improve the quality, safety and efficiency of healthcare.</p>
<hr />
<p><strong>April Sage, Director of Healthcare Vertical at Online Tech</strong></p>
<p><img class="alignleft" src="http://resource.onlinetech.com/eNews/right-april.jpg" alt="" width="92" height="138" />April has been involved in the IT industry for over two decades, initially founding a company teaching technology. In the 2000s, April founded a bioinformatics company supporting biotech, pharma, and bioinformatic companies in the development of research portals, drug discovery search engines, and other informatics software systems.</p>
<p>In her current position as Director, Healthcare Vertical of Online Tech, April focuses on HIPAA compliant solutions for the healthcare industry including dedicated hosting, cloud computing, and disaster recovery.<br />
<strong id="internal-source-marker_0.7480756430886686"><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-sponsors-iht2-health-it-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Certified vs. HIPAA Compliant</title>
		<link>http://resource.onlinetech.com/hipaa-certified-vs-hipaa-compliant/</link>
		<comments>http://resource.onlinetech.com/hipaa-certified-vs-hipaa-compliant/#comments</comments>
		<pubDate>Fri, 13 Apr 2012 14:17:43 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[hipaa certified]]></category>
		<category><![CDATA[hipaa certified data centers]]></category>
		<category><![CDATA[hipaa certified hosting]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[hipaa compliant]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6319</guid>
		<description><![CDATA[This is a blog post on the phrase ‘HIPAA certified’ to inform you that there is no such thing as ‘HIPAA certified.’ What’s the correct term, then? ‘HIPAA compliant.’ This means that you, as a covered entity, or business associate, &#8230; <a href="http://resource.onlinetech.com/hipaa-certified-vs-hipaa-compliant/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>This is a blog post on the phrase ‘HIPAA certified’ to inform you that there is no such thing as ‘HIPAA certified.’ What’s the correct term, then? ‘<strong>HIPAA compliant</strong>.’ This means that you, as a covered entity, or business associate, has been found in compliance with the HIPAA Security and Privacy Rules as established by the Department of Health and Human Services (HHS). You have done your due diligence by putting in policies, processes and procedures to achieve technical, administrative and physical safeguards to protect PHI.</p>
<p>The HHS does recognize any ‘HIPAA certification’ program as legitimate. When they come to inspect and audit, they will likely not care if you have a ‘HIPAA certified’ seal on your website. They care about the security and design of your controls to protect PHI to the best of your ability, and the actual policies and procedures your organization abides by.</p>
<p>While many use ‘certified’ and ‘compliant’ interchangeably to mean the same thing, they cannot be used to describe data centers, hosting providers or any service provider acting as a business associate to a covered entity that needs to achieve their own compliance. For example, it’s not &#8216;HIPAA certified data centers,&#8217; it’s &#8216;<strong><a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a></strong>.&#8217; Or &#8216;<strong><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a></strong>,&#8217; not &#8216;HIPAA certified hosting.&#8217;</p>
<p><a href="http://www.zdnet.com/blog/datacenter/will-your-cloud-be-hipaa-compliant/1212">This article</a>, from ZDNet is properly titled <em>Will Your Cloud Be HIPAA Compliant?</em> Yet, despite its title, ‘certified’ appears everywhere in the article as it refers to data center providers:</p>
<p><a href="http://resource.onlinetech.com/hipaa-certified-vs-hipaa-compliant/zdnet-article/" rel="attachment wp-att-6321"><img class="alignleft size-full wp-image-6321" title="" src="http://resource.onlinetech.com/wp-content/uploads/zdnet-article.png" alt="HIPAA Certified Data Centers?" width="635" height="246" /></a></p>
<p>But at least one person commenting on the article seems to understand the difference:</p>
<p><a href="http://resource.onlinetech.com/hipaa-certified-vs-hipaa-compliant/compliant-cloud-comment/" rel="attachment wp-att-6320"><img class="alignleft size-full wp-image-6320" title="" src="http://resource.onlinetech.com/wp-content/uploads/compliant-cloud-comment.png" alt="HIPAA Certified?" width="633" height="237" /></a></p>
<p>So for service providers in the healthcare industry &#8211; and for healthcare organizations that contract out to them, please take heed: the correct term is <strong>“HIPAA compliant”</strong> not “HIPAA certified.” Be wary of those that claim to be certified &#8211; because chances are, they might not really know what they’re talking about at all.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-certified-vs-hipaa-compliant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing on the Internet Advisor Radio Show</title>
		<link>http://resource.onlinetech.com/cloud-computing-on-the-internet-advisor-radio-show/</link>
		<comments>http://resource.onlinetech.com/cloud-computing-on-the-internet-advisor-radio-show/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 15:09:36 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6311</guid>
		<description><![CDATA[Mike Klein, COO and President of Online Tech will join a conversation about new business models driven by cloud computing on the Internet Advisor Show on 760am WJR on Saturday, April 14th from 4:30 to 4:45pm. Klein will join other technology and &#8230; <a href="http://resource.onlinetech.com/cloud-computing-on-the-internet-advisor-radio-show/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Mike Klein</strong>, COO and President of Online Tech will join a conversation about new business models driven by <a href="index.php?Itemid=536">cloud computing</a> on the Internet Advisor Show on 760am WJR on Saturday, April 14th from 4:30 to 4:45pm.</p>
<p>Klein will join other technology and business professionals in the discussion about cloud hosting, including:</p>
<p><strong>M.S. Krishnan</strong>, PhD., Joseph Handleman Professor of Information Systems and Innovation at the Ross School of Business, University of Michigan; Faculty Director of India Initiatives; Professor of Business Information Technology</p>
<p><strong>Gary Baker</strong>, Director of IT/CIO for the Society of Manufacturing Engineers (SME), previously SVP &amp; CIO at Gale, a part of Cenage Learning and VP of IT Delivery at Borders Group.</p>
<p>They will be also be presenting <em><a href="http://www.rossmich.org/article.html?aid=198">Cloud Computing: Approach Innovatively and Understand Trends</a></em> to the Ross School of Business Alumni Club of Southeast Michigan on Thursday, April 19th, 2012, hosted at Online Tech&#8217;s <a href="company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor 2 data center</a>. There will be tours of the data center at the event and networking. For more information and to register, visit the <a href="http://www.rossmich.org/article.html?aid=198">event page</a>.</p>
<p><strong>About the Internet Advisor Radio Program</strong></p>
<p>Foster Braun and Gary Baker co-host the Internet Advisor radio program (<a href="http://www.internetadvisor.net">www.internetadvisor.net</a>) on WJR 760AM – Detroit. Now in its 15th year, the program is on 4-6 pm ET on Saturdays. Internet Advisor is also syndicated on the Michigan Talk Network.  The goals of the program are to promote good Internet resources and solutions audiences located in Southeastern Michigan or the Midwest, and help listeners have a better online experience. WJR is known as the “Great Voice of the Great Lakes” and is one of the 12 original 50,000 watt, clear channel super stations.</p>
<hr />
<p><strong>Mike Klein, President, Online Tech</strong></p>
<p><img class="alignleft" src="http://www.onlinetech.com/images/stories/people/mike-klein-100.jpg" alt="Mike Klein of Online Tech" width="100" height="138" /></p>
<p>Mike is a serial entrepreneur with more than 30 years of high tech business leadership, technology, and startup experience including CEO of Interlink Networks, Managing Partner of CompanyCrafters, and CEO /Founder of Steeplechase Software, an INC 500 Company which he sold to Schneider Electric. Prior to becoming an entrepreneur, Mike spent the first decade of his career working in sales, strategic marketing, product development at Motorola Semiconductor and Rockwell International.</p>
<hr />
<p><strong>M.S. </strong><strong>Krishnan</strong>, <strong>PhD., Joseph Handleman Professor of Information Systems and Innovation at the Ross School of Business, University of Michigan</strong></p>
<p><img class="alignleft" src="http://www.bus.umich.edu/Photos/177030.jpg" alt="M.S. Krishnana, PhD." width="100" height="138" /></p>
<p>Dr. M. S. Krishnan (&#8220;Krishnan&#8221;) is Mary and Mike Hallman e-Business Fellow, Area Chairman and Professor of Business Information Technology at the University of Michigan Business School. Dr, Krishnan is also a Co-Director of the Center for Global Resource Leverage:India at the Michigan Business School. Dr. Krishnan received his Ph.D. in Information Systems from the Graduate School of Industrial Administration, Carnegie Mellon University in 1996. He has co-authored the book &#8220;The New Age of Innovation: Driving Co-Created Value with Global Networks&#8221; with C.K.Prahalad.</p>
<hr />
<p><strong>Gary Baker, Director of IT/CIO for the Society of Manufacturing Engineers (SME) and Co-Host of the Internet Advisors Radio Program</strong></p>
<p><img class="alignleft" src="http://internetadvisor.net/wp-content/uploads/2012/01/Gary.jpg" alt="Gary Baker" width="103" height="108" /></p>
<p>Gary Baker has had a long career working with computers and promoting technology development in Michigan. In the fall of 1997 when Foster called his ISP, Online Technologies Corporation (now Online Tech), and asked for help with some connection issues he talked with Gary, who was President and one of the founders. Their conversation and the whole idea of helping people enjoy their computer and online experience grew from there into the Internet Advisor show in early 1998 and an alliance that has become Detroit’s longest running locally produced technology talk show since then. Gary also appeared as the Internet Advisor on Channel 7 Action News, WXYZ-TV in Detroit, every Thursday morning from October 2000 to October 2002.</p>
<p>Gary is currently the Director of IT/CIO for the Society of Manufacturing Engineers (SME) and previously was the SVP &amp; CIO at Gale, a part of Cengage Learning and VP of IT Delivery at Borders Group in Ann Arbor. He was also a partner in Arthur Andersen’s Business Consulting, Director of IT Transformation Services at AlixPartners and an executive in EDS at GM. Gary is a sought after lecturer on IT topics and new processes and technologies locally and nationally.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cloud-computing-on-the-internet-advisor-radio-show/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech to Exhibit HIPAA Hosting Solutions at HIMSS 13 in New Orleans</title>
		<link>http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/</link>
		<comments>http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/#comments</comments>
		<pubDate>Wed, 11 Apr 2012 14:44:15 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[HIMSS 12]]></category>
		<category><![CDATA[himss 13]]></category>
		<category><![CDATA[himss 13 conference]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6169</guid>
		<description><![CDATA[Though it feels like HIMSS 12 was just a few weeks ago, we&#8217;re looking forward to exhibiting at next year&#8217;s HIMSS 13 event, and we&#8217;ve already booked our booth (#1369)! The annual HIMSS conference is one of the largest healthcare IT &#8230; <a href="http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" title="Online Tech is a Gold Corporate HIMSS Member" src="http://www.onlinetech.com/images/stories/misc/himss%20gold%20corporate%20member.png" alt="Online Tech is a Gold Corporate HIMSS Member" width="254" height="83" /></p>
<p>Though it feels like <a href="http://www.onlinetech.com/resources/events/seminars/online-tech-to-exhibit-at-himss-12">HIMSS 12</a> was just a few weeks ago, we&#8217;re looking forward to exhibiting at next year&#8217;s HIMSS 13 event, and we&#8217;ve already booked our booth (#1369)! The annual HIMSS conference is one of the largest healthcare IT and management systems conferences in the world, bringing healthcare industry professionals and exhibitors together from around the nation.</p>
<p>Located in New Orleans, HIMSS 13 will be held at the Ernest N. Morial Convention Center next to the Mississippi River. As the nation&#8217;s sixth largest convention center, we&#8217;re anxious to see if HIMSS 13 will break their record of attendees again &#8211; HIMSS 12 attendees of 37,032 broke the HIMSS 11 attendance of 31,500.</p>
<div id="attachment_6228" class="wp-caption alignleft" style="width: 376px"><a href="http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/himss-13-exhibition-floor/" rel="attachment wp-att-6228"><img class="wp-image-6228 " title="HIMSS 13 Exhibition Floor" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-13-Exhibition-Floor.png" alt="HIMSS 13 Exhibition Floor" width="366" height="183" /></a><p class="wp-caption-text">HIMSS 13 Exhibition Floor</p></div>
<p>Online Tech is an official gold corporate HIMSS member. And once again, Online Tech will be exhibiting our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> solutions for healthcare organizations, healthcare Software-as-a-Service (Saas) and other related organizations at <strong>Booth #1369. </strong>Find out more about our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a>, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/managed-servers">HIPAA managed servers</a>, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/colocation">HIPAA colocation</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">cloud-based disaster recovery</a> solutions.</p>
<p>We’re one of the first and few 100% HIPAA compliant hosting and <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> providers that have undergone an independent audit by a CHP (Certified HIPAA Practitioner) and CHSS (Cerified HIPAA Security Specialist) and can provide a copy of our audit report to clients under NDAs (non-disclosure agreements).</p>
<p>We also sign business associate agreements (BAAs) to clarify our role and responsibilities when it comes to protecting your personal health information (PHI) and breach notification policies.</p>
<div id="attachment_6217" class="wp-caption alignright" style="width: 330px"><a href="http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/ernest-convention-center-lobby-2/" rel="attachment wp-att-6217"><img class="wp-image-6217 " title="Ernest Convention Center Lobby" src="http://resource.onlinetech.com/wp-content/uploads/Ernest-Convention-Center-Lobby1.jpg" alt="Ernest Convention Center Lobby" width="320" height="213" /></a><p class="wp-caption-text">Ernest Convention Center Lobby</p></div>
<p>For more HIPAA hosting resources:</p>
<ul>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/100-hipaa-compliant">100% HIPAA Compliant</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-hipaa-compliance">What is HIPAA Compliance?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">What is a HIPAA Violation?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-compliant-case-studies">HIPAA Compliant Case Studies</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/who-needs-to-be-hipaa-compliant">Who Needs to be HIPAA Compliant?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/benefits-of-hipaa-compliant-hosting">Benefits of HIPAA Compliant Hosting</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources: Policies, Procedures and Training Materials</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-faq">HIPAA FAQ</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/five-questions-to-ask-your-business-associates">Five Questions to Ask Your Business Associates</a></li>
<li><a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider">Five Questions to Ask Your HIPAA Hosting Provider</a></li>
</ul>
<p><strong>Check back often for more information about HIMSS &#8217;13, including helpful links and the latest announcements about speakers, exhibitors and attendees!</strong></p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="319"><strong>HIMSS 13 Location:</strong></td>
<td valign="top" width="319"><strong>HIMSS 13 Date:</strong></td>
</tr>
<tr>
<td valign="top" width="319">Ernest N. Morial Convention Center<br />
900 Convention Center Boulevard<br />
New Orleans, LA 70130</td>
<td valign="top" width="319">Monday, March 4 &#8211; Thursday, March 7, 2013</td>
</tr>
<tr>
<td valign="top" width="319"><strong>HIMSS 13 Vendors:</strong></td>
<td valign="top" width="319"><strong>HIMSS 13 Hotels:</strong></td>
</tr>
<tr>
<td valign="top" width="319">Find rates, booth selection and more <a href="http://vendor.himss.org/himss12/exhPE.ASPX">here</a>.View the <a href="http://exhibitionfloor.himss.org/himss2013/public/FloorPlan.aspx?MapID=1&amp;CatID=0">HIMSS 13 Floor Plan</a>.</td>
<td valign="top" width="319">Available only for Attendees &#8211; Exhibitor housing will open in Summer 2012. Book your rooms <a href="https://onpeak.compassreservations.com/compass/external/index.cfm?meeting_ID=3770&amp;Meeting_ID_Code=493305440&amp;utm_medium=&amp;utm_source=&amp;utm_campaign=">here</a>.</td>
</tr>
</tbody>
</table>
