<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Managed Data Center News</title>
	<atom:link href="http://resource.onlinetech.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://resource.onlinetech.com</link>
	<description>A Guide to Managed Hosting</description>
	<lastBuildDate>Thu, 23 May 2013 15:30:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>Update from Online Tech: Major Data Center Initiatives &amp; Investments</title>
		<link>http://resource.onlinetech.com/update-from-online-tech-major-data-center-initiatives-investments/</link>
		<comments>http://resource.onlinetech.com/update-from-online-tech-major-data-center-initiatives-investments/#comments</comments>
		<pubDate>Thu, 23 May 2013 15:22:23 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[CEO Voices]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[cloud servers]]></category>
		<category><![CDATA[daily log review]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[mid-michigan data center]]></category>
		<category><![CDATA[vulnerability scanning]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11483</guid>
		<description><![CDATA[<p>Summer is just around the corner in Michigan and when we look outside, it feels like everything is growing right before our eyes.  I want to take a few minutes to give you an update on what’s been happening at &#8230; <a href="http://resource.onlinetech.com/update-from-online-tech-major-data-center-initiatives-investments/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/update-from-online-tech-major-data-center-initiatives-investments/">Update from Online Tech: Major Data Center Initiatives &#038; Investments</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Summer is just around the corner in Michigan and when we look outside, it feels like everything is growing right before our eyes.  I want to take a few minutes to give you an update on what’s been happening at Online Tech, as it feels like a lot of things are growing quickly with the company as well.<br />
<strong> </strong><br />
<strong>Data Center Updates</strong><br />
If you’ve been to our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a> in the last 6 months, you may have noticed our new Network Operations Center (NOC) that we built out late last year.  The NOC houses some of our engineers with systems displays on the wall for us to monitor the systems in real time.  This mirrors the NOC in our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor 2 data center</a> where we’re also monitoring all of the systems across all of our <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a>.</p>
<p>Next month we’ll also be breaking ground at the Mid-Michigan data center to add 2 additional 1-megawatt generators for additional backup capacity.  This $1.5M investment will continue to deliver N+1 (Tier 3) generator backup for all systems as we continue to grow the power footprint of the data center.</p>
<p><strong>New Emergency Broadcast System</strong><br />
<img class="alignleft" title="OT Emergency Broadcast System" src="http://gallery.mailchimp.com/60f5b43fc127bc7fffa563394/images/DRiPadac88bc.jpg" alt="OT Emergency Broadcast System" width="240" height="320" />One of the areas we’ve been focused on improving is the time it takes to notify our clients of a client-impacting event at the data center.  We took two significant steps over the last 6 months to improve our client-facing communications with a focus on rapid information and communication availability:</p>
<ol>
<li>We outsourced our VoIP phone system and Exchange server to a trusted partner so our communication tools will work independently of any data center issue that may arise.</li>
<li>We created an Outage Alarm system that can e-mail, text and call our clients in the case of an outage with just a few clicks.  This custom iPad application sits in each data center NOC connected to a 4G wireless network.  This new system dramatically shortens the time it takes to inform our clients of any major incident at the data center.</li>
</ol>
<p>Our transparency goal is to ensure we inform you of any issues before your customers or users notify you, so you’re in complete charge of the communications with your users.  Our emergency broadcast system allows us to provide very quick communication to you of an issue while allowing our operations team to stay focused on fixing the issue as quickly as possible.</p>
<p>Admittedly, we’re still learning how quickly to send out an alert message.  In the past few months, we have been a little too quick to use the system on what turned out to be minor issues with minimal client impact, but scared a number of our clients with broader than necessary alerts.  I apologize for the over-communication.  We’re working out the timing and breadth of using these alerts.<br />
<strong> </strong><strong></strong><br />
<strong>OTPortal Enhancements</strong><br />
Recently we added features to let you request and track firewall rule changes more easily, copy old firewall rule changes as a starting point for new rules, and have new firewall rules “expire” on a certain date, so that temporary rules don’t accidentally become permanent ones. This can help with security; we don’t want to leave ports or services open after they are no longer needed.</p>
<p>In the next 90 days, we’ll be announcing additional capabilities to the portal to make it easier to control your servers:</p>
<ul>
<li>The ability to view a list of your servers, and enable or disable access to common services, like FTP and HTTP for each one without needing to understand firewall rules to request these changes.</li>
<li>Cloud Server Controls: You will be able to start, stop and restart cloud servers through the portal. These actions can be done immediately, or scheduled in the future.</li>
<li>Cloud Server Snapshots:  You will be able to revert snapshots for <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud servers</a>. If you are about to install new software, you will be able to easily take a snapshot of the server beforehand. If anything goes wrong with the install, you can easily revert back to that snapshot. Snapshots are temporary and expire (and are automatically deleted) after 24 hours. They cannot be used as long-term backups.</li>
</ul>
<p>We have more upgrades in the pipeline based on some great suggestions from our clients on how we can improve the portal experience and make it more efficient for you to use.  We appreciate the feedback.  Please keep sharing your suggestions with us.  We find it very helpful in improving the portal user experience.<br />
<strong> </strong><br />
<strong>Security Services:</strong><br />
Is data security a concern?  If so, schedule a call with one of our systems engineers to discuss the options you can leverage to secure your servers, network and data.  Security tools like <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=cfc89d4cb7&amp;e=671abd48cf">Daily Log Review</a> and <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=2565556b8e&amp;e=671abd48cf">Monthly Vulnerability Scanning</a> can take the worry out of attempted breaches and let you sleep better at night.</p>
<p>Daily Log Review collects your server logs daily and analyzes them for anomalies, informing you if immediate action is necessary to protect your data.  Monthly Vulnerability Scanning checks your firewalls, networks, open ports and web applications for holes that hackers can get through and provides you a monthly action report for any open vulnerabilities.</p>
<p><strong>Webinars and White Papers:</strong><br />
Please join us for any number of our upcoming educational webinars.  We have a new series on data encryption starting June 4th, as well as an informational series on disaster recovery recorded at: <a href="http://www.onlinetech.com/events/webinars">http://www.onlinetech.com/events/webinars</a>.  We also have a new mobile security whitepaper available at: <a href="http://www.onlinetech.com/resources/white-papers">http://www.onlinetech.com/resources/white-papers</a>.</p>
<p><strong>Net Promoter Score:</strong><br />
Finally, thank you to all of our clients that filled out our one-question survey over the last 6 months as part of our Net Promoter System (NPS) to track and measure client satisfaction.  We received a lot of really good feedback – both on what we’re doing well and where we can improve.  We ended 2012 with impressive results – an NPS score of 80% which sits with the best across most industries for customer satisfaction scores.</p>
<p>We look forward to continuing to serve you and deliver one of the best hosting experiences in the business.</p>
<p>Sincere Regards,<br />
Mike Klein<br />
Co-CEO<br />
Online Tech LLC</p>
<p>The post <a href="http://resource.onlinetech.com/update-from-online-tech-major-data-center-initiatives-investments/">Update from Online Tech: Major Data Center Initiatives &#038; Investments</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/update-from-online-tech-major-data-center-initiatives-investments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 MTL: Managing Innovation in Client Relations &amp; Private Clouds</title>
		<link>http://resource.onlinetech.com/2013-mtl-managing-innovation-in-client-relations-private-clouds/</link>
		<comments>http://resource.onlinetech.com/2013-mtl-managing-innovation-in-client-relations-private-clouds/#comments</comments>
		<pubDate>Wed, 22 May 2013 19:16:00 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[michigan cloud]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[michigan technology]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[private cloud hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11466</guid>
		<description><![CDATA[<p>Michigan data center operator Online Tech will be exhibiting a range of secure hosting solutions for mission critical applications, including cloud hosting, colocation, managed servers, compliant hosting and disaster recovery, at the Midwest Technology Leaders 2013 symposium for IT executives &#8230; <a href="http://resource.onlinetech.com/2013-mtl-managing-innovation-in-client-relations-private-clouds/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-mtl-managing-innovation-in-client-relations-private-clouds/">2013 MTL: Managing Innovation in Client Relations &#038; Private Clouds</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://resource.onlinetech.com/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders/2013-midwest-tech-leaders/" rel="attachment wp-att-10387"><img class="alignleft size-full wp-image-10387" title="2013 Midwest Tech Leaders" src="http://resource.onlinetech.com/wp-content/uploads/2013-Midwest-Tech-Leaders.png" alt="2013 Midwest Tech Leaders" width="210" height="76" /></a><a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> operator Online Tech will be exhibiting a range of <a href="http://www.onlinetech.com/secure-hosting/overview">secure hosting</a> solutions for mission critical applications, including <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a>, <a href="http://www.onlinetech.com/colocation/overview">colocation</a>, <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">managed servers</a>, <a href="http://www.onlinetech.com/compliant-hosting/overview">compliant hosting</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a>, at the <a href="http://www.onlinetech.com/events/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders"><strong>Midwest Technology Leaders 2013</strong></a> symposium for IT executives and CIOs held in Detroit, Michigan.</p>
<p>Online Tech’s Director of Operations, Jason Yaeger, participated in a rapid fire Q&amp;A session this morning at the Midwest Technology Leaders conference in Plymouth, Michigan. Matt Roush introduced Online Tech as being a long time home of innovation in the state of Michigan. Jason discussed how Online Tech has managed innovation in client relations and <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">private cloud</a> environments:</p>
<p>Online Tech has taken the initiative to communicate and understand what our clients&#8217; pain points are. We recognize that your business requires uptime 24/7. After looking across the industry and acknowledging the frustration that comes with a lack of communication, Online Tech has now developed an Emergency Notification Systems that goes out to our clients within seconds of any outage.</p>
<p>Online Tech is Michigan’s most trusted provider of private cloud environments. We recognize that 75% of companies will be outsourcing to the private cloud environment in the next couple of years, with 25% of companies already there. Online Tech is making the selling process of those environments easier on our clients.</p>
<p><strong>About Jason Yaeger</strong><br />
Most recently, Jason was the recipient of the <a href="http://www.onlinetech.com/news/in-the-news/online-tech-wins-2012-crains-detroit-business-cio-of-the-year">2012 Crain’s Detroit Business CIO of the Year</a>, exemplifying innovation in technology strategy, industry leadership and a track record of “going beyond the call of duty.”</p>
<p>Jason Yaeger is also Online Tech’s Risk Management and Security Officer. Jason has guided the company through the successful completion of many audits, including <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70 Type I</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70 Type II</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">HIPAA </a>and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/overview">PCI</a>.</p>
<p><a href="http://resource.onlinetech.com/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders/jason-yaeger/" rel="attachment wp-att-10388"><img class="alignright size-full wp-image-10388" title="Jason Yaeger" src="http://resource.onlinetech.com/wp-content/uploads/Jason-Yaeger.png" alt="Jason Yaeger" width="312" height="261" /></a>Jason also led the investment in energy efficient improvements last year on Online Tech&#8217;s <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a> facility. As a result, Online Tech became the first <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> operator to earn the U.S. Environmental Protection Agency&#8217;s ENERGY STAR certification, putting Online Tech in the top 25 percent of facilities in the nation regarding energy performance. Read <a href="http://www.onlinetech.com/news/press-releases/online-tech-earns-epas-energy-star-certification-for-superior-energy-efficiency">Online Tech Earns EPA&#8217;s ENERGY STAR Certification for Superior Energy Efficiency</a> to learn more.</p>
<p>Read more about private clouds:<br />
<em><strong><a href="http://www.onlinetech.com/resources/e-tips/cloud-computing/private-cloud-computing-a-game-changer-for-disaster-recovery">Private Cloud Computing: A Game Changer for Disaster Recovery</a></strong></em><br />
<a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">Private cloud computing</a> offers a number of significant advantages – including lower costs, faster server deployments, and higher levels of resiliency. What is often over looked is how the Private Cloud can dramatically changes the game for <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> in terms of significantly lower costs, faster recovery times, and enhanced testability. … <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing/private-cloud-computing-a-game-changer-for-disaster-recovery">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/cloud-computing-benefits-and-security/">Pairing Cloud Computing Benefits with Security and Compliance</a></strong></em><br />
The added business value of cloud computing is multi-faceted, as Online Tech’s co-CEO Mike Klein outlined in a previous article, The Six Benefits of Cloud Computing, which I’ll summarize here: Lower Costs Pooling of computing resources means better efficiency and … <a href="http://resource.onlinetech.com/cloud-computing-benefits-and-security/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/precautions-with-the-hipaa-cloud-for-healthcare-software-as-a-service-saas-companies/">Precautions with the HIPAA Cloud for Healthcare Software as a Service (SaaS) Companies</a></strong></em><br />
A recent Google search brought me to a health IT blog, <em>Life as a Healthcare CIO</em>, and the post entitled <em>The Reality of SaaS</em>. The author discusses whether or not SaaS/cloud computing is appropriate for EHR (electronic health record) hosting … <a href="http://resource.onlinetech.com/precautions-with-the-hipaa-cloud-for-healthcare-software-as-a-service-saas-companies/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-mtl-managing-innovation-in-client-relations-private-clouds/">2013 MTL: Managing Innovation in Client Relations &#038; Private Clouds</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-mtl-managing-innovation-in-client-relations-private-clouds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 Midwest Technology Leaders Keynote: Competencies of the New CIO</title>
		<link>http://resource.onlinetech.com/2013-midwest-technology-leaders-keynote-competencies-of-the-new-cio/</link>
		<comments>http://resource.onlinetech.com/2013-midwest-technology-leaders-keynote-competencies-of-the-new-cio/#comments</comments>
		<pubDate>Wed, 22 May 2013 17:52:47 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[michigan CIOs]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[michigan technology]]></category>
		<category><![CDATA[midwest technology leaders]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11453</guid>
		<description><![CDATA[<p>Michigan data center operator Online Tech is exhibiting a range of secure hosting solutions for mission critical applications, including cloud hosting, colocation, managed servers, compliant hosting and disaster recovery, at the Midwest Technology Leaders 2013 symposium for IT executives and &#8230; <a href="http://resource.onlinetech.com/2013-midwest-technology-leaders-keynote-competencies-of-the-new-cio/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-midwest-technology-leaders-keynote-competencies-of-the-new-cio/">2013 Midwest Technology Leaders Keynote: Competencies of the New CIO</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://resource.onlinetech.com/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders/2013-midwest-tech-leaders/" rel="attachment wp-att-10387"><img class="alignleft size-full wp-image-10387" title="2013 Midwest Tech Leaders" src="http://resource.onlinetech.com/wp-content/uploads/2013-Midwest-Tech-Leaders.png" alt="2013 Midwest Tech Leaders" width="210" height="76" /></a><a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> operator Online Tech is exhibiting a range of <a href="http://www.onlinetech.com/secure-hosting/overview">secure hosting</a> solutions for mission critical applications, including <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a>, <a href="http://www.onlinetech.com/colocation/overview">colocation</a>, <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">managed servers</a>, <a href="http://www.onlinetech.com/compliant-hosting/overview">compliant hosting</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a>, at the <a href="http://www.onlinetech.com/events/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders"><strong>Midwest Technology Leaders 2013</strong></a> symposium for IT executives and CIOs held in Detroit, Michigan. Here&#8217;s a liveblog of one of the featured keynotes:<br />
<strong></strong></p>
<p><strong>Keynote: Competencies of the New CIO</strong><br />
<em>Speaker: Larry Bonfante- CIO, United States Tennis Association (USTA)</em></p>
<p>CIOs today must be more than a provider of technology and services. They must be able to engage with the consumer, board members and senior executives as business executives and thought leaders themselves.</p>
<p>Most CIOs have grown up in the IT realm, they know how to leverage that IT to help business, but the third leg (missing leg) is “human dynamics.” Today’s CIOs need strong relationship management and marketing skills, which are qualities that don’t always come easily to a CIO. Being the CIO of an organization today is a front-facing role and not just sharing IT knowledge.</p>
<p>People should be passionate about the organizations they work for. How many employees take their “souls” off and hang them at the door and put it on when they leave the office? We need our CIOs to bring their whole person and soul to the job.</p>
<p>Organizations need a vision to inspire people and find what makes their people “tick.” It needs to help people understand the link between their efforts and the company vision. It needs to become their vision and not just one hoisted on them.</p>
<p>The main purpose of IT is to drive business value. CIOs shouldn’t be in the business just for the sake of technology being “cool.” IT is about being the very fabric of the business and integrated with it.  IT needs to be part of the decision-making of the business. If you woke up your CIO at 2am, what would their answers be to the following questions:</p>
<ul>
<li>What matters? What are you striving for?</li>
<li>How are the things we doing in IT enabling those outcomes?</li>
<li>If we are doing things that don’t matter, why are we doing them?</li>
</ul>
<p>When it comes to communication, even if you think you have communicated enough, communicate some more! <strong>The key to communication is listening.</strong> CIOs need to become better listeners so they can become better communicators.</p>
<p>CIOs of yesterday were often easy to pick out of a crowd, because&#8230;</p>
<ol>
<li>They dress different than everyone else</li>
<li>They haven’t built relationships with anyone in the room</li>
<li>When they open their mouth, they speak “geek speak”</li>
</ol>
<p>Today’s CIO need to speak to people in clear English. When entering the boardroom, they need to be able to speak business in the language of board members and truly fit in. Tailoring the message to the audience in the room is key.</p>
<p>Everyone looks at life through their own lens and constantly ask, “What’s in it for me?” If CIOs are going to be effective relationship managers, the question needs to be: “What’s in it for them?” When you’re a leader, it’s never all about you. Leaders build their team and consistently give others credit, it’s about serving others. It is critically important to work members of your team as individuals and do what is effective for them.  CIOs owe it to people to develop them to the best THEY can be.</p>
<p>The post <a href="http://resource.onlinetech.com/2013-midwest-technology-leaders-keynote-competencies-of-the-new-cio/">2013 Midwest Technology Leaders Keynote: Competencies of the New CIO</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-midwest-technology-leaders-keynote-competencies-of-the-new-cio/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliant Hosting at the Internet Retailer Conference &amp; Exhibit (IRCE)</title>
		<link>http://resource.onlinetech.com/pci-compliant-hosting-at-the-internet-retailer-conference-exhibit/</link>
		<comments>http://resource.onlinetech.com/pci-compliant-hosting-at-the-internet-retailer-conference-exhibit/#comments</comments>
		<pubDate>Wed, 22 May 2013 13:46:43 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[IRCE 2013]]></category>
		<category><![CDATA[pci clouds]]></category>
		<category><![CDATA[pci colocation]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci managed servers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11440</guid>
		<description><![CDATA[<p>Two weeks from today marks the start of the 9th annual Internet Retailer Conference &#38; Exhibit (IRCE) in Chicago. We’ll be there at booth #108, among the 200 speakers and 9,500 executives related to e-retail. Topics range from creating a &#8230; <a href="http://resource.onlinetech.com/pci-compliant-hosting-at-the-internet-retailer-conference-exhibit/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/pci-compliant-hosting-at-the-internet-retailer-conference-exhibit/">PCI Compliant Hosting at the Internet Retailer Conference &#038; Exhibit (IRCE)</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-39f93fd8-cc7b-31b7-1f1d-07260f484eaf" dir="ltr"><img class="alignnone" title="IRCE 2013" src="http://irce.internetretailer.com/static/uploads/conf_site/IRCE-2013-Exhibits-Page-Exhibit-Hall-Overview.jpg" alt="IRCE 2013" width="614" height="291" /></p>
<p dir="ltr">Two weeks from today marks the start of the 9th annual <a href="http://www.onlinetech.com/events/internet-retailer-conference-a-exhibit-irce-2013">Internet Retailer Conference &amp; Exhibit </a>(IRCE) in Chicago. We’ll be there at booth #108, among the 200 speakers and 9,500 executives related to e-retail.</p>
<p dir="ltr">Topics range from creating a global presence using e-commerce, to e-marketing tips to boost traction on search, to focusing on B2B sales and marketing. Social commerce, e-commerce technologies, and online payment processes will also be hot button topics throughout the exhibit. Here’s just a few of the 220 speakers that will be presenting at the IRCE:</p>
<hr />
<strong><img class="alignleft" title="Mindy Grossman" src="http://irce.internetretailer.com/static/uploads/conf_site/Mindy_Grossman.jpg" alt="Mindy Grossman" width="107" height="132" />Mindy Grossman</strong><br />
Mindy Grossman is the CEO of HSN Inc. Her keynote address, How Boundaryless Retail Drives 21st Century Success, will be at June 6th, 8:30-9:00am. She’ll be explaining her philosophy of ‘Boundaryless Retail’ that has grown HSN into one of the top internet retailers in the country. Boundaryless retail is a culture that entangles commerce with engaging content and a social community that keeps consumers interacting with a company.</p>
<hr />
<p><strong><img class="alignleft" title="Al Gore" src="http://irce.internetretailer.com/static/uploads/conf_site/Al_Gore.jpg" alt="Al Gore" width="107" height="132" />Al Gore</strong><br />
Al Gore will be giving his address, The Global View: The Internet, Business, and The Worldwide Opportunity, on June 5th, 9:45-10:15am. He’ll be giving insight into how the internet’s ubiquitous nature can help companies compete on a global level. Being on the board of directors of Apple, as well as a senior strategic advisor to Google, this is an incredible chance to hear one of the leading experts talk about what the future of online business can be.</p>
<hr />
<p dir="ltr">Each day will have 5 different tracks to follow, with a total of 120 sessions. Squeezing all these speakers and sessions into a three day conference means you’ll never have time to see it all, so be sure to keep an eye on the blog throughout the conference. We’ll be live-blogging each day to make sure you get everything you can out of this wonderful opportunity.</p>
<p dir="ltr">Also, don’t forget to stop by and see us at booth #108, so don’t hesitate to visit us. We’ll be showing off our wide array of <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI compliant offerings</a>. Whether you have questions about <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/colocation">compliant colocation</a>, <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/managed-servers">managed servers</a>, or <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">clouds</a>, we can answer them for you, and help set you up with a solution that fits your project.</p>
<p>Resources:<br />
<a href="http://irce.internetretailer.com/2013/agenda/#/overview">http://irce.internetretailer.com/2013/agenda/#/overview</a><br />
<a href="http://www.onlinetech.com/events/internet-retailer-conference-a-exhibit-irce-2013">http://www.onlinetech.com/events/internet-retailer-conference-a-exhibit-irce-2013</a><br />
<a href="http://resource.onlinetech.com/internet-retailer-conference-exhibit-irce-2013/">http://resource.onlinetech.com/internet-retailer-conference-exhibit-irce-2013/</a></p>
<p>The post <a href="http://resource.onlinetech.com/pci-compliant-hosting-at-the-internet-retailer-conference-exhibit/">PCI Compliant Hosting at the Internet Retailer Conference &#038; Exhibit (IRCE)</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-compliant-hosting-at-the-internet-retailer-conference-exhibit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 5 Reasons Why Michigan is a Good Disaster Recovery Location</title>
		<link>http://resource.onlinetech.com/top-5-reasons-why-michigan-is-a-good-disaster-recovery-location/</link>
		<comments>http://resource.onlinetech.com/top-5-reasons-why-michigan-is-a-good-disaster-recovery-location/#comments</comments>
		<pubDate>Tue, 21 May 2013 19:37:24 +0000</pubDate>
		<dc:creator>Anna Ankenbrand</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Michigan Colocation]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[michigan disaster recovery]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11430</guid>
		<description><![CDATA[<p>The first and most important decision your organization can make regarding disaster recovery is deciding on the geographical location.  There are many things to consider including the probability and severity of natural disasters, other weather conditions like temperature, power structure &#8230; <a href="http://resource.onlinetech.com/top-5-reasons-why-michigan-is-a-good-disaster-recovery-location/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/top-5-reasons-why-michigan-is-a-good-disaster-recovery-location/">Top 5 Reasons Why Michigan is a Good Disaster Recovery Location</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p><iframe src="http://www.youtube.com/embed/QNt3no8Lge0?list=UUM8ZIzbuHrrqH6u0jdcNBhA" frameborder="0" width="560" height="315"></iframe></p>
<p>The first and most important decision your organization can make regarding <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> is deciding on the geographical location.  There are many things to consider including the probability and severity of natural disasters, other weather conditions like temperature, power structure of the area, and availability of a knowledgeable workforce.<br />
The state of Michigan offers many positives in all of these areas.  Let’s take a look at the top 5 reasons why Michigan is a good disaster recovery location.</p>
<p><strong>1.  Low Probability of Natural Disasters</strong> &#8211; It is hard to predict when and where a natural disaster will hit.  However, there are geographical locations that are more prone to natural disasters than others.  For example, the state of Florida and Texas has a high probability of hurricanes while California has a high probability of earthquakes.</p>
<p>There is an extremely low risk of natural disasters in the state of Michigan and it is one of the safest states in terms of natural disaster.  The NOAA (National Oceanic and Atmospheric Administration) found that the Great Lakes region has a low probability of hurricanes or tropical storms.</p>
<p>According to their research, the region experiences hurricane or tropical storm remnants, on average, twice a decade.  And in the majority of instances, the storms diminish to rain storms by the time they reach the region.  In the case of earthquakes, the U.S. Geological Survey (USGS) predicts that Michigan has less than 1% chance of having an earthquake in the next 50 years.</p>
<p><strong>2. Low Severity of Natural Disasters</strong> – Another consideration regarding natural disasters is the severity or impact that a natural disaster can have on a region.  For example, a more densely populated area, such as the East Coast, will experience greater devastation than less populated areas.  Hurricane Sandy was a great example of how populated East Coast cities suffered with power outages, flooding and fuel shortages.</p>
<p>According to FEMA’s website, the state of Michigan has only declared disasters a total of 33 times.  Only seven other states declared disaster less times including South Carolina, Utah, Wyoming, Connecticut, Delaware, Maryland, and Rhode Island.  Yet, four of these states rank in the top 10 of population density(1).  Therefore, Michigan offers less disasters and lower population density than most states.</p>
<p>“The natural disaster we do have is a tornado,” says Yan Ness.  The good news, bad news about a tornado is that the swath of damage of a tornado is measured by hundreds of yards, not miles like a hurricane.  So, in Michigan 50 miles is adequate for disaster recovery separation.  You can have equipment in one location and backup equipment 50 miles away.  This allows employees to quickly travel to the backup site in less than an hour if disaster strikes.</p>
<p><strong>3.  Two Separate Power Grids</strong> – A down utility grid could cause significant power outages following a natural disaster.  So, it is very important to consider a location that can offer you a strong power grid as well as the opportunity to use multiple power grids for increased availability and reliability.</p>
<p>According to Ness, since Michigan used to have a lot of auto plants that needed power, Michigan has a large capacity of power along with a very robust, sizable power grid.  One unique thing about Michigan is that the state has two separate power grids.  Michigan has two separate power companies – one serves the northern half of lower Michigan and the other serves the southeastern and southern half of Michigan.</p>
<p>Online Tech has data centers located in both power grids. So even though you are in one state you can drive between the data centers that are completely powered by different grids, different companies; yet they’re still connected by very cost effective fiber.</p>
<p><strong>4. Cool Temperatures</strong> &#8211; Michigan’s year round cool climate is ideal for disaster recovery locations.  With cool temperatures, <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a> do not need to rely as heavily on powered cooling as data centers in the south.  Michigan’s average heating day is 62 degrees which allows data centers to use free cooling about 90% of the time.  This helps Michigan data centers to lower utility costs but cool temperatures can also reduce the risk of servers overheating and potential hardware failure affecting data availability.  Read more about the benefits of Michigan cool climate <em><a href="http://resource.onlinetech.com/michigan-the-next-cool-thing-for-data-centers/">Michigan – The Next Cool Thing for Data Centers</a></em>.</p>
<p><strong>5. Well-Educated Workforce</strong> – A disaster recovery location should also have access to a knowledgeable, educated workforce.  After all, people are the ones who support a disaster recovery site.  Michigan boasts the 4th largest high-tech workforce in the U.S. and ranks as one of the top technology centers in the nation.  Michigan residents also have access to 27 colleges and universities that offer degrees in science, engineering and technology.</p>
<p>(1) <a href="http://www.worldatlas.com">www.worldatlas.com</a></p>
<p>The post <a href="http://resource.onlinetech.com/top-5-reasons-why-michigan-is-a-good-disaster-recovery-location/">Top 5 Reasons Why Michigan is a Good Disaster Recovery Location</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/top-5-reasons-why-michigan-is-a-good-disaster-recovery-location/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Security Checklist for Healthcare Organizations</title>
		<link>http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/</link>
		<comments>http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/#comments</comments>
		<pubDate>Tue, 21 May 2013 14:51:20 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[healthcare CIO]]></category>
		<category><![CDATA[hipaa checklist]]></category>
		<category><![CDATA[HIPAA cloud computing]]></category>