<div id="attachment_6287" class="wp-caption alignleft" style="width: 360px"><a href="http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/ernest-convention-center-exhibit-floor/" rel="attachment wp-att-6287"><img class=" wp-image-6287 " title="Ernest Convention Center Exhibit Floor" src="http://resource.onlinetech.com/wp-content/uploads/Ernest-Convention-Center-Exhibit-Floor.jpg" alt="Ernest Convention Center Exhibit Floor" width="350" height="234" /></a><p class="wp-caption-text">Ernest Convention Center Exhibit Floor</p></div>
<p><strong>About HIMSS</strong></p>
<p>HIMSS is a cause-based, not-for-profit organization exclusively focused on providing global leadership for the optimal use of information technology (IT) and management systems for the betterment of healthcare. Founded 51 years ago, HIMSS and its related organizations are headquartered in Chicago with additional offices in the United States, Europe and Asia.</p>
<p>HIMSS represents more than 44,000 individual members, of which more than two thirds work in healthcare provider, governmental and not-for-profit organizations. HIMSS also includes over 570 corporate members and more than 170 not-for-profit organizations that share our mission of transforming healthcare through the effective use of information technology and management systems.</p>
<p>HIMSS frames and leads healthcare practices and public policy through its content expertise, professional development, research initiatives, and media vehicles designed to promote information and management systems’ contributions to improving the quality, safety, access, and cost-effectiveness of patient care. To learn more about HIMSS and to find out how to join us and our members in advancing our cause, please visit our website at <a href="http://www.himss.org/">www.himss.org</a>.</p>
<p>References:<br />
<a href="http://press.himss.org/article_display.cfm?article_id=5392">HIMSS 12 Breaks Previous Attendance Records</a><br />
<a href="http://www.mccno.com/">New Orleans Ernest N. Morial Convention Center</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-to-exhibit-hipaa-hosting-solutions-at-himss-13-in-new-orleans/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stage 2 Meaningful Use Implications on HIPAA Hosting</title>
		<link>http://resource.onlinetech.com/stage-2-implications-on-hipaa-hosting/</link>
		<comments>http://resource.onlinetech.com/stage-2-implications-on-hipaa-hosting/#comments</comments>
		<pubDate>Tue, 10 Apr 2012 15:13:48 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[certified EHR]]></category>
		<category><![CDATA[certified EHR systems]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[stage 2 meaningful use]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6162</guid>
		<description><![CDATA[Initially I had some difficulty pinning down the exact objectives and implications Stage 2 meaningful use would have on health IT for healthcare organizations that deal with electronic protected health information (ePHI). I combed through the entire document for any &#8230; <a href="http://resource.onlinetech.com/stage-2-implications-on-hipaa-hosting/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Initially I had some difficulty pinning down the exact objectives and implications Stage 2 meaningful use would have on health IT for healthcare organizations that deal with electronic protected health information (ePHI). I combed through the entire document for any implications the proposed revisions might have on the <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> aspect of health IT, as that can affect the decisions our clients make and our ability to fulfill those needs to help meet compliance and meaningful use.</p>
<p>Here’s a rundown of what I could pinpoint through a review of the official federal register document, 42 CFR Parts 412, 413 and 495, Medicare and Medicaid Programs; Electronic Health Record Incentive Program &#8211; Stage 2.</p>
<p><strong>Encryption</strong></p>
<p>In Stage 2, the proposed rule is to highlight the importance of encryption while conducting a security risk analysis. While the proposal does not seek to make encryption a requirement under the HIPAA Security Rule, awareness of encryption and the security of data at rest will be emphasized as a key measure in the review of a security risk analysis/assessment.</p>
<p>The federal register acknowledges that a recent HHS analysis of reported shows nearly 40 percent of large breaches were due to lost or stolen devices &#8211; encryption could secure data on any device and prevent data leaks.</p>
<p><strong>Data Accessibility by Patients</strong></p>
<p>In Stage 1, a core objective requires eligible hospitals to provide patients with an electronic copy of their health information upon request. Stage 2 ups the ante by requiring hospitals to provide patients with timely electronic access to their health information within 4 business days of information being made available to the hospital.</p>
<p>Stage 2 proposes an online patient portal or personal health record (PHR) be available to allow patient access to lab results, problem list, medication lists and allergies. This provision would call for the integration of a patient portal system into the IT infrastructure of any eligible hospital, increasing the need to streamline and support an always-available system.</p>
<p>But what if there was hardware failure, or a natural disaster that affected your data and application availability? In the event of a disaster, a formal disaster recovery plan can ensure your data will be readily available to meet future meaningful use requirements. <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">Cloud-based disaster recovery</a> can provide recovery time objectives of four hours, meaning patient data can be recovered and available on a timely basis.</p>
<p><strong>Medical Imaging Accessibility</strong></p>
<p>A new core objective for Stage 2 proposes that imaging results and information are accessible through Certified EHR Technology. By making medical imaging results (CAT Scans, CT Scans, X-Rays, etc.) available through an EHR system, the provision intends to reduce unnecessary costs and radiation exposure from tests repeated only because a prior test is not available to the provider.</p>
<p>Making medical images accessible through these systems means the need the invest in high-capacity data storage. A high-capacity <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting/high-capacity-hipaa-cloud">HIPAA cloud hosting</a> solution can provide massive storage or synchronization with scalability to grow as your storage needs require.</p>
<p>The Stage 2 meaningful use proposed changes may affect the certification process for EHR systems. As Kyle Murphy writes in <a href="http://iht2blog.com/2012/04/05/what-does-onc-mean-by-a-certified-ehr/">What Does ONC Mean by a Certified EHR?</a> - to demonstrate meaningful use, you need a certified EHR system; to create a certifiable EHR system, you need to know how to meet the different stages of meaningful use.</p>
<p>References:<br />
<a href="http://www.gpo.gov/fdsys/pkg/FR-2012-03-07/pdf/2012-4443.pdf">Medicare and Medicaid Programs; Electronic Health Record Incentive Program &#8211; Stage 2</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/stage-2-implications-on-hipaa-hosting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Server Hack Leads to HIPAA Violation by Utah Department of Health</title>
		<link>http://resource.onlinetech.com/server-hack-leads-to-hipaa-violation-by-utah-department-of-health/</link>
		<comments>http://resource.onlinetech.com/server-hack-leads-to-hipaa-violation-by-utah-department-of-health/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 15:03:06 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[2012 hipaa violations]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6157</guid>
		<description><![CDATA[4/10 Update &#8211; 780,000 may be affected. A configuration error at the authentication level of a server allowed hackers from Eastern Europe to access 25,000 social security numbers and the personal records of over 181,000 individuals collected by the Utah &#8230; <a href="http://resource.onlinetech.com/server-hack-leads-to-hipaa-violation-by-utah-department-of-health/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>4/10 Update &#8211; 780,000 may be affected.</p>
<p>A configuration error at the authentication level of a server allowed hackers from Eastern Europe to access 25,000 social security numbers and the personal records of over 181,000 individuals collected by the Utah Department of Health (UDOH). The server was managed by the Utah Department of Technology Services (DTS). In the process of moving Medicaid claims records to a new server, hackers were able to access ePHI despite the DTS’s security system, resulting in the latest <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">HIPAA violation</a>.</p>
<p>Hackers removed 24,000 files from the server &#8211; according to the UDOH, one file can potentially contain claims information on hundreds of individuals. The UDOH reports that the DTS servers have multi-layered security systems containing perimeter security, network security, identity management, application security and data security, but the question remains, would they pass a HIPAA audit of their controls?</p>
<p>The UDOH claims that the DTS has process in place to secure their data, but the “particular server was not configured according to normal procedure.” This may have simply been an oversight by DTS staff, but it also raises the question of whether or not their employees are trained in HIPAA security policies and procedures.</p>
<p>An IT or data center organization that handles ePHI on their servers need to have multiple layers of security, including staff trained to implement technology in accordance with HIPAA standards. The DTS should have an appointed security and risk management officer employed to oversee training, with documented dates of completion.</p>
<p>The <a href="http://udohnews.blogspot.com/2012/04/impact-of-dts-data-breach-on-medicaid.html">UDOH blog</a> states the DTS has implemented new processes to prevent a future breach, including improving security controls related to implementing computer hardware and software, and increasing network monitoring and intrusion detection capabilities.</p>
<p>In a previous blog, I wrote about <a href="http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/">What to Look for in a Cloud Hosting Provider</a>, highlighting the U.S. General Services Administration (GSA)’s Dave McClure’s criteria for a secure <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> provider. One criterion included the need for continuous monitoring with real-time alerts instead of post-breach audits. The same holds true when seeking a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> or <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a> provider &#8211; network monitoring can alert IT staff of any unauthorized access to a server and allow them to move quickly to remediate.</p>
<p>For more on HIPAA violations, including violation types, minimum and maximum penalties, and common mistakes made by companies resulting in a data breach, read <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">What is a HIPAA Violation?</a></p>
<p>References:<br />
<a href="http://udohnews.blogspot.com/2012/04/impact-of-dts-data-breach-on-medicaid.html">Impact of Medicaid Data Breach on DTS Server Widens</a><br />
<a href="http://www.medlawblog.com/articles/hipaa-and-hit/data-breach-of-24000-medicaid-claims-by-hackers/">Data Breach of 24,000 Medicaid Claims by Hackers</a><br />
<a href="http://www.zdnet.com/blog/security/medicaid-hacked-over-181000-records-and-25000-ssns-stolen/11432">Medicaid Hacked: Over 181,000 Records and 25,000 SSNs Stolen</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/server-hack-leads-to-hipaa-violation-by-utah-department-of-health/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New PCI Compliant Hosting Solutions</title>
		<link>http://resource.onlinetech.com/new-pci-compliant-hosting-solutions/</link>
		<comments>http://resource.onlinetech.com/new-pci-compliant-hosting-solutions/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 12:27:17 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[pci cloud hosting]]></category>
		<category><![CDATA[pci colocation]]></category>
		<category><![CDATA[pci compliant clouds]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[pci dss hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci managed dedicated servers]]></category>
		<category><![CDATA[pci managed servers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6043</guid>
		<description><![CDATA[Our PCI cloud, colocation and managed server packages have just launched! Following the recent launch of our revamped and expanded HIPAA hosting section of our site, our PCI hosting pages provide everything you need to protect cardholder data with our &#8230; <a href="http://resource.onlinetech.com/new-pci-compliant-hosting-solutions/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Our PCI cloud, colocation and managed server packages have just launched!</p>
<p>Following the recent launch of our revamped and expanded <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> section of our site, our <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI hosting</a> pages provide everything you need to protect cardholder data with our full attestation of compliance with PCI DSS v.2.0.</p>
<p>Click through below for details.</p>
<p><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/packages/cloud-hosting"><img class=" alignnone" title="PCI Cloud Hosting" src="http://www.onlinetech.com/images/overview/pci-cloud-overview.png" alt="PCI Cloud Hosting" width="189" height="197" /></a><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/packages/managed-servers"><img class="alignnone" title="PCI Managed Servers" src="http://www.onlinetech.com/images/overview/pci-managed-servers-overview.png" alt="PCI Managed Servers" width="188" height="197" /></a><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/packages/colocation"><img class="alignnone" title="PCI Colocation" src="http://www.onlinetech.com/images/overview/pci-colocation-overview.png" alt="PCI Colocation" width="190" height="197" /></a></p>
<div id="attachment_6058" class="wp-caption alignright" style="width: 272px"><a href="http://resource.onlinetech.com/new-pci-compliant-hosting-solutions/pci-compliant-hosting-screenshot/" rel="attachment wp-att-6058"><img class="wp-image-6058   " title="PCI Compliant Hosting Screenshot" src="http://resource.onlinetech.com/wp-content/uploads/PCI-Compliant-Hosting-Screenshot.png" alt="PCI Compliant Hosting Screenshot" width="262" height="291" /></a><p class="wp-caption-text">PCI Compliant Hosting Screenshot</p></div>
<p>Get the facts about PCI and what you need to be PCI compliant:</p>
<ul>
<li><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/what-is-pci-compliance">What is PCI Compliance?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/pci-compliant-case-studies">PCI Compliant Case Studies</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/levels-of-pci-compliance">Levels of PCI Compliance</a></li>
<li><a href="http://www.onlinetech.com/resources/e-tips/pci-compliance/pci-compliant-hosting-guide">PCI Compliant Hosting Guide</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/who-needs-to-be-pci-compliant">Who Needs to Be PCI Compliant?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/pci-glossary-of-terms">PCI Glossary of Terms</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/benefits-of-pci-compliant-hosting">Benefits of PCI Compliant Hosting</a></li>
<li><a href="http://www.onlinetech.com/resources/e-tips/pci-compliance/risk-assessments-for-the-pci-compliant-cloud">Risk Assessments for the PCI Compliant Cloud</a></li>
</ul>
<p>Or watch our three-part PCI compliance webinar series with a PCI overview, detailed requirements and penetration testing discussion.</p>
<ul>
<li><a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-detailed-requirements">PCI Compliance: Detailed Requirements</a></li>
<li><a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-detailed-requirements">PCI Compliance: Overview</a></li>
<li><a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-penetration-testing">PCI Compliance: Penetration Testing</a></li>
</ul>
<p>Read about our <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/two-factor-authentication-for-vpn-login-faq">Two-Factor Authentication</a> service for VPN login in our FAQ.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/new-pci-compliant-hosting-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Report on Compliance</title>
		<link>http://resource.onlinetech.com/pci-report-on-compliance/</link>
		<comments>http://resource.onlinetech.com/pci-report-on-compliance/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 12:40:32 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[pci dss hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci report on compliance]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6126</guid>
		<description><![CDATA[If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, &#8230; <a href="http://resource.onlinetech.com/pci-report-on-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>If your company collects, transmits, stores or processes credit cardholder data, you will need to create a PCI DSS Report on Compliance at least annually for on-site assessments or self-reporting questionnaires. To sustain ongoing compliance after the initial point-in-time assessment, your company needs to design and implement a set of controls specific to PCI and security.</p>
<p>The PCI Security Standards Council provides a template for an attestation of compliance:</p>
<p><strong>Executive Summary</strong></p>
<ul>
<li>Entity’s payment card business description</li>
<li>High level network diagram</li>
</ul>
<p><strong>Description of Scope of Work and Approach Taken</strong></p>
<ul>
<li>How the assessment was made</li>
<li>Environment</li>
<li>Network segmentation used</li>