		<category><![CDATA[hipaa cloud hosting]]></category>
		<category><![CDATA[hipaa cloud providers]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa security]]></category>
		<category><![CDATA[mHealth]]></category>
		<category><![CDATA[mobile health IT]]></category>
		<category><![CDATA[mobile security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11411</guid>
		<description><![CDATA[<p>According to HITRUSTAlliance.net’s report on U.S. healthcare data breaches affecting 500 or more individuals, A Look Back: U.S. Healthcare Data Breach Trends, the leading cause of breaches involved theft (54 percent) and the leading sources of breached PHI (protected health &#8230; <a href="http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/">HIPAA Security Checklist for Healthcare Organizations</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-70418e96-c76e-39ba-7348-1fb0eb7c81b9" dir="ltr">According to HITRUSTAlliance.net’s report on U.S. healthcare data breaches affecting 500 or more individuals, <em>A Look Back: U.S. Healthcare Data Breach Trends</em>, the leading cause of breaches involved theft (54 percent) and the leading sources of breached PHI (protected health information) were laptops (25 percent) and paper records (24 percent).</p>
<p dir="ltr">The most frequently stolen items included laptops, desktops and mobile media (USB drives, CDs/DVDs, backup tapes). When it came to business associates, they accounted for 58 percent of the records breaches, and were implicated in 21 percent of the breach cases.</p>
<div id="attachment_11422" class="wp-caption alignright" style="width: 483px"><a href="http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/business-associate-breaches/" rel="attachment wp-att-11422"><img class="size-full wp-image-11422 " title="Business Associate Breaches; Source: HITRUSTAlliance.net" src="http://resource.onlinetech.com/wp-content/uploads/Business-Associate-Breaches.png" alt="Business Associate Breaches; Source: HITRUSTAlliance.net" width="473" height="114" /></a><p class="wp-caption-text">Business Associate Breaches; Source: HITRUSTAlliance.net</p></div>
<p dir="ltr">With numbers like these, physician practices and health system CIOs should be aware of the possible areas of IT risk in order to secure PHI (according to HITRUST) &#8211; for each of the following areas, I’ve provided resource links and tips:</p>
<p><strong>Information Security Policies and Procedures</strong><br />
Establishing a set of standards that are custom to your organization can help guide user behavior toward more secure practices. Policies are necessary to abide by the <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#Security%20Rule">HIPAA Security Rule</a>’s Organizational, Policies and Procedures and Documentation Requirements standard 164.316(a) for covered entities:</p>
<blockquote>
<p dir="ltr">Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart, taking into account those factors specified in § 164.306(b)(2)(i), (ii), (iii), and (iv) [the Security Standards: General Rules, Flexibility of Approach].</p>
</blockquote>
<p dir="ltr">Security policies should address password management, PHI storage/use, encryption, PHI exchange procedures, privacy filters, etc. For a list of example HIPAA resources, including policies, procedures and training materials from a variety of established medical centers and university health systems, visit <em><a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/resources/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources: Policies, Procedures and Training Materials</a>.</em></p>
<p><strong>Endpoint/Mobile Security</strong><br />
This involves protecting networks when connecting remotely via any number of devices, including laptops, desktops, servers, phones and tablets. Connecting remotely via a VPN (Virtual Private Network) that requires <a href="http://www.onlinetech.com/secure-hosting/technical-security/two-factor-authentication">two-factor authentication</a> (username/password, and a secondary form of authentication, typically via a cell phone call or text) may provide more assurance against the risk of unauthorized access to sensitive healthcare data. Other security services like firewalls, <a href="http://www.onlinetech.com/secure-hosting/technical-security/antivirus">antivirus</a> and <a href="http://www.onlinetech.com/secure-hosting/technical-security/patch-management">patch management</a> may also help secure endpoints.</p>
<p dir="ltr">Learn more about two-factor in our upcoming webinar, <em><a href="http://www.onlinetech.com/events/the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication">The Affordable Way to Maintain Security and Compliance with Two-Factor Authentication</a></em>, June 4 @2PM ET, or check back after for a recording of the presentation.</p>
<p dir="ltr">The BYOD (Bring Your Own Device) movement in the healthcare industry calls for a mobile security policy. Read our <a href="http://www.onlinetech.com/resources/white-papers/mobile-security">Mobile Security white paper</a> on how to keep devices and mobile apps secure, as well as a BYOD case study of a mobile security architecture designed and implemented successfully within a hospital environment.</p>
<p dir="ltr">Encrypting devices, email and other healthcare data is another industry best practice and addressable standard of HIPAA technical safeguards that require access control:</p>
<blockquote>
<p dir="ltr">A covered entity must, in accordance with §164.306… Implement a mechanism to encrypt and decrypt electronic protected health information.” (45 CFR § 164.312(a)(2)(iv))</p>
</blockquote>
<p dir="ltr">Join our upcoming webinar <em><a href="http://www.onlinetech.com/events/encryption-perspective-on-privacy-security-a-compliance">Encryption &#8211; Perspective on Privacy, Security &amp; Compliance</a></em> to learn more, or read about <em><a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a>.</em></p>
<p><strong>Network Security</strong><br />
Sensitive IT infrastructure including <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">managed servers</a>, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud</a>, power and networks should be protected by restricted access, and routers, switches and devices should meet HIPAA compliant requirements to protect ePHI (electronic protected health information) found on networks. Firewalls and Intrusion Detection Services can work to identify security breaches and notify you or your hosting provider to take action.</p>
<p><strong>Staff Training and Security Awareness</strong><br />
HIPAA security awareness and training is another administrative safeguard required by the HIPAA Security Rule &#8211; not only is a <a href="http://www.onlinetech.com/secure-hosting/administrative-security/staff-training">staff training</a> program required, but periodic retraining is necessary whenever new policies or procedures, significant software or hardware upgrades, new security technology, etc. are implemented within an organization.</p>
<p dir="ltr"><a href="http://www.onlinetech.com/secure-hosting/administrative-security/business-associate-training">Business associate training</a> is also important, as they were implicated in 21 percent of HIPAA breach cases, as mentioned earlier. Check that your vendors have a delegated security and risk officer, and that training is updated/established for new employees.</p>
<p><strong>Breach Response</strong><br />
The HIPAA breach notification rule dictates that covered entities must notify affected individuals/the media/the HHS (if affecting more than 500 state residents) of a data breach no later than 60 days after discovery. Business associates are also required to notify covered entities no later than 60 days.</p>
<p dir="ltr">As a healthcare CIO, check your vendor contracts, or business associate agreement (BAA) for terms on their roles and responsibilities when it comes to breach notification policy to ensure you’re on the same page, and you can gather the documents and information you need to accurately report to the OCR. To find out what the recent HIPAA omnibus rule dictates for BAAs, read <em><a href="http://resource.onlinetech.com/final-hipaa-omnibus-rule-business-associate-agreements-and-how-to-be-hipaa-compliant/">Final HIPAA Omnibus Rule: Business Associate Agreements &amp; Roadmap to Compliance</a>.</em></p>
<p dir="ltr">For a list of information that the OCR requests shortly after a self-reported HIPAA breach, including documentation, risk assessments, policies and procedures and more, read <em><a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/ocr-audit-requirements-following-a-self-reported-hipaa-breach">OCR Audit Requirements Following a Self-Reported HIPAA Breach</a>.</em></p>
<p><strong>Third-Party Assurance</strong><br />
Your third-parties may be your business associates now that the final omnibus rule has widened the scope of who may be audited and fined for not meeting HIPAA compliance. Think it’s not your problem? Think again &#8211; the new rule document states that the “proposed changes would make covered entities and business associates liable under § 160.402(c) for the acts of their business associate agents, in accordance 61 with the Federal common law of agency, regardless of whether the covered entity has a compliant business associate agreement in place.”</p>
<p dir="ltr">As I initially wrote about in <em><a href="http://resource.onlinetech.com/how-the-final-omnibus-rule-affects-hipaa-cloud-computing-providers/">How the Final Omnibus Rule Affects HIPAA Cloud Computing Providers</a></em>, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud service providers</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> providers now fall under the definition of a business associate. Covered entities can ensure their third-parties can meet HIPAA by reviewing their independent audit reports measuring their security standards and practices against the <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#OCRprotocol">OCR HIPAA Audit Protocol</a>. Anything less than fully compliant is a risk your organization can’t afford to take.</p>
<p dir="ltr"><strong>Access Control</strong><br />
A HIPAA standard that helps meet technical safeguards, access control refers to restricting PHI system access to only authorized persons or software. The specifications include:</p>
<ol>
<li><strong>Unique User ID</strong> &#8211; Just as it sounds, assign a unique username or code to track users.</li>
<li><strong>Emergency Access Procedure</strong> &#8211; This should be in the established policies and procedures that allows access to ePHI as needed in an emergency.</li>
<li><strong>Automatic Logoff</strong> &#8211; Establish a way to terminate electronic sessions after a predetermined time of inactivity.</li>
<li><strong>Encryption/Decryption</strong> &#8211; See Endpoint/Mobile Security.</li>
</ol>
<p><strong>Physical Security</strong><br />
HIPAA Security Standards for <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical safeguards</a>, specifically facility access controls, requires the implementation of:</p>
<blockquote>
<p dir="ltr">&#8230;policies and procedures to limit physical access to its electronic information systems and the facility or facilities in which they are housed, while ensuring that properly authorized access is allowed.</p>
</blockquote>
<p dir="ltr">Restricting physical access to servers should be on your list of IT security &#8211; only authorized personnel should have building access to where your data is stored or processed, and dual factor authentication with the use of badges and biometrics (fingerprint recognition) can assist in tighter access control. Environmental controls can also be managed with surveillance, monitoring and alarm systems, as well as policies for visitors.</p>
<p><img class="alignleft" title="HIPAA Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-hipaa.png" alt="HIPAA Compliant Hosting White Paper" width="221" height="100" />For more on using the cloud and secure hosting for HIPAA compliant solutions, read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Hosting white paper</a>. Questions to ask your HIPAA hosting provider, data center standards cheat sheet and a diagram of the <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical</a>, <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical</a> and <a href="http://www.onlinetech.com/secure-hosting/administrative-security">administrative security</a> components of a HIPAA hosting solution (including HIPAA compliant clouds) are included.</p>
<p><img class="alignright" title="Mobile Security White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-mobile.png" alt="Mobile Security White Paper" width="220" height="99" />Or read our <a href="http://www.onlinetech.com/resources/white-papers/mobile-security">Mobile Security white paper</a> for how to secure electronic protected health information (ePHI) while using mobile devices in the workplace, ideal for any healthcare organization interested in implementing a secure BYOD (Bring Your Own Device) environment.</p>
<p>Still have questions? <a href="http://www.onlinetech.com/contact">Contact</a> us or <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">chat</a> now.</p>
<p>References:<br />
<a href="http://www.hitrustalliance.net/breachreport/HITRUST%20Report%20-%20U.S.%20Healthcare%20Data%20Breach%20Trends.pdf">A Look Back: U.S. Healthcare Data Breach Trends</a> (PDF)<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/physsafeguards.pdf">HIPAA Security Standards: Physical Safeguards</a> (PDF)<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/">Breach Notification Rule</a></p>
<p>The post <a href="http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/">HIPAA Security Checklist for Healthcare Organizations</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-security-checklist-for-healthcare-organizations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>May Microsoft Security Updates</title>
		<link>http://resource.onlinetech.com/may-microsoft-security-updates/</link>
		<comments>http://resource.onlinetech.com/may-microsoft-security-updates/#comments</comments>
		<pubDate>Mon, 20 May 2013 13:36:05 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[windows security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11402</guid>
		<description><![CDATA[<p>Last week Microsoft had ten different vulnerabilities patched, including another cumulative Internet Explorer update. Two of the patches are considered critical, with the other eight labelled ‘Important’. The patch for Internet Explorer is meant to resolve eleven different vulnerabilities found &#8230; <a href="http://resource.onlinetech.com/may-microsoft-security-updates/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/may-microsoft-security-updates/">May Microsoft Security Updates</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-17837863-c225-926a-e328-315f243ea9e6" dir="ltr">Last week Microsoft had ten different vulnerabilities patched, including another cumulative Internet Explorer update. Two of the patches are considered critical, with the other eight labelled ‘Important’.</p>
<p dir="ltr">The patch for Internet Explorer is meant to resolve eleven different vulnerabilities found within the browser. These vulnerabilities could result in remote code execution if the user lands on a specially made web page using Internet Explorer, allowing the attacker to gain the same rights as the user. This affects Internet Explorer 6-10 on Windows clients.</p>
<p dir="ltr">The other critical update resolves one vulnerability disclosed to take the place of a temporary fix Microsoft announced last week. It also allows remote code execution if a user views a malicious website within the browser. This vulnerability may only affect Internet Explorer 8, which is an older version of the browser, but it happens to currently be the most used version. An attacker that exploits this vulnerability could end up with the same rights as the user. Microsoft mentions that one way to lower the effect of remote code execution attacks is to configure user rights on a basis of need. If a user isn’t dependent on certain administrative rights in order to fulfill their duties, it would be best to pare down their access.</p>
<p dir="ltr">The updates labelled important are split into a few different groups:</p>
<p><strong>Denial Of Service:</strong><br />
MS13-039 is an update to all supported editions of Windows 8 and Windows Server 2012. The vulnerability could allow a DoS situation if an attacker sends a specifically made HTTP packet to an affected server or client. Microsoft is resolving this by correcting the way that HTTP.sys handles certain HTTP headers. This patch will require a restart.</p>
<p><strong>Spoofing:</strong><br />
This update is for a vulnerability within the .NET Framework. Successfully exploited, an attacker could change the contents of an XML file without affecting the signature of the file. It would allow them to function as an authentic user. Microsoft is re-evaluating how the .NET Framework validates signatures in XML files and policy requirements for authentication.</p>
<p><strong>Remote Code Execution:</strong><br />
There are three different ‘important’ vulnerabilities that are resolved that could allow an attacker the rights of an appropriate user. The patches affect Microsoft Publisher, Microsoft Lync, Microsoft Word 2003, and Microsoft Word Viewer. These updates may require the user to restart.</p>
<p><strong>Information Disclosure:</strong><br />
Two patches resolve information disclosure vulnerabilities. The first is for Microsoft Visio, and was fixed by Microsoft changing the way the XML parser resolves outside entities within specially made files. This vulnerability would not be able to change the rights of an attacker, but would be able to give them more information that could aid in further compromising the system. The other patch is for Windows Writer. An attacker could successfully exploit this vulnerability by having a user visit a website and click on a specially crafted URL. The attacker could then override proxy settings for Writer, and overwrite files within that system. Both of these updates may require a restart.</p>
<p><strong>Elevation of Privilege</strong>:<br />
The last update is to fix an elevation of privilege vulnerability within Windows XP, Vista, Windows Server 2008, Windows 7, Windows 8, Windows Server 2012, and Windows RT. This exploit would allow the elevation if an attacker ran a specially crafted application on the system. They would have to have proper login credentials in order to perform this exploit, and would also need to be locally logged in. This update will require a restart.</p>
<p>Resource:<br />
<a href="http://technet.microsoft.com/en-us/security/bulletin/ms13-may">Microsoft Security Bulletin for May</a></p>
<p>The post <a href="http://resource.onlinetech.com/may-microsoft-security-updates/">May Microsoft Security Updates</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/may-microsoft-security-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encryption at the Hardware and Storage Level</title>
		<link>http://resource.onlinetech.com/encryption-at-the-hardware-and-storage-level/</link>
		<comments>http://resource.onlinetech.com/encryption-at-the-hardware-and-storage-level/#comments</comments>
		<pubDate>Fri, 17 May 2013 15:43:27 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[data encryption]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[encryption for hipaa]]></category>
		<category><![CDATA[encryption for pci]]></category>
		<category><![CDATA[hardware encryption]]></category>
		<category><![CDATA[software encryption]]></category>
		<category><![CDATA[storage encryption]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11385</guid>
		<description><![CDATA[<p>We’ve got three webinars lined up for the month of June with IT security professionals to help educate you and take your questions about encryption. For the first one of the series, join Chris Heuman, Practice Leader for RISC Management &#8230; <a href="http://resource.onlinetech.com/encryption-at-the-hardware-and-storage-level/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/encryption-at-the-hardware-and-storage-level/">Encryption at the Hardware and Storage Level</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>We’ve got three webinars lined up for the month of June with IT security professionals to help educate you and take your questions about encryption.</p>
<p>For the first one of the series, join Chris Heuman, Practice Leader for RISC Management and Consulting for a discussion on the value of encryption for <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a>, <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI</a> and many other regulatory frameworks and the successful components of a data security program that integrates encryption. Find out how you can sign up online for <em><a href="http://www.onlinetech.com/events/encryption-perspective-on-privacy-security-a-compliance">Encryption – Perspective on Privacy, Security &amp; Compliance</a>.</em></p>
<p>The second in the encryption webinar series features Mark Stanislav, Security Evangelist at Duo Security as he discusses encryption for Linux, and Farooq Ahmed, Software Development Manager of Online Tech who will cover encryption for Windows. Sign up for <em><a href="http://www.onlinetech.com/events/encryption-at-the-software-level-linux-and-windows">Encryption at the Software Level: Linux and Windows</a>.</em></p>
<p>For the third and final encryption webinar, join Steve Aiello, Systems Support Manager at Online Tech for a presentation on encryption at the hardware and storage level.</p>
<p><strong>Title</strong>: <em>Encryption at the Hardware and Storage Level</em><br />
<strong>When</strong>: Tuesday, June 25, 2013 @2PM ET<br />
<strong>Register</strong>: <a href="http://www.onlinetech.com/events/encryption-at-the-hardware-and-storage-level">Find the GoToMeeting link at our website.</a><br />
<strong>Description</strong>: Join Steve Aiello, Systems Support Manager at Online Tech for an informative webinar on encryption at the hardware and storage level.  Steve will discuss how encryption can be applied at various levels from the hardware and storage perspective. Impacts on performance, backup, security, and available resources may suggest very different encryption implementations.</p>
<p>This webinar explores the variety of places where encryption can be employed to mitigate risk of data loss or breach, and some of the considerations for choosing the most appropriate method to employ.</p>
<p><strong>Steve Aiello, Systems Support Manager, Online Tech</strong><br />
Steven Aiello is a Systems Support Manager with Online Tech, the Midwest’s premier managed data center operator. His certifications include CISSP (Certified Information System Security Professional), ISACA CISA, VMware VCP ( VMware Certified Professional), Cisco CCNA ( Cisco Certified Network Associate), Comptia Security+, and Certified Incident Responder (New Mexico Tech).</p>
<p>Steve is also presenting at Security B-Sides Detroit on securable infrastructures, June 7-8. Security B-Sides is a grassroots, DIY, open security conference bringing together a large number of IT and security professionals. Learn more about the event in <em><a href="http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/">Online Tech Presents on IT Security at Detroit B-Sides Security Conference</a>.</em></p>
<p>The post <a href="http://resource.onlinetech.com/encryption-at-the-hardware-and-storage-level/">Encryption at the Hardware and Storage Level</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/encryption-at-the-hardware-and-storage-level/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Encryption at the Software Level: Linux and Windows</title>
		<link>http://resource.onlinetech.com/encryption-at-the-software-level-linux-and-windows/</link>
		<comments>http://resource.onlinetech.com/encryption-at-the-software-level-linux-and-windows/#comments</comments>
		<pubDate>Thu, 16 May 2013 13:07:52 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hipaa encryption]]></category>
		<category><![CDATA[pci dss encryption]]></category>
		<category><![CDATA[pci encryption]]></category>
		<category><![CDATA[software encryption]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11365</guid>
		<description><![CDATA[<p>Encryption’s the name of the game these days, whether it’s at the software, hardware or storage level. And it’s an industry best practice for organizations that need to meet HIPAA and PCI compliance. We’ve got three webinars lined up for &#8230; <a href="http://resource.onlinetech.com/encryption-at-the-software-level-linux-and-windows/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/encryption-at-the-software-level-linux-and-windows/">Encryption at the Software Level: Linux and Windows</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-3d08088c-a9b8-5a62-ef04-9042e7c47465" dir="ltr">Encryption’s the name of the game these days, whether it’s at the software, hardware or storage level. And it’s an industry best practice for organizations that need to meet <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a> and <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI compliance</a>. We’ve got three webinars lined up for the month of June with IT security professionals to help educate you and take your questions about encryption.</p>
<p dir="ltr">For the first one of the series, join Chris Heuman, Practice Leader for RISC Management and Consulting for a discussion on the value of encryption for HIPAA, PCI and many other regulatory frameworks and the successful components of a data security program that integrates encryption. Find out how you can sign up online for <a href="http://www.onlinetech.com/events/encryption-perspective-on-privacy-security-a-compliance">Encryption &#8211; Perspective on Privacy, Security &amp; Compliance</a>.</p>
<p dir="ltr">The second in the encryption webinar series features Mark Stanislav, Security Evangelist at Duo Security as he discusses encryption for Linux, and Farooq Ahmed, Software Development Manager of Online Tech who will cover encryption for Windows.</p>
<p><strong>Title</strong>: <em>Encryption at the Software Level: Linux and Windows</em><br />
<strong>When</strong>: Tuesday, June 18, 2013 @2PM ET<br />
<strong>Register</strong>: <a href="http://www.onlinetech.com/events/encryption-at-the-software-level-linux-and-windows">Find the GoToMeeting link at our website</a>.<br />
<strong>Description</strong>: Join Farooq Ahmed, Software Development Manager for Online Tech and Mark Stanislav, Security Evangelist for Duo Security, for an informative webinar on encryption at the software level for Linux and Windows.  Farooq and Mark will discuss how encryption can be applied at various levels, from the software application code.</p>
<p>Impacts on performance, backup, security, and available resources may suggest very different encryption implementations. This webinar explores the variety of places where encryption can be employed to mitigate risk of data loss or breach, and some of the considerations for choosing the most appropriate method to employ.</p>
<hr />
<p><strong><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/stories/people/Mark%20Stanislav.jpeg" alt="Mark Stanislav" width="90" height="90" />Mark Stanislav, Security Evangelist, Duo Security</strong><br />
Mark Stanislav is the Security Evangelist for Duo Security, an Ann Arbor-based startup focused on <a href="http://www.onlinetech.com/secure-hosting/technical-security/two-factor-authentication">two-factor authentication</a> and mobile security. With a career spanning over a decade, Mark has worked within small business, academia, startup, and corporate environments, primarily focused on Linux architecture, information security, and web application development.</p>
<p>Mark earned his Bachelor of Science Degree in Networking &amp; IT Administration and his Master of Science Degree in Technology Studies, focused on Information Assurance, both from Eastern Michigan University. Mark also holds his CISSP, Security+, Linux+, and CCSK certifications.</p>
<hr />
<p><strong><img class="alignleft  wp-image-11399" title="Farooq_Ahmed" src="http://resource.onlinetech.com/wp-content/uploads/Farooq_Ahmed.png" alt="Farooq_Ahmed" width="94" height="140" />Farooq Ahmed, Software Development Manager, Online Tech</strong><br />
Farooq Ahmed is Online Tech’s Software Development Manager and is the Chief Architect of OTPortal, Online Tech’s feature-rich dashboard which delivers on-demand access to server monitoring, management and customer support 24&#215;7.</p>
<p>His career spans more than 14 years with analysis, design and .Net development with VB.Net and C#. Farooq has designed components for online payment systems and the banking industry. Farooq earned a Master’s in Computer Science from the University of Karachi.</p>
<hr />
<p>Stay tuned for info on our third encryption webinar! And read more about encryption in:</p>
<p><strong><em><a href="http://resource.onlinetech.com/federal-health-it-budget-increases-by-28-percent-encryption-mobile-security-ehr-safety/">Federal Health IT Budget Increases by 28 Percent: Encryption, Mobile Security &amp; EHR Safety</a></em></strong><br />
The proposed federal fiscal 2014 budget calls for a 28 percent increase to support further development of health IT initiatives while taking over where HITECH funding stops (ending in fiscal year 2013). The Office for Civil Rights’ (ONC) funding will … <a href="http://resource.onlinetech.com/federal-health-it-budget-increases-by-28-percent-encryption-mobile-security-ehr-safety/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">2013 State of HIPAA Encryption &amp; Authentication for Healthcare</a></strong></em><br />
According to the Healthcare Information Security Today report, 2013 Outlook: Survey Offers Update on Safeguarding Patient Information, most healthcare organizations believe that encryption would greatly improve their data security. Forty-one percent plan to encrypt all mobile devices and removable media, … <a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a></strong></em><br />
To address the question of whether or not to use data encryption when it comes to meeting HIPAA compliance and keeping patient health information (PHI) protected, let’s revisit the Health Insurance Portability and Accountability Act of 1996 (HIPAA): … <a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/encryption-at-the-software-level-linux-and-windows/">Encryption at the Software Level: Linux and Windows</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/encryption-at-the-software-level-linux-and-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech’s Michigan Data Centers Use Free Cooling</title>
		<link>http://resource.onlinetech.com/online-techs-michigan-data-centers-use-free-cooling/</link>
		<comments>http://resource.onlinetech.com/online-techs-michigan-data-centers-use-free-cooling/#comments</comments>
		<pubDate>Wed, 15 May 2013 15:10:18 +0000</pubDate>
		<dc:creator>Anna Ankenbrand</dc:creator>
				<category><![CDATA[Michigan Colocation]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[data center cooling]]></category>
		<category><![CDATA[data center efficiency]]></category>
		<category><![CDATA[free cooling]]></category>
		<category><![CDATA[green data centers]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11354</guid>
		<description><![CDATA[<p>In many cooler geographical U.S. regions, data centers are looking at taking advantage of using the outside environment to cool their IT equipment.  Although this free cooling concept has been in existence for more than 30 years, it has becoming &#8230; <a href="http://resource.onlinetech.com/online-techs-michigan-data-centers-use-free-cooling/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/online-techs-michigan-data-centers-use-free-cooling/">Online Tech’s Michigan Data Centers Use Free Cooling</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>In many cooler geographical U.S. regions, data centers are looking at taking advantage of using the outside environment to cool their IT equipment.  Although this free cooling concept has been in existence for more than 30 years, it has becoming more widely adopted during the past 2 to 3 years as energy prices continue to rise.</p>
<p>With three <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a>, Online Tech has been utilizing Michigan’s cool air temperatures to help lower their data centers costs.  “We naturally use less energy because it is cooler in Michigan,” says Yan Ness, Online Tech Co-CEO.</p>
<p><iframe src="http://www.youtube.com/embed/MlWuRqq47eM" frameborder="0" width="560" height="315"></iframe></p>
<p>As<em> <a href="http://resource.onlinetech.com/michigan-the-next-cool-thing-for-data-centers/">Michigan – The Next Cool Thing for Data Centers</a></em> mentions, Michigan’s year round cool climate is ideal for data centers.  As Ness points out that Michigan’s average heating day is 62 degrees and free cooling kicks in around 50 degrees.  So, air conditioning units can take advantage of the environment, even in the spring and fall, about 90% of the time in Michigan. “This is why Michigan is a great place to have data centers.  We should bring all servers all over the south up here and put them in our buildings,” says Ness.</p>
<p>Online Tech has been utilizing free cooling in their Michigan data centers for a few years.  In 2011, Online Tech invested over $1 million dollars into the <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a> incorporating higher energy efficiencies.  Old air conditioning units were upgraded to new units that were suitable for free cooling and more energy efficient.  “The savings has almost paid for the equipment,” says Ness.</p>
<p>Online Tech’s Michigan data centers not only incorporate free cooling to lower cooling costs.  All of our Michigan data centers are designed using hot/cold aisle containment and hot/cold configuration.  At the end of each row cabinets, a hidden plastic container directs all of the cold air into the center of the servers.  This maximizes the use of the cold air to cool the equipment and lessen the amount of cold air escaping.</p>
<p>Also, servers are organized in a hot/cold aisle configuration.  This hot/cold aisle layout lines up servers racks in alternating rows with server hot air exhausts pointing in the same direction and improves airflow management.</p>
<p>If you are interested in learning other ways to make your data center more efficient read <em><a href="http://resource.onlinetech.com/investing-in-data-center-efficiencies-part-one/">Investing in Data Center Efficiencies &#8211; Part One</a></em> and <em><a href="http://resource.onlinetech.com/investing-in-data-center-efficiencies-part-two/">Investing in Data Center Efficiencies &#8211; Part Two</a>.</em></p>
<p>The post <a href="http://resource.onlinetech.com/online-techs-michigan-data-centers-use-free-cooling/">Online Tech’s Michigan Data Centers Use Free Cooling</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-techs-michigan-data-centers-use-free-cooling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming Webinar: The Affordable Way to Maintain Security and Compliance with Two-Factor Authentication</title>
		<link>http://resource.onlinetech.com/upcoming-webinar-the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication/</link>
		<comments>http://resource.onlinetech.com/upcoming-webinar-the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication/#comments</comments>
		<pubDate>Wed, 15 May 2013 13:27:04 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[two-factor authentication]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11339</guid>
		<description><![CDATA[<p>Stolen credentials? Hacked social network accounts? Not with two-factor authentication! Learn more about how to protect your company and data with a simple security service. Join Dug Song, CEO of Duo Security and Jason Yaeger, Director of Operations/Risk Management &#38; &#8230; <a href="http://resource.onlinetech.com/upcoming-webinar-the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/upcoming-webinar-the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication/">Upcoming Webinar: The Affordable Way to Maintain Security and Compliance with Two-Factor Authentication</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Stolen credentials? Hacked social network accounts? Not with <a href="http://www.onlinetech.com/secure-hosting/technical-security/two-factor-authentication">two-factor authentication</a>! Learn more about how to protect your company and data with a simple security service. Join Dug Song, CEO of Duo Security and Jason Yaeger, Director of Operations/Risk Management &amp; Security Officer of Online Tech as they discuss a cost-effective way to achieve security and compliance with two-factor authentication.</p>
<p><strong>Title</strong>: <em>The Affordable Way to Maintain Security and Compliance with Two-Factor Authentication</em><br />
<strong>When</strong>: Tuesday, June 4, 2013 @2PM ET<br />
<strong>Register</strong>: <a href="https://www4.gotomeeting.com/register/136696567">Online with GoToMeeting</a><br />
<strong>Description</strong>: Never suffer from weak passwords again. According to Mandiant, 100% of security breaches involve stolen credentials. Not a week goes by without news of another high-profile security breach&#8211; trusted websites like LinkedIn, LivingSocial, Evernote, and more. And in a cascade of damage, when these sites are breached, passwords are stolen and can be reused to access additional accounts. The impact on your business and the professional reputation of your business can be disastrous.</p>
<p>If you must meet industry compliance standards such as <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA compliance</a> or <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI DSS compliance</a>, two-factor authentication is a best practice to fulfill authorization and authentication requirements. Join Dug Song, CEO of Duo Security and Jason Yaeger, Director of Operations/Risk Management &amp; Security Officer of Online Tech as they discuss how to employ two-factor authentication to protect your data and your business.</p>
<hr />
<p><strong><img class="alignleft" style="margin-right: 10px; margin-bottom: 10px;" src="http://www.onlinetech.com/images/stories/people/Dug%20Song.jpg" alt="Dug Song" width="90" height="136" />Dug Song, CEO of Duo Security</strong></p>
<p>Dug has a history of leading successful products and companies to solve pressing security problems. Dug spent 7 years as founding Chief Security Architect at <a href="http://www.arbornetworks.com/">Arbor Networks</a>, protecting 80% of the world&#8217;s Internet service providers, and growing to $120M+ annual revenue before its acquisition by Danaher.</p>
<p>Before Arbor, Dug built the first commercial network anomaly detection system (acquired by NFR / <a href="http://checkpoint.com/">Check Point</a>), and managed security in the world&#8217;s largest production Kerberos environment (University of Michigan).</p>
<p>Dug&#8217;s contributions to the security community include popular open source security (<a href="http://www.openbsd.org/cgi-bin/man.cgi?query=ssh&amp;sektion=1#end">OpenSSH</a>,<a href="http://libdnet.googlecode.com/">libdnet</a>, <a href="http://monkey.org/~dugsong/dsniff/">dsniff</a>), distributed filesystem (<a href="http://www.citi.umich.edu/projects/nfsv4/">NFSv4</a>), and operating system (<a href="http://openbsd.org/">OpenBSD</a>) projects, and co-founding the USENIX Workshop On Offensive Technologies (<a href="http://www.usenix.org/event/woot07/">WOOT</a>).</p>
<hr />
<p><strong><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/stories/people/jason-yeager-160.png" alt="Jason Yaeger" width="90" height="120" />Jason Yaeger, Director of Operations/Risk Management &amp; Security Officer, Online Tech</strong></p>
<p>In his three years at Online Tech, Jason has guided the company through successful completion of many audits, including SAS 70 Type I, SAS 70 Type II, SSAE 16, and HIPAA. In addition to overseeing operations across all of Online Tech’s data centers, Jason is also the Vice President of the Southeast Michigan Chapter of 7&#215;24 Exchange.</p>
<p>Prior to Online Tech, Jason was Director of Internet Operations at 20/20 Communications where he spent 8 years developing the company’s wireless and internet initiatives.</p>
<hr />
<p>More About Two-Factor Authentication:</p>
<p><em><strong><a href="http://resource.onlinetech.com/evernote-adds-two-factor-authentication/">Evernote Adds Two-Factor Authentication</a></strong></em><br />
On Saturday the online SaaS (software as a service) note-collecting Evernote posted a blog with subsequent email stating that they had discovered and blocked unauthorized activity on their network. In response to the attack, they reset the passwords of the … <a href="http://resource.onlinetech.com/evernote-adds-two-factor-authentication/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/two-factor-authentication-helps-fight-unauthorized-access/">Two-Factor Authentication Helps Fight Unauthorized Access</a></strong></em><br />
Access is a huge security concern for every company, no matter the industry. Thus, having an extra layer of technical security in place that employees must go through in order to access a company’s network can help reduce the risk … <a href="http://resource.onlinetech.com/two-factor-authentication-helps-fight-unauthorized-access/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/simple-security-improvements-with-your-mobile-device/">Simple Security Improvements with Your Mobile Device</a></strong></em><br />
Two, 2-minute security improvements to secure your account My inbox receives between 100 and 200 work emails daily – so far, as of writing this at 4:11pm, I’m up to 155. I won’t share my personal email stats – it … <a href="http://resource.onlinetech.com/simple-security-improvements-with-your-mobile-device/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/upcoming-webinar-the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication/">Upcoming Webinar: The Affordable Way to Maintain Security and Compliance with Two-Factor Authentication</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/upcoming-webinar-the-affordable-way-to-maintain-security-and-compliance-with-two-factor-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Presents on IT Security at Detroit B-Sides Security Conference</title>
		<link>http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/</link>
		<comments>http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/#comments</comments>
		<pubDate>Tue, 14 May 2013 15:07:07 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[detroit IT]]></category>
		<category><![CDATA[detroit technology]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[michigan IT]]></category>
		<category><![CDATA[michigan technology]]></category>
		<category><![CDATA[securable infrastructures]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11328</guid>
		<description><![CDATA[<p>Online Tech’s Systems Support Manager, Steve Aiello, will be presenting at Security B-Sides Detroit on securable infrastructures, June 7-8. Security B-Sides is a grassroots, DIY, open security conference bringing together a large number of IT and security professionals found in &#8230; <a href="http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/">Online Tech Presents on IT Security at Detroit B-Sides Security Conference</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p dir="ltr"><img class="alignleft" title="B-Sides Detroit" src="http://www.securitybsides.com/f/1327011664/bsides_detroit_logo_full_color_12212011_400px.jpg" alt="B-Sides Detroit" width="280" height="280" />Online Tech’s Systems Support Manager, Steve Aiello, will be presenting at Security B-Sides Detroit on securable infrastructures, June 7-8. Security B-Sides is a grassroots, DIY, open security conference bringing together a large number of IT and security professionals found in different cities such as San Francisco, Boston, Las Vegas, Denver, Los Angeles, and even Sao Paulo, Brazil.</p>
<p><strong>When</strong>: Friday &#8211; Saturday; June 7-8, 2013<br />
<strong>Where</strong>: Renaissance Conference Center, GM Renaissance Center, Tower 300 Level 2, Detroit, MI 48243<br />
<strong>Cost</strong>: Free<br />
<strong>Schedule</strong>: <a href="http://www.securitybsides.com/w/page/62849966/BSidesDetroit13Sessions">View Calendar of Talks</a><br />
<strong>RSVP</strong>: <a href="http://bsidesdetroit13.eventbrite.com/">Via EventBrite.com</a></p>
<p dir="ltr">Read on for more about Steve’s talk Saturday, June 8 at 10 AM ET:</p>
<p dir="ltr"><strong>Title</strong>: <em><strong>Building Securable Infrastructures</strong></em></p>
<p dir="ltr"><strong>Abstract</strong>: This session asks the question: “How do I design my environment to be securable?”  Until computing systems are designed and built with security and in mind we will be trapped in a cycle of post implementation Band-Aid style fixes.  Without designing infrastructures from the ground up with security in mind and real attempt to defend against directed attacks will be largely unsuccessful.</p>
<ul>
<li>How do we evaluate products in a systematic manor to eliminate vulnerabilities we invite into our environments?</li>
<li>Where is money more wisely spent: on developing quality security policies and guidelines? Or on buying, configuring, and maintaining security products?</li>
<li>What are critical questions that we should be asking our vendors when we are evaluating new products for our environments?</li>
</ul>
<p dir="ltr"><strong>Speaker bio</strong>: Steven Aiello is a Systems Support Manager with Online Tech, the Midwest’s premier managed data center operator. His certifications include CISSP (Certified Information System Security Professional), ISACA CISA, VMware VCP ( VMware Certified Professional), Cisco CCNA ( Cisco Certified Network Associate), Comptia Security+, and Certified Incident Responder (New Mexico Tech).</p>
<p>Other talks include topics such as:</p>
<p><a href="http://www.securitybsides.com/w/page/62849966/BSidesDetroit13Sessions#t20"><em><strong>The Ever-Evolving Threat Landscape</strong></em></a> &#8211; This talk covers how the threat landscape has changed in the past decade, as well as exemplifying the advanced capabilities of malware.<br />
<a href="http://www.securitybsides.com/w/page/62849966/BSidesDetroit13Sessions#t3"><em><strong>In Case of ZOMBIES Break Glass</strong></em></a> &#8211; Exactly what it sounds like. How to survive real scenarios that may bring about the zombie apocalypse.<br />
<a href="http://www.securitybsides.com/w/page/62849966/BSidesDetroit13Sessions#t24"><em><strong>So You Want to Hire a Penetration Testing?: 10 Tips for Success</strong> </em></a>- Mark Stanislav of Duo Security describes the process of hiring and working with an Ethical Hacking (EH) services company.</p>
<p dir="ltr">Steve presented on <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> and business continuity for a webinar series earlier this year. <a href="http://www.onlinetech.com/events/disaster-recovery-webinar-series">View all three webinars and slides</a>.</p>
<p><strong>About B-Sides</strong><br />
Each BSides is a community-driven framework for building events for and by information security community members. The goal is to expand the spectrum of conversation beyond the traditional confines of space and time. It creates opportunities for individuals to both present and participate in an intimate atmosphere that encourages collaboration. It is an intense event with discussions, demos, and interaction from participants. It is where conversations for the next-big-thing are happening.</p>
<p>The post <a href="http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/">Online Tech Presents on IT Security at Detroit B-Sides Security Conference</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-presents-on-security-at-detroit-b-sides-security-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 Midwest Technology Leaders Symposium Next Week in Detroit, Michigan</title>
		<link>http://resource.onlinetech.com/2013-midwest-technology-leaders-symposium-next-week-in-detroit-michigan/</link>
		<comments>http://resource.onlinetech.com/2013-midwest-technology-leaders-symposium-next-week-in-detroit-michigan/#comments</comments>
		<pubDate>Mon, 13 May 2013 19:50:40 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[Michigan Colocation]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[detroit michigan]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[michigan cybersecurity]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[michigan events]]></category>
		<category><![CDATA[michigan hosting providers]]></category>
		<category><![CDATA[michigan IT]]></category>
		<category><![CDATA[michigan technology]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11316</guid>
		<description><![CDATA[<p>The 2013 Midwest Technology Leaders Symposium starts in a week, so if you haven’t gotten yourself registered yet, you still have a little time to get yourself on the list. This symposium is the chance to hear from some of &#8230; <a href="http://resource.onlinetech.com/2013-midwest-technology-leaders-symposium-next-week-in-detroit-michigan/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-midwest-technology-leaders-symposium-next-week-in-detroit-michigan/">2013 Midwest Technology Leaders Symposium Next Week in Detroit, Michigan</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-428ed38b-9f67-baa3-e613-56eb4fdc48ca" dir="ltr">The <a href="http://www.onlinetech.com/events/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders"><strong>2013 Midwest Technology Leaders</strong> <strong>Symposium</strong></a> starts in a week, so if you haven’t gotten yourself registered yet, you still have a little time to get yourself on the list. This symposium is the chance to hear from some of the most successful CIOs in the Midwest.</p>
<p dir="ltr">Speaker Niel Nickolaisen, the CIO of Western Governers University is going to be detailing some IT best practices that leaders can implement to determine what objectives to focus on, and how to boost their IT performance to give their customers the best possible customer service. This talk is going to be chock-full of case-studies, true to life examples, and executable processes that can help revitalize your IT department.</p>
<p dir="ltr">Adriana Karaboutis, VP and Global CIO for Dell, is also going to be at the symposium. Her talk, <em><strong>The CIO as Innovator: How to Create True Business Value</strong></em>, is going to give some insight into how she translated her position at Dell by focusing on agility and innovation. This should be really informative for any CIOs looking to meet their goals and create value that can be felt by the entire business.</p>
<p dir="ltr">Another CIO you can hear at the conference (and one I’m particularly excited to hear from) is David Behen, CIO of the State of Michigan. Back in February <a href="http://resource.onlinetech.com/michigan-cio-david-behen-michigan-is-the-ideal-place-for-data-centers/">we heard David Behen speak</a> at Eastern Michigan University about some of the IT initiatives currently planned or implemented within the state.</p>
<p dir="ltr">He explained that the state of Michigan is focused on improving four key areas:</p>
<ul>
<li>Cybersecurity</li>
<li>Health IT</li>
<li>The Michigan.gov website</li>
<li>Data centers</li>
</ul>
<p dir="ltr">Behen was also quoted as saying that &#8220;the state of Michigan is the ideal place for data centers.&#8221;</p>
<p dir="ltr">He’s right, too. Michigan has one of the lowest incidences of natural disasters in the united states (second only to Alaska). Also, Michigan has milder summers and colder winters than other parts of the country. The ability to cool your data center with less power, coupled with the generally lower cost of electricity means your data center isn’t going to break the bank the way it may in other states.</p>
<p dir="ltr">The symposium will be held at The Inn at St. John’s in Detroit on May 21-22. If you’re going to be there, don’t forget to come say hello to us. We’ll be exhibiting our extensive range of <a href="http://www.onlinetech.com/secure-hosting/overview">hosting solutions</a>. Whether it’s <a href="http://www.onlinetech.com/colocation/overview">colo</a>, <a href="http://www.onlinetech.com/compliant-hosting/overview">compliance</a>, or <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud</a>, we’ve got the hosting service you need for your mission critical applications.</p>
<p>Resources and Other Reading:<br />
<a href="http://www.xchange-events.com/mtl13/">Midwest Technology Leaders Detroit 2013</a><br />
<a href="http://resource.onlinetech.com/choosing-your-data-center-location-why-michigan/">Choosing Your Data Center Location: Why Michigan?</a><br />
<a href="http://resource.onlinetech.com/michigan-the-next-cool-thing-for-data-centers/">Michigan &#8211; The Next Cool Thing for Data Centers</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-midwest-technology-leaders-symposium-next-week-in-detroit-michigan/">2013 Midwest Technology Leaders Symposium Next Week in Detroit, Michigan</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-midwest-technology-leaders-symposium-next-week-in-detroit-michigan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Seek and Destroy: U.S. Energy Firms Warned of Recent IT Threats</title>
		<link>http://resource.onlinetech.com/seek-and-destroy-u-s-energy-firms-warned-of-recent-it-threats/</link>
		<comments>http://resource.onlinetech.com/seek-and-destroy-u-s-energy-firms-warned-of-recent-it-threats/#comments</comments>
		<pubDate>Mon, 13 May 2013 19:04:16 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[daily log review]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[federal cybersecurity]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[technical security]]></category>
		<category><![CDATA[two-factor authentication]]></category>
		<category><![CDATA[web application firewalls]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11305</guid>
		<description><![CDATA[<p>Last Thursday, the U.S. government released a warning about the increasing risk of cyber attacks targeting critical energy corporations; seeking to destroy or manipulate industrial machinery in attempts to seize control of networks that deliver energy or run industrial processes, &#8230; <a href="http://resource.onlinetech.com/seek-and-destroy-u-s-energy-firms-warned-of-recent-it-threats/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/seek-and-destroy-u-s-energy-firms-warned-of-recent-it-threats/">Seek and Destroy: U.S. Energy Firms Warned of Recent IT Threats</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Last Thursday, the U.S. government released a warning about the increasing risk of cyber attacks targeting critical energy corporations; seeking to destroy or manipulate industrial machinery in attempts to seize control of networks that deliver energy or run industrial processes, according to NYTimes.com and Washington Post.</p>
<p dir="ltr">According to the Washington Post, the unclassified alert was issued by the Depart. of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team or ICS-CERT, and released on a computer network accessible only to authorized industry and government users (hence why you won’t find a link to the report here).</p>
<p dir="ltr">NYTimes.com reports a key distinction in the latest warnings about the potential new attacks as attempts to destroy, rather than just obtain or steal information from U.S. companies. While the majority of previous attacks have been motivated by gaining competitive advantages by stealing trade secrets, the newest threats appear to be motivated by the intention to shut down industrial machinery and energy delivery.</p>
<p dir="ltr">The article also reports that senior officials briefed on the latest attacks claimed they targeted the administrative systems of 10 major unnamed U.S. energy companies. Another U.S. official reports the warning was released after intrusion to a corporate system that deals with chemical processes. The Washington Post also reports that foreign adversaries have been probing the computer systems that operate chemical, electric and water plants.</p>
<p dir="ltr">In February, an executive order was issued to direct federal agencies to provide timely information about threats to cybersecurity to the industry to enable proactive measures to protect their company and consumers, as well as critical infrastructure. The latest warning points out that the most likely targets, such as phone networks and electric utility grids are privately owned entities and not federally-run.</p>
<p dir="ltr">What is currently going on with federal cybersecurity? NYTimes Tech Blog, Bits, reports that the Dept. of Homeland Security has recently lost four top cybersecurity officials as they departed from office in the last four months &#8211; including Richard Spires, the former CIO of DHS, who did not provide a reason for resignation after being on administrative leave since March 15, according to the Washington Business Journal. The agency reports needing to expand its workforce by as many as 600, citing a need to employ a large number of skilled hackers to keep up with developing threats.</p>
<p dir="ltr">Back in last November, I wrote an article, <em><a href="http://resource.onlinetech.com/another-dead-end-for-u-s-cybersecurity/">Another Dead End for U.S. Cybersecurity?</a></em> on the struggles of passing a cybersecurity bill in Senate that would set standards for companies that operate critical U.S. infrastructure, including power grids and chemical plants. While the executive order recently administered may supersede the twice-stalled and once-revised bill, significant time (potential R&amp;D time) has been lost in thwarting bipartisan attempts in national cybersecurity.</p>
<p dir="ltr">NYTimes.com reports that there are no clear technical security standards outlined in the warning from last week other than to adhere to best practices that “many computer professionals already advise.” So, why not read up about our <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical security services</a> and also industry best practices, from <a href="http://www.onlinetech.com/secure-hosting/technical-security/daily-log-review">daily log review</a> to <a href="http://www.onlinetech.com/secure-hosting/technical-security/two-factor-authentication">two-factor authentication</a> for VPN (Virtual Private Network) to <a href="http://www.onlinetech.com/secure-hosting/technical-security/web-application-firewall-waf">web application firewalls (WAFs)</a>.</p>
<p dir="ltr">Encrypting data, whether at rest or in transit, is another best practice that can enhance data privacy while meeting federal and industry data security compliance standards. Join our upcoming <em><a href="http://www.onlinetech.com/events/encryption-perspective-on-privacy-security-a-compliance">Encryption &#8211; Perspective on Privacy, Security &amp; Compliance</a></em> webinar on June 11 and submit your security questions in advance for a chance to discuss encryption with security professional Chris Heuman, Practice Leader for RISC Management and Consulting.</p>
<p>Finally, a comprehensive business continuity and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> plan can help protect your business against any type of business interruption, including the threat of potential cyber attacks. Prepare for the unexpected with these disaster recovery resources:<br />
<em><a href="http://resource.onlinetech.com/disaster-recovery/">Business Continuity and Disaster Recovery</a></em><br />
<em> <a href="http://resource.onlinetech.com/five-questions-to-ask-your-disaster-recovery-provider/">Seeking a Disaster Recovery Solution? Five Questions to Ask Your DR Provider</a></em><br />
<em> <a href="http://resource.onlinetech.com/state-of-michigan-michigan-businesses-firm-up-it-security-with-disaster-recovery-plan/">State of Michigan &amp; Michigan Businesses Firm Up IT Security with Disaster Recovery Plan</a></em></p>
<p>References:<br />
<a href="http://www.nytimes.com/2013/05/13/us/cyberattacks-on-rise-against-us-corporations.html?pagewanted=1&amp;_r=0&amp;ref=todayspaper">Cyberattacks Against U.S. Corporations Are on the Rise</a><br />
<a href="http://bits.blogs.nytimes.com/2013/05/13/tough-times-at-homeland-security/">Tough Times at Homeland Security</a><br />
<a href="http://www.washingtonpost.com/world/national-security/us-warns-industry-of-heightened-risk-of-cyberattack/2013/05/09/39a04852-b8df-11e2-aa9e-a02b765ff0ea_story.html">U.S. Warns Industry of Heightened Risk of Cyberattack</a><br />
<a href="http://www.bizjournals.com/washington/blog/fedbiz_daily/2013/05/richard-spires-resigns-as-dhs-cio.html">Richard Spires Resigns as DHS CIO After Taking Administrative Leave</a></p>
<p>The post <a href="http://resource.onlinetech.com/seek-and-destroy-u-s-energy-firms-warned-of-recent-it-threats/">Seek and Destroy: U.S. Energy Firms Warned of Recent IT Threats</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/seek-and-destroy-u-s-energy-firms-warned-of-recent-it-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming Webinar: Encryption &#8211; Perspective on Privacy, Security &amp; Compliance</title>
		<link>http://resource.onlinetech.com/upcoming-webinar-encryption-perspective-on-privacy-security-compliance/</link>
		<comments>http://resource.onlinetech.com/upcoming-webinar-encryption-perspective-on-privacy-security-compliance/#comments</comments>
		<pubDate>Mon, 13 May 2013 13:47:02 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[data encryption]]></category>
		<category><![CDATA[encrypting data for hipaa]]></category>
		<category><![CDATA[encryption webinar]]></category>
		<category><![CDATA[healthcare encryption]]></category>
		<category><![CDATA[pci dss encryption]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11286</guid>
		<description><![CDATA[<p>Join Chris Heuman, Practice Leader for RISC Management and Consulting, and Online Tech for an informative webinar on the value of encryption for HIPAA, PCI and many other regulatory frameworks and the successful components of a data security program that &#8230; <a href="http://resource.onlinetech.com/upcoming-webinar-encryption-perspective-on-privacy-security-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/upcoming-webinar-encryption-perspective-on-privacy-security-compliance/">Upcoming Webinar: Encryption &#8211; Perspective on Privacy, Security &#038; Compliance</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Join Chris Heuman, Practice Leader for RISC Management and Consulting, and Online Tech for an informative webinar on the value of encryption for <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a>, <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI</a> and many other regulatory frameworks and the successful components of a data security program that integrates encryption.</p>
<p><strong>Title</strong>: <em>Encryption &#8211; Perspective on Privacy, Security, &amp; Compliance</em><br />
<strong>Register</strong>: <a href="http://www.onlinetech.com/events/encryption-perspective-on-privacy-security-a-compliance">GotoMeeting via Online Tech</a><br />
<strong>When</strong>: Tuesday, June 11, 2013 from 2-3PM ET<br />
<strong>Description</strong>: HIPAA, HITECH, the Omnibus Rule, PCI-DSS, and many other regulations and frameworks speak to the importance or requirement of encryption. Adequate encryption of regulated and sensitive data can help your organization meet or exceed the privacy and information security regulatory requirements you face, if it is implemented correctly.</p>
<p>Join Chris Heuman, Practice Leader for RISC Management and Consulting, for an informative webinar on the value of encryption and the successful components of a data security program that integrates encryption. Chris Heuman will discuss the legal safe harbors for suitably encrypted data, typical encryption methodologies, how to document your choices and implementation, and how to demonstrate a successful program to an auditor.</p>
<p><a href="http://www.onlinetech.com/events/upcoming-events">View other upcoming events!</a></p>
<hr />
<p><em><strong><img class="alignleft" title="Chris Heuman" src="http://www.onlinetech.com/images/stories/misc/chris_heuman.png" alt="Chris Heuman" width="94" height="136" />Christopher Heuman CHP, CHSS, CSCS, CISSP &#8211; Practice Leader, RISC Management &amp; Consulting </strong></em></p>
<p>Prior to consulting, Chris Heuman  worked in healthcare organizations in an information systems and data security capacity for over 20 years. Chris held increasingly responsible positions in healthcare IT from systems and network administration to project management, infrastructure management and information security. Prior to founding RISC Management, Chris developed consulting programs focused on information security and compliance specifically for healthcare institutions as a Director of Engineering Services at mCurve, and Practice Leader for Compliance and Security at ecfirst. Through his practical experience and certifications as a Certified HIPAA Professional (CHP), Certified Security Compliance Specialist (CSCS) and Certified Information Systems Security Professional (CISSP), Chris is uniquely experienced to assist healthcare organizations in understanding and meeting the myriad compliance and security regulations and requirements they face.</p>
<p>As the Practice Leader at RISC Management, Chris helps healthcare providers and healthcare technology organizations by providing services in the areas of risk analysis, vulnerability assessment, business continuity management and planning, business impact analysis, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> planning, social engineering tests, data loss prevention, education and training, project management and consensus building at all organizational levels. In addition, Chris has presented training programs in the HIPAA, HITECH, compliance and security space, and has been a featured presenter for statewide healthcare organizations, for Health Information Exchanges, as a guest speaker for MBA programs, and has delivered tailored training to dozens of healthcare-related organizations and accreditation bodies.</p>
<p>For more information, Chris can be contacted at <a href="mailto:Chris.Heuman@RISCsecurity.com">Chris.Heuman@RISCsecurity.com</a> or through www.RISCsecurity.com.</p>
<hr />
<p>More About Encryption:</p>
<p><strong><em><a href="http://resource.onlinetech.com/federal-health-it-budget-increases-by-28-percent-encryption-mobile-security-ehr-safety/">Federal Health IT Budget Increases by 28 Percent: Encryption, Mobile Security &amp; EHR Safety</a></em></strong><br />
The proposed federal fiscal 2014 budget calls for a 28 percent increase to support further development of health IT initiatives while taking over where HITECH funding stops (ending in fiscal year 2013). The Office for Civil Rights’ (ONC) funding will … <a href="http://resource.onlinetech.com/federal-health-it-budget-increases-by-28-percent-encryption-mobile-security-ehr-safety/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">2013 State of HIPAA Encryption &amp; Authentication for Healthcare</a></strong></em><br />
According to the Healthcare Information Security Today report, 2013 Outlook: Survey Offers Update on Safeguarding Patient Information, most healthcare organizations believe that encryption would greatly improve their data security. Forty-one percent plan to encrypt all mobile devices and removable media, … <a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a></strong></em><br />
To address the question of whether or not to use data encryption when it comes to meeting HIPAA compliance and keeping patient health information (PHI) protected, let’s revisit the Health Insurance Portability and Accountability Act of 1996 (HIPAA): … <a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/upcoming-webinar-encryption-perspective-on-privacy-security-compliance/">Upcoming Webinar: Encryption &#8211; Perspective on Privacy, Security &#038; Compliance</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/upcoming-webinar-encryption-perspective-on-privacy-security-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Guidance for Mobile Security Webinar: “Welcome to the Wild, Wild West of Security”</title>
		<link>http://resource.onlinetech.com/pci-dss-guidance-for-mobile-security-webinar-welcome-to-the-wild-wild-west-of-security/</link>
		<comments>http://resource.onlinetech.com/pci-dss-guidance-for-mobile-security-webinar-welcome-to-the-wild-wild-west-of-security/#comments</comments>
		<pubDate>Fri, 10 May 2013 16:09:28 +0000</pubDate>
		<dc:creator>Marla Sokolowski</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci mobile]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11275</guid>
		<description><![CDATA[<p>“Welcome to the Wild, Wild West of security.” That’s how guest host Adam Goslin opened the latest in Online Tech’s “Tuesday at 2” webinar series, PCI DSS Guidance for Mobile Security. The COO of High Bit Security lent his expertise &#8230; <a href="http://resource.onlinetech.com/pci-dss-guidance-for-mobile-security-webinar-welcome-to-the-wild-wild-west-of-security/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/pci-dss-guidance-for-mobile-security-webinar-welcome-to-the-wild-wild-west-of-security/">PCI DSS Guidance for Mobile Security Webinar: “Welcome to the Wild, Wild West of Security”</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>“Welcome to the Wild, Wild West of security.”</p>
<p>That’s how guest host Adam Goslin opened the latest in Online Tech’s <a href="http://www.onlinetech.com/events/webinars">“Tuesday at 2” webinar series</a>, <em><a href="http://www.onlinetech.com/events/pci-dss-guidance-for-mobile-security">PCI DSS Guidance for Mobile Security</a></em>.</p>
<p>The COO of High Bit Security lent his expertise to an hour-long presentation on PCI mobile payment guidelines as they relate to PCI DSS (Payment Card Industry Data Security Standards) and PA DSS (Payment Application Data Security Standards) compliance.</p>
<p>“The mobile arena is one that has been exploding over the last couple years and is sure to provide non-stop challenges to those organizations that are interested in making available mobile payment applications to support or supplement their existing communication with their customers,” Goslin said.</p>
<p>Data security for mobile payments continues to evolve while transactions are anticipated to hit the $1.3 trillion mark by 2015. In February 2013, the PCI Security Standards Council (SSC) released a document covering security guidelines for merchants accepting mobile payments to protect credit card information.</p>
<p>In the webinar, Goslin reviews – for merchants and developers – the highlights and pitfalls contained within that supplement, designed to educate merchants on the factors and risks of using mobile devices, along with other challenges related to PCI compliant mobile payment processing.</p>