<li>Details for each sample set tested</li>
<li>Any international entities requiring compliance with PCI DSS</li>
<li>Wireless networks or applications</li>
<li>Version of PCI DSS used to conduct assessment (2.0 is the latest)</li>
</ul>
<p><strong>Details About Reviewed Environment</strong></p>
<ul>
<li>Network diagrams</li>
<li>Cardholder data environment</li>
<li>List of hardware and software in the cardholder data environment (CDE)</li>
<li>Service providers</li>
<li>Third-party applications</li>
<li>Individuals interviewed</li>
<li>Documentation reviewed</li>
<li>Reviews of managed service providers</li>
</ul>
<p><strong>Contact Information and Reporting Date</strong></p>
<p><strong>Quarterly Scan Results</strong></p>
<ul>
<li>Including the four most recent ASV (approved scanning vendor) scan results</li>
</ul>
<p><strong>Findings and Observations</strong></p>
<ul>
<li>Requirements and sub-requirements</li>
<li>Explain N/A responses</li>
<li>Validation of all compensating controls</li>
</ul>
<p>When it comes to documenting details about your reviewed environment, any of your managed service providers/<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI hosting</a> providers should be able to produce their own attestation of compliance report to inform your company about their controls and security. This can save you the time it takes to review and report on their compliance as it affects your company and cardholder data.</p>
<p>References:<br />
<a href="https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf">PCI DSS Quick Reference Guide (Version 2.0)</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-report-on-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What to Look for in a Cloud Hosting Provider</title>
		<link>http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/</link>
		<comments>http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 12:55:00 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[benefits of cloud computing]]></category>
		<category><![CDATA[cloud computing security]]></category>
		<category><![CDATA[cloud drivers]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud hosting costs]]></category>
		<category><![CDATA[cloud hosting security]]></category>
		<category><![CDATA[hybrid clouds]]></category>
		<category><![CDATA[managed cloud]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6094</guid>
		<description><![CDATA[A recent study by KPMG on federal cloud adoption reveals main drivers, demotivators and tips for what to look for in a cloud hosting provider for both private and the public sector. The study reported findings on governments, citizens, cloud &#8230; <a href="http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A recent study by KPMG on federal cloud adoption reveals main drivers, demotivators and tips for what to look for in a <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> provider for both private and the public sector. The study reported findings on governments, citizens, cloud service providers and IT leaders.</p>
<div id="attachment_6097" class="wp-caption alignright" style="width: 417px"><a href="http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/cloud-hosting-security/" rel="attachment wp-att-6097"><img class="wp-image-6097  " title="Cloud Hosting Security" src="http://resource.onlinetech.com/wp-content/uploads/Cloud-Hosting-Security.png" alt="Cloud Hosting Security" width="407" height="327" /></a><p class="wp-caption-text">Cloud Hosting Security</p></div>
<p>Security is a major concern when it comes to the cloud, but certification could help &#8211; while 47 percent of government respondents cite security as their most significant concern, nearly 80 percent claimed they would be more confident if cloud services were certified by a government entity.</p>
<p>Cost is the main driver for both government and the private sector to move to the cloud, with 73% and 75% respectively claiming it was necessary to realize cost reductions and savings in order to move to a cloud environment.</p>
<p>But how significant would those savings need to be in order to make the transition? At 43%, the private sector only needs 1-10% reduction in IT or non-IT costs to switch over, while the public sector appears to be confused, with 29% claiming they didn’t know what percent reduction in budgetary costs they needed in order to make a cloud decision.</p>
<p>In addition to cost, technical drivers, such as flexibility, scalability, simplicity, security and advanced technology, were ranked as either important or extremely important by 79% of government respondents, and likewise by the private sector.</p>
<div id="attachment_6106" class="wp-caption alignleft" style="width: 457px"><a href="http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/cloud-drivers/" rel="attachment wp-att-6106"><img class=" wp-image-6106 " title="Cloud Drivers" src="http://resource.onlinetech.com/wp-content/uploads/Cloud-Drivers.png" alt="Cloud Drivers" width="447" height="268" /></a><p class="wp-caption-text">Cloud Drivers</p></div>
<p>Strategic factors, such as process transformation, linkage to business/organization partners, speed to market/implementation and a focus on core competencies were ranked as important or extremely important by 77% of private businesses. This extends the <a href="http://resource.onlinetech.com/benefits-of-private-cloud-computing-compliant-cost-effective/">benefits of cloud computing</a> to a broader business perspective as companies prepare for long-term growth and reorganize priorities in order to realize increased efficiency.</p>
<p>What does a government (and as should any company concerned with security) look for in a cloud provider? Dave McClure, Associate Administrator of the Office of Citizen Services and Innovative Technologies at the U.S. General Services Administration (GSA) lists a few:</p>
<ul>
<li>“Cloud service providers face a long and tough accreditation and authorization process” including an assessment of access controls and tests to determine the level of knowledge a cloud provider has about relevant potential risks.</li>
<li>Continuous monitoring with real-time alerts instead of post-breach audits is important in order to be “on top of any breach as fast as we can be,” according to McClure.</li>
<li>For optimal security, multiple levels of technical controls, operational controls and policy controls are necessary to eliminate risk from all angles. Similar to the pillars of <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA</a> safeguards that require policies regarding administrative, technical and physical security, complete data protection requires vigilance and cohesion in many different areas of an organization.</li>
<li>McClure also is concerned with the <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/managed-cloud">managed cloud</a> &#8211; he says he is looking for providers that have a clear vision when it comes to integrating and managing the cloud within a legacy environment, more commonly known as hybrid clouds. <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/hybrid-cloud-hosting">Hybrid clouds</a> integrate different types of IT infrastructures to support a highly customized IT environment with cloud servers used to support some services but not all.</li>
</ul>
<p>The study provides some excellent closing insights/tips for a range of professionals, including government leaders, government IT professionals, cloud vendors and more. Recognizing the new security challenges presented by the cloud, the study advises government leaders (or business leaders) to find an effective and accurate way to audit several areas under the cloud, including:</p>
<ul>
<li>Internal audits</li>
<li>Global security</li>
<li>Regulatory implications of data privacy</li>
<li>Storage, <a href="http://www.onlinetech.com/colocation/overview">colocation</a> and more.</li>
</ul>
<p>The study urges professionals to ask the following questions as they navigate the cloud vendor selection process:</p>
<ul>
<li>How can you ensure all regulatory requirements are met?</li>
<li>What internal controls over data security need to be implemented?</li>
<li>How will the data breach/disclosure process play out?</li>
<li>What is the process for sharing data encryption keys internally and with a vendor? etc.</li>
</ul>
<p>For more on the cloud, check out our comprehensive <a href="http://www.onlinetech.com/resources/wiki">Cloud Wiki</a> and our informative <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing">Cloud Computing E-Tips</a>.<br />
References:</p>
<p><a href="http://www.kpmg.com/Ca/en/IssuesAndInsights/ArticlesPublications/Documents/Exploring-the-Cloud-A-Global-Study-of-Governments-Adoption-of-Cloud.pdf">KPMG Global Study of Governments&#8217; Adoption of the Cloud</a> (PDF)<strong id="internal-source-marker_0.825805279891938"><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/what-to-look-for-in-a-cloud-hosting-provider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Global Payments Inc. PCI Data Breach Affects 1.5 Million</title>
		<link>http://resource.onlinetech.com/global-payments-inc-pci-data-breach-affects-1-5-million/</link>
		<comments>http://resource.onlinetech.com/global-payments-inc-pci-data-breach-affects-1-5-million/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 12:25:21 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[global payments inc.]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant data centers]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=6085</guid>
		<description><![CDATA[Nearly 1.5 million consumers have been hit by a major credit card hack &#8211; a statement by Global Payments Inc. reports that credit card numbers may have been exported by hackers with access to its payment processing system. Global Payments &#8230; <a href="http://resource.onlinetech.com/global-payments-inc-pci-data-breach-affects-1-5-million/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Nearly 1.5 million consumers have been hit by a major credit card hack &#8211; a statement by Global Payments Inc. reports that credit card numbers may have been exported by hackers with access to its payment processing system. Global Payments Inc. is one of the world’s largest electronic transaction processing companies, processing Visa and MasterCard card transactions.</p>
<p>Although the company has locations throughout the U.S., Canada, U.K., Europe and Asia-Pacific regions, the hackers reportedly only hit the North American portion of its network, according to MSNBC.MSN.com.</p>
<p>The company reports the cardholder data accessed is enough to make online purchases and potentially clone credit cards to commit fraud, despite not having access to names, addresses or social security numbers. The breach could potentially affect Visa and MasterCard cardholders, as well as Discover Financial Services and American Express. The company has launched a site, <a href="http://www.2012infosecurityupdate.com/index.html">2012 Information Security Update</a>, to offer insight into the incident and tips for both cardholders and merchants on what to look out for and how to further protect themselves from fraud.</p>
<p>The unauthorized intrusion in the company’s processing system was discovered in early March, and the cards were exposed between Jan. 21 and Feb. 25. A recent update reveals the company is still investigating and states the total cost of the breach is unknown, while they are working to achieve compliance with Visa’s PCI DSS compliance requirements.</p>
<p><strong>Effects of a PCI Compliance Data Breach</strong></p>
<p>Visa recently removed Global Payments from its comprehensive <a href="http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf">Global Registry of Service Providers</a> (PDF) that are official PCI DSS validated entities, although they still allow the company to process Visa card payments. MasterCard has yet to remove the company from their list of compliant processors as they are awaiting the investigation results.</p>
<p>What are the other consequences of a PCI data breach? MarketWatch.com reports that another credit card processor company that suffered a 40 million account breach in 2005 eventually sold their assets to another company after being dropped by multiple credit-card networks.</p>
<p>&#8220;Clearly not being PCI compliant has financial liability,&#8221; Global Payments Chairman and Chief Executive Garcia said, according to MarketWatch.com when questioned about the company’s lack of PCI compliance and its effect on costs for future merchant clients.</p>
<p>Taking risks when it comes to meeting PCI compliance standards can result in major business and reputation loss, in addition to remediation costs. Get started on the path to compliance by partnering with a <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI hosting</a> provider that can attest to full PCI compliance (read their full report to determine the scope of requirements they cover and what your company still needs to cover). A PCI compliant hosting provider can cover many of the technical requirements you need to lighten the burden of compliance by keeping cardholder data safe within fully audited <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data centers</a>.</p>
<p>Read more about the <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/levels-of-pci-compliance">Levels of PCI Compliance</a> to determine what kind of merchant you are based on your transaction volume, and what you need to do in order to achieve compliance. <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/what-is-pci-compliance">What is PCI Compliance?</a> lists the 12 requirements that your company needs to have in place.</p>
<p>And our <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/pci-glossary-of-terms">PCI Glossary of Terms</a> defines the basic PCI hosting-related terms you need to understand any PCI document. <a href="http://www.onlinetech.com/contact">Contact</a> us if you still have questions, or ask your questions via <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">Chat</a> now.</p>
<p>References:<br />
<a href="http://redtape.msnbc.msn.com/_news/2012/03/30/10940640-global-payments-under-15-million-account-numbers-hacked">Global Payments: Under 1.5 Million Account Numbers Hacked</a><br />
<a href="http://www.marketwatch.com/story/global-payments-still-tallying-data-breach-costs-2012-04-02">Global Payments Still Tallying Data Breach Costs</a><br />
<a href="http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf">Visa’s Global Registry of Service Providers &#8211; PCI DSS Validated Entities (PDF)</a><br />
<a href="http://www.globalpaymentsinc.com/USA/aboutUs/companyOverview.html">About Global Payments Inc.</a><br />
<a href="http://online.wsj.com/article/SB10001424052702304750404577320033811143226.html">Card Firm Says Systems Now Secure</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/global-payments-inc-pci-data-breach-affects-1-5-million/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Hosting Q&amp;A with a Certified HIPAA Practitioner &amp; Security Specialist</title>
		<link>http://resource.onlinetech.com/hipaa-hosting-qa-with-a-certified-hipaa-practitioner-security-specialist/</link>
		<comments>http://resource.onlinetech.com/hipaa-hosting-qa-with-a-certified-hipaa-practitioner-security-specialist/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 12:36:34 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[hipaa answers]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[hipaa FAQ]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa q&A]]></category>
		<category><![CDATA[hipaa questions]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[offsite backup]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5972</guid>
		<description><![CDATA[We get a lot of questions from clients about HIPAA compliance and security. To help clear up any confusion, our Certified HIPAA Practitioner (CHP) and Certified HIPAA Security Specialist (CHSS) Joe Dylewski of ATMP Solutions answered the questions we shared &#8230; <a href="http://resource.onlinetech.com/hipaa-hosting-qa-with-a-certified-hipaa-practitioner-security-specialist/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>We get a lot of questions from clients about HIPAA compliance and security. To help clear up any confusion, our Certified HIPAA Practitioner (CHP) and Certified HIPAA Security Specialist (CHSS) Joe Dylewski of <a href="http://www.atmpgroup.com/">ATMP Solutions</a> answered the questions we shared with him below:</p>
<p><strong>Q: What is the association of NIST w/ an independent HIPAA audit?</strong><br />
A: NIST is the National Institute of Standard and Technology. ATMP, utilizing SecureGRC, leverages NIST guidance when conducting HIPAA Risk Assessments.</p>
<p><strong>Q: Is it possible to be HIPAA compliant without an HROC (HIPAA Report on Compliance – or without a HIPAA risk assessment?</strong><br />
A: No. 45 CFR 164.308(a)(1)(ii)(a) is a required Implementation Specification under the HIPAA Security Rule, Security Management Process Standard. An HROC is not a required document. However, organizations must be able to produce evidence that they have completed an assessment and resolved any deficiencies or vulnerabilities. An HROC demonstrates the auditable steps that an organization took in that process.</p>
<p><strong>Q: Can you explain where the HITECH act specifies antivirus is “required”?</strong><br />
A: “Protection from Malicious Software,” 45 CFR 164.308(a)(5)(ii)(b), is an Addressable Implementation specification under the HIPAA Security Rule, Security Awareness and Training Standard. Addressable does not equate to Optional.</p>
<p>“Protection from Malicious Software” is one of the key HIPAA Implementation Specifications as it speaks to the Confidentiality, Integrity, and Availability of Electronic Protected Health Information.</p>
<p><strong>Q: What about offsite backup and/or disaster recovery?</strong><br />