<p>Goslin breaks down the documentation scenarios that the PCI guidelines cover and defines the security risks of the mobile platform in general and to the payment transaction process specifically. He also dives into merchants’ responsibility as it relates to the security of mobile devices used for transactions.</p>
<p>In a section of the webinar discussing the implementation of a secure payment solution, Goslin says, “you want to make sure you’ve done everything in your power to make that solution as secure as possible,” and discusses each step in that process.</p>
<p>Goslin also covers tips to merchants for selecting the right payment-acceptance solution.</p>
<p>To watch a full replay of the webinar, <a href="http://onlinetech.com/events/pci-dss-guidance-for-mobile-security">click here</a>.</p>
<p><img class="alignleft" title="PCI Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-pci.png" alt="PCI Compliant Hosting White Paper" width="251" height="114" /></p>
<p>Looking for more information on <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting </a>requirements, recommendations, and the foundation of a secure <a href="http://resource.onlinetech.com/franchise-point-of-sale-pos-systems-targeted-in-nationwide-pci-data-breach/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a>?</p>
<p><a href="http://resource.onlinetech.com/franchise-point-of-sale-pos-systems-targeted-in-nationwide-pci-data-breach/resources/white-papers/pci-compliant-data-centers">Download our PCI Compliant Hosting white paper</a> now for a complete guide to PCI hosting with IT vendors.</p>
<p>Related Articles:<br />
<em><strong><a href="http://resource.onlinetech.com/customer-privacy-in-cloud-computing-contracts-key-for-pci-compliance/">Customer Privacy in Cloud Computing Contracts Key for PCI Compliance</a></strong></em><br />
On January 31, the Payment Card Industry Security Standards Council issued its new set of card data security guidelines for merchants and payment providers. The supplemental document addresses increasing risks to e-commerce environments and how online businesses should work with … <a href="http://resource.onlinetech.com/customer-privacy-in-cloud-computing-contracts-key-for-pci-compliance/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/pci-compliance-supplement-gives-tips-for-merchants/">PCI Compliance Supplement Gives Tips For Merchants</a></strong></em><br />
Last month the Payment Card Industry Security Standards Council (PCI SSC) released their Information Supplement: PCI DSS E-Commerce Guidelines. These guidelines were focused on e-commerce merchants, and how to keep compliant whether outsourcing payment processing, keeping it in-house, or creating … <a href="http://resource.onlinetech.com/pci-compliance-supplement-gives-tips-for-merchants/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/pci-compliant-requirements-pci-compliant-services-matrix/">PCI Compliant Requirements &amp; PCI Compliant Services Matrix</a></strong></em><br />
The PCI DSS (Payment Card Industry Data Security Standards) require the use of certain technical security services. Below is a matrix of the requirements paired with actual PCI compliant services that fulfill them. Click on each PCI compliant service to … <a href="http://resource.onlinetech.com/pci-compliant-requirements-pci-compliant-services-matrix/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/pci-dss-guidance-for-mobile-security-webinar-welcome-to-the-wild-wild-west-of-security/">PCI DSS Guidance for Mobile Security Webinar: “Welcome to the Wild, Wild West of Security”</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-dss-guidance-for-mobile-security-webinar-welcome-to-the-wild-wild-west-of-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Indiana HIMSS Spring Conference: Health Reform and Future of Public Health</title>
		<link>http://resource.onlinetech.com/indiana-himss-spring-conference-health-reform-and-future-of-public-health/</link>
		<comments>http://resource.onlinetech.com/indiana-himss-spring-conference-health-reform-and-future-of-public-health/#comments</comments>
		<pubDate>Thu, 09 May 2013 14:03:53 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[health reform]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[indiana himss]]></category>
		<category><![CDATA[public health]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11264</guid>
		<description><![CDATA[<p>Online Tech exhibited HIPAA hosting solutions at booth #9 at the Indiana HIMSS Spring Conference hosted in Carmel, Indiana. The conference theme centered around Innovation in HIT (Health Information Technology). Impact of Health Reform Seema Verma, SVC Consulting, Indiana Health &#8230; <a href="http://resource.onlinetech.com/indiana-himss-spring-conference-health-reform-and-future-of-public-health/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/indiana-himss-spring-conference-health-reform-and-future-of-public-health/">Indiana HIMSS Spring Conference: Health Reform and Future of Public Health</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech exhibited <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana HIMSS Spring Conference hosted in Carmel, Indiana. The conferenc<strong></strong>e theme centered around Innovation in HIT (Health Information Technology).</p>
<p><strong>Impact of Health Reform</strong><br />
<em>Seema Verma, SVC Consulting, Indiana Health Reform Lead Affordable Care Act: Impact on the Indiana Market</em></p>
<p>Seema covered several areas of penalties coming out of the ACA, including both the individual and employer mandate. The penalty for the individual mandate is low to begin with and going up over time, with there being some exemptions from the mandate such as religion.</p>
<p>The employer mandate will really affect those with more than 50 full-time equivalent employees. Employers could be subject to penalties if full-time employees receive premium tax credit. Employers will be very cautious about not expanding beyond 50 employees, causing potential issues in the business world.</p>
<p><strong>What does the market look like in 2019?</strong><br />
There could be a huge rise in public programs, specifically with the Medicaid expansion. More and more employers will be dropping insurance programs and we will see a rise in individual insurance plans.</p>
<p>There will be several upcoming changes to the insurance market, some of which will limit insurance companies profits and also the increase in health insurance premiums.</p>
<p>With a community rating premiums will be based on age, location, and smoking status, no pre-existing condition exclusion allowed. Those that are healthier will be faced with higher rates, while lose who are less healthy will face lower premium rates.</p>
<p>Seema discussed several key facets surrounding the upcoming healthcare exchanges next year. One of the early concerns with the exchanges was that the ACA mandates that each states&#8217; exchange offer at least 2 multi-state plans.</p>
<p>She noted in her slides that the key challenges for exchanges will include:</p>
<ul>
<li>Federal government running the majority of exchanges</li>
<li>Exchanges begin enrollments starting October this year</li>
<li>Defined open enrollment periods</li>
<li>Interfaces between states and exchange yet to be established or tested</li>
<li>Will they lower costs?</li>
<li>How will insurers participate?</li>
</ul>
<p>The biggest “Crystal Ball Prediction?”:<br />
It will take several years to fully understand the impact of the ACA.</p>
<hr />
<p><strong>Future of Public Health in Indiana</strong><br />
<em>Dr. William VanNess, State Health Commissioner</em></p>
<p>Core Values and practices for Indiana State Department of Health (ISDH) include:</p>
<ul>
<li>Health promotion and prevention</li>
<li>Vaccines-providing for those who cant’ afford</li>
<li>Equitable care throughout community health centers</li>
<li>Vital records</li>
<li>Health protection. ISDH is going to great lengths to make sure that water, indoor air and food are all clean</li>
<li>Collaboration with local health departments</li>
<li>Data collection, analysis and information dissemination</li>
</ul>
<p>Governor Pence told the ISDH to read Good to Great by Jim Collins and check to see that they were on the right track for the next five years. Dr. VanNess set out to find what still works and what needs to change. His team got together, went through the book and found several areas they wanted to focus on in the state of Indiana.</p>
<p>Infant mortality was one of the biggest concerns that jumped out to Dr.VanNess. He delved in and looked at what was causing such a high infant mortality rate and found several factors that led to it and set about to correct. He visited several counties comparing numbers and found that an Amish county had less than a 2% infant mortality rate.</p>
<p>Creating a healthy Indiana overall was another goal that came out of the five year plan and to do so, it really comes down to lifestyle choices. Obesity and smoking are huge health concerns within the state, and again, it came down to lifestyle choices and setting out to educate patients in order to change that.</p>
<p>A final piece included in their five year plan was the immunization rate of 19-35 month olds. With the implementation of CHIRP, hospitals and physician efforts to meet a requirement in Stage 1 of meaningful use will be aided.</p>
<p><strong>Future of Public Health in Indiana:</strong><br />
We still don’t know everything that the Affordable Care Act is going to bring. There are roughly 2,000 blanks that still need to be filled in with ACA.</p>
<p><strong>About Indiana HIMSS</strong><br />
The Indiana Chapter of HIMSS is one of over forty affiliated chapters of the Healthcare Information and Management Systems Society, the largest health care information systems professional organization in the nation. Our purpose is to bring health care professionals together to promote the exchange of experiences and knowledge among colleagues, and to assist members in their professional growth. We accomplish this objective by presenting educational seminars/conferences, networking opportunities, and a forum for the exchange of ideas among those committed to the goal of improving patient care through the effective use of information technology.</p>
<p>Chapter members come from diverse backgrounds, all involved in some aspect of health care information systems and management. Our members consist of professionals from hospitals and clinical organizations, third-party payors, administrators, information technology vendors, consultants, management engineers, telecommunications professionals, physicians, nurses and medical informatics professionals – essentially anyone interested in the trends of health care information and management systems.</p>
<p>The post <a href="http://resource.onlinetech.com/indiana-himss-spring-conference-health-reform-and-future-of-public-health/">Indiana HIMSS Spring Conference: Health Reform and Future of Public Health</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/indiana-himss-spring-conference-health-reform-and-future-of-public-health/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Indiana HIMSS Spring Conference: Innovations in HIT (Health Information Technology)</title>
		<link>http://resource.onlinetech.com/indiana-himss-spring-conference-innovations-in-hit-health-information-technology/</link>
		<comments>http://resource.onlinetech.com/indiana-himss-spring-conference-innovations-in-hit-health-information-technology/#comments</comments>
		<pubDate>Wed, 08 May 2013 14:56:39 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[health information technology]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIT]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11254</guid>
		<description><![CDATA[<p>Online Tech exhibited HIPAA hosting solutions at booth #9 at the Indiana HIMSS Spring Conference hosted in Carmel, Indiana yesterday. The conference theme centered around Innovation in HIT (Health Information Technology). Keynote Address: Troy Trygstad, PharmD, MBA, PhD Vice President, &#8230; <a href="http://resource.onlinetech.com/indiana-himss-spring-conference-innovations-in-hit-health-information-technology/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/indiana-himss-spring-conference-innovations-in-hit-health-information-technology/">Indiana HIMSS Spring Conference: Innovations in HIT (Health Information Technology)</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech exhibited <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana HIMSS Spring Conference hosted in Carmel, Indiana yesterday. The conferenc<strong></strong>e theme centered around Innovation in HIT (Health Information Technology).</p>
<p>Keynote Address:<br />
Troy Trygstad, PharmD, MBA, PhD<br />
Vice President, Pharmacy Programs<br />
Community Care of North Carolina<br />
Medication Management Innovations</p>
<p>Troy is still a part time pharmacist in North Carolina. He thinks there is great opportunity to improve the health trajectory where patients go about their daily lives.</p>
<p>Putting the Affordable Care Act aside altogether, the following are health systems trends and trends of health reform that are occurring and needed to occur anyways:</p>
<ul>
<li>Reduced cost shifting and increased sharing</li>
<li>Increased focus on prevention</li>
<li>Increased accountability</li>
<li>Increased cross-setting, and inter-entity collaboration</li>
<li>Increased capture, exchange and application of data</li>
</ul>
<p>So what is the result of all this? There is a rise in questions such: what are we doing for patients when they aren’t in the four walls of my hospital or office? There is a huge shift in how patients not interact with the healthcare system and how they want to receive their health information.</p>
<p>He noted that healthcare is very likely the next fiscal cliff pointing towards inadequate, misaligned, or non-existent payment systems for pharmaceutical care. Higher healthcare spending is not necessarily associated with better quality. Troy went on to discuss payment systems in the healthcare and what we can expect to see in the future in regards to the various payment systems.</p>
<p>Troy through a trivia question out to the audience and asked if anyone knew the significance of the following date:</p>
<p>April 12, 1955</p>
<p>Several people jumped on their Smartphone’s and one brave soul responded that it was the day the polio vaccine was announced.</p>
<p>Troy was proving the point that information is right at our fingertips. The Internet has become our extended care team. It is where people go when they need health care information and non-healthcare information. Consumers are going to want instant access to their health information. Just send me a text when the results are ready would you?</p>
<p>Health Information Technology Trends that are occurring:</p>
<ul>
<li>EMR/HIS gold rush starting to easy up &#8211; The focus is now on leveraging data and value added and plug-in products</li>
<li>Vertical and horizontal integration of PHI</li>
<li>Big Data &#8211; Population health and quality measure are driving priorities; refocusing of positive predicative value; and logistics</li>
<li>Patient empowerment is starting to emerge more and more in regards to personal health records, records portability, virtual care, devices, pricing transparency and new settings of care</li>
</ul>
<p><strong>About Indiana HIMSS</strong><br />
The Indiana Chapter of HIMSS is one of over forty affiliated chapters of the Healthcare Information and Management Systems Society, the largest health care information systems professional organization in the nation. Our purpose is to bring health care professionals together to promote the exchange of experiences and knowledge among colleagues, and to assist members in their professional growth. We accomplish this objective by presenting educational seminars/conferences, networking opportunities, and a forum for the exchange of ideas among those committed to the goal of improving patient care through the effective use of information technology.</p>
<p>Chapter members come from diverse backgrounds, all involved in some aspect of health care information systems and management. Our members consist of professionals from hospitals and clinical organizations, third-party payors, administrators, information technology vendors, consultants, management engineers, telecommunications professionals, physicians, nurses and medical informatics professionals – essentially anyone interested in the trends of health care information and management systems.</p>
<p>The post <a href="http://resource.onlinetech.com/indiana-himss-spring-conference-innovations-in-hit-health-information-technology/">Indiana HIMSS Spring Conference: Innovations in HIT (Health Information Technology)</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/indiana-himss-spring-conference-innovations-in-hit-health-information-technology/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tackling Healthcare CIO Challenges: Securing Infrastructure, IT Expertise and Costs</title>
		<link>http://resource.onlinetech.com/benefits-of-hipaa-hosting-for-healthcare-cios-fixed-costs-it-expertise-and-secure-it-systems/</link>
		<comments>http://resource.onlinetech.com/benefits-of-hipaa-hosting-for-healthcare-cios-fixed-costs-it-expertise-and-secure-it-systems/#comments</comments>
		<pubDate>Wed, 08 May 2013 13:41:23 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[healthcare CIO]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11226</guid>
		<description><![CDATA[<p>Nearly one in five healthcare CIOs have had a security breach within the past 12 months, according to statistics compiled by McKesson in Understanding Your CIO. Their top infrastructure IT focus is on systems that secure personal health information (22 &#8230; <a href="http://resource.onlinetech.com/benefits-of-hipaa-hosting-for-healthcare-cios-fixed-costs-it-expertise-and-secure-it-systems/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/benefits-of-hipaa-hosting-for-healthcare-cios-fixed-costs-it-expertise-and-secure-it-systems/">Tackling Healthcare CIO Challenges: Securing Infrastructure, IT Expertise and Costs</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-1fc9bc43-7fa0-9984-7899-25b6463b376e" dir="ltr"><img class="alignleft" title="HIPAA Compliant Hosting" src="http://www.onlinetech.com/images/homeshouts/home-hipaa-icon.png" alt="HIPAA Compliant Hosting" width="50" height="60" />Nearly one in five healthcare CIOs have had a security breach within the past 12 months, according to statistics compiled by McKesson in <em>Understanding Your CIO</em>. Their top infrastructure IT focus is on systems that secure personal health information (22 percent), followed by servers/virtual servers (18 percent) and a focus on mobile devices (16 percent).</p>
<p dir="ltr">CIOs consider the lack of staffing resources as the most significant barrier to implementing IT systems, and more than 50 percent say they expect an increase in IT staff within the next 12 months. However, more than six out of 10 say they’re concerned about their organization’s skills and ability to capitalize on their technology investments.</p>
<p dir="ltr">The lack of financial support is a secondary barrier to successfully implementing IT.</p>
<p dir="ltr">People are an important part of the IT puzzle &#8211; finding the particular expertise needed to run secure systems housing protected health information (PHI) takes time and resources. Partnering with a hosting provider that can provide their HIPAA audit report on compliance verifying they conduct regular <a href="http://www.onlinetech.com/secure-hosting/administrative-security/business-associate-training">business associate training</a> of their tech staff satisfies a few healthcare CIO concerns:</p>
<ol>
<li>CIOs don’t need to worry about hiring as many in-house IT personnel to manage their servers if they use the managed services/support of a hosting company.</li>
<li>It’s more cost-effective to have a fixed rate for infrastructure and management rather than dealing with fluctuating and unpredictable costs to manage in-house IT (read <a href="http://www.onlinetech.com/resources/e-tips/michigan-colocation/leasing-vs-building-a-data-center">Leasing vs. Building a Data Center</a>).</li>
<li>If your hosting provider has already undergone an independent HIPAA audit, you don’t have to pay your auditors to conduct one.</li>
<li>With a <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting provider</a>, you know they’ve put in the work needed to meet compliance, including investing in their <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> and hosting solution security.</li>
</ol>
<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignleft" title="HIPAA Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-hipaa.png" alt="HIPAA Compliant Hosting White Paper" width="252" height="114" /></a>For a complete guide to HIPAA <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical</a>, <a href="http://www.onlinetech.com/secure-hosting/administrative-security">administrative</a> and <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical security</a>, read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Hosting white paper</a>. This white paper explores the impact of HITECH and HIPAA on data centers. It includes a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> outsourcing, and vendor selection criteria.</p>
<p>You might also like:<br />
<em><strong><a href="http://resource.onlinetech.com/healthcare-data-breach-means-prison-time-class-action-lawsuit/">Healthcare Data Breach Leads to Prison Time; Class Action Lawsuit</a></strong></em><br />
For two years, a former emergency department worker of Florida Hospital Celebration gained unauthorized access to more than 763,000 electronic patient health records and sold 12,000 of them to a co-conspirator (and operator of two chiropractic centers) to solicit patients … <a href="http://resource.onlinetech.com/healthcare-data-breach-means-prison-time-class-action-lawsuit/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/how-to-ensure-business-associates-are-hipaa-compliant/">Ensuring Business Associate Compliance: Are You Doing Your Due Diligence?</a></strong></em><br />
Business associates should be required to provide some type of evidence or proof of compliance to their covered entities. – Healthcare Information Security Today: 2013 Outlook Survey This quote comes from a study that reports only 32 percent of survey … <a href="http://resource.onlinetech.com/how-to-ensure-business-associates-are-hipaa-compliant/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/overcoming-healthcare-cio-challenges-with-secure-scalable-hipaa-hosting/">Overcoming Healthcare CIO Challenges with Secure &amp; Scalable HIPAA Hosting</a></strong></em><br />
McKesson’s Understanding Your CIO article catalogues a list of statistics derived from surveys, polls and interviews of healthcare CIOs. It’s a very informative snapshot of the position’s latest responsibilities and concerns as the healthcare IT landscape rapidly evolves due to … <a href="http://resource.onlinetech.com/overcoming-healthcare-cio-challenges-with-secure-scalable-hipaa-hosting/">Continue reading →</a></p>
<p>References:<br />
<a href="http://betterhealth.mckesson.com/2013/04/understanding-your-cio/">Understanding Your CIO</a><br />
<a href="http://himss.files.cms-plus.com/HIMSSorg/Content/files/leadership_FINAL_REPORT_022813.pdf">2013 HIMSS Leadership Survey</a></p>
<p>The post <a href="http://resource.onlinetech.com/benefits-of-hipaa-hosting-for-healthcare-cios-fixed-costs-it-expertise-and-secure-it-systems/">Tackling Healthcare CIO Challenges: Securing Infrastructure, IT Expertise and Costs</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/benefits-of-hipaa-hosting-for-healthcare-cios-fixed-costs-it-expertise-and-secure-it-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Celebrate Corporate Compliance and Ethics Week!</title>
		<link>http://resource.onlinetech.com/celebrate-corporate-compliance-and-ethics-week/</link>
		<comments>http://resource.onlinetech.com/celebrate-corporate-compliance-and-ethics-week/#comments</comments>
		<pubDate>Tue, 07 May 2013 17:27:54 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[compliance week]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11232</guid>
		<description><![CDATA[<p>Everybody put your party hats on, it’s time to celebrate! May 5-11 is Corporate Compliance and Ethics week, which means it’s the perfect time for taking stock of your business and finding some great ways to make compliance a culture &#8230; <a href="http://resource.onlinetech.com/celebrate-corporate-compliance-and-ethics-week/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/celebrate-corporate-compliance-and-ethics-week/">Celebrate Corporate Compliance and Ethics Week!</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Corporate Compliance and Ethics Week" src="http://www.hcca-info.org/portals/0/Images/Webpage_Images/Products/2013CandElogo.gif" alt="Corporate Compliance and Ethics Week" width="200" height="200" />Everybody put your party hats on, it’s time to celebrate! May 5-11 is <strong>Corporate Compliance and Ethics week</strong>, which means it’s the perfect time for taking stock of your business and finding some great ways to make compliance a culture you and your staff can celebrate year-round.</p>
<p dir="ltr">Online Tech is doing our part to celebrate Compliance Week by spending some time with our friends down in the Indy-city for the Indiana HIMSS spring conference today. With the focus of today’s conference being innovation, compliance week couldn’t have come at a better time.</p>
<p dir="ltr">Health IT, with hot topics like BYOD and mobile health are paving the way for different ways for patients and physicians to think about healthcare responsibility and management, which brings compliance struggles into the limelight. Couple that with the Health and Human Services (HHS) decision to hold Business Associates (BA) responsible for their spoke in the <a href="http://onlinetech.com/compliant-hosting/hipaa-compliant-hosting/resources/100-hipaa-compliant">HIPAA compliance</a> wheel, and all eyes should be on the compliance guidelines.</p>
<p dir="ltr">With all the importance put on having each company and their BAs compliant, it’s hard to hear that <a href="http://resource.onlinetech.com/how-to-ensure-business-associates-are-hipaa-compliant/">68% of healthcare directors and IT managers who responded to the Healthcare Information Security Today 2013 Outlook Survey</a> aren’t confident in the security measures controlled by their BAs. Here are a few tips that could help lower that statistic:</p>
<p><strong>Get The Audit Report</strong><br />
This is step one when you’re shopping around for a <a href="http://onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a> provider. Any prospective provider should have been independently audited and will have a report to share with you. Do your due diligence and check that report. While it isn’t going to guarantee your total compliance, you need to know your patient’s data is being secured, even if you aren’t there to secure it.<br />
<strong></strong></p>
<p><strong>Get a BAA Signed</strong><br />
This isn’t negotiable. Hosting providers for healthcare companies are considered Business Associates, and as such need to sign a Business Associate Agreement (BAA) with you, clearly stating what duties they’ll be performing, and what <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical</a>, <a href="http://www.onlinetech.com/secure-hosting/administrative-security">administrative</a>, and <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical</a> safeguards they have in place for your PHI. Word from the wise:</p>
<blockquote>
<p dir="ltr">If you use a cloud service, it should be your business associate. If they refuse to sign a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#Business%20Associate%20Agreement">business associate agreement</a>, don’t use the cloud service. –<em> David S. Holtzman of the Health Information Privacy Division of OCR during a speech at the Health Care Compliance Association’s 16th Annual Compliance Institute.</em></p>
</blockquote>
<p dir="ltr">That should be true of any hosting solution and provider you consider working with.</p>
<p dir="ltr">So celebrate getting compliant along with us and the Society of Corporate Compliance and Ethics. Read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA white paper</a>. Check out our <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/resources">HIPAA hosting resources</a>. Most importantly, let us know what you’re doing to keep compliant throughout the year!</p>
<p>Resources:<br />
<a href="http://www.corporatecompliance.org/products/allproducts/corporatecomplianceweekproducts.aspx">Society of Corporate Compliance and Ethics</a><br />
<a href="http://www.indianahimss.org">www.indianahimss.org</a><br />
<a href="https://s3.amazonaws.com/public-inspection.federalregister.gov/2013-01073.pdf">HHS: Modifications to the HIPAA Privacy, Security, Enforcement and Breach Notification Rules (PDF)</a></p>
<p>The post <a href="http://resource.onlinetech.com/celebrate-corporate-compliance-and-ethics-week/">Celebrate Corporate Compliance and Ethics Week!</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/celebrate-corporate-compliance-and-ethics-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Exhibits Secure Hosting the 2013 Midwest Technology Leaders Symposium</title>
		<link>http://resource.onlinetech.com/midwest-technology-leaders/</link>
		<comments>http://resource.onlinetech.com/midwest-technology-leaders/#comments</comments>
		<pubDate>Tue, 07 May 2013 14:16:09 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[michigan IT]]></category>
		<category><![CDATA[michigan technology]]></category>
		<category><![CDATA[midwest technology leaders]]></category>
		<category><![CDATA[secure hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11217</guid>
		<description><![CDATA[<p>Only two weeks until the Midwest Technology Leaders 2013 Symposium, a chance to collaborate with some of the top IT executives in the midwest. It will be held May 21-22 at the Inn at St. John’s in Detroit. Online Tech &#8230; <a href="http://resource.onlinetech.com/midwest-technology-leaders/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/midwest-technology-leaders/">Online Tech Exhibits Secure Hosting the 2013 Midwest Technology Leaders Symposium</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid--ec93fdc-7f56-8ef0-a8a1-bbeb417208ef" dir="ltr">Only two weeks until the <a href="http://www.onlinetech.com/events/online-tech-exhibits-secure-hosting-at-2013-midwest-technology-leaders">Midwest Technology Leaders 2013 Symposium</a>, a chance to collaborate with some of the top IT executives in the midwest. It will be held May 21-22 at the Inn at St. John’s in Detroit.</p>
<p dir="ltr">Online Tech is very proud to have our Director of Operations Jason Yaeger speaking on a CIO panel at the conference. Jason has received the <a href="http://www.onlinetech.com/news/in-the-news/online-tech-wins-2012-crains-detroit-business-cio-of-the-year">2012 Crain’s Business CIO of the Year</a> award, and spoke just two weeks ago at the <a href="http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/">7&#215;24 Exchange Southern California Chapter’s meeting</a>.</p>
<p dir="ltr">We’re also going to be at the Midwest Technology Leaders conference showing off the breadth of our hosting services, ranging from <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> to <a href="http://www.onlinetech.com/colocation/overview">colocation</a>. Need to be <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a>, <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI</a> or <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting">SOX</a> compliant? We can set up a compliant solution no matter what type of service you’re after.</p>
<p dir="ltr">There are also going to be other really great speakers at the event. Here’s just a taste of what you’ll see:</p>
<p dir="ltr"><strong>Dell Keynote &#8211; Adriana Karaboutis, VP &amp; Global CIO, DELL</strong></p>
<p dir="ltr"><em>From the auto industry to the tech industry and everything in between, the transformational CIO no longer focuses only on system performance and efficiency, but on providing an adaptable and flexible environment to create value and enable CEOs to meet their strategic goals. Innovation and agility are the cornerstones of the most successful IT organizations. Hear from Dell VP &amp; CIO Andi Karaboutis about how she transformed her organization to focus more on innovation and agility in order to drive business value.</em></p>
<p dir="ltr"><strong>Reinventing Michigan through IT, David Behen, CIO State of Michigan</strong></p>
<p dir="ltr"><em>Michigan Department of Technology, Management and Budget CIO David Behen will talk about “Reinventing Michigan Through IT.” Behen will discuss the department’s goals and mission, the State’s key IT metrics, IT Investment Fund projects, Michigan’s Cyber Range and Cyber Security.</em></p>
<p dir="ltr">If you’d like more information about the Midwest Technology Leaders symposium, visit their site <a href="http://www.xchange-events.com/mtl13/agenda/">here</a>. While you’re there come say hello to Online Tech  and we can talk to you about your mission critical applications, and how we can keep you up and running.</p>
<p>The post <a href="http://resource.onlinetech.com/midwest-technology-leaders/">Online Tech Exhibits Secure Hosting the 2013 Midwest Technology Leaders Symposium</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/midwest-technology-leaders/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Michigan Data Centers Fuel State IT Industry Job Growth</title>
		<link>http://resource.onlinetech.com/michigan-data-centers-fuel-state-it-industry-job-growth/</link>
		<comments>http://resource.onlinetech.com/michigan-data-centers-fuel-state-it-industry-job-growth/#comments</comments>
		<pubDate>Mon, 06 May 2013 17:34:05 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[indiana jobs]]></category>
		<category><![CDATA[michigan business]]></category>
		<category><![CDATA[michigan cloud computing]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[michigan disaster recovery]]></category>
		<category><![CDATA[michigan IT]]></category>
		<category><![CDATA[michigan jobs]]></category>
		<category><![CDATA[ohio jobs]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11210</guid>
		<description><![CDATA[<p>In March, managed Michigan data center operator Online Tech attended the 2013 Governor’s Economic Summit in Detroit, Michigan to collaborate with other state leaders in order to develop solutions to address the state’s employer talent needs. A few fast facts &#8230; <a href="http://resource.onlinetech.com/michigan-data-centers-fuel-state-it-industry-job-growth/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/michigan-data-centers-fuel-state-it-industry-job-growth/">Michigan Data Centers Fuel State IT Industry Job Growth</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-260f32a7-7ae4-ee18-889f-c05ea27bc77a" dir="ltr">In March, managed <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> operator Online Tech attended the 2013 Governor’s Economic Summit in Detroit, Michigan to collaborate with other state leaders in order to develop solutions to address the state’s employer talent needs.</p>
<p dir="ltr">A few fast facts about the growing IT industry in Michigan:</p>
<ul>
<li dir="ltr">
<p dir="ltr">Despite major job reductions in many Michigan industries as a result of the recent recession, the number of IT firms and jobs expanded from 2005-2009. IT jobs grew at a five percent growth rate over the last two years.</p>
</li>
<li dir="ltr">
<p dir="ltr">The DTMB and Bureau of Labor Market Information and Strategies Initiatives predicts that the IT and media cluster will outpace most Michigan industries in job expansion over the next 10 years.</p>
</li>
<li dir="ltr">
<p dir="ltr">Between 2008-18, IT industry employment is expected to grow by 13.7 percent, over twice as fast as total job expansion in Michigan.</p>
</li>
<li dir="ltr">
<p dir="ltr">Of the entire IT and media cluster industry structure, IT support services account for 79 percent.</p>
</li>
</ul>
<p dir="ltr">With the growing demand for IT workers comes the need for an educated workforce in the region &#8211; many graduates leave the state and contribute to the current workforce’s lack of technical skills. When it comes to measuring the labor supply in the IT industry, approximately 7,000 tech degrees or certificates were granted in Michigan in 2010, increasing 10 percent from the relatively flat from 2006-09. The top career by number of program graduates is Computer Systems Network and Computer and Information Science.</p>
<p dir="ltr">One sector of that IT industry is the managed data center business that is expected to grow by $18.5 billion by 2015 with a range of hosting services, including <a href="http://www.onlinetech.com/colocation/overview">colocation</a>, <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">managed servers</a>, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a>. In 2012, Michigan ranked fourth in the country for new major corporate expansions, growing nearly 300 percent from 85 new building/expansion projects in 2011 to 337 in 2012.</p>
<p dir="ltr">Contributing to that corporate expansion, Online Tech has invested $1 million in our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a> and will be investing <a href="http://www.onlinetech.com/news/in-the-news/mlive-com-online-tech-plans-to-invest-1-million-in-flint-facility">another $1 million</a> this year. We’re also planning to expand across the Midwest &#8211; check out our current career opportunities!</p>
<p dir="ltr"><strong>We’re hiring in both Mid, Southeast Michigan, Indiana and Ohio:</strong></p>
<p><a href="http://www.onlinetech.com/company/careers/infrastructure-manager">Infrastructure Manager (Mid-Michigan)</a><br />
The Infrastructure Manager is responsible for the budget, people, processes, and systems for our data centers, network, cloud, and storage systems.</p>
<p><a href="http://www.onlinetech.com/company/careers/account-executive2">Account Executive (Southeast Michigan)</a><br />
Grow the customer base for one of the fastest growing, most highly regarded high tech companies in Southeast Michigan. As an Account Executive, you will be responsible for acquiring new customers and expanding existing customer relationships. This position reports directly to the Director of Sales. With an uncapped compensation plan and with a Michigan territory, you can achieve your goals and also be home every night.</p>
<p><a href="http://www.onlinetech.com/company/careers/account-executive-indiana-and-ohio">Account Executive (Indiana and Ohio)</a><br />
Grow the customer base for one of the fastest growing, most highly regarded high tech companies in the Midwest. As an Account Executive, you will be responsible for acquiring new customers and expanding existing customer relationships. This position reports directly to the Director of Sales, and it comes with a competitive total compensation package that includes both a base salary component and an uncapped commission component.</p>
<p><a href="http://www.onlinetech.com/company/careers/senior-sales-engineer-indiana-and-ohio">Senior Sales Engineer (Indiana and Ohio)</a><br />
The Senior Sales Engineer role is primarily responsible for supporting our Account Executives by developing technical solutions to meet our customers’ requirements and working with our operations team to kick off the order deployment process. The job focuses on new and existing customers in the Indianapolis and Columbus markets, and it has the opportunity to expand into a broader set of sales responsibilities, including managing the commercial aspects of our customer relationships and prospect development.</p>
<p dir="ltr">Related Articles:</p>
<p><em><strong><a href="http://resource.onlinetech.com/michigan-data-centers-contribute-to-states-4th-nationwide-ranking-for-corporate-expansion/">Michigan Data Centers Contribute to State’s 4th Nationwide Ranking for Corporate Expansion</a></strong></em><br />
According to Mlive.com, Michigan ranked fourth in the country for new major corporate facilities and expansions in 2012. Site Selection magazine’s annual Governor’s Cup reports that Michigan increased from 85 qualified new building/expansion projects in 2011 to 337 in 2012 … <a href="http://resource.onlinetech.com/michigan-data-centers-contribute-to-states-4th-nationwide-ranking-for-corporate-expansion/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/online-tech-shares-michigan-data-center-perspective-at-2013-governors-economic-summit/">Online Tech Shares Michigan Data Center Perspective at 2013 Governor’s Economic Summit</a></strong></em><br />
Online Tech co-CEOs Yan Ness and Mike Klein will be attending the 2013 Governor’s Economic Summit next week in Detroit, Michigan to collaborate with other state leaders and contribute a Michigan hosting provider‘s perspective. Governor Rick Snyder will lead a … <a href="http://resource.onlinetech.com/online-tech-shares-michigan-data-center-perspective-at-2013-governors-economic-summit/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/michigan-data-centers-fuel-state-it-industry-job-growth/">Michigan Data Centers Fuel State IT Industry Job Growth</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/michigan-data-centers-fuel-state-it-industry-job-growth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI-Ready? Not Enough for Fully Compliant PCI Hosting</title>
		<link>http://resource.onlinetech.com/pci-ready-not-enough-for-pci-compliance/</link>
		<comments>http://resource.onlinetech.com/pci-ready-not-enough-for-pci-compliance/#comments</comments>
		<pubDate>Fri, 03 May 2013 18:28:05 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[daily log review]]></category>
		<category><![CDATA[log monitoring]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[pci compliant services]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci ready]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11173</guid>
		<description><![CDATA[<p>Obscure marketing lingo happens to the best of us, and one of those potentially deceptive terms, when it comes to compliant hosting, is &#60;insert your compliance&#62;-ready. Whether it’s PCI-ready, or HIPAA-ready, it’s a key indicator that the hosting provider using &#8230; <a href="http://resource.onlinetech.com/pci-ready-not-enough-for-pci-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/pci-ready-not-enough-for-pci-compliance/">PCI-Ready? Not Enough for Fully Compliant PCI Hosting</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Obscure marketing lingo happens to the best of us, and one of those potentially deceptive terms, when it comes to compliant hosting, is &lt;insert your compliance&gt;-ready. Whether it’s PCI-ready, or HIPAA-ready, it’s a key indicator that the hosting provider using the term is not actually compliant, or that they may not provide all of the technical and managed services needed to help your company meet compliance.</p>
<p dir="ltr">For example: if your <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting provider</a> lists ‘log monitoring’ as a managed service within your PCI compliant hosting package, it might not actually fulfill the complete requirement. PCI standard 10.3 requires that you:</p>
<blockquote>
<p dir="ltr">Record at least the following audit trail entries for all system components for each event &#8211; a whole list of events follow, including user ID, type of event, data and time, success or failure indication, etc.</p>
</blockquote>
<p dir="ltr">But the requirement 10.6 also requires log review:</p>
<blockquote>
<p dir="ltr">Review logs for all system components at least daily. Log reviews must include those servers that perform security functions like intrusion-detection system (IDS) and authentication, authorization, and accounting protocol (AAA) servers (for example, RADIUS).</p>
</blockquote>
<p dir="ltr">Going beyond automated logging, which a PCI-ready hosting provider might offer, is the need for either you or your provider to review and analyze logs daily. This is a time-consuming burden that might be better outsourced if possible &#8211; which is possible, as long as you avoid the PCI-ready solutions out there that don’t actually give you everything you need, such as <a href="http://www.onlinetech.com/secure-hosting/technical-security/daily-log-review">daily log review</a>.</p>
<p dir="ltr"><img class="alignnone" title="Daily Log Review" src="http://www.onlinetech.com/images/stories/misc/dailylogreview.png" alt="Daily Log Review" width="620" height="450" /></p>
<p dir="ltr">Offsite backup and disaster recovery are two services often overlooked by those that need to meet PCI compliance, despite the clear requirements for a data backup plan, disaster recovery plan, emergency mode operation plan, testing and revision procedures, and application and data criticality analysis (9.5 and 12.9.1).</p>
<p dir="ltr"><img class="alignnone" title="PCI Offsite Backup" src="http://www.onlinetech.com/images/stories/misc/offsitebackup.png" alt="PCI Offsite Backup" width="612" height="302" /></p>
<p dir="ltr">PCI requirement 9.5 calls for backups to be stored in a secure location and preferably in an offsite location/facility, or data center. Auditors need to review the physical security of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a> to ensure proper authorization, control access and environmental controls are all in place for the highest standards of security.</p>
<p dir="ltr">Why pay for an incomplete solution and have to fill in the gaps? Don’t settle for PCI-ready, strive for fully PCI compliant with all of the essential managed services, and know which PCI standards your provider can fulfill vs. where you need to pick up the slack.</p>
<p>This handy chart of PCI compliant services matched with each of the PCI requirements can help you determine what can be solved with a PCI compliant hosting solution:</p>
<table>
<tbody>
<tr>
<td><strong>PCI Requirements</strong></td>
<td><strong>PCI Compliant Services</strong></td>
</tr>
<tr>
<td width="300"><strong>10.6: </strong>Review logs for all system components at least daily.<strong></strong><br />
<strong>10.3: </strong>Record at least the following audit trail entries for all system components for each event &#8211; including user ID, type of event, data and time, success or failure indication, etc.<br />
<strong>10.7: </strong>Retain audit trail history for at least one year, with a min. of three months immediately available for analysis (online, archived, or restorable from back-up).</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/daily-log-review"><img class="alignleft" style="margin-right: 10px; margin-bottom: 10px;" src="http://www.onlinetech.com/images/packages/daily-log-review.png" alt="daily-log-review" width="100" height="100" /></a><strong></strong><a href="http://www.onlinetech.com/secure-hosting/technical-security/daily-log-review"><strong>Daily Log Review</strong></a><br />Monitoring and analyzing user and system activity can help detect patterns of normal use and potentially malicious users. Daily log review is the process of regularly reviewing and reporting on log activity.While some providers may offer logging (tracking user activity, transporting and storing log events), Online Tech provides the complete logging experience with daily log review, analysis, and monthly reporting.</td>
</tr>
<tr>
<td><strong>10.5.5: </strong>Use file-integrity monitoring or change-detection software on logs to ensure that existing log data cannot be changed without generating alerts.<strong></strong><strong><br />11: </strong>Deploy file integrity monitoring tools to alert personnel to unauthorized modification of critical system files, configuration files or content files. Configure the software to perform critical file comparisons at least weekly.</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/file-integrity-monitoring-fim"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/file-integrity-monitoring.png" alt="file-integrity-monitoring" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/file-integrity-monitoring-fim"><strong>File Integrity Monitoring (FIM)</strong></a><br />
Monitoring your files and systems provides valuable insight into your technical environment and provides an additional layer of data security. File integrity monitoring (FIM) is a service that can monitor any changes made to your files.</td>
</tr>
<tr>
<td><strong>6.6: </strong>For public-facing web applications, ensure:Verify that public-facing web applications are reviewed (using either manual or automated vulnerability security assessment tools or methods), as follows:</p>
<ul>
<li>At least annually and after any changes</li>
<li>By an organization that specializes in application security</li>
<li>That all vulnerabilities are corrected, and the application is re-evaluated after corrections</li>
</ul>
<p>Verify that a web-application firewall is in front of public-facing web applications to detect and prevent web-based attacks.</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/web-application-firewall-waf"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/web-application-firewall.png" alt="web-application-firewall" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/web-application-firewall-waf"><strong>Web Application Firewall (WAF)</strong></a><br />
Protect your web servers and databases from malicious online attacks by investing in a web application firewall (WAF). A network firewall’s open port allows Internet traffic to access your websites, but it can also open up servers to potential application attacks (database commands to delete or extract data are sent through a web application to the backend database) and other malicious attacks.</td>
</tr>
<tr>
<td><strong>8.3: </strong>Incorporate two-factor authentication for remote access (network-level access originating from outside the network) to the network by employees, administrators, and third parties.(For example, remote authentication and dial-in service (RADIUS) with tokens; or other technologies that facilitate two-factor authentication.</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/two-factor-authentication"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/two-factor-authentication.png" alt="two-factor-authentication" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/two-factor-authentication"><strong>Two-Factor Authentication</strong></a><br />
Online Tech offers two-factor authentication for VPN (Virtual Private Network) access as an optimal security measure to protect against online fraud and unauthorized access for clients that connect to their networks from a remote location.<strong> </strong></td>
</tr>
<tr>
<td><strong>11.2: </strong>Run internal and external network vulnerability scans at least quarterly and after any significant change in the network (such as new system component installations, changes in network topology, firewall rule modifications, product upgrades).</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/vulnerability-scanning"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/vulnerability-scanning.png" alt="vulnerability-scanning" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/vulnerability-scanning"><strong>Vulnerability Scanning</strong></a><br />
Vulnerability scanning checks your firewalls, networks and ports. It is a web application that can detect outdated versions of software, web applications that aren’t securely coded, or misconfigured networks.</td>
</tr>
<tr>
<td><strong>6.1: </strong>Ensure that all system components and software are protected from known vulnerabilities by having the latest vendor-supplied security patches installed. Install critical security patches within one month of release.</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/patch-management"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/patch-management.png" alt="patch-management" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/patch-management"><strong>Patch Management</strong></a><br />
Why is patch management so important? If your servers aren’t updated and managed properly, your data and applications are left vulnerable to hackers, identity thieves and other malicious attacks against your systems.</td>
</tr>
<tr>
<td><strong>5.1: </strong>Deploy anti-virus software on all<br />
systems commonly affected by malicious<br />
software (particularly personal computers<br />
and servers).<strong></strong><strong><br />5.2: </strong>Ensure that all anti-virus mechanisms are current, actively running, and generating audit logs.</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/antivirus"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/anti-virus.png" alt="anti-virus" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/antivirus"><strong>Antivirus</strong></a><br />
Antivirus software can detect and remove malware in order to protect your data from malicious attacks. Significantly reduce your risks of data theft or unauthorized access by investing in a simple and effective solution for optimal server protection.</td>
</tr>
<tr>
<td><strong>4.1: </strong>Use strong cryptography and security protocols (for example, SSL/TLS, IPSEC,SSH, etc.) to safeguard sensitive cardholder data during transmission over open, public networks.</td>
<td><a href="http://www.onlinetech.com/secure-hosting/technical-security/ssl-certificate"><img style="margin-right: 10px; margin-bottom: 10px; float: left;" src="http://www.onlinetech.com/images/packages/ssl-certificate.png" alt="ssl-certificate" width="100" height="100" /></a><a href="http://www.onlinetech.com/secure-hosting/technical-security/ssl-certificate"><strong>SSL Certificate</strong></a><br />
In order to safely transmit information online, a SSL (Secure Sockets Layer) certificate provides the encryption of sensitive data, including financial and healthcare. A SSL certificate verifies the identity of a website, allowing web browsers to display a secure website.</td>
</tr>
</tbody>
</table>
<p>References:<br />
<a href="https://www.pcisecuritystandards.org/documents/pci_dss_v2.pdf">Payment Card Industry Data Security Standard, Requirements and Security Assessment Procedures, Version 2.0</a> (PDF)</p>
<p>Other PCI DSS resources:<br />
<a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/resources/pci-compliant-hosting-faq">PCI Compliant Hosting FAQ</a><br />
<a href="http://www.onlinetech.com/resources/e-tips/pci-compliance/four-ways-to-gain-transparency-with-pci-hosting-providers">Four Ways to Gain Transparency with PCI Hosting Providers</a><br />
<a href="http://www.onlinetech.com/resources/white-papers/pci-compliant-data-centers">PCI Compliant Hosting White Paper</a></p>
<p>The post <a href="http://resource.onlinetech.com/pci-ready-not-enough-for-pci-compliance/">PCI-Ready? Not Enough for Fully Compliant PCI Hosting</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-ready-not-enough-for-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 ETA Expo: Government Panel Discussion</title>
		<link>http://resource.onlinetech.com/2013-eta-expo-government-panel-discussion/</link>
		<comments>http://resource.onlinetech.com/2013-eta-expo-government-panel-discussion/#comments</comments>
		<pubDate>Thu, 02 May 2013 18:48:34 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[eta expo]]></category>
		<category><![CDATA[ETAexpo2013]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11164</guid>
		<description><![CDATA[<p>Online Tech is exhibiting PCI hosting solutions at the 2013 ETA (Electronic Transactions Association) Annual Meeting &#38; Expo at booth #1237. The conference will be held in New Orleans from April 30-May 2 at the New Orleans Convention Center. Government &#8230; <a href="http://resource.onlinetech.com/2013-eta-expo-government-panel-discussion/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-eta-expo-government-panel-discussion/">2013 ETA Expo: Government Panel Discussion</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting</a> solutions at the 2013 ETA (Electronic Transactions Association) Annual Meeting &amp; Expo at booth #1237. The conference will be held in New Orleans from April 30-May 2 at the New Orleans Convention Center.</p>
<p><strong>Government Panel</strong><br />
<em>Panelists: Marla Blow, Associate Director, Cards and Prepaid Markets Division, Consumer Financial Protection Bureau</em><br />
<em>Patti Poss, Chief of the Mobile Technology Unit, Division of Financial Practices, Bureau of Consumer Protection, Federal Trade Commission</em><br />
<em>Maximilian D. Schmeiser, PhD, Economist, Consumer Research Section, Consumer and Community Affairs, Board of Governors of the Federal Reserve System</em><br />
Moderator: Jason Oxman, CEO, ETA</p>
<p dir="ltr">All the vendors in attendance at the show are behind every consumer transaction in the industry.</p>
<p dir="ltr">The panel was an introduction to the government bodies that are involved within the industry. Each panelist explained what they did and their role within the payments industry.</p>
<p dir="ltr">Patti: With the Mobile Technology unit and it works across the consumer safety program. The FTC has been focusing on mobile technology for a while now. The FTC has broad jurisdiction across the industry. Mainly focus on protecting consumers from unfair and fraudulent actions within the industry.</p>
<p dir="ltr">Marla: CPD has been around for about two years. Clarity within the market, making sure institutions are playing by the rules, ensuring there is a level playing field. Making sure banks and nonbanks are held to the same standards. Within the bureau, she works with policy specifically.Think about privacy and work with the FTC on privacy issues. Mobile, payments, credit cards debit cards, retail checking accounts.</p>
<p dir="ltr">Max: Heading the boards efforts for consumers move to mobile financial transactions. Corresponding reports, access consumer financial services 2013 (Google). Works with several federal reserve groups that monitor financial transactions. On a group that watches issues with mobile financial services. Strong interest in anything that touches the US financial payments. monitor payment trends. Collaborate with other regulators on issues related to mobile payments.</p>
<p dir="ltr">What should the industry be doing? What gaps do you see in the industry?</p>
<p dir="ltr">Patti: Just because there is a new medium doesn’t mean there are no rules there. In regards to online and mobile payments.</p>
<p dir="ltr">Marla: How mobile payments are different from traditional transactions. Mobile brings more people to the table, thus making regulations more tedious and time consuming. Particularly for merchants who don’t technically read the regulations around the financial transaction areas.</p>
<p dir="ltr">Where are we in the educational effort in relation to mobile payments in regard to consumers? What are their concerns? What does that tell us about what the industry should be doing?</p>
<p dir="ltr">Max:  Consumers are aware of it’s existence, but are not sure how or where they can make such payments. Main reasons some people don’t use it:</p>
<ol>
<li dir="ltr">
<p dir="ltr">Security &#8211; Concerned with it broadly (maybe not accurate)</p>
</li>
<li dir="ltr">
<p dir="ltr">Just don’t see any benefit &#8211; appears to complicated for them. They like the ease of traditional payment methods.</p>
</li>
</ol>
<p dir="ltr">Patti: We looked at three areas that offer potential with mobile payments for consumers:</p>
<ol>
<li dir="ltr">
<p dir="ltr">What happens when something goes wrong? &#8211; Do consumers have the correct info and know who to go to when something goes wrong, and do they know what sort of liability are they taking on?</p>
</li>
<li dir="ltr">
<p dir="ltr">Security &#8211; Is the information secure and how they are protecting consumers sensitive financial information?</p>
</li>
<li dir="ltr">
<p dir="ltr">Privacy &#8211; Lots of joint partnerships that can develop, but that comes in exchange for data. Who gets the data? Do the consumers know who has the data?</p>
</li>
</ol>
<p dir="ltr">Marla: Questions have been raised as to how to best notify the consumers of the terms they are accepting and how those agreements appear on a small mobile screen. Trying out figure out if  there is a better way to get information to consumers so they can more readily digest terms and conditions.</p>
<p dir="ltr">There is a micro and macro level market going on with the mobile payment space. There is obviously concern with protecting privacy when a consumer uses their phone to make a payment, but does not want to receive tons of marketing notifications from those vendors in the future. How well is the industry walking that line?</p>
<p dir="ltr">Patti: There is a general framework I will talk about to answer that.</p>
<ul>
<li dir="ltr">
<p dir="ltr">Privacy by design &#8211; Are merchants thinking about privacy as they are really developing their products or are they slapping it on at the last minute? Do you know where the data flow is going and coming from.</p>
</li>
</ul>
<ul>
<li dir="ltr">
<p dir="ltr">Simplified choice &#8211; Do you have pages and pages for consumers to read so they know where their data is, or can you boil it down and make it clear and easily understandable for consumers to read.</p>
</li>
<li dir="ltr">
<p dir="ltr">Transparency &#8211; Is there somewhere consumers can go to actually learn about what you are doing with their data</p>
</li>
</ul>
<p dir="ltr">Max: There is some inconsistency between consumers in what they say and what they do. They say they absolutely will not give up their information and location to receive offers from merchants, but then when they are at the point of sale and they are on their apps, they do end up giving up that information.</p>
<hr />
<p><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/resources/white-papers/pci-compliant-data-centers"><img class="alignleft" src="http://www.onlinetech.com/images/stories/misc/pci-white-paper-sm.gif" alt="PCI Compliant Data Centers" width="200" height="165" /></a>Looking for more information on PCI hosting requirements, recommendations, and the foundation of a secure <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a>?</p>
<p><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/resources/white-papers/pci-compliant-data-centers">Download our PCI Compliant Hosting white paper</a> now for a complete guide to PCI hosting with IT vendors.</p>
<p><strong>Still have questions? </strong><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/contact">Contact us</a> or <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">chat</a> with us now. Find out more about our fully compliant, <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/compliant-hosting/pci-compliant-hosting/overview">PCI hosting</a> solutions, or <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/secure-hosting/hipaa-compliant-hosting/quote">submit a quote request</a> for your project today.</p>
<hr />
<p>The post <a href="http://resource.onlinetech.com/2013-eta-expo-government-panel-discussion/">2013 ETA Expo: Government Panel Discussion</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-eta-expo-government-panel-discussion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 ETA Expo: Staying Ahead of Change in the Payments Industry</title>
		<link>http://resource.onlinetech.com/2013-eta-expo-staying-ahead-of-change-in-the-payments-industry/</link>
		<comments>http://resource.onlinetech.com/2013-eta-expo-staying-ahead-of-change-in-the-payments-industry/#comments</comments>
		<pubDate>Thu, 02 May 2013 14:25:56 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[ETAexpo2013]]></category>
		<category><![CDATA[payments industry]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11148</guid>
		<description><![CDATA[<p>Online Tech is exhibiting PCI hosting solutions at the 2013 ETA (Electronic Transactions Association) Annual Meeting &#38; Expo at booth #1237. The conference will be held in New Orleans from April 30-May 2 at the New Orleans Convention Center. Keynote: &#8230; <a href="http://resource.onlinetech.com/2013-eta-expo-staying-ahead-of-change-in-the-payments-industry/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-eta-expo-staying-ahead-of-change-in-the-payments-industry/">2013 ETA Expo: Staying Ahead of Change in the Payments Industry</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting</a> solutions at the 2013 ETA (Electronic Transactions Association) Annual Meeting &amp; Expo at booth #1237. The conference will be held in New Orleans from April 30-May 2 at the New Orleans Convention Center.</p>
<p><strong>Keynote: Big Change and Pocket Change: Staying Ahead of Change in the Payments Industry</strong><br />
<em>Speaker: David Nelms, Chairman &amp; CEO, Discover Financial Services</em></p>
<p dir="ltr">Key players in the card industry have left and become independent entities and brands. The payments industry has had the largest number of mergers and acquisitions of any other industry. Technology and regulations have also changed within the industry. Discover went from being a domestic network in 1998 to a global network by 2012. David encouraged others in the industry to welcome these kinds of advances across the board.</p>
<p dir="ltr">Global payments have nearly doubled in ten years from $17 to 36 trillion. Global card transactions have simply become a bigger slice of a bigger pie. The use of cards for transactions now outdoes the use of cash and checks combined.</p>
<p dir="ltr">He went on to discuss that change is the sign of a healthy industry and with change comes opportunity. The payment industry is not the first to experience such change. David compared  the television industry to the payment card industry. Over time, several barriers to entry were eliminated and new affiliates could ultimately go directly to the consumer, bypassing several channels.</p>
<p dir="ltr">Payments Value Stream used to look like the following:</p>
<ul>
<li>Networks</li>
<li>Acquirers</li>
<li>Merchants</li>
<li>Consumer</li>
</ul>
<p dir="ltr">As an industry, the payment industry is doing a good job of creating innovation, choices and added value for consumers. Consumers want ease of use, relevancy and security. New players, new technology and a lot of uncertainty are consistent components of the industry.</p>
<p dir="ltr"><strong>Big Trends Happening in the Payment Industry:</strong></p>
<ol>
<li>Mobile technologies &#8211; Smartphones are the hub and center of the consumer’s universe. Phones will become way of payment at the point of sale. There will be battles over security and control.</li>
<li>Physical Cards &#8211; Physical cards will still be with us for a long time.</li>
<li>Commerce and payments are beginning to blend. Consumers are being offered more and more  ways to pay and the point of sale is going mobile.</li>
<li>EMV is coming to the US</li>
<li>Retail banking is moving from branches to internet and mobile.</li>
<li>Information is more valuable and enabling. Consumers digital footprints are now moving to the cloud. Industry players are trying quickly to learn about consumers behavior and patterns based on that information.</li>
<li>Partnerships are just as important as ever.</li>
</ol>
<p dir="ltr">Discover wants to be the best partner in the industry. It is an alternative network for alternative payments in the US.  Discover is also partnering with other networks around the world.</p>
<p dir="ltr">David discussed some of Discover’s partnerships, some of which include PayPal and RuPay. Through partnerships, Discover is able to create benefits for consumers that include: complete financial flexibility, security and simplicity. For merchants, they offer simplified setup and new business.</p>
<p dir="ltr">The payment industry is growing and attractive. They have survived and are thriving as they move forward. The changes in the industry change rapidly whether it be from participants, technology, consumer behavior to regulations.</p>
<p>Key lecture takeaway:<br />
Embrace change and look for ways to add more value.</p>
<hr />
<p dir="ltr"><strong><img class="alignleft" title="David W. Nelms" src="http://www2.electran.org/am13/img/PHOTO-SPEAKER-NELMS.jpg" alt="David W. Nelms" width="90" height="126" />David Nelms, Chairman &amp; CEO, Discover Financial Services</strong></p>
<p dir="ltr">David W. Nelms is Chairman of the Board of Directors and Chief Executive Officer of Discover Financial Services.  He is responsible for all Discover® branded financial services, including credit cards and banking products, including Discover Student Loans and Discover Home Loans; the Discover Network, a comprehensive payments network that supports multiple card products, issuers and processors; PULSE, one of the nation’s leading PIN debit networks; and Diners Club International, a global payments network.  He is also Chairman of Discover Bank, the issuing bank for the Discover card brands.</p>
<p>Before his appointment at Discover in September 1998, Mr. Nelms served as a Vice Chairman of MBNA America Bank.  Prior to that, he held management positions at Progressive Insurance, General Electric Company and in the consulting industry.</p>
<hr />
<p><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/resources/white-papers/pci-compliant-data-centers"><img class="alignleft" src="http://www.onlinetech.com/images/stories/misc/pci-white-paper-sm.gif" alt="PCI Compliant Data Centers" width="200" height="165" /></a>Looking for more information on PCI hosting requirements, recommendations, and the foundation of a secure <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a>?</p>
<p><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/resources/white-papers/pci-compliant-data-centers">Download our PCI Compliant Hosting white paper</a> now for a complete guide to PCI hosting with IT vendors.</p>
<p><strong>Still have questions? </strong><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/contact">Contact us</a> or <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">chat</a> with us now. Find out more about our fully compliant, <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/compliant-hosting/pci-compliant-hosting/overview">PCI hosting</a> solutions, or <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/secure-hosting/hipaa-compliant-hosting/quote">submit a quote request</a> for your project today.</p>
<hr />
<p>The post <a href="http://resource.onlinetech.com/2013-eta-expo-staying-ahead-of-change-in-the-payments-industry/">2013 ETA Expo: Staying Ahead of Change in the Payments Industry</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-eta-expo-staying-ahead-of-change-in-the-payments-industry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Let’s Save the Planet by Filling Up the Data Centers</title>
		<link>http://resource.onlinetech.com/lets-save-the-planet-by-filling-up-the-data-centers/</link>