A: The ability to store a recoverable set of Electronic Protected Health Information (ePHI), and test that process, are critical components that are governed by multiple HIPAA Implementation Specifications and Standards:</p>
<p><em>Contingency Plan Standard, 45 CFR 164.308(a)(7</em><em>)(i)</em></p>
<ul>
<li>Data <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">Backup</a> Plan (Required) – 45 CFR 164.308(a)(7)(ii)(A)</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">Disaster Recovery</a> Plan (Required) – 45 CFR 164.308(a)(7)(ii)(B)</li>
<li>Emergency Mode Operation Plan (Required) – 45 CFR 164.308(a)(7)(ii)(C)</li>
<li>Testing and Revision Procedures (Addressable) – 45 CFR 164.308(a)(7)(ii)(D)</li>
</ul>
<p><em>Device and Media Controls Standard, 45 CFR 164.310(d)(1)</em></p>
<ul>
<li>Data Backup and Storage (Addressable) – 45 CFR 164.310(d)(2)(iv)</li>
</ul>
<p>In addition to the Standards and Implementation Specifications listed, there are many others that factor into the procedures and safeguards that are implemented in the Backup and Recovery Process.</p>
<p><strong>Q: What about a firewall?</strong><br />
A: A firewall can be considered in multiple Standards and Implementation Specifications across the HIPAA Administrative, Physical, and Technical Safeguards. Remember that the purpose of a firewall is to restrict access to networks through a selective process of blocking inbound traffic.  In some cases, firewalls or content filters will also block outbound traffic.</p>
<p>While HIPAA does not call for the direct implementation of firewall technology, in most cases, it is the most reasonable and practical approach to addressing the requirements laid out in the HIPAA regulations.</p>
<p><strong>Q: What methodology did you use to come up with the 136 audited components for ATMP’s independent HIPAA audit?</strong><br />
A: In the development of the assessment methodology, a combination of technical, health care, and HIPAA knowledge was used. HIPAA is very clear in some areas and provides guidance in other areas. An objective risk based approach was integrated in the overall assessment process making it adaptable to any Covered Entity or Business Approach.</p>
<p><strong>Q: Can you explain why there is no such thing as “HIPAA certified”?</strong><br />
A: Unlike other compliance standards such as ISO and <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting">SOX</a>, HIPAA has not yet implemented a single audit standard. The industry relies on individuals and organizations who possess background in Information Technology, Health Care, and HIPAA to reasonably guide Covered Entities and Business Associates through the compliance process.</p>
<p>One of the main reasons that HIPAA has not implemented a single audit standard is due to the fact that one set of regulations governs all health care entities and their business partners. In other words, unlike <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI</a>, HIPAA does not have a subset of requirements in place, based on the size of the organization. HIPAA, in its original and current state, was designed to be a flexible, scalable, and vendor neutral architecture for compliance.</p>
<p><strong>Q: How many audited components go with each standard/citation ?</strong><br />
A: Based on the size and type of organization, we have adopted the following framework:</p>
<div id="attachment_5973" class="wp-caption alignleft" style="width: 466px"><a href="http://resource.onlinetech.com/hipaa-hosting-qa-with-a-certified-hipaa-practitioner-security-specialist/defined-scope-of-compliance/" rel="attachment wp-att-5973"><img class="size-full wp-image-5973" title="Defined Scope of HIPAA Compliance" src="http://resource.onlinetech.com/wp-content/uploads/Defined-Scope-of-Compliance.png" alt="Defined Scope of HIPAA Compliance" width="456" height="385" /></a><p class="wp-caption-text">Defined Scope of HIPAA Compliance</p></div>
<p>Still have other HIPAA-related questions? For more <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> resources, see our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-faq">HIPAA FAQ</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a>.</p>
<hr />
<p><img class="alignleft" src="http://www.onlinetech.com/images/stories/people/joe-dylewski-100.jpg" alt="Joe Dylewski of ATMP Group" width="100" height="138" /></p>
<p><strong>Joe Dylewski, President, ATMP Group</strong></p>
<p>Joseph Dylewski is a twenty-five year Information Technology Professional veteran, a Certified HIPAA Professional (CHP), and a Certified HIPAA Security Specialist (CHSS) with ten years spent exclusively in the Healthcare Industry. In addition to holding positions as a Project Manager and Director of Information Technology, Joseph has also served as a Healthcare IT Services Practices Director and Account Manager with a proven track-record of successfully delivering end-to-end IT application and infrastructure project services. Joseph also currently serves as an Assistant Professor at Madonna University.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-hosting-qa-with-a-certified-hipaa-practitioner-security-specialist/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Liveblogging from HIT &#8217;12 &#8211; Day 1</title>
		<link>http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/</link>
		<comments>http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 19:26:48 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[health information technology]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5950</guid>
		<description><![CDATA[We&#8217;re liveblogging from Jacksonville, Florida for the next couple of days, covering the HIT (Healthcare Information Technology) ’12 conference, Healthcare Information Transformation April 3-4, 2012. Online Tech&#8217;s HIPAA hosting solutions are fully audited and compliant to provide complete PHI protection for &#8230; <a href="http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re liveblogging from Jacksonville, Florida for the next couple of days, covering the HIT (Healthcare Information Technology) ’12 conference, Healthcare Information Transformation April 3-4, 2012.</p>
<p>Online Tech&#8217;s <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solutions are fully audited and compliant to provide complete PHI protection for many different healthcare organizations. We&#8217;ll be presenting on a panel, &#8220;PHI in the Cloud&#8221; to discuss <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> audits, contracts and compliance checklists.</p>
<p><strong>3:17 PM ET &#8211; Sunny skies in Florida:</strong></p>
<div id="attachment_5951" class="wp-caption alignleft" style="width: 433px"><a href="http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/florida2/" rel="attachment wp-att-5951"><img class=" wp-image-5951    " title="HIT '12 Conference on Healthcare Information Transformation" src="http://resource.onlinetech.com/wp-content/uploads/Florida2.jpg" alt="HIT '12 Conference on Healthcare Information Transformation" width="423" height="317" /></a><p class="wp-caption-text">HIT &#39;12 Conference on Healthcare Information Transformation</p></div>
<div id="attachment_5956" class="wp-caption alignleft" style="width: 433px"><a href="http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/florida1/" rel="attachment wp-att-5956"><img class=" wp-image-5956    " title="HIT '12 Conference on Healthcare Information Transformation" src="http://resource.onlinetech.com/wp-content/uploads/Florida1.jpg" alt="HIT '12 Conference on Healthcare Information Transformation" width="423" height="317" /></a><p class="wp-caption-text">HIT &#39;12 Conference on Healthcare Information Transformation</p></div>
<hr />
<p><strong>Online Tech&#8217;s HIPAA hosting booth set up and ready for tomorrow!</strong></p>
<div id="attachment_6032" class="wp-caption alignleft" style="width: 422px"><a href="http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/online-tech-hipaa-hosting-booth/" rel="attachment wp-att-6032"><img class=" wp-image-6032  " title="Online Tech HIPAA Hosting Booth" src="http://resource.onlinetech.com/wp-content/uploads/Online-Tech-HIPAA-Hosting-Booth.jpg" alt="Online Tech HIPAA Hosting Booth" width="412" height="549" /></a><p class="wp-caption-text">Online Tech HIPAA Hosting Booth</p></div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/liveblogging-from-hit-12-day-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Presents at Ann Arbor Virtualization Users Group Event</title>
		<link>http://resource.onlinetech.com/online-tech-presents-at-ann-arbor-virtualization-users-group-event/</link>
		<comments>http://resource.onlinetech.com/online-tech-presents-at-ann-arbor-virtualization-users-group-event/#comments</comments>
		<pubDate>Mon, 02 Apr 2012 13:10:55 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[ann arbor virtualization users group]]></category>
		<category><![CDATA[hyper-v]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5932</guid>
		<description><![CDATA[Online Tech will be speaking at the Ann Arbor Virtualization Users Group event April 19. Event topics include VMware via Command line &#8211; VMware SRM Lessons &#8211; Hyper-V Briefing. Online Tech Systems Administrator Chris Schmitt will speak at the event &#8230; <a href="http://resource.onlinetech.com/online-tech-presents-at-ann-arbor-virtualization-users-group-event/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech will be speaking at the Ann Arbor Virtualization Users Group event April 19. Event topics include VMware via Command line &#8211; VMware SRM Lessons &#8211; Hyper-V Briefing.</p>
<p>Online Tech Systems Administrator Chris Schmitt will speak at the event on <strong>Hyper-V Briefing</strong>. Chris will discuss the current state of the art in Hyper-V deployments and future features of Windows Server 8.</p>
<p>Other highlights of the event include:</p>
<p><strong>Topic:</strong> <em>How-To: VMware Command Line &#8211; GUIs are for Wimps</em><br />
<strong>Speaker</strong>: VMware vExpert Rodney Mach of HiperLogic<br />
<strong>Objectives</strong>: Manage your VMware environment at the command line, which opens up automation and reporting opportunities that aren&#8217;t possible via GUI. Learn how to create scripts from scratch and modify scripts online, as well as other tips, ticks and tools to successfully manage VMware via command line.</p>
<p><strong>Topic:</strong> <em>vCenter Site Recovery Manager in the Real World</em><br />
<strong>Speaker</strong>: Senior Server Engineer at a Mid-Michigan Insurance company Tim Wade<br />
<strong>Objectives</strong>: Real world implementation examples from the inside, including <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">private cloud</a> infrastructure, <a href="http://www.onlinetech.com/managed-services/managed-san-hosting">SAN storage</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a>.</p>
<p>The event will be held 6-8pm at Aubrees Tavern in Ypsilanti, Michigan. RSVP is required &#8211; find more event information and sign up here: <a href="http://aavmug.ning.com/events/aavugapril192012">http://aavmug.ning.com/events/aavugapril192012</a></p>
<p><strong>About The Ann Arbor Virtualization Users Group (AAVUG)</strong></p>
<p>The Ann Arbor Virtualization Users Group is an informal group of people who meet to share Virtualization solutions and ideas. Members with different degrees of knowledge learn from and support each other. AAVUG is a learning center, an open forum for new Virtualization enthusiasts as well as die hards. Events/meetings are held bi-monthly and include tips, help sessions, technology briefing and occasional demonstrations of hardware and software.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-presents-at-ann-arbor-virtualization-users-group-event/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing in 2012: Ready for Enterprise?</title>
		<link>http://resource.onlinetech.com/cloud-computing-in-2012-ready-for-enterprise/</link>
		<comments>http://resource.onlinetech.com/cloud-computing-in-2012-ready-for-enterprise/#comments</comments>
		<pubDate>Fri, 30 Mar 2012 12:48:31 +0000</pubDate>
		<dc:creator>Aaron Riddle</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[benefits of cloud computing]]></category>
		<category><![CDATA[benefits of cloud hosting]]></category>
		<category><![CDATA[cloud computing 2012]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud hosting 2012]]></category>
		<category><![CDATA[enterprise cloud]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[sox compliance]]></category>
		<category><![CDATA[sox hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5920</guid>
		<description><![CDATA[It’s no surprise that computing, applications, and data storage have been creeping ever so more and more into the idea of “the cloud.” Cloud computing is becoming more and more prevalent in everyday computing and has no signs of slowing &#8230; <a href="http://resource.onlinetech.com/cloud-computing-in-2012-ready-for-enterprise/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>It’s no surprise that computing, applications, and data storage have been creeping ever so more and more into the idea of “the cloud.” <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">Cloud computing</a> is becoming more and more prevalent in everyday computing and has no signs of slowing down from a personal perspective, and soon to be from an enterprise perspective.</p>
<div id="attachment_5921" class="wp-caption alignleft" style="width: 200px"><a href="http://resource.onlinetech.com/cloud-computing-in-2012-ready-for-enterprise/cloud-computing/" rel="attachment wp-att-5921"><img class="size-full wp-image-5921" title="Cloud Computing" src="http://resource.onlinetech.com/wp-content/uploads/Cloud-Computing.png" alt="Cloud Computing" width="190" height="148" /></a><p class="wp-caption-text">Cloud Computing</p></div>
<p>From a personal perspective, I can say that cloud computing is definitely the future and is here to stay. I can remember a few years ago when I would use my school’s email address and attach papers and homework to emails and send them to myself in order to print later that day, using it as a means to access my data at another computer. That’s the reason why the cloud is popular among personal users. Having that freedom to access data in multiple locations is the new wave of computing and is slowly being enveloped by today’s society.  We are seeing the cloud being used in everyday personal use more and more as Apple’s iCloud, Windows SkyDrive and Dropbox become increasingly integrated into some of our favorite websites and programs.</p>
<p>From a enterprise perspective however, we have seen, for quite some time, that many believe the cloud is not a viable option for their business.  As long as I can remember, there has always been a fear among organizations/companies about moving into a cloud environment. Whether it’s security, privacy or compliance, there has always been hesitation when considering if the cloud is right for your business.</p>
<p>With regards to security, big organizations have always had an uneasy feeling when it comes to cloud computing. Old traditional security architectures will not work in a cloud environment. When dealing with clouds, you also have to understand virtualization and make sure it’s secure and configured properly. While these are very easy to transition to, there is some planning that needs to be done to ensure the transition goes smoothly.</p>
<p>With security being discussed, compliance also comes into play. Whether it’s with <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI DSS</a>, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA</a> or <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting">SOX</a> compliance, it’s always a factor in any computing spectrum. Each type of compliance has its own guidelines, policies and procedures that need to be followed and in place to achieve said compliance. With all of the fines that could be placed on your own organization for not abiding by those rules, it’s essential that when looking at a cloud provider (or any sort of data/web hosting provider for that matter) to put in the research to determine their level of compliance.</p>
<p>Even with these added issues, I think that you’ll soon see organizations finally turn the other cheek and see the <a href="http://www.onlinetech.com/resources/wiki/cloud-computing/cloud-computing-benefits">benefits</a> (lower costs and scalability) and begin to lose this fear of “the cloud” and look at it as not “Should we use it?”, but “How can we use it?” Now is the time for it to thrive in the enterprise market, and I believe 2012 is the year for it to make its mark.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cloud-computing-in-2012-ready-for-enterprise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Speaks on Cloud Computing at Upcoming Healthcare IT Conference</title>
		<link>http://resource.onlinetech.com/online-tech-speaks-on-cloud-computing-at-healthcare-conference/</link>
		<comments>http://resource.onlinetech.com/online-tech-speaks-on-cloud-computing-at-healthcare-conference/#comments</comments>
		<pubDate>Thu, 29 Mar 2012 19:34:08 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[HIPAA cloud computing]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5875</guid>
		<description><![CDATA[Online Tech will be attending and participating on a panel at the HIT (Healthcare Information Technology) &#8217;12 conference, Healthcare Information Transformation, in Jacksonville, Florida next week, April 3-4, 2012. A variety of health plans, physician groups, hospitals, governmental associations and service &#8230; <a href="http://resource.onlinetech.com/online-tech-speaks-on-cloud-computing-at-healthcare-conference/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech will be attending and participating on a panel at the HIT (Healthcare Information Technology) &#8217;12 conference, Healthcare Information Transformation, in Jacksonville, Florida next week, April 3-4, 2012. A variety of health plans, physician groups, hospitals, governmental associations and service providers will be in attendence to discuss improving patient care with IT.</p>