		<comments>http://resource.onlinetech.com/lets-save-the-planet-by-filling-up-the-data-centers/#comments</comments>
		<pubDate>Thu, 02 May 2013 13:43:01 +0000</pubDate>
		<dc:creator>Anna Ankenbrand</dc:creator>
				<category><![CDATA[CEO Voices]]></category>
		<category><![CDATA[Data Centers]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[data center efficiency]]></category>
		<category><![CDATA[data center energy]]></category>
		<category><![CDATA[green data centers]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11135</guid>
		<description><![CDATA[<p>In 2013, the biggest trend for data centers is making them more energy efficient. There are very simple things companies can do like turning off the lights in the data center to more strategic plans like locating data centers in &#8230; <a href="http://resource.onlinetech.com/lets-save-the-planet-by-filling-up-the-data-centers/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/lets-save-the-planet-by-filling-up-the-data-centers/">Let’s Save the Planet by Filling Up the Data Centers</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>In 2013, the biggest trend for <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> is making them more energy efficient. There are very simple things companies can do like turning off the lights in the data center to more strategic plans like locating data centers in cool geographical areas like the state of Michigan. If interested in learning more, see the list of articles below.</p>
<p>All of these individual ideas can make a difference. But what is that “big idea” that could make a significant impact on the environment and drive innovation to create even more efficiencies?</p>
<p><iframe width="560" height="315" src="http://www.youtube.com/embed/2kxW906xZvE" frameborder="0" allowfullscreen></iframe></p>
<p>“The best thing is to fill the data centers,” says Yan Ness, Online Tech Co-CEO.</p>
<p>Ness gives the example of how much energy resources are actually consumed by a mid-sized company to run their servers.</p>
<p>A 100-employee company would typically have around 15 servers to manage their email, store files, and run their applications. Each server uses the same energy, equal to a 300-watt light bulb. If you add up 15 300-watt light bulbs, running 7X24, that’s equivalent to driving a car 250,000 miles every year.</p>
<p>It is very likely that these companies are not running as efficient as possible. The companies may not realize how much energy is being consumed or they are unable to financially justify investing in more efficient equipment. So, what would happen if we move the 15 servers into a specialty data center?</p>
<p>We would automatically see more energy efficiencies just by moving this equipment out of the closet and into more efficient data centers. Then if we would move those 15 servers into a data center’s cloud, 90% less energy would be consumed.</p>
<p>Once all of the data centers are filled, something interesting will happen. All sorts of ingenuity around making data centers more efficient will grow even more because it makes financial sense to do so.</p>
<p>What do you think?  Does Ness have the “big idea” by filling up the data centers?</p>
<p><strong>Incorporating Energy Efficiencies in Data Centers</strong><br />
<a href="http://resource.onlinetech.com/the-next-generation-data-center-how-michigan-data-centers-fit-the-bill/">The Next Generation Data Center:  How Michigan Data Centers Fit the Bill</a><br />
<a href="http://resource.onlinetech.com/investing-in-data-center-efficiencies-part-one/">Investing in Data Center Efficiencies – Part One</a><br />
<a href="http://resource.onlinetech.com/michigan-the-next-cool-thing-for-data-centers/http:/resource.onlinetech.com/investing-in-data-center-efficiencies-part-two/">Investing in Data Center Efficiencies – Part Two</a><br />
<a href="http://resource.onlinetech.com/michigan-the-next-cool-thing-for-data-centers/">Michigan – The Next Cool Thing for Data Centers</a><br />
<a href="http://resource.onlinetech.com/could-wind-farms-power-michigan-data-centers/">Could Wind Farms Power Michigan Data Centers?</a></p>
<p>The post <a href="http://resource.onlinetech.com/lets-save-the-planet-by-filling-up-the-data-centers/">Let’s Save the Planet by Filling Up the Data Centers</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/lets-save-the-planet-by-filling-up-the-data-centers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 ETA Expo Keynote:  The Mobile Commerce Revolution</title>
		<link>http://resource.onlinetech.com/keynote-%e2%80%a8the-mobile-commerce-revolution-michael-abbott-ceo-isis/</link>
		<comments>http://resource.onlinetech.com/keynote-%e2%80%a8the-mobile-commerce-revolution-michael-abbott-ceo-isis/#comments</comments>
		<pubDate>Wed, 01 May 2013 19:47:03 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[ETAexpo2013]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci mobile]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11118</guid>
		<description><![CDATA[<p>Online Tech is exhibiting PCI hosting solutions at the 2013 ETA (Electronic Transactions Association) Annual Meeting &#38; Expo at booth #1237. The conference will be held in New Orleans from April 30-May 2 at the New Orleans Convention Center. Keynote: &#8230; <a href="http://resource.onlinetech.com/keynote-%e2%80%a8the-mobile-commerce-revolution-michael-abbott-ceo-isis/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/keynote-%e2%80%a8the-mobile-commerce-revolution-michael-abbott-ceo-isis/">2013 ETA Expo Keynote:  The Mobile Commerce Revolution</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-261b4e26-617e-eda2-9634-493edfdd1db8" dir="ltr">Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting</a> solutions at the 2013 ETA (Electronic Transactions Association) Annual Meeting &amp; Expo at booth #1237. The conference will be held in New Orleans from April 30-May 2 at the New Orleans Convention Center.</p>
<p><strong>Keynote:  The Mobile Commerce Revolution</strong><br />
<em>Speaker: Michael Abbott, CEO, Isis</em></p>
<p dir="ltr">Mike opened his presentation by explaining that mobile technology isn’t new thing, it’s been around for over 10 years. Nokia was already experimenting with mobile technology in the early 2000’s&#8230;</p>
<p dir="ltr">So&#8230; ‘why now?’ Why is this technology coming to the forefront now?</p>
<p dir="ltr">Abbott notes that mobile phones are our personal representation. Find someone under 25 who has a landline. It’s virtually impossible. A decade ago, cameras weren’t on phones. By the end of this year half of all the pictures taken in the us will be taken on a mobile phone.</p>
<p dir="ltr">Why does the consumer want this technology?</p>
<p dir="ltr">Mike shared the example of consumers sifting through coupons on the weekends. They first had to search out coupons from the  stores they wanted to shop at and then they had to match the  coupons in the aisles of the grocery store. Is that really 21st century technology? Is that what we should be doing right now? Instead of your wallet being a repository for receipts, with mobile technology, it can become a two way communication channel. Putting the consumer/merchant back in control. That’s the goal of mobile payments.</p>
<p dir="ltr">Mike showed the audience a slide of statistics, breaking down where consumers are at in the adaption process of mobile technology showing that:</p>
<ul>
<li>86% of consumers polled were interested in adopting a Mobile Wallet</li>
<li>73% want to add retail coupons to their Mobile Wallet.</li>
</ul>
<p dir="ltr">What is it going to take for consumers to adopt a mobile wallet?</p>
<p dir="ltr">It’s not a technology problem, it’s a business system problem. A four-sided market needs to be developed to include the following:</p>
<p><strong>Mobile Operators</strong></p>
<ul>
<li>Need standards everyone can adopt</li>
<li>Needs to be scalable</li>
<li>Build a supply chain</li>
<li>Create a reason to invest.</li>
</ul>
<p><strong>Banks</strong></p>
<ul>
<li>They want something secure</li>
<li>They need it to represent scale</li>
<li>And they want something that is better than using cards</li>
</ul>
<p><strong>Merchants</strong></p>
<ul>
<li>They want communication with their customers</li>
<li>It needs to be for all vendors, not just can’t just be for the big guys</li>
</ul>
<p><strong>Consumers</strong></p>
<ul>
<li>They want what they have right now in their wallet, but on their mobile  phones</li>
<li>It needs to make their life simpler.</li>
</ul>
<p dir="ltr">Isis is a platform for the industry in mobile technology. How that works:</p>
<p dir="ltr"><strong>For banks</strong>: They want to be sure they are secure and one-to-one communication channel. Isis does not want to push their brand in front of their partners, because consumers still want to still see their card brand in their mobile wallet.</p>
<p dir="ltr"><strong>For Merchants</strong>: They want a rich two-way communication channel with their consumers, delivering loyalty cards and coupons automatically that the consumer has selected.</p>
<p><strong>Mobile Tips From Isis</strong></p>
<ul>
<li><strong>Choice</strong> &#8211; Everything must be built on choice for the consumer. From their choice in carrier to their choice of the cards they keep in their wallet. At the end of the day, the consumer should always be in charge of their choice.</li>
<li><strong>Privacy</strong> &#8211; Privacy means good business. Consumers need to feel secure with their wallet. Your wallet doesn’t spy on you today, it shouldn’t do that tomorrow.</li>
<li><strong>Security</strong> &#8211; Easy to create something with billions of apps, but if you are going to transfer from plastic cards to mobile wallet, it MUST be secure.</li>
</ul>
<p dir="ltr">In wrapping up his keynote address, Mike pointed out that consumers want what they already have, but in an easier to use format. Businesses can use mobile technology and make it contextually and time relevant to the consumer at point of sale. They’re making the world clickable and your phone is becoming your mouse.</p>
<p><strong>What we learned as key takeaways:</strong></p>
<ol>
<li>Control – The consumer is being put in control of everything in their wallet.</li>
<li>Simplicity- Consumers want simplicity and want to be able to know how to pay with their phone first.</li>
<li>Magical- Consumers think the technology is awesome</li>
<li>Viral – Al it takes is one time to teach the consumer and after that they “get it” and it goes viral because they show others.</li>
</ol>
<p><strong>How other companies can get in the game:</strong></p>
<ol>
<li>Go contactless now</li>
<li>Rethink your value propositions – It’s all about partnerships. No way a central corporation can plan out the technology on a large scale.</li>
<li>Start small. Think big. Scale fast.  – Everything Isis does in regards to their technology starts small and they perfect that technology. When they get the right “elixir:, they can scale it out fast.</li>
</ol>
<hr />
<p><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/resources/white-papers/pci-compliant-data-centers"><img class="alignleft" src="http://www.onlinetech.com/images/stories/misc/pci-white-paper-sm.gif" alt="PCI Compliant Data Centers" width="200" height="165" /></a>Looking for more information on PCI hosting requirements, recommendations, and the foundation of a secure <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a>?</p>
<p><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/resources/white-papers/pci-compliant-data-centers">Download our PCI Compliant Hosting white paper</a> now for a complete guide to PCI hosting with IT vendors.</p>
<p><strong>Still have questions? </strong><a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/contact">Contact us</a> or <a href="https://hosted2.whoson.com/chat/chatstart.htm?domain=www.onlinetech.com">chat</a> with us now. Find out more about our fully compliant, <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/compliant-hosting/pci-compliant-hosting/overview">PCI hosting</a> solutions, or <a href="http://resource.onlinetech.com/unencrypted-data-big-problem-for-banks-merchants/secure-hosting/hipaa-compliant-hosting/quote">submit a quote request</a> for your project today.</p>
<p>Or download our <a href="http://www.onlinetech.com/resources/white-papers/mobile-security">Mobile Security white paper</a> for more on how to secure data with mobile devices and mobile applications.</p>
<hr />
<p>The post <a href="http://resource.onlinetech.com/keynote-%e2%80%a8the-mobile-commerce-revolution-michael-abbott-ceo-isis/">2013 ETA Expo Keynote:  The Mobile Commerce Revolution</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/keynote-%e2%80%a8the-mobile-commerce-revolution-michael-abbott-ceo-isis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Utah Healthcare Data Breach Costs the State $9 Million</title>
		<link>http://resource.onlinetech.com/utah-healthcare-data-breach-costs-the-state-9-million/</link>
		<comments>http://resource.onlinetech.com/utah-healthcare-data-breach-costs-the-state-9-million/#comments</comments>
		<pubDate>Wed, 01 May 2013 14:47:10 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[encryption for hipaa]]></category>
		<category><![CDATA[health IT security]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[hipaa data breach]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violation]]></category>
		<category><![CDATA[utah data breach]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11111</guid>
		<description><![CDATA[<p>Last March, the Utah Department of Technology Services (DTS) was hacked and 280,000 individuals had their Social Security numbers compromised. A year later, a report is released revealing that the state has spent about $9 million total on remediation &#8211; &#8230; <a href="http://resource.onlinetech.com/utah-healthcare-data-breach-costs-the-state-9-million/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/utah-healthcare-data-breach-costs-the-state-9-million/">Utah Healthcare Data Breach Costs the State $9 Million</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-3eec7f92-608c-0734-5bd1-40a633ca8282" dir="ltr">Last March, the Utah Department of Technology Services (DTS) was hacked and 280,000 individuals had their Social Security numbers compromised. A year later, a report is released revealing that the state has spent about $9 million total on remediation &#8211; including security audits, upgrades and credit monitoring for victims, in addition to $770/20 hours in resolution for each of the 122,000 victims. Total fraud could amount to $406 million (Javelin Strategy &amp; Research).</p>
<p dir="ltr">This data breach exemplifies the major financial consequences of a misconfigured server, as I wrote about last April in <a href="http://resource.onlinetech.com/server-hack-leads-to-hipaa-violation-by-utah-department-of-health/">Server Hack Leads to HIPAA Violation by Utah Department of Health</a>. The Salt Lake Tribune reports that a server containing Medicaid data was compromised after it was placed online without changing the vendor-supplied password.</p>
<p dir="ltr">The data was unencrypted; a best practice particularly when it comes to abiding by the Health Insurance Portability and Accountability Act (HIPAA), the laws created to protect patient data. Read more about encryption in <a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a>.</p>
<p dir="ltr">Changing vendor passwords is another general best practice when it comes to security, particularly with servers containing protected health information (PHI). This is a basic security practice that all IT staff should be aware of &#8211; particularly in the healthcare industry, but also for any company that is security-conscious.</p>
<p dir="ltr">To meet HIPAA compliance, the standard for Security Awareness and Training (164.308(a)(5)) is part of implementing the Administrative Safeguards required by the HIPAA Security Rule. Acknowledging that many security risks and vulnerabilities are internal, the standard requires:</p>
<blockquote>
<p dir="ltr">Implement a security awareness and training program for all members of its workforce (including management).</p>
</blockquote>
<p dir="ltr">The rule requires training of the entire workforce by the compliance date of the Security Rule, with additional periodic retraining whenever any environmental or operational changes occur that may affect the security of sensitive data. With any new policies and procedures, upgraded software or hardware, new security technology, etc., security retraining is required. Read more on <a href="http://www.onlinetech.com/secure-hosting/administrative-security/staff-training">Staff Training</a> as part of the <a href="http://www.onlinetech.com/secure-hosting/administrative-security">Administrative Security</a> tools required to keep data secure.</p>
<p dir="ltr">These security practices apply even if you decide to outsource your IT operations to a hosting company &#8211; if you’re seeking a <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a> provider to maintain your servers, choose one that has undergone an independent audit to verify they can provide the optimal level of security needed in their <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">data centers</a> and throughout their company.</p>
<p dir="ltr">Read more in our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Hosting white paper</a> for a complete guide to the technical, physical and administrative security required to meet compliance.</p>
<p dir="ltr">Read more about data breaches and resolutions in:</p>
<p><em><strong><a href="http://resource.onlinetech.com/healthcare-data-breach-means-prison-time-class-action-lawsuit/">Healthcare Data Breach Leads to Prison Time; Class Action Lawsuit</a></strong></em><br />
For two years, a former emergency department worker of Florida Hospital Celebration gained unauthorized access to more than 763,000 electronic patient health records and sold 12,000 of them to a co-conspirator (and operator of two chiropractic centers) to solicit patients … <a href="http://resource.onlinetech.com/healthcare-data-breach-means-prison-time-class-action-lawsuit/">Continue reading →</a></p>
<p><strong><em><a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">2013 State of HIPAA Encryption &amp; Authentication for Healthcare</a></em></strong><br />
According to the Healthcare Information Security Today report, 2013 Outlook: Survey Offers Update on Safeguarding Patient Information, most healthcare organizations believe that encryption would greatly improve their data security. Forty-one percent plan to encrypt all mobile devices and removable media, … <a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates/">HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates</a></strong></em><br />
Of the HIPAA data breaches reported in 2013 so far, nearly 40 percent have involved a business associate. A look at the overall percentage of business associate involvement with data breaches dating back to 2009 reveals that almost 30 percent … <a href="http://resource.onlinetech.com/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates/">Continue reading →</a></p>
<p>References:<br />
<a href="https://www.javelinstrategy.com/blog/2013/04/28/financial-pain-ensues-when-custodians-of-health-fail-to-be-good-stewards-of-privacy/">Financial Pain Ensues When Custodians of Health Fail to be Good Stewards of Privacy</a><br />
<a href="http://www.sltrib.com/sltrib/news/56210404-78/security-breach-health-data.html.csp">Report: Utah’s Health Data Breach Was a Costly Mistake</a></p>
<p>The post <a href="http://resource.onlinetech.com/utah-healthcare-data-breach-costs-the-state-9-million/">Utah Healthcare Data Breach Costs the State $9 Million</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/utah-healthcare-data-breach-costs-the-state-9-million/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Continuity and Disaster Recovery</title>
		<link>http://resource.onlinetech.com/disaster-recovery/</link>
		<comments>http://resource.onlinetech.com/disaster-recovery/#comments</comments>
		<pubDate>Tue, 30 Apr 2013 18:35:15 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[offsite backup]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11100</guid>
		<description><![CDATA[<p>When considering business continuity and disaster recovery options, there’s really only one constant from business to business: it’s important to have. No matter how small or large your business, if something happens and there isn’t a plan, your company may &#8230; <a href="http://resource.onlinetech.com/disaster-recovery/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/disaster-recovery/">Business Continuity and Disaster Recovery</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-08d39366-5c31-077c-3982-8d6fd2d05153" dir="ltr">When considering business continuity and disaster recovery options, there’s really only one constant from business to business: it’s important to have. No matter how small or large your business, if something happens and there isn’t a plan, your company may never be able to get back on its feet again.</p>
<p dir="ltr">But, where do you start?</p>
<p><strong>Map out your needs</strong><br />
Steve Aiello mentioned in his <a href="http://onlinetech.com/events/disaster-recovery-webinar-series">webinar series</a> that the best starting point is to find out where the sources of income are for your business. He proposes that the best way to do this is to map out your company’s departments, dependencies, and processes first. This is going to give you a clear and concise idea of where the effect will fall, depending on different causes. It’s also a good time for a company to take stock of their processes, to ensure you’re running everything as efficiently as possible within your framework. Within the planning, you’ll also want to find out what aspects of your business are most time sensitive to have up and running.</p>
<p><strong>Look at your options</strong><br />
When you’re thinking about <a href="http://onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> specifically, there are lots of facets that your company may need. For instance, in the event that your company is situated in a location with a high incidence of natural disasters (the east coast gets bombarded with hurricanes, California has their earthquakes, and don’t get me started on tornado alley&#8230;), it would do you well to have an offsite backup that’s farther away from your site. That way if one location goes down, the other can take the load and keep your company up and running while you clean up.</p>
<p dir="ltr">Another great aspect to look at when considering the location of your backup, is cost. Putting backup data in a location with cooler temperatures means not having to rely on powered heating for as much of the year. That can really help when your disaster recovery budget is tight. Another money saving option is placing your <a href="http://onlinetech.com/managed-services/it-disaster-recovery/drnow">disaster recovery solution in the cloud</a>. Not only can you spin up servers much faster than a more traditional IT infrastructure, but it allows the flexibility of only paying for the bandwidth and power that’s necessary. This way you don’t have to pay for resources you aren’t going to use, or find yourself stuck without the power you sorely need (especially in a crisis situation).</p>
<p><strong>Consider outsourcing</strong><br />
Even with your data center in-house, outsourcing your disaster recovery solution can be helpful in many ways. Instead of having to shoulder the burden of managing your <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a>, a <a href="http://onlinetech.com/managed-services/overview">hosting provider</a> can provide the facility that will be way more cost-effective and less time intensive.</p>
<p dir="ltr">Having staff from a hosting provider manage your services can also mean not having to spend the time and resources training your own IT staff. Not to mention, in a disaster situation there are likely to be many different things your staff is going to be concerned with &#8211; taking a thing or two off their plate when it really counts can mean a little less sleep lost for you and them (and I can’t think of anything more important than that).</p>
<p dir="ltr">Here are some other resources that may be helpful when considering disaster recovery strategies:</p>
<p><em><a href="http://onlinetech.com/events/disaster-recovery-webinar-series">Disaster Recovery Webinar Series</a></em><br />
Join Online Tech&#8217;s Systems Support Manager Steve Aiello as he leads a three-part webinar series on the topic of disaster recovery.</p>
<p><em><a href="http://resource.onlinetech.com/five-questions-to-ask-your-disaster-recovery-provider/">Seeking a Disaster Recovery Solution? Five Questions to ask your DR Provider</a></em><br />
Disaster recovery plans have become crucial for nearly every industry that relies on connectivity and uptime for business survival.</p>
<p><em><a href="http://resource.onlinetech.com/pci-compliant-disaster-recovery/">PCI Compliant Disaster Recovery</a></em><br />
Within PCI DSS (Payment Card Industry Data Security Standards), there is a standard dedicated to having the merchant create an incident response plan in order to act quickly and surely in the event of a breach.</p>
<p>The post <a href="http://resource.onlinetech.com/disaster-recovery/">Business Continuity and Disaster Recovery</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/disaster-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How the Data Center Industry Lowers the Carbon Footprint</title>
		<link>http://resource.onlinetech.com/data-center-industry-lowers-carbon-footprint/</link>
		<comments>http://resource.onlinetech.com/data-center-industry-lowers-carbon-footprint/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 15:50:03 +0000</pubDate>
		<dc:creator>Anna Ankenbrand</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[data center efficiency]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[energy efficiency]]></category>
		<category><![CDATA[energy efficient data centers]]></category>
		<category><![CDATA[green data centers]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11059</guid>
		<description><![CDATA[<p>Data Center Industry Lowers Carbon Footprint For many years, the data center industry has received a bad rap for being energy hogs.  In 2007, the U.S. Environmental Protection Agency warned everyone that data centers and servers would consume 3% of &#8230; <a href="http://resource.onlinetech.com/data-center-industry-lowers-carbon-footprint/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/data-center-industry-lowers-carbon-footprint/">How the Data Center Industry Lowers the Carbon Footprint</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p><strong>Data Center Industry Lowers Carbon Footprint</strong><br />
For many years, the data center industry has received a bad rap for being energy hogs.  In 2007, the U.S. Environmental Protection Agency warned everyone that data centers and servers would consume 3% of the nation’s energy by 2011. &#8211; <em>This prediction did not happen. It is actually around 1.5%</em> &#8211; Then last year, the New York Times published a damaging article “Power, Pollution, and the Internet” claiming that most data centers wastefully consume a lot of energy.  Read <em><a href="http://resource.onlinetech.com/how-the-cloud-is-changing-the-data-centers-bad-reputation-for-energy-inefficiency/">How the Cloud is Changing the Data Center’s Bad Reputation for Energy Inefficiency</a></em> for a response to some of the major points of the article. What organizations and experts fail to understand is how data centers are actually lowering the carbon footprint.</p>
<p><strong>Lowering the Carbon Footprint</strong><br />
I had a chance to sit down with Yan Ness, co-CEO of Online Tech to discuss his thoughts on how the data center industry has impacted their carbon footprint. Watch the video below:</p>
<p><iframe src="http://www.youtube.com/embed/RlGuz4HURkc?list=UUM8ZIzbuHrrqH6u0jdcNBhA" frameborder="0" width="560" height="315"></iframe></p>
<p>Every piece of hardware consumes some energy.  And for data centers this hardware consumes a lot of power.  As a result, the data center industry has begun using technology to make hardware more efficient.  “We can do more today than we could three or five years ago,” says Ness.  “We use less energy to do more work.”</p>
<p>Ness also uses the following example: If you take all the hundreds of companies who are consuming energy to power their servers and air conditioning and move them into a centralized location there are important advantages. First, the data center is much more efficient than any of the office buildings that were running their servers. Secondly, there is one centralized company paying for all of the power consumed by the servers and other equipment. Now, it makes economical sense for that data center to make capital investments and become more energy efficient; whereas it would be very unlikely that any of these companies could make these types of investments.</p>
<p>Data centers are in the business to store data. It does take power to run the servers, run the equipment, and run the air conditioning to keep the servers cool. And this power costs money. What people fail to consider is that it is in the data center industry’s best interest to become as energy efficient as possible. There is a direct benefit to constantly monitor the energy use of their facilities and make investments to improve efficiencies since it affects the bottom line.<br />
<strong></strong></p>
<p><strong>Data Center Energy Efficiencies</strong><br />
The data center industry has made great strides in incorporating technology and investing in capital improvements to lower their carbon footprint. In 2012, Online Tech invested $1 million dollars into their <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/mid-michigan-data-center">Mid-Michigan data center</a> and received an EPA ENERGY STAR certification for their energy efficiencies. This improvement resulted in Online Tech being in the top 25 percent of facilities in the nation regarding energy performance. Read how <a href="http://resource.onlinetech.com/investing-in-data-center-efficiencies-part-one/">Online Tech has incorporated other energy efficiencies</a> in their <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a>.</p>
<p>Related Articles:<br />
<em><strong><a href="http://resource.onlinetech.com/the-next-generation-data-center-how-michigan-data-centers-fit-the-bill/">The Next Generation Data Center: How Michigan Data Centers Fit the Bill</a></strong></em><br />
Wouldn’t it be cool to have a time machine like Marty McFly in “Back to the Future” to see what technology will be in 20 and 30 years from now? Unfortunately, that’s only possible in the movies. In What will … <a href="http://resource.onlinetech.com/the-next-generation-data-center-how-michigan-data-centers-fit-the-bill/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/could-wind-farms-power-michigan-data-centers/">Could Wind Farms Power Michigan Data Centers?</a></strong></em><br />
Globally, data centers are seeing increases in their power consumption as well as higher energy costs. If you combine these factors together, you can understand why CIOs and data center operators are looking to alternative energy resources to reduce energy … <a href="http://resource.onlinetech.com/could-wind-farms-power-michigan-data-centers/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/michigan-data-center-operator-online-tech-expert-interview-what-is-high-availability/">Online Tech Expert Interview: What is High Availability?</a></strong></em><br />
Using a High Availability (HA) architecture can greatly reduce the risk of losing revenue and customers due to a loss of Internet connectivity or loss of power. However, how much do you really understand about a high availability infrastructure? What … <a href="http://resource.onlinetech.com/michigan-data-center-operator-online-tech-expert-interview-what-is-high-availability/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/data-center-industry-lowers-carbon-footprint/">How the Data Center Industry Lowers the Carbon Footprint</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/data-center-industry-lowers-carbon-footprint/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Compliance Day at the 2013 ETA Expo Tackles Mobile Security Challenges</title>
		<link>http://resource.onlinetech.com/pci-dss-compliance-day-at-the-2013-eta-expo-tackles-mobile-security/</link>
		<comments>http://resource.onlinetech.com/pci-dss-compliance-day-at-the-2013-eta-expo-tackles-mobile-security/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 15:43:39 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[pci cloud]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci mobile]]></category>
		<category><![CDATA[pci mobile security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11066</guid>
		<description><![CDATA[<p>Tomorrow is Compliance Day at the 2013 ETA (Electronic Transactions Association) Annual Meeting &#38; Expo in New Orleans; an event for the payments industry, including hosting and other IT vendors. Online Tech will be exhibiting PCI hosting solutions at booth &#8230; <a href="http://resource.onlinetech.com/pci-dss-compliance-day-at-the-2013-eta-expo-tackles-mobile-security/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/pci-dss-compliance-day-at-the-2013-eta-expo-tackles-mobile-security/">PCI DSS Compliance Day at the 2013 ETA Expo Tackles Mobile Security Challenges</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p dir="ltr"><img class="alignleft" title="PCI Cloud Computing" src="http://www.onlinetech.com/images/packages/packages-pci-cloud.png" alt="PCI Cloud Computing" width="148" height="148" />Tomorrow is Compliance Day at the <strong><a href="http://www.onlinetech.com/events/2013-eta-annual-meeting-a-expo">2013 ETA (Electronic Transactions Association) Annual Meeting &amp; Expo</a></strong> in New Orleans; an event for the payments industry, including hosting and other IT vendors. Online Tech will be exhibiting <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting solutions</a> at booth #1237, including:</p>
<ul>
<li><a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">PCI Cloud Hosting</a></li>
<li><a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">PCI Managed Servers</a></li>
<li><a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">PCI Colocation</a></li>
<li><a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">PCI Disaster Recovery</a></li>
</ul>
<p dir="ltr">Read our previous article featuring an interview with one of the Compliance Day conference speakers Randy Gainer, partner with Davis Wright Tremaine LLP, about <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud service providers</a> and the challenge of PCI cloud computing in <a href="http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/">Cloud-Based Mobile Payment Considerations at ETA Expo: PCI Compliant Cloud is Essential</a>.</p>
<p dir="ltr">Other notable presentations on Compliance Day, April 30, include:</p>
<p><strong>The Future of PCI: Securing Mobile Payments in a Changing World</strong><br />
<em>Speaker: Troy Leach, Chief Technology Officer (CTO), PCI Security Standards Council</em></p>