<p>April Sage, Director of the Healthcare Vertical at Online Tech, will be speaking on a panel about PHI (protected health information) in the Cloud.</p>
<p><a href="http://resource.onlinetech.com/online-tech-speaks-on-cloud-computing-at-healthcare-conference/phi-in-the-cloud/" rel="attachment wp-att-5886"><img class=" wp-image-5886  alignleft" title="PHI in the Cloud" src="http://resource.onlinetech.com/wp-content/uploads/PHI-in-the-Cloud.jpg" alt="PHI in the Cloud" width="410" height="124" /></a></p>
<p><strong>PHI in the Cloud will discuss:</strong></p>
<ul>
<li>Negotiating contracts with cloud vendors</li>
<li>Making business decisions based on ROI and vendor delivery</li>
<li>Auditing-site visits</li>
<li><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC</a> and other cloud vendor/<a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> audits</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">Offsite backup</a>, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> and data destruction</li>
<li>Creating your checklist to ensure your <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a> solution is fully compliant</li>
</ul>
<p>The panel will be moderated by Shahid Shah, CEO of Netspective, Managing Editor of HITSphere and Chief Blogger of HealthcareGuy.com. Other speakers include:</p>
<ul>
<li>Edith Dees, VP/CIO of Holy Spirit Health System</li>
<li>Ronald Cowan, VP of Information Management/CIO of Lewistown Hospital</li>
</ul>
<p>How do we fit into the healthcare IT picture? Online Tech provides a variety of compliant and audited <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solutions including <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a>, <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/packages/colocation">HIPAA colocation</a> and <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/packages/managed-servers">HIPAA managed servers</a> for healthcare organizations and healthcare software providers that need their applications and data hosted in <a href="file:///C:/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">compliant data centers</a>.</p>
<p>View more about the conference panels and other workshops <a href="http://www.opalevents.org/conferencehtml/current/healthcare_information_transformation/healthcare_information_transformation_agenda.php">here</a>.</p>
<hr />
<p><img class="alignleft" title="002e7b8" src="http://resource.onlinetech.com/eNews/right-april.jpg" alt="AprilSage" width="80" height="120" /></p>
<p><strong>April Sage, CPHIMS, Director Healthcare Vertical, Online Tech</strong><br />
April Sage has been involved in the IT industry for over two decades, initially founding a technology program in the pre-Windows era teaching DOS, WordPerfect, and FoxPro. In 2000, April founded a bioinformatics company that supported biotech, pharma, and bioinformatic companies in the development of research portals, drug discovery search engines, and other software systems.</p>
<p>Since then, April has been involved in the development and implementation of online business plans and integrated marketing strategies across insurance, legal, entertainment, and retail industries until her current position as Director Healthcare Vertical of Online Tech.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-speaks-on-cloud-computing-at-healthcare-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech: First Michigan Data Center to Earn EPA’s ENERGY STAR Certification</title>
		<link>http://resource.onlinetech.com/online-tech-first-michigan-data-center-to-earn-epas-energy-star-certification/</link>
		<comments>http://resource.onlinetech.com/online-tech-first-michigan-data-center-to-earn-epas-energy-star-certification/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 12:45:34 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[ann arbor data centers]]></category>
		<category><![CDATA[energy efficient data centers]]></category>
		<category><![CDATA[green data centers]]></category>
		<category><![CDATA[green hosting facilities]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5821</guid>
		<description><![CDATA[Online Tech is the first data center operator in Michigan to earn EPA’s ENERGY STAR certification for its Mid-Michigan data center &#8211; meaning we perform within the top 25 percent of similar facilities nationwide for energy efficiency. What is ENERGY &#8230; <a href="http://resource.onlinetech.com/online-tech-first-michigan-data-center-to-earn-epas-energy-star-certification/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is the first data center operator in Michigan to earn EPA’s ENERGY STAR certification for its Mid-Michigan data center &#8211; meaning we perform within the top 25 percent of similar facilities nationwide for energy efficiency.</p>
<div id="attachment_5828" class="wp-caption alignleft" style="width: 341px"><a href="http://resource.onlinetech.com/online-tech-first-michigan-data-center-to-earn-epas-energy-star-certification/2012-energy-star-certification/" rel="attachment wp-att-5828"><img class=" wp-image-5828  " title="2012 ENERGY STAR Certification" src="http://resource.onlinetech.com/wp-content/uploads/2012-ENERGY-STAR-Certification.png" alt="2012 ENERGY STAR Certification" width="331" height="152" /></a><p class="wp-caption-text">2012 ENERGY STAR Certification</p></div>
<p>What is ENERGY STAR? ENERGY STAR is a federal joint program of the U.S. Environmental Protection Agency and U.S. Department of Energy to promote energy efficient products, services and buildings to significantly reduce greenhouse gas emissions and save on energy costs. The program has been adopted internationally as the official standard for energy efficient consumer products and services across Europe and Asia.</p>
<p>ENERGY STAR energy performance ratings can apply to all types of buildings, including hospitals, schools, banks, data centers and many others. According to the U.S. Energy Information Administration, commercial buildings alone account for 18% of total energy consumption.</p>
<p>Data center facilities, power and energy expenses account for 70-80 percent of total operational costs, though variable by region, according to a <a href="http://www.romonet.com/files/download/pdf/Build%20Or%20Buy_%20The%20Economics%20Of%20Data%20Center%20Facilities.pdf">Forrester report</a>. Compared to the 30 percent of a typical commercial building’s annual budget, according to <a href="http://www.energystar.gov/ia/business/comm_real_estate/downloads/BOMAKingsleyNewsletter.pdf?ae62-96c5">BOMA/Kingsley</a>, the energy required to cool, heat and operate a data center is immense.</p>
<p>Online Tech is also featured in the <a href="http://www.energystar.gov/index.cfm?fuseaction=labeled_buildings.locator">Energy Star online building registry</a> as an officially certified green data center operator. Our Mid-Michigan data center was originally built by EDS as General Motor’s disaster recovery data center &#8211; equipped with dual power from diverse routes, a pooled UPS system, multiple Internet Service Providers (ISPs) with diverse fiber feeds into the data center, multiple levels of physical security, including two-factor authentication, and 400 tons of cooling capacity with full N+1 redundancy.</p>
<div id="attachment_5866" class="wp-caption alignleft" style="width: 623px"><a href="http://resource.onlinetech.com/online-tech-first-michigan-data-center-to-earn-epas-energy-star-certification/mid-michigan/" rel="attachment wp-att-5866"><img class="size-full wp-image-5866" title="Online Tech's Mid-Michigan Data Center" src="http://resource.onlinetech.com/wp-content/uploads/mid-michigan.png" alt="Online Tech's Mid-Michigan Data Center" width="613" height="228" /></a><p class="wp-caption-text">Online Tech&#39;s Mid-Michigan Data Center</p></div>
<p>Find more detailed specifications about our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a> and all of our <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a>.</p>
<p>For more information about ENERGY STAR Certification for Industrial Facilities:<br />
<a href="http://www.energystar.gov/index.cfm?c=business.bus_bldgs">www.energystar.gov/labeledbuildings</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-first-michigan-data-center-to-earn-epas-energy-star-certification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIT &#8217;12 Conference on Healthcare Information Transformation</title>
		<link>http://resource.onlinetech.com/hit-12-conference-on-healthcare-information-transformation/</link>
		<comments>http://resource.onlinetech.com/hit-12-conference-on-healthcare-information-transformation/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 19:39:46 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5849</guid>
		<description><![CDATA[We&#8217;ve been busy! Online Tech is attending the HIT (Healthcare Information Technology) &#8217;12 Conference on Healthcare Information Transformation in Jacksonville, FL from April 3-4. The tagline is Leveraging IT to Improve Healthcare Delivery, with a focus on how implementing new &#8230; <a href="http://resource.onlinetech.com/hit-12-conference-on-healthcare-information-transformation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve been busy! Online Tech is attending the <strong><em>HIT (Healthcare Information Technology) &#8217;12 Conference on Healthcare Information Transformation</em></strong> in Jacksonville, FL from April 3-4.</p>
<div class="wp-caption alignright" style="width: 171px"><img title="HIT '12" src="http://www.onlinetech.com/images/stories/misc/hit-conference.png" alt="HIT '12" width="161" height="207" /><p class="wp-caption-text">HIT &#39;12</p></div>
<p>The tagline is <em>Leveraging IT to Improve Healthcare Delivery</em>, with a focus on how implementing new technology can lower costs, increase efficiency and improve patient care. The conference will examine the challenges of implementing health IT infrastructures and new technology, including security and privacy issues and federal regulations/meaningful use guidelines.</p>
<p>The top 12 issues to be covered at the conference concern healthcare IT executives:</p>
<ol>
<li>Prioritizing HIT issues in 2012 and beyond</li>
<li>IT innovation in the time of compliance</li>
<li>The challenges of ICD-10 implementation</li>
<li>Storage growth; keeping up with demand</li>
<li>Moving from data to analytics/business intelligence</li>
<li>Health information exchanges: architecture, applications, connectivity</li>
<li>Creating a mobile plan and infrastructure</li>
<li>Making information available anytime, anywhere</li>
<li>Meaningful use stage 2 and beyond—optimizing IT strategies</li>
<li>Considering the <a href="/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">cloud</a> for EHRs—or not</li>
<li>Integrating inpatient and outpatient information systems</li>
<li>Protecting data and privacy</li>
</ol>
<p><strong>How do we fit into the healthcare IT picture?</strong></p>
<p>Online Tech provides a variety of compliant and audited <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solutions including <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA cloud hosting</a>, <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/packages/colocation">HIPAA colocation</a> and <a href="file:///C:/secure-hosting/hipaa-compliant-hosting/packages/managed-servers">HIPAA managed servers</a> for healthcare organizations and healthcare software providers that need their applications and data hosted in <a href="file:///C:/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">compliant data centers</a>. Our audited solutions can help you achieve HIPAA compliance and create an IT system within federal regulations.</p>
<p>Find more information about the event, including location, attendees and speakers <a href="http://www.onlinetech.com/resources/events/seminars/hit-12-conference-on-healthcare-information-transformation">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hit-12-conference-on-healthcare-information-transformation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Receives Corp! Magazine&#8217;s 2012 DiSciTech Award</title>
		<link>http://resource.onlinetech.com/online-tech-receives-corp-magazines-2012-discitech-award/</link>
		<comments>http://resource.onlinetech.com/online-tech-receives-corp-magazines-2012-discitech-award/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 17:00:49 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[michigan economy]]></category>
		<category><![CDATA[mobile health IT]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5837</guid>
		<description><![CDATA[Online Tech President and COO Mike Klein will be accepting a 2012 DiSciTech Award from Corp! magazine at the awards ceremony Tuesday morning at the MSU Management Education Center in Troy, Michigan. The awards are given to honorees in Science &#8230; <a href="http://resource.onlinetech.com/online-tech-receives-corp-magazines-2012-discitech-award/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech President and COO Mike Klein will be accepting a 2012 DiSciTech Award from Corp! magazine at the awards ceremony Tuesday morning at the MSU Management Education Center in Troy, Michigan.</p>
<p>The awards are given to honorees in Science &amp; Technology, including Michigan companies or organizations that work in alternative energy,  advanced electronic and controls, advanced manufactoring, software, life sciences and more.</p>
<p>Awards are also distributed to those in the website, digital marketing, search engine optimization (SEO), blogs, webinars and other related digital industries.</p>
<p>The awards event will open with comments from Jennifer Kluge, Corp! Publisher and keynote speaker Linda Daichendt, Executive Director of the Mobile Technology Association of Michigan. The speech will cover mobile technology and its impact on Michigan business, with discussions on:</p>
<ul>
<li>How is mobile technology changing the way we live and the way business is conducted?</li>
<li>What is the current state of the mobile industry, its future, and its’ impact on Michigan’s economy?</li>
<li>How is mobile technology impacting specific verticals, and what opportunities does it provide – particularly in Michigan?</li>
<li>What are the challenges that Michigan must overcome to become a national leader in the mobile technology sector?</li>
<li>What do consumers really think about mobile, and how are they using it?</li>
<li>What are the options that companies can use to incorporate mobile into their business operations and marketing strategies to benefit themselves and/or their clients?</li>
</ul>
<p>Online Tech will also be featured in Corp! Magazine&#8217;s March/April Special Edition ePublication, to be released March 29th.</p>
<p>Find out more about the <a href="http://www.corpmagazine.com/events-and-community/corp-events/discitech-awards">DiSciTech event</a>, including location, time and registration.</p>
<p>For more on mobile technology, try reading:<br />
<a href="http://resource.onlinetech.com/mhealth-app-regulations-fda-hipaa/">Mobile Health App Regulations: FDA &amp; HIPAA</a><br />
<a href="http://resource.onlinetech.com/the-rise-of-the-healthcare-app-industry/">The Rise of the Healthcare App Industry</a><br />
<a href="http://resource.onlinetech.com/federal-mobile-strategy-increasing-access-to-mission-critical-data-streamlining-it/">Federal Mobile Strategy: Increasing Access to Mission-Critical Data &amp; Streamlining IT</a><br />
<a href="http://resource.onlinetech.com/mobile-security-are-most-apps-safe/"> Mobile Security: Are Most Apps Safe?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-receives-corp-magazines-2012-discitech-award/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Speaks at Crain&#8217;s Detroit Event on Michigan Business</title>
		<link>http://resource.onlinetech.com/online-tech-speaks-at-crains-detroit-event-on-michigan-business/</link>
		<comments>http://resource.onlinetech.com/online-tech-speaks-at-crains-detroit-event-on-michigan-business/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 15:19:39 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[ann arbor data centers]]></category>
		<category><![CDATA[economic gardening]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5802</guid>
		<description><![CDATA[Online Tech CEO Yan Ness will speak Tuesday morning on a panel at Crain&#8217;s Detroit Business Second-Stage Workshop in partnership with the Small Business Association of Michigan (SBAM), intended to provide resources and programs to help Michigan business growth opportunities. &#8230; <a href="http://resource.onlinetech.com/online-tech-speaks-at-crains-detroit-event-on-michigan-business/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Online Tech CEO <a href="http://www.onlinetech.com/company/online-tech-team">Yan Ness</a> will speak Tuesday morning on a panel at Crain&#8217;s Detroit Business Second-Stage Workshop in partnership with the <a href="https://www.sbam.org/WelcometoSBAM">Small Business Association of Michigan</a> (SBAM), intended to provide resources and programs to help Michigan business growth opportunities.</p>
<p>Speaking on Michigan&#8217;s economic gardening success stories, Yan will join other panelists at the workshop, including:</p>
<ul>
<li>Bonnie Alfonso, President and CEO of Alfie Logo Gear for Work and Play</li>
<li>Robert D. Fowler, President and CEO of Small Business Association of Michigan (SBAM)</li>
<li>With a keynote by Mark Lange, Executive Director of the Edward Lowe Foundation.</li>
</ul>