<p dir="ltr">This session will provide an overview of what’s ahead with the release of the latest version of the PCI DSS mobile standards, as well as how to use the new PCI SSC mobile resources to ensure compliance. It will also shed light on today’s mobile payment environment as well as the associated risks and challenges when it comes to securing payment card data. Read our <a href="http://www.onlinetech.com/resources/white-papers/pci-compliant-data-centers">PCI Compliant Hosting white paper</a> or our <a href="http://www.onlinetech.com/resources/white-papers/mobile-security">Mobile Security white paper</a> for more about compliance and IT.</p>
<p dir="ltr">The session will also address the relationship between PCI standards and EMV (the global standard for credit and debit payment cards based on chip card technology; EMV stands for Europay, MasterCard and Visa, the original developers of the EMV specifications in 1994). Additionally, the discussion will cover new technologies available to reduce security risks and how to take advantage of them when planning for PCI in your business.</p>
<p dir="ltr">Other sessions focus largely on the theme of tackling mobile device security and mobile payment processing with <em>The Future of Device Security</em> and <em>Card Brand Panel</em>, featuring experts from all four card brands.</p>
<p dir="ltr">Not attending the ETA expo? Even if you are, sign up for our upcoming free webinar next week on PCI DSS Guidance for Mobile Security featuring guest Adam Goslin, COO of High Bit Security and Online Tech as we review the challenges and details of the recent PCI mobile guidelines as they relate to PCI DSS and PA DSS compliance. Submit your questions in advance:</p>
<p><strong>Title</strong>: PCI DSS Guidance for Mobile Security<br />
<strong>When</strong>: Tuesday, April 9 @2PM ET<br />
<strong>Register</strong>: <a href="http://www.onlinetech.com/events/pci-dss-guidance-for-mobile-security">Visit the Event page for registration link.</a><br />
<strong>Description</strong>: In February, 2013, the PCI Security Standards Council released a document covering Mobile Payment Acceptance Security Guidelines.  High Bit Security COO, Adam Goslin, will review the highlights of the recent guidelines, detailing some of the clarity and pitfalls contained in the recent mobile guidance from the PCI SSC, including impacts to PCI-DSS and PA-DSS compliance.</p>
<hr />
<p><strong><img class="alignleft" title="Adam Goslin" src="http://resource.onlinetech.com/wp-content/uploads/Adam-Goslin-Photo.jpg" alt="Adam Goslin" width="100" height="150" />Adam Goslin, COO, High Bit Security, LLC</strong><br />
Adam has an IT career that spans more than 15 years, going on to found High Bit Security, a national security services provider, providing penetration testing solutions to clients who need to protect sensitive data in industries such as Healthcare, Credit Card, Financial, or companies that otherwise store Intellectual Property or Personally Identifiable Information. High Bit Security also provides security consulting services to our clients to assist them with their compliance objectives across PCI-DSS, PA-DSS, or simply wish to perform a security best practices audit of their organization. www.HighBitSecurity.com</p>
<hr />
<p>Read more about mobile PCI compliance in:</p>
<p><em><strong><a href="http://resource.onlinetech.com/pci-webinar-recap-updates-to-pci-dss-compliance-for-e-commerce-and-cloud-computing-security/">PCI Webinar Recap: Updates to PCI-DSS Compliance for E-Commerce and Cloud Computing Security</a></strong></em><br />
On February 26th, Adam Goslin, COO of High Bit Security, joined us for the webinar Updates to PCI-DSS Compliance for E-Commerce and Cloud Computing Security. In the hour-long discussion Adam really dug into the specifics of the supplements that came … <a href="http://resource.onlinetech.com/pci-webinar-recap-updates-to-pci-dss-compliance-for-e-commerce-and-cloud-computing-security/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/new-industry-guidelines-for-secure-mobile-payments/">New Industry Guidelines for Secure, PCI Compliant Mobile Payments</a></strong></em><br />
The PCI SSC (Payment Card Industry Security Standards Council) is looking alive this year, rolling out supplemental guides to help clarify a number of evolving PCI technical issues, including: PCI Cloud Computing E-commerce Security ATM Security Mobile Payment Acceptance Security … <a href="http://resource.onlinetech.com/new-industry-guidelines-for-secure-mobile-payments/">Continue reading →</a></p>
<p>References:<br />
<a href="http://www.emvco.com/about_emv.aspx">About EMV</a><br />
<a href="http://www2.electran.org/am13/wp-content/uploads/AM13CDAgenda.pdf">2013 ETA Compliance Day</a> (PDF)</p>
<p>The post <a href="http://resource.onlinetech.com/pci-dss-compliance-day-at-the-2013-eta-expo-tackles-mobile-security/">PCI DSS Compliance Day at the 2013 ETA Expo Tackles Mobile Security Challenges</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-dss-compliance-day-at-the-2013-eta-expo-tackles-mobile-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pairing Cloud Computing Benefits with Security and Compliance</title>
		<link>http://resource.onlinetech.com/cloud-computing-benefits-and-security/</link>
		<comments>http://resource.onlinetech.com/cloud-computing-benefits-and-security/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 15:04:28 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[benefits of cloud computing]]></category>
		<category><![CDATA[cloud benefits]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[HIPAA cloud computing]]></category>
		<category><![CDATA[hipaa compliant cloud]]></category>
		<category><![CDATA[pci cloud computing]]></category>
		<category><![CDATA[pci compliant cloud]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11047</guid>
		<description><![CDATA[<p>The added business value of cloud computing is multi-faceted, as Online Tech’s co-CEO Mike Klein outlined in a previous article, The Six Benefits of Cloud Computing, which I’ll summarize here: Lower Costs Pooling of computing resources means better efficiency and &#8230; <a href="http://resource.onlinetech.com/cloud-computing-benefits-and-security/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/cloud-computing-benefits-and-security/">Pairing Cloud Computing Benefits with Security and Compliance</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-62f1dbf0-46d6-ee31-57f8-0566a91217f9" dir="ltr"><img class="alignleft" title="Private Cloud Computing" src="http://www.onlinetech.com/images/packages/packages-private-cloud.png" alt="Private Cloud Computing" width="170" height="170" />The added business value of <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> is multi-faceted, as Online Tech’s co-CEO Mike Klein outlined in a previous article, <em><a href="http://resource.onlinetech.com/the-six-benefits-of-cloud-computing/">The Six Benefits of Cloud Computing</a></em>, which I’ll summarize here:</p>
<p><strong>Lower Costs</strong><br />
Pooling of computing resources means better efficiency and use of the entire shared IT infrastructure, since only what is needed is distributed to applications on-demand.</p>
<p dir="ltr"><strong>Lower Maintenance Costs</strong></p>
<ol>
<li>Save on hardware upfront and maintenance costs since the cloud uses less physical resources.</li>
<li dir="ltr">If you outsource to a cloud service provider (CSP), you save on server, storage, network and virtualization staffing.</li>
</ol>
<p><strong>Cap-Ex Free Computing</strong><br />
The cloud allows you to eliminate the capital expense associated with building the server infrastructure.</p>
<p><strong>Faster Deployment</strong><br />
Instead of installing and networking a new hardware server, a new server can be brought up and destroyed in a matter of minutes with the cloud.</p>
<p><strong>Scalable</strong><br />
By buying the minimal amount of resources needed, you can easily add storage, RAM and CPU as application demands grow.</p>
<p><strong>Resiliency and Redundancy</strong><br />
With a private cloud, you get automatic failover between hardware platforms, as well as disaster recovery services that bring up your server set in a separate data center in the event of an anomaly at your primary data center.</p>
<p dir="ltr">Yet even with these benefits, concerns around data and application security cause CIO hesitation in adopting the cloud for mission-critical support. The following articles offer insight on cloud security, from the e-commerce, retail and banking industries that deal with credit cardholder data, to the healthcare industry that deals with protected health information (PHI) of patients.</p>
<p><em><strong><a href="http://resource.onlinetech.com/overcoming-healthcare-cio-challenges-with-secure-scalable-hipaa-hosting/">Overcoming Healthcare CIO Challenges with Secure &amp; Scalable HIPAA Hosting</a></strong></em><br />
Big data is the big thing nowadays – analyzing and applying the mass amounts of health information collected daily is one way to improve patient care; an important objective not only due to the obvious but also necessary to keep up with the evolving healthcare payment model as it moves away from pay-per-service to patient health improvement.</p>
<p dir="ltr">But supporting all this big data and processes requires a robust IT system – one solution is a <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/packages/cloud-hosting/high-capacity-hipaa-cloud">high-capacity HIPAA cloud</a>; ideal for massive storage or synchronization. The cloud is highly scalable and grows with changing storage requirements. If outsourced, ask your <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/packages">HIPAA cloud provider</a> if they also provide <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a>, a HIPAA requirement. … <a href="http://resource.onlinetech.com/overcoming-healthcare-cio-challenges-with-secure-scalable-hipaa-hosting/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/state-of-cloud-security-vetting-applications-and-cloud-providers-for-compliance-and-security/">State of Cloud Security: Vetting Applications and Cloud Providers for Compliance and Security</a></strong></em><br />
Only 43 percent of organizations audit or assess cloud computing resources before deployment. While vetting cloud computing providers for security may seem time-consuming, organizations should ask if their <a href="http://www.onlinetech.com/">cloud infrastructure as a service providers</a> (IaaS) can provide an updated audit report of their services and data center facilities. What types of audits should you look for in a cloud computing/data center provider?</p>
<p><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a><br />
The Statement on Standards for Attestation Engagements No. 16 replaced <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a> in June 2011. A SSAE 16 audit measures the controls relevant to financial reporting; it verifies that the controls and processes set in place by a data center are actually followed. There are two types:  … <a href="http://resource.onlinetech.com/state-of-cloud-security-vetting-applications-and-cloud-providers-for-compliance-and-security/">Continue reading →</a></p>
<p><em><strong><a href="http://resource.onlinetech.com/your-cloud-hosting-provider-may-be-pci-compliant-but-that-doesnt-mean-you-are/">Your Cloud Hosting Provider May Be PCI Compliant But That Doesn’t Mean You Are</a></strong></em><br />
Compliance is non-transferable, is the jist of the PCI SSC’s recent supplement on <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">PCI cloud computing</a> guidelines for merchants (e-commerce, retail, franchise and anyone that deals with credit cardholder data). Directly referencing merchants that work with cloud service providers (CSP’s), the supplement lists a number of challenges of working with CSPs, one being important enough to single out in standard 5.1:</p>
<p>What does “I am PCI compliant” mean? Essentially, even if you contract with a <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting provider</a> that has successfully achieved an attestation of compliance with PCI DSS version 2.0, meaning they were independently audited and reviewed by a Qualified Security Assessor (QSA), this does not mean you as the merchant/client automatically achieves PCI compliance. A PCI cloud computing service provider can fulfill a number of the <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/resources/pci-compliant-services">PCI technical requirements</a>, but you still need to do due diligence to maintain your organization’s security and compliance. … <a href="http://resource.onlinetech.com/your-cloud-hosting-provider-may-be-pci-compliant-but-that-doesnt-mean-you-are/">Continue reading →</a></p>
<p>The post <a href="http://resource.onlinetech.com/cloud-computing-benefits-and-security/">Pairing Cloud Computing Benefits with Security and Compliance</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cloud-computing-benefits-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliant Tips: Working With a Hosting Provider</title>
		<link>http://resource.onlinetech.com/pci-compliant-tips-working-with-a-hosting-provider/</link>
		<comments>http://resource.onlinetech.com/pci-compliant-tips-working-with-a-hosting-provider/#comments</comments>
		<pubDate>Thu, 25 Apr 2013 19:07:25 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11040</guid>
		<description><![CDATA[<p>Any company that stores, transmits, and/or processes credit card data needs to be compliant with the Payment Card Industry Data Security Standards (PCI DSS). This is oftentimes a cumbersome task, involving time, money, and other resources that can put strain &#8230; <a href="http://resource.onlinetech.com/pci-compliant-tips-working-with-a-hosting-provider/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/pci-compliant-tips-working-with-a-hosting-provider/">PCI Compliant Tips: Working With a Hosting Provider</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-1b6c3906-428e-3bf6-f5f6-d9ca0f55013c" dir="ltr">Any company that stores, transmits, and/or processes credit card data needs to be compliant with the Payment Card Industry Data Security Standards (PCI DSS). This is oftentimes a cumbersome task, involving time, money, and other resources that can put strain on a business. In order to simplify the road to compliance, many companies choose to outsource their applications to a <a href="http://onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI hosting provider</a>.</p>
<p dir="ltr">This can have its own set of challenges, however. The responsibility for <a href="http://onlinetech.com/compliant-hosting/pci-compliant-hosting/resources/what-is-pci-compliance">PCI compliance</a> is ultimately on the merchant, making the decision of who to work with an important and difficult choice. Hopefully these tips can help make that process a little easier.</p>
<p><strong>Get the audit reports</strong><br />
When shopping around for a PCI compliant hosting provider, doing the due diligence to make sure they’ve followed all the necessary guidelines will save time and money when your auditor comes to call. Any potential providers should have a PCI DSS Report on Compliance (ROC) from their independent audit available to share with you. Not only will it provide you with explicit processes they use to keep them compliant, but the ROC can then be given to the QSA (Quality Security Assessor) to make your own audit simpler and quicker.</p>
<p><strong>Keep your service providers organized</strong><br />
Organization is going to go a long way, no matter what subject we’re talking about. However, in regards to PCI hosting providers, having a concise list of providers that you work with, complete with contract information, is imperative. This list is going to make it easier for you to track the provider’s audit records, to ensure that they can prove to you ongoing compliance. Be sure to update that report any time a provider is added, removed, or if the contract has changed.</p>
<p><strong>Get accountability in writing</strong><br />
PCI hosting providers should have a process in the event of a data breach. This plan should include a time frame for merchant notification. It should also include both the process of storing, and of destroying data once the contract has expired. Understanding how your data is being disposed of can keep you and your service provider from ending up with a fate similar to Walgreens, who was found in California last year with a mixture of hazardous waste and PHI in their dumpsters, and had to <a href="http://www.freeadvice.com/news/Business+Law/walgreens-judgment.htm">pay over $16 million in fines</a>.<br />
<strong></strong></p>
<p><strong>Monitor your provider’s compliance</strong><br />
As we’ve said countless times before: compliance isn’t just a check in the box, but a constant process to provide ongoing security to customers. While it would be easy to simply see that a hosting provider has been independently audited, it is crucial to continue checking back in. This way you have transparency into details of the provider’s workings that are important to your business &#8211; things like their dates of compliance and audit reports, for example. Simply put, having a good relationship with your hosting provider can help your business run more smoothly, and could keep you from the nasty costs and customer dissatisfaction that comes with a data breach.</p>
<p dir="ltr">To a business owner, the safety of customer data should be paramount to all other concerns. PCI compliant hosting providers can work together with merchants to keep that data protected without the extensive costs and resources associated with in-house hosting. But not all service providers are the same. So take the time to truly qualify your service provider. Not only can it save you time and money in the long run, it might save you some sleepless nights too.</p>
<p>Other Reading:<br />
<a href="http://resource.onlinetech.com/who-needs-pci-compliance-exactly/">Who Needs PCI Compliance, Exactly?</a><br />
<a href="http://resource.onlinetech.com/pci-compliance-breakdown-a-tale-of-two-servers/">PCI Compliance Breakdown: A Tale of Two Servers</a><br />
<a href="http://resource.onlinetech.com/tackling-pci-compliance-challenges-in-the-cloud/">Tackling PCI Compliance Challenges in the Cloud</a></p>
<p>The post <a href="http://resource.onlinetech.com/pci-compliant-tips-working-with-a-hosting-provider/">PCI Compliant Tips: Working With a Hosting Provider</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/pci-compliant-tips-working-with-a-hosting-provider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 HCCA: The Evolving Congressional Landscape</title>
		<link>http://resource.onlinetech.com/2013-hcca-the-evolving-congressional-landscape/</link>
		<comments>http://resource.onlinetech.com/2013-hcca-the-evolving-congressional-landscape/#comments</comments>
		<pubDate>Wed, 24 Apr 2013 15:11:57 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[federal health IT]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[healthcare legislation]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=11028</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare &#8230; <a href="http://resource.onlinetech.com/2013-hcca-the-evolving-congressional-landscape/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-hcca-the-evolving-congressional-landscape/">2013 HCCA: The Evolving Congressional Landscape</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #919 at the Health Care Compliance Association (HCCA)’s <a href="http://www.onlinetech.com/events/2013-health-care-compliance-association-compliance-institute">17th Annual Compliance Institute Conference</a> April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.<strong><br />
</strong></p>
<p><strong>The Evolving Congressional Landscape</strong><br />
<em>Speaker: Kimberly Brandt, Chief Oversight Counsel, Senate Finance Committee, Minority Staff</em><br />
*All views are her own and not Senator Hatch’s or the Finance Committee’s.</p>
<p>What does the Senate Finance Committee Do?<br />
Quick Facts on the Senate Finance Committee:</p>
<ul>
<li>Largest committee in the Senate</li>
<li>24 members  (Including chair and ranking member: 13 Democrats and 11 Republicans)</li>
<li>One of the most powerful committees in congress</li>
<li>Oversee 50% of the federal budget</li>
<li>Confirms over 80 presidential nominations</li>
<li>Jurisdiction of Department of HHS – Centers for Medicare and Medicaid.</li>
</ul>
<p>What the Senate Finance Committee does:</p>
<ul>
<li>Legislative Hearings &#8211; Markups and approval of legislation such as Patient Protection and Affordable Care Act</li>
<li>Oversight Hearings – deals with fraud, waste and abuse issues and the implementation of PPACA</li>
<li>Confirmation Hearings  &#8211; The Senate Finance Committee confirms:</li>
</ul>
<ul>
<li>Secretary of HHS,</li>
<li>CMS Administrator</li>
<li>Inspector General of HHS</li>
</ul>
<p>The three biggest priorities for 113th congress include:</p>
<ul>
<li>Healthcare Patient Protection and Affordable Care Act (PPACA)</li>
<li>Implementation Tax</li>
<li>Reform Entitlement Reform – which is a huge issue with Medicare, Medicaid and Social Security hurrying towards insolvency.</li>
</ul>
<p>The Senate Finance Committee will also be conducting investigations on Physician Owned Distributors (PODs). There are concerns related to conflict of interests in regards to PODs that may place personal profit ahead of care. The OIG issued a Special Fraud Alert concerning POD’s. Some of the arrangements are suspect and they want to be sure the arrangements are legal.</p>
<p>There is a high level of regulations as a result of PPACA. Lots of regulator reform and burden issues will continue to be an area of focus surrounding adoption and implementation of PPACA. Fraud and abuse issues are on the rise and a strong focus will be on health reform anti-fraud provisions.</p>
<p>The focus is shifting from complete repeal of PPACA, to targeted repeal between Democrats and Republicans. There have been numerous oversight efforts related to PPACA provisions. Most recently over $1 billion was cut from exchanges related to co-op loan programs due to the fiscal cliff deal.</p>
<p>In regards to the implementation of the PPACA exchanges, 33 states are going to participate in the federal exchanges, while 18 states and D.C. are going to run their own exchanges. These numbers were unexpected and it was actually thought that it would go the other way.</p>
<p>There is great concern regarding the costs of implementing PPACA. So far, HHS has given states more than 3.5 billion to build the technology and infrastructure to operate the health insurance exchanges, yet the IRS and HHS systems are insufficient. $300 million is needed to be sure that the IRS has the right technology and infrastructure in place this year.<br />
For more information visit:<br />
<a href="http://www.finance.senate.gov/">www.finance.senate.gov</a></p>
<p>Related Articles:<br />
<em><a href="http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/">2013 HCCA: Latest Trends in Data Breach Threats</a></em><br />
<em><a href="http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/">2013 HCCA: Mobile Threats and How Healthcare Can Reduce Risks</a></em><br />
<a href="http://resource.onlinetech.com/2013-hcca-cyber-compliance/">2013 HCCA: Cyber Compliance</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-hcca-the-evolving-congressional-landscape/">2013 HCCA: The Evolving Congressional Landscape</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-hcca-the-evolving-congressional-landscape/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud-Based Mobile Payment Considerations at ETA Expo: PCI Compliant Cloud is Essential</title>
		<link>http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/</link>
		<comments>http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/#comments</comments>
		<pubDate>Wed, 24 Apr 2013 14:30:40 +0000</pubDate>
		<dc:creator>Stephanie Vogel</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud-based mobile]]></category>
		<category><![CDATA[electronic transactions association]]></category>
		<category><![CDATA[ETA]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[pci cloud hosting]]></category>
		<category><![CDATA[pci compliant cloud]]></category>
		<category><![CDATA[pci mobile security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10998</guid>
		<description><![CDATA[<p>Only a week left until the 2013 ETA (Electronic Transactions Association) Annual Meeting &#38; Expo in New Orleans. This conference is going to be held at the New Orleans Convention Center from April 30-May 2, and is expected to have &#8230; <a href="http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/">Cloud-Based Mobile Payment Considerations at ETA Expo: PCI Compliant Cloud is Essential</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-145ae9b7-3c44-cceb-dec2-b0c5aaf84bd9" dir="ltr"><img class="alignnone" title="2013 ETA Annual Meeting &amp; Expo" src="http://www2.electran.org/am13/img/GRAPHIC-LANDING-AM13.jpg" alt="2013 ETA Annual Meeting &amp; Expo" width="586" height="302" /></p>
<p dir="ltr">Only a week left until the <strong><a href="http://www.onlinetech.com/events/2013-eta-annual-meeting-a-expo">2013 ETA (Electronic Transactions Association) Annual Meeting &amp; Expo</a></strong> in New Orleans. This conference is going to be held at the New Orleans Convention Center from April 30-May 2, and is expected to have over 3,000 industry executives to learn from and collaborate with.</p>
<p dir="ltr">Compliance is one of the many subjects being highlighted at the expo. Compliance Day will be held on April 30th, and will have over a dozen different speakers, both on panels and running sessions devoted to compliance in the payments industry.</p>
<p dir="ltr">One of these speakers is Randy Gainer, a partner with Davis Wright Tremaine LLP, who I had the pleasure of speaking with in regards to his session on challenges associated with cloud-based mobile solutions. Having focused on data breach litigation for over 9 years, and with over 20 years working for Davis Wright Tremaine LLP in the IT sphere, he has great insight into key areas of prevention and risk throughout the payments industry.</p>
<p dir="ltr">Gainer explained that there is a shift in focus when moving to the cloud. Instead of taking care of an infrastructure in-house, businesses are increasingly relying on outsourced <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud service providers</a> (CSP) for the security of that core infrastructure. This can be a huge plus for businesses that no longer have to deal with the challenges of creating and maintaining that foundation, including merchants and mobile payment providers.</p>
<p dir="ltr">However, Gainer attests that it doesn’t remove security from the considerations of the company. Instead, the focus should change to securing the applications that will be placed on the cloud infrastructure, after ensuring that the CSP meets <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI DSS compliance</a> for their part in the puzzle.</p>
<p dir="ltr">Outsourcing to a CSP means finding the right provider to partner with. A good CSP should fundamentally have at least two independent audit reports available for your review. The first is PCI DSS Level 1 report on compliance, prepared by an independent, qualified QSA (Qualified Security Assessor).</p>
<p dir="ltr">The second audit report is the <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2 Type II</a> (not to be confused with <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/soc-1-hosting">SOC 1</a> or <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>) developed by the AICPA (American Institute of Certified Public Accountants) specifically for technology vendors handling sensitive information. (Gainer notes that it’s important for a merchant to perform their due diligence on the CPA as well).</p>
<p dir="ltr">With many businesses not really sure how best to assess cloud security, Gainer explains that companies have, in the past, started small. That involved putting less critical data in a cloud environment first, where security is not as large of a concern. That doesn’t mean that there aren’t any secure cloud providers out there. “There are a subset of cloud vendors who have stepped up, and are securing sensitive data in the cloud,” Gainer mentions.</p>
<p dir="ltr"><a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting/pci-private-cloud"><img class="alignleft" title="PCI Compliant Cloud" src="http://www.onlinetech.com/images/packages/packages-pci-starter-cloud.png" alt="PCI Compliant Cloud" width="170" height="170" /></a>So, what can we expect in the future? Gainer says that we’re still in the early days of <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/packages/cloud-hosting">PCI compliant cloud</a> adoption. But there is promise. The supplements that came out earlier this year by the PCI SSC push an important point: you can meet PCI DSS compliance with a cloud service provider.</p>
<p dir="ltr">“It’s encouraging to me &#8211; it helped rebut the myth that it just can’t be done in the cloud. It’s a useful change to the [PCI] SSC],” stated Gainer, who cites the apprehension associated with perceived cloud insecurities. “It has the potential to be as good, and probably better than in-house platforms.”</p>
<p dir="ltr">If you’re going to be at the ETA Meeting &amp; Expo next week, Randy Gainer’s talk, <em>Legal and Technical Security Challenges for Cloud-Based Mobile Payment Solutions</em>, looks to be very informative. Any merchants who need a compliant environment and are already working or plan to partner with a CSP do not want to miss this learning opportunity. He will be speaking 3:15-4pm on Tuesday April 30th.</p>
<p dir="ltr">Also, don’t forget to come say hello to Online Tech in <strong>booth #1237</strong> between sessions.</p>
<hr />
<p><strong>Randy Gainer, Davis Wright Tremaine LLP</strong></p>
<p><img class="alignleft" title="Randy Gainer" src="http://www.dwt.com/files/Professional/647ca61a-41f0-41cd-b933-24e29e338302/Presentation/Photo/employee_GainerRandynew.jpg" alt="Randy Gainer" width="98" height="140" />Randy Gainer litigates information technology, intellectual property, communications, and media cases as Partner for <a href="http://www.dwt.com/">Davis Wright Tremaine LLP</a>. He also advises business leaders regarding steps they need to take to comply with data security laws and industry standards, privacy requirements, and data breach notification statutes, and assists businesses conducting information system risk assessments.</p>
<p dir="ltr"><em>Please note that Randy Gainer has no business relationship with Online Tech other than the generous sharing of his domain expertise.</em></p>
<p><a href="http://www.onlinetech.com/resources/white-papers/mobile-security"><img class="alignright" title="Mobile Security White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-mobile.png" alt="Mobile Security White Paper" width="251" height="113" /></a>Find out how to handle mobile app and device security in by reading our <strong><a href="http://www.onlinetech.com/resources/white-papers/mobile-security">Mobile Security white paper</a></strong>. This white paper explores approaches to mobile security from risk assessment (what data are truly at risk), enterprise architecture (protect the data before the devices), policies and technologies, and concludes with an example of a mobile security architecture designed and implemented within a hospital environment in which both enabling caregivers and protecting privacy, integrity, and confidentiality are paramount.</p>
<p><a href="http://www.onlinetech.com/resources/white-papers/pci-compliant-data-centers"><img class="alignleft" title="PCI Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-pci.png" alt="PCI Compliant Hosting White Paper" width="251" height="114" /></a>Looking for more information on PCI hosting requirements, recommendations, and the foundation of a secure <a href="http://resource.onlinetech.com/franchise-point-of-sale-pos-systems-targeted-in-nationwide-pci-data-breach/company/michigan-data-centers/compliance/pci-compliant-data-centers">PCI compliant data center</a>?</p>
<p><a href="http://resource.onlinetech.com/franchise-point-of-sale-pos-systems-targeted-in-nationwide-pci-data-breach/resources/white-papers/pci-compliant-data-centers">Download our PCI Compliant Hosting white paper</a> now for a complete guide to PCI hosting with IT vendors.</p>
<p>Related Articles:<br />
<em><a href="http://resource.onlinetech.com/pci-compliance-at-the-eta-annual-meeting-expo/">PCI Compliant at the ETA Annual Meeting &amp; Expo</a></em><br />
<em><a href="http://www.onlinetech.com/resources/e-tips/pci-compliance/four-ways-to-gain-transparency-with-pci-hosting-providers">Four Ways to Gain Transparency with PCI Hosting Providers</a></em><br />
<em><a href="http://www.onlinetech.com/resources/e-tips/pci-compliance/risk-assessments-for-the-pci-compliant-cloud">Risk Assessments for the PCI Compliant Cloud</a></em></p>
<p>The post <a href="http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/">Cloud-Based Mobile Payment Considerations at ETA Expo: PCI Compliant Cloud is Essential</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cloud-based-mobile-payment-considerations-at-eta-expo-pci-compliant-cloud-is-essential/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 HCCA: Latest Trends in Data Breach Threats</title>
		<link>http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/</link>
		<comments>http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/#comments</comments>
		<pubDate>Tue, 23 Apr 2013 19:07:33 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[2011 hipaa audits]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10986</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare &#8230; <a href="http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/">2013 HCCA: Latest Trends in Data Breach Threats</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #919 at the Health Care Compliance Association (HCCA)’s <a href="http://www.onlinetech.com/events/2013-health-care-compliance-association-compliance-institute">17th Annual Compliance Institute Conference</a> April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.<strong><br />
</strong></p>
<p><strong>Advanced Discussion Group: The Latest Trends in Data Breach Threats</strong><br />
<em>Speaker: Ted Kobus, Co-Leader, Privacy and Data Protection, BakerHostetler</em></p>
<p>Ted directed an open roundtable discussion among twenty or so audience members who worked within either a compliance, government or consultant role surrounding data breaches.</p>
<p dir="ltr">Those that worked on the compliance side of a data breach were asked to share what their role entailed after a breach occurred and how they move forward providing information to appropriate parties in the wake of a breach. All were in agreement that their position required heavy lifting on the side of analysis in order to determine:</p>
<ul>
<li>What sort of data had been breached</li>
<li>How much data had been breached</li>
<li>What sorts of organizations needed to be involved in the aftermath of the breach</li>
<li>What portion of the general public was affected by the breach</li>
<li>Which stakeholders needed to be involved in the decision making process to move forward</li>
</ul>
<p dir="ltr">There was some volleying back and for the between the audience on whether or not it is better to push a notification through when there had been a breach before sufficient facts and evidence had been collected, and then back track if the breach was not as big as initially anticipated. Or whether it was better to gather as much information as possible and answer the items bulleted above before making any sort of public facing announcement.</p>