<p>Yan will speak about why Michigan is good for business and promoting local entrepreneurship, with a focus on the advantages of starting Internet/tech companies, including cost-efficiency with great IT infrastructures that support fiber connectivity in <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a>.</p>
<p>Attendees will include 80-100 small business owners and local business developers. The event will be held tomorrow morning in Grand Rapids, Michigan, at the Amway Grand Hotel. Find more information at <a href="http://www.crainsdetroit.com/article/20120223/CRAINSEVENTS/302239994">Crain&#8217;s Events</a>, including directions, contact information, sponsorship opportunities and fees.</p>
<p><strong>SBAM on Entrepreneurship:</strong><br />
The Small Business Association of Michigan is an outspoken champion of the new economic development strategy in Michigan. Economic Gardening is a principle pushed to the forefront by SBAM that focuses state resources on growing and sustaining local, Michigan based companies.</p>
<p><strong>What&#8217;s the Theory of Economic Gardening in Michigan?</strong><br />
<strong></strong>As SBAM&#8217;s perspective states, the economic gardening strategy is based on growing a local economy by investing in the people, companies and ideas in your community. The theory supports encouraging entrepreneurs to launch new companies or help them grow small existing businesses and networks to support the state economy and continue self-sustained growth.</p>
<p>For further reading, the Michigan Environmental Council has a <a href="http://www.environmentalcouncil.org/priorities/article.php?x=185">great report</a> discussing the theory of economic gardening.</p>
<p>Read more about Online Tech <a href="http://www.onlinetech.com/news/in-the-news">In the News</a> for the latest headlines we&#8217;re making in Michigan and beyond. Or get more details on our <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a>, including features, locations and compliance.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-speaks-at-crains-detroit-event-on-michigan-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Event Planning at a Data Center</title>
		<link>http://resource.onlinetech.com/event-planning-at-a-data-center/</link>
		<comments>http://resource.onlinetech.com/event-planning-at-a-data-center/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 13:00:18 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[ann arbor data centers]]></category>
		<category><![CDATA[data center events]]></category>
		<category><![CDATA[data center planning]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5270</guid>
		<description><![CDATA[When you think of a data center, what is the first thing that comes to mind? Racks? Raised floors? Gray walls? While those are all fair assumptions when thinking of data centers&#8230;did you ever consider that some of them may &#8230; <a href="http://resource.onlinetech.com/event-planning-at-a-data-center/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>When you think of a <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a>, what is the first thing that comes to mind? Racks? Raised floors? Gray walls? While those are all fair assumptions when thinking of data centers&#8230;did you ever consider that some of them may be modern, colorful and just the right place to host your next techie event? I know, I know. Host your next event at a data center? Huh?</p>
<div id="attachment_4024" class="wp-caption aligncenter" style="width: 494px"><a href="http://resource.onlinetech.com/upcoming-data-center-events-ann-arbor-open-house/ann-arbor-2-data-center/" rel="attachment wp-att-4024"><img class=" wp-image-4024 " title="Ann Arbor 2 Data Center" src="http://resource.onlinetech.com/wp-content/uploads/Ann-Arbor-2-Data-Center.jpg" alt="Ann Arbor 2 Data Center" width="484" height="199" /></a><p class="wp-caption-text">Ann Arbor 2 Data Center</p></div>
<p>Last December, we tested the waters of just such an event with an open house for our newest location. Guests were able to mingle and network while enjoying food and tours of the facility. Several breakout sessions were held in our various conference rooms led by industry experts and insiders. See photos from the event on the <a href="http://www.flickr.com/photos/onlinetech/sets/72157628294670005/with/6461578431/" target="_blank">OTFlickr</a> and <a href="http://resource.onlinetech.com/2011-ann-arbor-data-center-open-house/">more information</a> about the event.</p>
<div id="attachment_5273" class="wp-caption alignleft" style="width: 344px"><a href="http://resource.onlinetech.com/event-planning-at-a-data-center/open-house-2011/" rel="attachment wp-att-5273"><img class=" wp-image-5273   " title="Online Tech Data Center Open House 2011" src="http://resource.onlinetech.com/wp-content/uploads/Open-House-2011.png" alt="Online Tech Data Center Open House 2011" width="334" height="466" /></a><p class="wp-caption-text">Online Tech Data Center Open House 2011</p></div>
<p>This year we are looking to utilize the space and bring more of our own seminars in house. Several outside groups have expressed interest in utilizing the meeting space to host their own seminars and events in our Ann Arbor 2 location (our newest <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor data center</a>) this year:</p>
<ul>
<li>The Michigan PowerShell Group will be hosting their meeting at the data center today during the International PowerShell User Group Day on March 19th at 6:00 P.M. ET.</li>
<li>On April 19th, the Ross School of Business Alumni Club of Southeast Michigan will hold their <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">Cloud Computing</a> Seminar on innovation and trends at the Online Tech&#8217;s newest Ann Arbor data center. M.S. Krishnan, Ross Professor and Executive Education instructor, as well as Gary Baker and Online Tech’s President and COO Mike Klein will be presenting. <a href="http://www.rossmich.org/article.html?aid=198">Get more information on the event</a>.</li>
</ul>
<p>Our newest data center boasts a sleek, modern and (dare I say it?) artsy office area. With several high top work stations, laid back sitting areas and various sized conference rooms, our Ann Arbor 2 data center has become a place to meet, mingle and manage.</p>
<p>Planning an event at a data center is really no different than any other venue. Once you have a great location that speaks for itself, just throw in a presentation, food and people for a great mix. Easy.</p>
<p>References:<br />
Open house photos by Noah Wolf of OT Operations.<br />
<strong id="internal-source-marker_0.04710730561055243"><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/event-planning-at-a-data-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is a HIPAA Violation?</title>
		<link>http://resource.onlinetech.com/what-is-a-hipaa-violation/</link>
		<comments>http://resource.onlinetech.com/what-is-a-hipaa-violation/#comments</comments>
		<pubDate>Fri, 16 Mar 2012 13:18:57 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violation]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5737</guid>
		<description><![CDATA[What is a HIPAA violation? While an endless variety of scenarios exist, a few of the most common and avoidable include certain characteristics, such as unencrypted data, employee error, data stored on devices lost or stolen, business associates, and a &#8230; <a href="http://resource.onlinetech.com/what-is-a-hipaa-violation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">What is a HIPAA violation?</a> While an endless variety of scenarios exist, a few of the most common and avoidable include certain characteristics, such as unencrypted data, employee error, data stored on devices lost or stolen, business associates, and a lapse in notification.</p>
<p>The penalties and fines for a HIPAA violation range from monetary to potential imprisonment for criminal offenses:</p>
<table border="1" cellpadding="5">
<tbody>
<tr>
<td><strong>VIOLATION TYPE</strong></td>
<td><strong>MINIMUM PENALTY</strong></td>
<td><strong>MAXIMUM PENALTY</strong></td>
</tr>
<tr>
<td>Individual didn&#8217;t know they violated HIPAA</td>
<td>$100/violation; annual max of $25,000/repeat violations</td>
<td>$50,000/violation; annual max of $1.5 million</td>
</tr>
<tr>
<td>Reasonable cause and not willful neglect</td>
<td>$1,000/violation; annual max of $100,000/repeat violations</td>
<td>$50,000/violation; annual max of $1.5 million</td>
</tr>
<tr>
<td>Willful neglect but corrected within time</td>
<td>$10,000/violation; annual max of $250,000/repeat violations</td>
<td>$50,000/violation; annual max of $1.5 million</td>
</tr>
<tr>
<td>Willful neglect and is not corrected</td>
<td>$50,000/violation; annual max of $1.5 million</td>
<td>$50,000/violation; annual max of $1.5 million</td>
</tr>
</tbody>
</table>
<p>Source: American Medical Association, www.AMA-ASSN.org</p>
<p>Another category of a HIPAA violation includes covered entities and individuals that knowingly breached the HIPAA rules (criminal). A HIPAA breach committed with intent to sell, transfer or use individually identifiable health information for personal or financial gain, or malicious harm, can result in fines of $250,000 and imprisonment for up to ten years.</p>
<p>I wrote more on the topic of common mistakes and the preventative measures any covered entity can take to eliminate the risks that may lead to a data breach here:</p>
<p><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">What is a HIPAA Violation?</a></p>
<p>Find real cases and read more about the events, repercussions, and impact of a data breach:<br />
<a href="http://resource.onlinetech.com/total-cost-of-a-hipaa-violation-18-5-million/">Total Cost of a HIPAA Violation: 18.5 Million</a><br />
<a href="http://resource.onlinetech.com/michigan-hipaa-violations/">Michigan HIPAA Violations</a><br />
<a href="http://resource.onlinetech.com/sutter-health-hipaa-breach-lessons-learned/">Sutter Health HIPAA Breach: Lessons Learned</a><br />
<a href="http://resource.onlinetech.com/military-healthcare-contractor%e2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/">Military Healthcare Contractor&#8217;s HIPAA Breach Followed By a $4.9 Billion Lawsuit</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/what-is-a-hipaa-violation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Total Cost of a HIPAA Violation: 18.5 Million</title>
		<link>http://resource.onlinetech.com/total-cost-of-a-hipaa-violation-18-5-million/</link>
		<comments>http://resource.onlinetech.com/total-cost-of-a-hipaa-violation-18-5-million/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 12:38:18 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5713</guid>
		<description><![CDATA[Who: Blue Cross Blue Shield of Tennessee (BCBST) Who was affected: Over 1 million members of the BCBST had their information stolen, including names, SSNs, diagnosis codes, birthdates and health plan IDs. What: 57 unencrypted hard drives were stolen from &#8230; <a href="http://resource.onlinetech.com/total-cost-of-a-hipaa-violation-18-5-million/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Who</strong>: Blue Cross Blue Shield of Tennessee (BCBST)</p>
<p><strong>Who was affected</strong>: Over 1 million members of the BCBST had their information stolen, including names, SSNs, diagnosis codes, birthdates and health plan IDs.</p>
<p><strong>What</strong>: 57 unencrypted hard drives were stolen from a leased facility in Tennessee, out of a data storage closet. According to the resolution agreement, the BCBST were relocating staff from the facility and had not yet moved the servers from the closet to their new location.</p>
<p><strong>Charged with</strong>: The OCR (Office of Civil Rights, official HIPAA-enforcement entity) found the BCBST failed to have ‘adaquate facility access controls,’ according to their <a href="http://www.hhs.gov/news/press/2012pres/03/20120313a.html">press release</a>. This put them in violation of implementing the appropriate physical safeguards as listed in the HIPAA Security Rule.</p>
<p>They were also found in violation of the administrative safeguards by failing to perform a security evaluation after operational changes.</p>
<p><strong>What they could have done differently</strong>: Encrypt all data at rest, including their archived data stored on hard drives. This is a strongly recommended best practice for healthcare organizations that need to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a>.</p>
<p>They also could have chosen to store their data in a secure, offsite location that had the appropriate physical safeguards/access controls, another important feature of <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a>.</p>
<p><strong>When</strong>: BCBST was alerted October 2, 2009 of an unresponsive server at the facility, but didn’t investigate until October 5, 2009. Official completion date of review, audit and affected individual notification was October 29, 2010.</p>
<p><strong>How much did it cost them</strong>: Although the settlement case required BCBST to pay HHS 1.5 million, the company has spent nearly $17 million in investigation, notification and protection costs to date, bringing the total to 18.5 million. Affected individuals received free credit monitoring services, free identity monitoring, consultation, and restoration.</p>
<p><strong>What are their next steps</strong>: BCBST encrypted all of its at-rest data, which they claim to be “a voluntary effort which goes above and beyond current industry standards.” While it might not be explicitly required by HIPAA standards, it’s pretty close (read <a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a> for tips) :</p>
<blockquote>
<p dir="ltr">A covered entity must, in accordance with §164.306… Implement a mechanism to encrypt and decrypt electronic protected health information.” (45 CFR § 164.312(a)(2)(iv))</p>
</blockquote>
<p>BCBST entered a 450 day corrective action plan, which includes sending their written PHI security policies and procedures to HHS, monitoring their employees to ensure they’re trained and following HIPAA compliant policies and procedures, and conduct a risk management plan.</p>
<p>For more on <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-a-hipaa-violation">HIPAA violations</a> and the effects of data breaches, try reading <a href="http://resource.onlinetech.com/how-a-hipaa-breach-can-negatively-impact-your-business/">How a HIPAA Breach Can Negatively Impact Your Business</a>, or <a href="http://resource.onlinetech.com/sutter-health-hipaa-breach-lessons-learned/">Sutter Health HIPAA Breach: Lessons Learned</a>.</p>
<p>References:<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/resolution_agreement_and_cap.pdf">HHS Resolution Agreement</a><br />
<a href="http://www.bcbst.com/about/news/releases/Settlement_in_2009_Hard_Drive_Data_Theft.htm">BlueCross, HHS Reach Settlement in 2009 Hard Drive Data Theft</a><br />
<a href="http://www.bcbst.com/learn/special-information/eastgate/">Eastgate Hard Drive Theft</a><br />
<a href="http://www.hhs.gov/news/press/2012pres/03/20120313a.html">HHS Settles HIPAA Case With BCBST for $1.5 Million</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/total-cost-of-a-hipaa-violation-18-5-million/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Cloud Hosting to Achieve Meaningful Use</title>
		<link>http://resource.onlinetech.com/hipaa-compliant-clouds-to-achieve-meaningful-use/</link>
		<comments>http://resource.onlinetech.com/hipaa-compliant-clouds-to-achieve-meaningful-use/#comments</comments>
		<pubDate>Wed, 14 Mar 2012 12:53:59 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[ehr systems]]></category>
		<category><![CDATA[HIPAA cloud computing]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[hipaa clouds]]></category>
		<category><![CDATA[hipaa compliant cloud hosting]]></category>
		<category><![CDATA[hipaa compliant clouds]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[meaningful use]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5665</guid>
		<description><![CDATA[Support for the adoption of cloud hosting in healthcare in order to meet meaningful use standards, foster the exchange of information and improve economic conditions is increasing. A scholarly article published late last year by the American Journal of Public &#8230; <a href="http://resource.onlinetech.com/hipaa-compliant-clouds-to-achieve-meaningful-use/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Support for the adoption of cloud hosting in healthcare in order to meet meaningful use standards, foster the exchange of information and improve economic conditions is increasing. A scholarly article published late last year by the American Journal of Public Health, <em>Public Health Surveillance and Meaningful Use Regulations: A Crisis of Opportunity</em>, states:</p>
<blockquote><p>Cloud computing may be a solution for public health information systems. Through shared computing resources, public health departments could reap the benefits of electronic reporting within federal funding constraints.</p>
<p>…public health would have a new computing infrastructure to support connections with healthcare for meaningful use. Remote hosting and shared systems would overcome the problem of insufficient funding and infrastructure for public health systems.</p></blockquote>
<div id="attachment_5685" class="wp-caption alignright" style="width: 378px"><a href="http://resource.onlinetech.com/hipaa-compliant-clouds-to-achieve-meaningful-use/cloudhealthit/" rel="attachment wp-att-5685"><img class="size-full wp-image-5685 " title="Cloud Computing for Health IT" src="http://resource.onlinetech.com/wp-content/uploads/CloudHealthIT.png" alt="Cloud Computing for Health IT" width="368" height="136" /></a><p class="wp-caption-text">Cloud Computing for Health IT</p></div>
<p>The article focuses on the issue of integrating meaningful use requirements into the mandatory automation of EHRs (electronic health records), and several common industry challenges that healthcare organizations face, including:</p>
<ul>
<li>Different types of IT systems</li>
<li>Diverse and numerous service providers</li>
<li>Costs of becoming compliant within requirements</li>
</ul>
<p><strong>EHR Implementation: Costs and Controversies</strong></p>
<p>In a survey conducted by the Association of State and Territorial Health Officers, 77 percent of respondents cite a lack of funding as the main demotivating factor in EHR implementation. One common misconception is that EHR systems aren’t beneficial in any way or even cost-effective in the long run – a recent <a href="http://www.nytimes.com/2012/03/06/business/digital-records-may-not-cut-health-costs-study-cautions.html">NYTimes.com article</a> is more infamously misconstrued as sending the wrong message on the topic.</p>
<p>The article cites a <em>Health Affairs</em> study that concluded the amount of tests ordered by doctors goes up with the use of digital records systems, implying that EHR systems lead to an influx of expenses not seen with the use of paper records, and are unlikely to cut healthcare costs. The study has been criticized for its limited data set and basis on correlation, not a controlled test, by field experts and the media, and even in a <a href="http://bits.blogs.nytimes.com/2012/03/06/electronic-health-records-a-study-and-perspective/">blog post</a> written by the very author of the article, Steve Lohr.</p>
<p>Lohr writes a great blog post in response to the outcry over his NYTimes article [including widely circulated <a href="http://www.healthit.gov/buzz-blog/meaningful-use/study-facts/">criticism</a> from Farzad Mostashari, the National Coordinator for Health Information technology) that goes on to provide a quote from a doctor cut from the article for space: “An electronic health record is only part of the solution. The real gains come from improving the quality of the information the doctor receives, so it is more accurate, complete and timely.”</p>
<p>He goes on to make the point that healthcare, as an economic system, is based on a fee-per-service incentive model, and not on actually making patients healthier. EHRs are part of the plan to change the current system to provide incentives based on the health of patients, not just the amount of services rendered, to ensure overall, permanent cost-savings.</p>
<p>This then developed into a larger discussion on the state of American healthcare and costs that isn’t relevant here, but he makes a great point that the debate is not about whether or not the technology should or should not be adopted, but rather <em>how</em> it should be adopted – there is ultimate consensus that EHRs will and do improve healthcare workflow efficiency.</p>
<p>So what is the actual impact of a fully functional EHR system on healthcare organizations’ operations and communications?</p>
<div id="attachment_5668" class="wp-caption alignleft" style="width: 401px"><a href="http://resource.onlinetech.com/hipaa-compliant-clouds-to-achieve-meaningful-use/ehr_benefits/" rel="attachment wp-att-5668"><img class="size-full wp-image-5668 " title="EHR Benefits" src="http://resource.onlinetech.com/wp-content/uploads/EHR_Benefits.png" alt="EHR Benefits" width="391" height="308" /></a><p class="wp-caption-text">EHR Benefits</p></div>
<p>According to HealthIT.gov and the scholarly article “Systematic Review: Impact of Health Information Technology on Quality, Efficiency and Costs of Medical Care,” the top three positive impacts include the quality of communication with other providers (92 percent), prescription refills (95 percent) and, as the top contender, timely access to medical records (97 percent).</p>
<p><strong>How Does Cloud Computing Fit into the Picture?</strong></p>
<p>If healthcare organizations have a limited budget for EHR system implementation due to related costs of supporting a change in their IT infrastructure, then cloud computing can offer a viable solution by eliminating capital costs and providing on-demand network access.</p>
<p>To take full advantage of cost-savings and remove the barrier of not having time or personnel to manage a new IT infrastructure, outsourcing to a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting/high-capacity-hipaa-cloud">HIPAA cloud hosting</a> vendor just makes sense. As a healthcare company that handles PHI (protected health information), by law, you need to meet HIPAA compliance standards for your data hosting solution and the data centers your PHI is hosted in. If you need to change your IT infrastructure and still meet compliance under budget, a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> provider can help, provided they are knowledgeable about the law and physical, network and technical security requirements.</p>
<p>Security in the cloud is another issue the AJPH article addresses by verifying that cloud applications can meet HIPAA compliance security requirements by means of a number of methods: VPNs (virtual private networks) to encrypt data transmissions and firewalls. Antivrus and OS patch management is also required.</p>
<p>In addition to being a cost-effective and secure solution, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> services can provide ease of data sharing with other users across networks for real-time collaboration and more efficient workflows, saving time, and theoretically, improving patient care.</p>
<p>References:<br />
<a href="http://www.nytimes.com/2012/03/06/business/digital-records-may-not-cut-health-costs-study-cautions.html">Digital Records May Not Cut Health Costs, Study Cautions</a><br />
<a href="http://www.healthit.gov/providers-professionals/benefits-electronic-health-records-ehrs">The Benefits of Electronic Health Records (EHRs)</a><br />
<a href="http://annals.ba0.biz/content/144/10/742.full">Systematic Review: Impact of Health Information Technology on Quality, Efficiency and Costs of Medical Care</a><br />
<a href="http://www.healthit.gov/buzz-blog/meaningful-use/study-facts/">Recent Study: Get the Facts</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-compliant-clouds-to-achieve-meaningful-use/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliance with Service Providers</title>
		<link>http://resource.onlinetech.com/pci-compliance-with-service-providers/</link>
		<comments>http://resource.onlinetech.com/pci-compliance-with-service-providers/#comments</comments>
		<pubDate>Tue, 13 Mar 2012 13:05:41 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[pci dss compliant hosting]]></category>
		<category><![CDATA[pci dss hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5631</guid>
		<description><![CDATA[The PCI sub-requirements and testing procedures 12.8-12.84 concern the relationship between merchants and their service providers, including PCI compliant hosting providers. The sub-requirements fall under the main requirement #12: Maintain an Information Security Policy – meaning a merchant must maintain a &#8230; <a href="http://resource.onlinetech.com/pci-compliance-with-service-providers/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The<strong> PCI sub-requirements and testing procedures 12.8-12.84 </strong>concern the relationship between merchants and their service providers, including <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliant hosting</a> providers.</p>
<p>The sub-requirements fall under the main requirement <strong><em>#12: Maintain an Information Security Policy </em></strong>– meaning a merchant must maintain a policy that addresses information security for all personnel, including internal employees, contractors and consultants. The sub-requirements 12.8-12.84 include language that specifically refers to service providers.</p>
<p>According to my <a href="http://resource.onlinetech.com/pci-compliance-status-data-breaches/">earlier blog post</a> and <a href="http://www.verizonbusiness.com/resources/reports/rp_2011-payment-card-industry-compliance-report_en_xg.pdf">Verizon’s 2011 PCI Compliance Report</a> (PDF), this is one of the most difficult <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Payment Card Industry">PCI DSS</a> requirements for most organizations to achieve, with only 39 percent of merchants at full achievement.</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="85"><span style="color: #00ccff;"><strong>12.8</strong></span></td>
<td valign="top" width="553">If <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Cardholder Data">cardholder data</a> is shared with service providers [backup tape storage or managed service providers, or those that use the data for fraud modeling purposes], you must maintain and implement policies and procedures to manage server providers.<strong></strong></td>
</tr>
<tr>
<td valign="top" width="85"><strong>How do you test it?</strong></td>
<td valign="top" width="553">You can test it by observing, reviewing policies and procedures, and reviewing supporting documentation for the rest of the requirements:</td>
</tr>
</tbody>
</table>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="85"><strong>12.8.1</strong></td>
<td valign="top" width="553">Maintain a list of service providers.<strong> </strong></td>
</tr>
<tr>
<td valign="top" width="85"><strong>How do you test it?</strong></td>
<td valign="top" width="553">Pretty self-explanatory; keep a current and comprehensive list of vendors and verify it is updated whenever you sign with a new provider or end a contract. It’s also good practice to keep tabs on your service providers’ audit types and dates for your own verification of ongoing compliance.</td>
</tr>
</tbody>
</table>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="85"><strong></strong><strong>12.8.2</strong></td>
<td valign="top" width="553">Maintain a written agreement that includes an acknowledgement that the service providers are responsible for the security of cardholder data the service providers possess.</td>
</tr>
<tr>
<td valign="top" width="85"><strong>How do you test it?</strong></td>
<td valign="top" width="553">Check in your contract for specific language around the roles and responsibilities of your service providers when it comes to securing cardholder data. For example, if there’s a known data breach of your server, what’s the timeframe and process in which the service provider should notify you? And how long should data be retained after your contract expires, and how should it be deleted? And, more importantly, who has ownership or rights to your data?</td>
</tr>
</tbody>
</table>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="85"><strong></strong><strong>12.8.3</strong></td>
<td valign="top" width="553">Ensure there is an established process for engaging service providers including proper due diligence prior to engagement.</td>
</tr>
<tr>
<td valign="top" width="85"><strong>How do you test it?</strong></td>
<td valign="top" width="553">Create document with policies and procedures around how you qualify a vendor’s ability to provide a secure <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a> and services. Ensure you do your due diligence to save yourself a headache later – check their PCI audit report for the full scope of their compliance and compare it to what you still need to cover.</td>
</tr>
</tbody>
</table>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="85"><strong>12.8.4</strong></td>
<td valign="top" width="553">Maintain a program to monitor service providers’ PCI DSS compliance status at least annually.</td>
</tr>
<tr>
<td valign="top" width="85"><strong>How do you test it?</strong></td>
<td valign="top" width="553">Establish a way internally to verify your service provider’s ongoing PCI compliance status each year, whether you assign a point of contact to exemplify their due diligence in analyzing their audit reports or you keep in touch with your service provider’s security officer to verify dates of compliance.</td>
</tr>
</tbody>
</table>
<p>Find out more about PCI DSS and what you need to achieve compliance &#8211; read our <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/two-factor-authentication-for-vpn-login-faq">Two-Factor Authentication</a> FAQ.</p>
<p>Recommended links:<br />
<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms"> PCI Glossary of Terms</a><br />
<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/levels-of-pci-compliance"> Levels of PCI Compliance</a><br />
<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/who-needs-to-be-pci-compliant"> Who Needs to be PCI Compliant?</a></p>
<p>References:<br />
<a href="http://www.sans.org/reading_room/whitepapers/compliance/contracting-pci-dss-compliance_33403">Contracting for PCI DSS Compliance from The SANS Institute (PDF)</a><br />
<a href="https://www.pcisecuritystandards.org/documents/pci_dss_v2.pdf">PCI DSS Requirements and Security Assessment Procedures, Version 2.0 (PDF)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-compliance-with-service-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyze Your Workflow Before Selecting a HIPAA Hosting Provider</title>
		<link>http://resource.onlinetech.com/analyze-your-workflow-before-selecting-a-hipaa-hosting-provider/</link>
		<comments>http://resource.onlinetech.com/analyze-your-workflow-before-selecting-a-hipaa-hosting-provider/#comments</comments>
		<pubDate>Mon, 12 Mar 2012 13:36:44 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[business workflow]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[health it implementation]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[implementing health it]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5625</guid>
		<description><![CDATA[Understanding your operation’s workflow is key to implementing and selecting IT vendors that support your processes and can also potentially offer a way to streamline workflow. ModernHealthcare.com recently published an article about the ‘disappointing results’ seen in health IT deployment. &#8230; <a href="http://resource.onlinetech.com/analyze-your-workflow-before-selecting-a-hipaa-hosting-provider/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Understanding your operation’s workflow is key to implementing and selecting IT vendors that support your processes and can also potentially offer a way to streamline workflow. ModernHealthcare.com recently published an article about the ‘disappointing results’ seen in health IT deployment. The article mentions that the HHS’ Agency for Healthcare Research and Quality (AHRQ) emphasizes a need for closer attention to business workflow for the success of IT implementation.</p>
<div id="attachment_5626" class="wp-caption alignright" style="width: 203px"><a href="http://resource.onlinetech.com/wp-content/uploads/patient-checkin-workflow.png"><img class=" wp-image-5626  " title="Example of Patient Check-in Workflow" src="http://resource.onlinetech.com/wp-content/uploads/patient-checkin-workflow.png" alt="Example of Patient Check-in Workflow" width="193" height="521" /></a><p class="wp-caption-text">Example of Patient Check-in Workflow</p></div>
<p>The AHRQ is seeking budget approval to conduct field assessments and collect data in order to create an updated workflow toolkit for healthcare IT – the last toolkit was updated in 2008. Although dated, the real issue may be the lack of awareness of the toolkit and the need to evaluate internal workflow prior to the vendor selection process.</p>
<p>While the HHS has fairly decent resources available, they’re not always easy to find. And with the latest federal <a href="http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/">HIPAA audit program</a> and action taken against <a href="http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/">business associates involved in data breaches</a>, any industry that touches PHI are now paying more attention to the laws to avoid the penalties and fees associated with a breach than they were back in 2008.</p>
<p>The workflow diagram to the right shows the detailed steps taken during a patient check-in.</p>
<p>Just a few examples of clinic workflows include:</p>
<ul>
<li>Answering phones</li>
<li>Appointment systems</li>
<li>Ordering and reporting diagnostic testing</li>
<li>Ordering medications</li>
<li>Making referrals</li>
<li>Billing and coding</li>
</ul>
<p>HIMSS has an informative slideshow detailing the ARHQ’s Workflow Assessment Toolkit, developed specifically for health IT in ambulatory care, answering the question of why is it important to understand your workflow when planning, implementing, and using health IT.</p>
<p>The first answer is to avoid potential problems down the road when it comes to disrupting clinical and administrative workflows – implementing an EHR system and other technologies creates changes in patient care, billing and other processes. Planning ahead can help with the process overhaul, but I believe healthcare organizations should not only plan for these changes, but also plan to create an entirely new set of processes and train their employees in them, whether that means using the expertise of their vendors or hiring new, experienced personnel.</p>
<p>The second answer refers to assisting in vendor selection. Making an IT overhaul, for security, efficiency and legal reasons, requires asking the question, how can we work smarter? And, what can we eliminate or change for the better? Whether that’s consolidating points of contact or steps taken, eliminating the middle man, or choosing a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a> provider that can effectively manage your services while you focus on your own business or patients, you need to make a <em>Keep</em>, <em>Throw Out</em> and <em>Overhaul</em> list of processes prior to signing a contract. How can you go out and get what you need if you aren’t quite sure what that is?</p>
<p>If you need some assistance with workflow flowcharts, the ARHQ has examples and guides on how to define a process <a href="http://healthit.ahrq.gov/portal/server.pt/community/health_it_tools_and_resources/919/workflow_assessment_for_health_it_toolkit/27865">here</a>.</p>
<p>References<br />
<a href="http://www.modernhealthcare.com/article/20120309/NEWS/303099953/ahrq-disappointing-results-often-seen-in-health-it-deployment">AHRQ: ‘Disappointing Results’ Often Seen in Health IT Deployment</a><br />
<a href="http://www.himss.org/content/files/MEPI/201111_WorkflowAssessmentHealthITAmbulatoryCare_CarayonPascale.pdf">Workflow Assessment for Health IT in Ambulatory Care</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/analyze-your-workflow-before-selecting-a-hipaa-hosting-provider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliance Status &amp; Data Breaches</title>
		<link>http://resource.onlinetech.com/pci-compliance-status-data-breaches/</link>
		<comments>http://resource.onlinetech.com/pci-compliance-status-data-breaches/#comments</comments>
		<pubDate>Thu, 08 Mar 2012 13:39:55 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[pci dss compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci requirements]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5400</guid>
		<description><![CDATA[Only 21 percent of organizations were found to be fully PCI compliant during their first assessment of attestation in the Verizon 2011 Payment Card Industry Compliance Report, showing only a 1 percent increase since their 2010 report (statistics based on &#8230; <a href="http://resource.onlinetech.com/pci-compliance-status-data-breaches/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Only 21 percent of organizations were found to be fully <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Payment Card Industry">PCI compliant </a>during their first assessment of attestation in the Verizon 2011 Payment Card Industry Compliance Report, showing only a 1 percent increase since their 2010 report (statistics based on QSA assessments). Translating to a 79 percent fail percentage, the organizations, on average, only met 78 percent of the test procedures defined in the DSS (Data Security Standards).</p>
<div id="attachment_5402" class="wp-caption aligncenter" style="width: 538px"><a href="http://resource.onlinetech.com/pci-compliance-status-data-breaches/pci_compliance_status_breaches/" rel="attachment wp-att-5402"><img class="size-full wp-image-5402" title="PCI Compliance Status Breaches" src="http://resource.onlinetech.com/wp-content/uploads/PCI_Compliance_Status_Breaches.png" alt="PCI Compliance Status Breaches" width="528" height="386" /></a><p class="wp-caption-text">PCI Compliance Status Breaches</p></div>
<p><strong>Challenges to Meeting Compliance</strong><br />
The report lists a number challenges that serve as barriers to meeting full PCI compliance and the full set of requirements. Those challenges include:</p>
<table border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td valign="top" width="206"><strong>Trained Personnel</strong></td>
<td valign="top" width="424">Fully staffed and expert IT departments can be difficult to find and maintain for ongoing compliance.</td>
</tr>
<tr>
<td valign="top" width="206"><strong>Corporate Will</strong></td>
<td valign="top" width="424">This refers to the inability of management or directors to recognize the importance of compliance &#8211; compliance is “considered to be a drag on the economy by most businesses rather than an assumed part of the risk of doing business.”With this type of attitude, resources are often not allocated to meet compliance by implementing proper controls, policies and procedures.</td>
</tr>
<tr>
<td valign="top" width="206"><strong>Complexity</strong></td>
<td valign="top" width="424"><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/what-is-pci-compliance">PCI requirements</a> are specific and lengthy &#8211; the Verizon report claims PCI has well over 200 requirements (while the 12 requirements are notorious, each one has multiple listed sub-requirements).The time and resources needed to address each requirement can be extensive.</td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>What were the most difficult requirements to achieve?</strong></p>
<p style="text-align: left;">Only 37 percent of organizations met the PCI requirement #11 &#8211; regularly test security systems and processes, and 39 percent were able to maintain a policy that addresses information security, requirement #12.</p>
<p style="text-align: left;">The most challenging sub-requirement, according to the report, was under #10 – tracking and monitoring. #10.5.5 requires organizations to use <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#File Integrity Monitoring">file-integrity monitoring</a> (FIM) or change detection software on logs to ensure that existing log data cannot be changed without generating alerts.</p>
<p style="text-align: left;">The two requirements that were achieved by most organizations were #7 – restrict access to data by business need-to-know and #4 – <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Encryption">encrypt</a> transmission of <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Cardholder Data">cardholder</a> data and sensitive information across public networks.</p>
<p style="text-align: left;">Another approach to meeting PCI compliance includes reducing scope by meeting certain milestones and thus reducing potential risk to cardholder data. Eighty-eight of organizations met goal #1 – remove sensitive authentication data and limit data retention. Stored sensitive data can be a liability to any organization and decrease their ability to meet compliance requirements.</p>
<p style="text-align: left;"><strong>What are the top causes of a PCI breach?</strong></p>
<p style="text-align: left;">The report also details the top “threat actions,” meaning the cause or action that contributed to PCI breach incidents. The top five are as follows:</p>
<ul style="text-align: left;">
<li>44% sent data to external sites/entities (malware)</li>
<li>44% allowed remote access or control (malware)</li>
<li>43% was due to the exploitation of default or guessable credentials (hacking)</li>
<li>42% was due to the exploitation of backdoor or command and control channel (hacking)</li>
<li>36% was a result of physical tampering (physical skimmers for the intent of fraud)</li>
</ul>
<p style="text-align: left;">While no data center or <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliant hosting</a> provider can make an individual merchant PCI compliant, they <strong>can</strong> help your organization by having PCI compliant controls already in place when it comes to certain technical requirements. Remember, due diligence is always required when you partner with a PCI hosting vendor – check their PCI audit report to determine the full scope and understanding of their compliance; don’t just take their word for it.</p>
<p style="text-align: left;">Read more about PCI security requirements in our FAQ for <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/resources/two-factor-authentication-for-vpn-login-faq">Two-Factor Authentication</a>.</p>
<p style="text-align: left;">References:<br />
<a href="http://www.verizonbusiness.com/resources/reports/rp_2011-payment-card-industry-compliance-report_en_xg.pdf">Verizon 2011 Payment Card Industry Compliance Report</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-compliance-status-data-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming Webinar: Cloud Computing for EHR/RCM Systems</title>
		<link>http://resource.onlinetech.com/upcoming-webinar-cloud-computing-for-ehrrcm-systems/</link>
		<comments>http://resource.onlinetech.com/upcoming-webinar-cloud-computing-for-ehrrcm-systems/#comments</comments>
		<pubDate>Wed, 07 Mar 2012 13:37:00 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[cloud computing webinars]]></category>
		<category><![CDATA[cloud hosting webinars]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[hipaa clouds]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[hipaa compliant clouds]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa webinars]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5346</guid>
		<description><![CDATA[Mark your calendars for next Tuesday at 2 P.M. ET if you&#8217;re interested in healthcare IT, healthcare software, EHR/RCM systems and/or HIPAA compliance and cloud computing issues. Our free educational webinar featuring a discussion on cloud computing vs. traditional server-based EHR (electronic health &#8230; <a href="http://resource.onlinetech.com/upcoming-webinar-cloud-computing-for-ehrrcm-systems/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Mark your calendars for next Tuesday at 2 P.M. ET if you&#8217;re interested in healthcare IT, healthcare software, EHR/RCM systems and/or HIPAA compliance and cloud computing issues. Our <a href="http://www.onlinetech.com/resources/events/webinars/comparing-cloud-vs-traditional-server-based-ehrrcm-systems" target="_blank">free educational webinar</a> featuring a discussion on <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">cloud computing</a> vs. traditional server-based EHR (electronic health records) and RCM (revenue cycle management) systems will strive to answer important questions about compliance, meaningful use and more.</p>
<p><a href="http://resource.onlinetech.com/upcoming-webinar-cloud-computing-for-ehrrcm-systems/cloudehr_webinar/" rel="attachment wp-att-5380"><img class="size-full wp-image-5380 alignleft" title="CloudEHR_Webinar" src="http://resource.onlinetech.com/wp-content/uploads/CloudEHR_Webinar.png" alt="" width="321" height="263" /></a></p>
<p><strong>Guest Speaker:</strong> Satish Malnaik, CEO of NextServices<br />
<strong>Moderator:</strong> April Sage, CPHIMS, Director of Healthcare Vertical<br />
<strong>When: </strong>March 13, Tuesday 2 P.M. ET<br />
<strong></strong></p>
<p><strong><a href="http://www.onlinetech.com/resources/events/webinars/comparing-cloud-vs-traditional-server-based-ehrrcm-systems" target="_blank">Register today!</a></strong></p>
<p>As the healthcare industry picks up momentum toward meaningful use, practical implementation and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a> questions have risen to the forefront of consideration.</p>
<ul>
<li>Should new systems be hosted in-house?</li>
<li>Do I outsource just the EHR/RCM system or the entire solution as a platform?</li>
<li>Are clouds safer or riskier for <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#Protected Health Information" target="_blank">PHI</a> security?</li>
<li>What about for PHI availability?</li>
</ul>
<p>During this informative webinar, Satish Malnaik, CEO of NextServices, and April Sage, Director of Healthcare Vertical for Online Tech, will compare cloud vs. traditional server-based EHR/RCM systems.</p>
<p>Questions and discussion points are encouraged and welcomed from webinar attendees in advance and during the webinar. <a href="http://www.onlinetech.com/resources/events/webinars/comparing-cloud-vs-traditional-server-based-ehrrcm-systems" target="_blank">Sign up and submit your questions.</a></p>
<p>Looking for more information about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA compliant clouds</a>? Find out more about in our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> section of our site.</p>
<p>Or browse through our previously recorded and transcribed <a href="http://www.onlinetech.com/resources/events/webinars">webinars</a> for more on cloud hosting and HIPAA compliance.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p><img class="alignleft" style="margin: 5px;" title="002e7b8" src="http://www.onlinetech.com/images/stories/people/satishmalnaik.png" alt="SatishMalnaik" width="106" height="120" /></p>
<p><strong>Satish Malnaik, Chief Executive Officer, NextServices </strong><br />
Satish Malnaik is an entrepreneurial enthusiast, CEO and Co-Founder of NextServices, a company that enables seamless healthcare delivery by providing an innovative platform that blends technology, healthcare analytics and knowledge-based services for medical facilities and providers.</p>
<p>These days, he is fascinated with the change and evolution of the development of healthcare technology as well as cloud-based platforms that focus on better capturing, transporting, integrating and managing data. Prior to co-founding NextServices, Mr. Malnaik worked in various E-business, ERP and technology initiatives for Fortune 100 clients, such as Thomson Healthcare (Thomson Reuters), and consulting with firms such as BearingPoint (formerly KPMG Consulting).</p>
<p>Mr. Malnaik received his MBA from the University of Michigan Ross School of Business and he also holds a master&#8217;s degree in Engineering (MS) from the University of Toledo, Ohio. Prior to that, he completed his undergraduate degree in Engineering (BE/ BS) from The University of Mumbai in India. Satish is currently serving in an advisory role on the Strategic Advisory Board at N-Squared Growth Capital (NY) and on the Advisory Council at DDW (AGA). Previously, he also served on the Advisory Board of Billing Services at ADP®AdvancedMD and as a mentor at the Ross School of Business on Financing Research Commercialization practicum for new technology and innovation.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p><img class="alignleft" style="margin: 5px;" title="002e7b8" src="http://resource.onlinetech.com/eNews/right-april.jpg" alt="AprilSage" width="80" height="120" /></p>
<p><strong>April Sage, CPHIMS, Director Healthcare Vertical, Online Tech</strong><br />
April Sage has been involved in the IT industry for over two decades, initially founding a technology program in the pre-Windows era teaching DOS, WordPerfect, and FoxPro. In 2000, April founded a bioinformatics company that supported biotech, pharma, and bioinformatic companies in the development of research portals, drug discovery search engines, and other software systems.</p>
<p>Since then, April has been involved in the development and implementation of online business plans and integrated marketing strategies across insurance, legal, entertainment, and retail industries until her current position as Director Healthcare Vertical of Online Tech.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/upcoming-webinar-cloud-computing-for-ehrrcm-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The HIPAA Security Rule, According to the HHS (VIDEO)</title>
		<link>http://resource.onlinetech.com/the-hipaa-security-rule-according-to-the-hhs-video/</link>
		<comments>http://resource.onlinetech.com/the-hipaa-security-rule-according-to-the-hhs-video/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 14:09:34 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[hhs]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=5335</guid>
		<description><![CDATA[The U.S. Department of Health and Human Services (HHS) has created a series of informative videos offering tips and advice for covered entities and those that need to meet HIPAA compliance. This particular video showcases the HIPAA Security Rule and &#8230; <a href="http://resource.onlinetech.com/the-hipaa-security-rule-according-to-the-hhs-video/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>The U.S. Department of Health and Human Services (HHS) has created a series of informative videos offering tips and advice for covered entities and those that need to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a>. This particular video showcases the HIPAA Security Rule and five high-level overviews and realistic applications of the rule.</p>
<p>While this is a definite step in the right direction for the OCR’s attempts in spreading awareness with an easier-to-understand and more practical approach, I hope they continue to delve even deeper into educating the public about HIPAA.</p>
<p><iframe src="http://www.youtube.com/embed/QWRn2r5R7ts" frameborder="0" width="560" height="315"></iframe></p>
<p>Transcription of the main points of the video below:</p>
<p>How do you get started on creating a security plan for your office?</p>
<ol>
<li><strong>Experts recommend beginning with a risk analysis</strong> – a risk analysis can help you develop establish the safeguards you need at your practice.</li>
<li><strong>Develop and put into place administrative safeguards</strong> – those are office rules and procedures that keep your data secure. For example, you need to decide what information each staff person should have access to.</li>
<li><strong>Your plan needs to include physical safeguards</strong> – like, positioning computers and printers out of patient areas; security locks, or an alarm system.</li>
<li><strong>Install technical safeguards</strong> – this can include hardware, software, and any other technology that limits access to electronic health records. For example, a software program that keeps computer viruses out of your information system. Or tracks who accesses patient information and who makes changes to patient records.</li>
<li><strong>Encrypting health records</strong> stored on computer hard drives is a vital step in keeping information confidential.</li>
</ol>
<p>Keeping your health information secure is an ongoing process – making security part of your office routine requires diligence. But it’s the only way to protect your patients’ information and to protect your practice from fines and penalties.</p>
<p>Visit our HIPAA compliant resource section of our site for additional resources, including <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-compliant-case-studies">HIPAA Compliant Case Studies</a>, <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider">Five Questions to Ask Your HIPAA Hosting Provider</a> and <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/tips-for-passing-a-hipaa-audit">Tips for Passing a HIPAA Audit</a>.</p>
<p>References:<br />
<a href="http://youtu.be/QWRn2r5R7ts">HHS on YouTube</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/the-hipaa-security-rule-according-to-the-hhs-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