<p dir="ltr">The discussion went on to include the focus of CEOs versus Compliance Officers in the wake of the breach. For most CEOs of an organization, reputation, operations and financials are going to be their primary point of focus in the wake of a breach, but will take a backseat during the initial breach investigation.</p>
<p dir="ltr">Questions circled back around to whether or not is right or wrong to push out notification of the breach, before all of the information is collected. After a bit of deliberation on the key questions to ask, most audience members agreed that the following questions should be answered before any type of notification is pushed out the door.</p>
<ul>
<li>How did the breach happen?</li>
<li>What is the organization going to put in place so that it does not happen again?</li>
<li>What data was breached and how much?</li>
<li>Was it encrypted?</li>
<li>Who from the general public are you going to be hearing from?</li>
</ul>
<p dir="ltr">With the answer to those questions in place, the notification and communication that ensues between the organization, affected public and media will be much smoother to deal with from the PR side of the situation.</p>
<p dir="ltr">Ted noted that the two biggest aspects of the Final Rule to make note of for every organization was compliance and documentation.</p>
<p dir="ltr">Key discussion takeaway?</p>
<p dir="ltr">Your organization must make developing a culture of compliance its first priority. It will make life easier on everyone in the organization in the event of a breach investigation.</p>
<p>Related Articles:<br />
<em><a href="http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/">2013 HCCA: The Defining Moments of a Data Breach</a></em><br />
<em> <a href="http://resource.onlinetech.com/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates/">HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates</a></em><br />
<em> <a href="http://resource.onlinetech.com/healthcare-industry-loses-7-billion-due-to-data-breaches/">Healthcare Industry Loses $7 Billion Due to HIPAA Data Breaches</a></em></p>
<p>The post <a href="http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/">2013 HCCA: Latest Trends in Data Breach Threats</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-hcca-latest-trends-in-data-breach-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Center Compliance &#8211; It’s Mission Critical! Online Tech Presents on HIPAA &amp; PCI</title>
		<link>http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/</link>
		<comments>http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/#comments</comments>
		<pubDate>Tue, 23 Apr 2013 16:27:32 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[data center audits]]></category>
		<category><![CDATA[data center compliance]]></category>
		<category><![CDATA[data center standards]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[ssae 16]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10979</guid>
		<description><![CDATA[<p>Online Tech’s Director of Operations and previous Crain’s Detroit CIO of the Year, Jason Yaeger, is presenting today at the 7&#215;24 Exchange Southern California Chapter’s meeting, Data Center Compliance &#8211; It’s Mission Critical! As Online Tech’s Risk Management and Security &#8230; <a href="http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/">Data Center Compliance &#8211; It’s Mission Critical! Online Tech Presents on HIPAA &#038; PCI</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="docs-internal-guid-24e9bd8e-37ac-69b9-c91f-766e9d145211" dir="ltr">Online Tech’s Director of Operations and previous Crain’s Detroit CIO of the Year, Jason Yaeger, is presenting today at the 7&#215;24 Exchange Southern California Chapter’s meeting, <a href="http://www.onlinetech.com/events/online-tech-presents-on-pci-a-hipaa-hosting-at-7x24-exchange-in-los-angeles">Data Center Compliance &#8211; It’s Mission Critical!</a> As Online Tech’s Risk Management and Security Officer, Jason has had experience leading the company through the successful completion of <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70 Type I</a>, <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70 Type II</a>, <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>, <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a> and <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI</a>.</p>
<p><strong>Where</strong>: T5 Data Center, El Segundo, CA<br />
<strong>Time</strong>: 3:30-6PM<br />
<strong>Date</strong>: Tuesday, April 23, 2013<br />
<strong>Description</strong>: With so much confusion surrounding compliance issues, please join us for an in-depth discussion about auditing and compliance in the <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> including understanding how SAS 70; SSAE 16, SOC 1, 2 &amp; 3 reports impact the data center as well as comparing, contrasting and elucidating the features of PCI DSS and HIPAA. Find out how auditing and compliance impact processes, design and operations. After the panel, tours will be conducted of T5’s new data center.</p>
<p dir="ltr"><strong>Panelists include:</strong></p>
<p><em>Lynn McIntier, IT Audit Senior Manager at SingerLewak LLP</em><br />
SingerLewak LLP is a regional accounting and consulting firm. Lynn was previously Senior Manager of IT Consulting &amp; Audit at Moss Adams LP as well as IT Manager at Irving Tanner Company. Lynn is a expert in audit related to IT operations and brings a wealth of experience to the panel discussion.</p>
<p><em>Marcy Maxwell, Director, Security Operations and Business Controls, Digital Realty</em><br />
Marcy brings 18 years of industry security experience to the panel discussion from her positions at AboveNet, 365 Main and Digital Realty. Marcy is responsible for driving operational consistency for Digital Realty&#8217;s security operations across the portfolio of 22.6M square feet, which includes Security Policy, Emergency Response training programs, and the annual SOC 2 program.</p>
<p><em><img class="alignleft" title="Jason Yaeger" src="http://resource.onlinetech.com/wp-content/uploads/Jason-Yaeger.png" alt="Jason Yaeger" width="250" height="209" />Jason Yaeger, Online Tech&#8217;s Director of Operations, Risk Management and Security Officer</em><br />
He has guided the company through the successful completion of many audits including SAS 70 Type I, SAS 70 Type II, SSAE 16, SOC 1-3, HIPAA and most recently PCI. He will share how these audits and compliance standards affect not only operations and processes, but also other design implications. He is also Vice President and founding member of 7&#215;24 Exchange Southeast Michigan Chapter.</p>
<p dir="ltr">For more about data center standards and audits, read:</p>
<p dir="ltr"><a href="http://www.onlinetech.com/resources/e-tips/sas-70/data-center-standards-cheat-sheet-from-hipaa-to-soc-2">Data Center Standards Cheat Sheet &#8211; From HIPAA to SOC 2</a></p>
<p>The post <a href="http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/">Data Center Compliance &#8211; It’s Mission Critical! Online Tech Presents on HIPAA &#038; PCI</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/data-center-compliance-its-mission-critical-online-tech-presents-on-hipaa-pci/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 HCCA: Mobile Threats and How Healthcare Can Reduce Risks</title>
		<link>http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/</link>
		<comments>http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/#comments</comments>
		<pubDate>Tue, 23 Apr 2013 14:38:18 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Mobile Security]]></category>
		<category><![CDATA[byod]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[mHealth]]></category>
		<category><![CDATA[mobile health IT]]></category>
		<category><![CDATA[mobile healthcare]]></category>
		<category><![CDATA[mobile security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10970</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare &#8230; <a href="http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/">2013 HCCA: Mobile Threats and How Healthcare Can Reduce Risks</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #919 at the Health Care Compliance Association (HCCA)’s <a href="http://www.onlinetech.com/events/2013-health-care-compliance-association-compliance-institute">17th Annual Compliance Institute Conference</a> April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.<strong><br />
</strong></p>
<p><strong>Mobile Threats and How Healthcare can Reduce Risks</strong><br />
<em>Speakers: Rick Cam, President &amp; Co-Founder, ID Experts</em><br />
<em> Ted Kobus, Co-Leader, Privacy &amp; Data Protection, Baker Hostetler</em></p>
<p dir="ltr">Rick and Ted opened with a couple of questions for the audience:</p>
<ul>
<li>How many of your organizations allow use of personal mobile devices in your practices?</li>
<li>Does your organization have policies and best practices in place for using those devices?</li>
<li>How many are in compliance roles within your organization that set those policies and standards?</li>
</ul>
<p dir="ltr">They cited a study that had been conducted to find how many organizations allow their employees to bring their own devices (<a href="http://www.onlinetech.com/events/byod-from-concept-to-reality">BYOD</a>) to work. Roughly 81% answered that their employees can bring their own device to work. 53% of those surveyed are allowed to use unsecure wi-fi access. They continued by asking how many people in the room had longer than a 4-digit password for the cell phones and tablets. Ted and Rick went on to explain that most password policies within organizations are inconsistent across the board for devices that are used for or contain <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms#Protected%20Health%20Information">PHI (protected health information)</a>.</p>
<p dir="ltr">While they noted that cell phones and tablets are a great platform for collaborating and sharing information across organizations, how organizations deal with inconsistencies in their policies will determine how well they are able to mitigate risks in relation to a BYOD policy for employees.</p>
<p dir="ltr">Creating BYOD policies are necessary for organizations to mitigate risk and there are several ways to go about implementing those policies and creating a culture of compliance. Treating the device as corporate property is the quickest way to begin installing a culture of compliance in an organization where BYOD policies are in place. Employees wouldn’t be quick to share a company-owned phone or laptop with their spouses and children.</p>
<p dir="ltr">Another solution to mitigate the risk that is inherent with these devices is to install <a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">encryption</a>. Ted and Rick shared several examples where devices had been stolen and encryption could helped prevent the breach of PHI data if they had been in place and turned on. Just because the device requires a password, does not mean that the device is encrypted.</p>
<p dir="ltr">An audience member raised the question as to whether a BYOD is really in the best interest of an organization. The audience member pointed out that their organization issues every employee a company owned iPhone that is encrypted, but several employees still insist on being able to use their own device and they wanted to know how to deal with those kinds of situations when they arise.</p>
<p dir="ltr">Ted and Rick suggested having an organization wide training day for policies and best practices for the use of personal devices, citing that a CEO is not going to want to attend an entire of training and that may trickle down encouraging employees to simply use the organization issued device.</p>
<p dir="ltr">BYOD policies, information that may have been on one device gets moved to another device. Encrypting individual files vs. encrypting the entire device. Just because there is a password on it does not equal encryption.</p>
<p dir="ltr">Text messaging is another issue for many organizations at this point in time and the usage of text messaging is growing rapidly. Many organizations, again, have not yet identified all of the risks associated with sharing information via text message. By educating people to slow down and check the information they are sending, organizations will be a step ahead and better able to mitigate risks associated with text messaging.</p>
<p>Key lecture takeaway?<br />
“The only thing worse than not having a policy? Not following your policy.”</p>
<p><a href="http://www.onlinetech.com/resources/white-papers/mobile-security"><img class="alignleft" title="Mobile Security White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-mobile.png" alt="Mobile Security White Paper" width="251" height="113" /></a>Find out how to handle mobile security in your workplace by reading our <strong><a href="http://www.onlinetech.com/resources/white-papers/mobile-security">Mobile Security white paper</a></strong>. This white paper explores approaches to mobile security from risk assessment (what data are truly at risk), enterprise architecture (protect the data before the devices), policies and technologies, and concludes with an example of a mobile security architecture designed and implemented within a hospital environment in which both enabling caregivers and protecting privacy, integrity, and confidentiality are paramount.</p>
<p>Related Links:<br />
<a href="http://resource.onlinetech.com/global-mobile-trends-see-rise-in-byod-policies-lag/">Global Mobile Trends See Rise in BYOD; Policies Lag</a><br />
<a href="http://resource.onlinetech.com/mobile-security-white-paper-policies-technology-byod/">Mobile Security White Paper: Policies, Technology &amp; BYOD</a><br />
<a href="http://resource.onlinetech.com/protecting-health-information-in-the-era-of-mobile-devices-the-practicalities-problems-of-byod/">Protecting Health Information in the Era of Mobile Devices: The Practicalities &amp; Problems of BYOD</a><br />
<a href="http://resource.onlinetech.com/recommendations-for-mobile-health-it-advancement/">Recommendations for Mobile Health IT Advancement</a><br />
<a href="http://resource.onlinetech.com/securing-smartphones-simple-steps-to-avoid-a-data-breach/">Securing Smartphones: Simple Steps to Avoid a Data Breach</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/">2013 HCCA: Mobile Threats and How Healthcare Can Reduce Risks</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-hcca-mobile-threats-and-how-healthcare-can-reduce-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 HCCA: The Defining Moments of a Data Breach</title>
		<link>http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/</link>
		<comments>http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/#comments</comments>
		<pubDate>Mon, 22 Apr 2013 20:24:33 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HCCA]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[hipaa data breach]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10963</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare &#8230; <a href="http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/">2013 HCCA: The Defining Moments of a Data Breach</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #919 at the Health Care Compliance Association (HCCA)’s <a href="http://www.onlinetech.com/events/2013-health-care-compliance-association-compliance-institute">17th Annual Compliance Institute Conference</a> April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.<strong><br />
</strong></p>
<p><strong>The Defining Moments of a Data Breach</strong><br />
<em>Speakers: John Ford, Principal, Sienna Group LLC</em><br />
<em> Kurt Long, CEO, Founder, FairWarning Inc.</em></p>
<p dir="ltr">Kurt and John have teamed up several times to give this presentation and the following presentation was a dialogue between both Kurt and John on dealing with healthcare data breaches.</p>
<p dir="ltr"><strong>Kurt</strong> &#8211; Data breaches with a healthcare organization take on many forms. Research shows that most organizations are not well prepared to detect and combat data breaches.</p>
<p dir="ltr"><strong>John</strong> &#8211; Fraud is a huge issue. In many of the fraud scenarios, it pertains mainly to patient data. Healthcare fraud in the U.S. costs the industry $80 billion to $225 per year. The key to lowering the number is to catch the criminal behavior at the point of origin.</p>
<p dir="ltr"><strong>Kurt</strong> – Organization today are dealing with much more heightened issues pertaining to a data breach. There are several types of “follow-up” crimes that can come out of a data breach of patient information. Kurt highlighted the following:</p>
<ul>
<li>IRS tax fraud</li>
<li>Identifying theft – creating false financial information is very common with deceased patients.</li>
<li>Racketeering</li>
<li>Mail fraud</li>
<li>Immigration fraud</li>
<li>Creation of “shell” businesses for the purpose of money laundering</li>
</ul>
<p dir="ltr">Organized criminals have noticed that health care providers have incredibly critical information pertaining to an individuals’ financial information and their systems often have major privacy and security vulnerabilities.</p>
<p dir="ltr"><strong>John</strong> &#8211; Most people are not prepared for data breach that occurs through organized crime. Those types of organizations typically receive a call from law enforcement (considered an external notification) and in those cases, everything comes to a grinding halt for about 48 hours while executive and operational teams are deployed to investigate the source of the breach.</p>
<p dir="ltr">The general theme at that point in time is to develop a breach response plan. Most people do not have an adequate plan that they test prior to any sort of breach and are scrambling to put one in place.</p>
<p dir="ltr">Organizations need to have a plan already in place because time is not your organization’s time in a situation that big. Upon notification of the breach, the organization will be pressed for an explanation from everyone; from the media to patients and providers.</p>
<p dir="ltr">John listed the key issues to address at that time of a breach:</p>
<ul>
<li>Learning how the internal breach occurred</li>
<li>Figuring out why the breach was not detected to begin with</li>
<li>Understanding the scope of fraud as a result of the breach</li>
<li>Steps patients and providers should be taking as a result of the breach</li>
<li>What the organization is doing as a result of the breach</li>
</ul>
<p dir="ltr">Having a well-crafted plan in place for a data breach will be imperative for your organization. The plan must include a method for active user activity monitoring and thorough log correlation and analysis.</p>
<p dir="ltr"><strong>Kurt</strong> &#8211; By using constructive knowledge leading up to a data breach and proactively taking the correct steps trying to implement the correct processes, you may be immune to civil penalties.</p>
<p dir="ltr"><strong>John</strong> &#8211; Modern strategies out there to impede fraud and future strategies will strive to stop the fraud at the point of origin.</p>
<p dir="ltr"><a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encryption</a> and authentication are not going to help after a breach. The organization has to go out and find the answers and track down the user logs, essentially shutting the businesses down for 105 days while they try to figure out where the breach came from.</p>
<p dir="ltr">Take-away points from the presentation:</p>
<ul>
<li>Healthcare organizations have unique vulnerabilities to data breaches and fraud given the type of sensitive data the record contain and the wide-spread access to the care-providing functions</li>
<li>Criminal organizations are maturing and beginning to target the vulnerabilities of healthcare organizations with the intent to commit fraud</li>
<li>The current model of backtracking to figure out where a breach came from is inefficient  and does very little to actually pinpoint the issue</li>
<li>Healthcare organizations need to do a better job at monitoring user activity to detect abuse of the system and more efficiently find information in the event of a breach. Learn more <a href="http://www.onlinetech.com/secure-hosting/technical-security/daily-log-review">daily log review</a> and <a href="http://www.onlinetech.com/secure-hosting/technical-security/file-integrity-monitoring-fim">file integrity monitoring</a> (FIM) and how these technical services can help your organization prevent or remediate effectively after a data breach.</li>
</ul>
<p>Related Articles:<br />
<a href="http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/">2013 HCCA: Hidden Liabilities in the EHR</a><br />
<a href="http://resource.onlinetech.com/2013-hcca-cyber-compliance/">2013 HCCA: Cyber Compliance</a><br />
<a href="http://resource.onlinetech.com/2013-state-of-hipaa-encryption-authentication-for-healthcare/">2013 State of HIPAA Encryption &amp; Authentication for Healthcare</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/">2013 HCCA: The Defining Moments of a Data Breach</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-hcca-the-defining-moments-of-a-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 HCCA: Hidden Liabilities in the EHR</title>
		<link>http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/</link>
		<comments>http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/#comments</comments>
		<pubDate>Mon, 22 Apr 2013 18:54:11 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[EHR]]></category>
		<category><![CDATA[electronic health records]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10953</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare &#8230; <a href="http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/">2013 HCCA: Hidden Liabilities in the EHR</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #919 at the Health Care Compliance Association (HCCA)’s <a href="http://www.onlinetech.com/events/2013-health-care-compliance-association-compliance-institute">17th Annual Compliance Institute Conference</a> April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.<strong><br />
</strong></p>
<p><strong>Hidden Liabilities in the EHR</strong><br />
<em>Speakers: Catherine Gray, Director Corporate Compliance, Vidant Health</em><br />
<em>Yolanda Whichard, Medical Internal Auditor, Office of Audit and Compliance, Vidant Health</em></p>
<p dir="ltr">Catherine stimulated thought on some of the pitfalls and issues of EHR (electronic health record) systems within hospitals and physician offices. Vidant Health systems works with ten hospitals from small to full-fledge academic hospitals, serving 29 counties in North Carolina.</p>
<p dir="ltr">The biggest pitfalls she points out with some EHR systems are:</p>
<ul>
<li>Data is in multiple locations, lots of duplications, readers may miss new information just because there is so much information in so many places.</li>
<li>Most nursing documentation is captured in flow sheets that carry multiple dropdown boxes. With dropdown boxes, it becomes very hard to capture unique health items for the patients.</li>
<li>Academic medical institutions occasionally carry forward notes that were made by medical students.</li>
<li>User login and user electronic signature should link to credentials, but don’t necessarily do so each time a care provider logs into their EHR systems. Some programs also won’t recognize credentials when an order is placed. If this happens, Medicaid will deny the order until they receive the care provider’s credentials through the system.</li>
<li>Some patients see EHR as a barrier between patients and their physicians. Particularly it is a long-term doctor-patient relationship, the patient may not feel as if the doctor is listening if they are continuously entering data in a computer.</li>
<li>EHR systems are easier, not necessarily faster when shifting through medical information for a patient.</li>
<li>There is a certain amount of fear with fields that auto-populate. The information must be evaluated before it’s finalized and sent anywhere or carried forward.</li>
<li>Copy and paste features should be used for information that is consistent. Some information that is copied and carried forward in a patient’s EHR file may be coming from information outside of the EHR.</li>
</ul>
<p dir="ltr">The information is meaningful and reflects the quality of care you give. Patients have access to their information now more than ever; it is key to make it meaningful for them.</p>
<p dir="ltr">The second speaker, Yolanda went on to discuss contractual landmines that may arise in purchasing an EHR system. You cannot trust every contractor of EHR systems you run across. You need to be sure you have covered the following areas in your contract with your EHR provider:</p>
<ul>
<li>Liability shift</li>
<li>Data ownership</li>
<li>Indemnifications</li>
<li>End user license agreement</li>
<li>Fees (future upgrades and enhancements/ support and maintenance)</li>
</ul>
<p dir="ltr">Interoperability is key to have between all EHR systems. It has been documented in certain cases, where a patients medical information was deleted from one section of an EHR system, but was not deleted from another section of an EHR. The particular case that was discussed, resulted in unnecessary surgery for one patient.</p>
<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignright" title="HIPAA Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-hipaa.png" alt="HIPAA Compliant Hosting White Paper" width="253" height="115" /></a>For a complete guide to HIPAA <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical</a>, <a href="http://www.onlinetech.com/secure-hosting/administrative-security">administrative</a> and <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical security</a>, read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Hosting white paper</a>. This white paper explores the impact of HITECH and HIPAA on data centers. It includes a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> outsourcing, and vendor selection criteria.</p>
<p>Related Articles:<br />
<em><a href="http://resource.onlinetech.com/federal-health-it-budget-increases-by-28-percent-encryption-mobile-security-ehr-safety/">Federal Health IT Budget Increases by 28 Percent: Encryption, Mobile Security &amp; EHR Safety</a></em><br />
<em> <a href="http://resource.onlinetech.com/liveblogging-from-himss-13-managing-privacy-and-security-challenges-of-patient-ehr-portals/">Liveblogging from HIMSS 13: Managing Privacy and Security Challenges of Patient EHR Portals</a></em><br />
<em> <a href="http://resource.onlinetech.com/safeguarding-patient-data-in-ehrs/">Safeguarding Patient Data in EHRs</a></em></p>
<p>The post <a href="http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/">2013 HCCA: Hidden Liabilities in the EHR</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-hcca-hidden-liabilities-in-the-ehr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 HCCA: Cyber Compliance</title>
		<link>http://resource.onlinetech.com/2013-hcca-cyber-compliance/</link>
		<comments>http://resource.onlinetech.com/2013-hcca-cyber-compliance/#comments</comments>
		<pubDate>Mon, 22 Apr 2013 17:28:35 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[cyber compliance]]></category>
		<category><![CDATA[cyber risks]]></category>
		<category><![CDATA[cyber vigilence]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[health IT security]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[patient data security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10944</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare &#8230; <a href="http://resource.onlinetech.com/2013-hcca-cyber-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-hcca-cyber-compliance/">2013 HCCA: Cyber Compliance</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #919 at the Health Care Compliance Association (HCCA)’s <a href="http://www.onlinetech.com/events/2013-health-care-compliance-association-compliance-institute">17th Annual Compliance Institute Conference</a> April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.</p>
<p><strong>Cyber Compliance: What Every Compliance Professional Needs to Know about Cyber Risks and Cyber Vigilance</strong><br />
<em>Speakers:</em> <em>David Childers, President and CEO, Compli</em><br />
<em>Vivek Krishnamurthy, Associate, Foley Hoag LLP</em></p>
<p dir="ltr"><strong>David</strong> &#8211; Cyber crime is the highest growing economic crime and has become more lucrative than dealing drugs. Historically data breaches and cyber crime was reserved for large organizations and banks, because data was most plentiful there. The scene has changed now.  Mid-level folks with RF scanners are now going into bars stealing identities.  Reputation damage and risk is 5-7 times more impactful to an organization’s base market than an economic crisis. At $194 per record lost, it gets costly if you add up how many records you lose. Brand damage, share price, employee morale and business relations goes down.</p>
<p dir="ltr">Why cyber crime? And why is it a problem? You had to be a criminal and coder originally to really pose as a cyber threat. Malicious intent and ability to code were needed, and that&#8217;s not the case anymore. Malware as a service companies exist outside of the company. Espionage exists in corporate and government settings. Some people are going to mess with systems because they believe the companies are doing something they don&#8217;t approve of. And finally, terrorists are beginning to use cyber crime more and more.</p>
<p dir="ltr"><strong>Vivek</strong>- Health records are huge sources of information and personally identifiable info that is important to a cyber criminal. All you need to steal someone&#8217;s identity and finances can all be contained within health records.  Cyber terrorists increasingly are targeting critical systems. Healthcare is at risk of being a target in the eyes of those who want to wreak havoc on control systems and network controls. If your IV pump can be controlled remotely, that poses a huge threat. Everyone needs to be attuned to these kinds of motivations and how it could affect them.</p>
<p dir="ltr"><strong>David</strong>- Activism can come from your own employees. Who is the internal cybercrime risk? Disgruntled employees are a huge risk for any organization. It is important to get them out of your system as quickly as possible.</p>
<p dir="ltr">Major organizations such as CIA, FBI, NASA… all got hacked last year. There is no such thing as complete IT security. It is key to know who your cyber neighbors are when operating in the <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud</a>. Everyone needs to also create a human firewall at this day in age. Educate your team: what, why, how. People are the weakest link to your system. Increase your threat awareness and stay vigilant. Cyber governance, means cyber vigilance. The groups trying to get your information are coming from all over. They are competing with one another. It&#8217;s possible that the threat could be coming from a terrorist or even someone disgruntled with your organization.</p>
<p dir="ltr"><strong>Vivek</strong>- Relevant to data breaches, HIPAA is the main framework and the keystone federal law. What does <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a> have to do with us? HIPAA Security Rule:</p>
<p dir="ltr">(2) Protect against any reasonably anticipated threats or hazards to the security or integrity of such information.</p>
<p dir="ltr">(3) Protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required.</p>
<p dir="ltr">When HIPAA was being drafted by HHS, people were concerned with work stations being left unlock or an employee who left and was possibly disgruntled.</p>
<p dir="ltr">Vivek highlighted the following emerging &#8220;Reasonably Anticipated Threats&#8221;:</p>
<ul>
<li>Operating system flaws</li>
<li>Flaws in EMR system</li>
<li>Patient Information Apps</li>
<li>Networked medical devices and control systems</li>
<li>Mission critical IT systems on the cloud. What happens on a cloudless day?</li>
</ul>
<p dir="ltr">Lots of people are movie to the cloud. Responding to the threats is key. You need to have someone in your organization who is constantly vigilant and developing and implementing cyber incident response protocols and procedures.</p>
<p dir="ltr">Social engineering attacks are also  on the rise. All of us have several accounts across the internet, whether they be social network accounts, shopping accounts or bank account. All have a lost password recovery feature. One may ask you for the last 4 digits of your credit card and another site may ask you for the first four digits. A savvy hacker will search that out and use it against you.</p>
<p>Once a data breach has occurred, local law enforcement and FBI are who you want to work with, but if you believe you are being hacked, the US Secret Service is who you want to work with. There are over 30 offices of secret service able to help if you believe you are being hacked.</p>
<p>The post <a href="http://resource.onlinetech.com/2013-hcca-cyber-compliance/">2013 HCCA: Cyber Compliance</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-hcca-cyber-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Liveblogging: 2013 Health Care Compliance Association Compliance (HCCA) Institute</title>
		<link>http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/</link>
		<comments>http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/#comments</comments>
		<pubDate>Mon, 22 Apr 2013 13:09:31 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[HCCA]]></category>
		<category><![CDATA[health care compliance institute]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10920</guid>
		<description><![CDATA[<p>Online Tech is exhibiting at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, &#8230; <a href="http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/">Liveblogging: 2013 Health Care Compliance Association Compliance (HCCA) Institute</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting at booth #919 at the Health Care Compliance Association (HCCA)’s 17th Annual Compliance Institute Conference April 21-24 in National Harbor, MD. The conference draws in healthcare compliance professionals, risk managers, privacy officers, healthcare CFOs and CEOs, and more.</p>
<p>Online Tech&#8217;s <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> solutions include:</p>
<ul>
<li><a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/packages/colocation">HIPAA compliant colocation</a> with high availability power and offsite backup options.</li>
<li><a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/packages/managed-servers">HIPAA compliant dedicated servers</a> with fully managed services.</li>
<li><a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA compliant private clouds</a> with fully managed services.</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">HIPAA compliant disaster recovery</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a>.</li>
</ul>
<hr />
<p>Good morning from HCCA! Online Tech is exhibiting at booth #919.</p>
<div id="attachment_10923" class="wp-caption alignnone" style="width: 597px"><a href="http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/mike-kroon-exhibiting-hipaa-hosting-solutions-at-hcca/" rel="attachment wp-att-10923"><img class=" wp-image-10923 " title="Mike Kroon Exhibiting HIPAA Hosting Solutions at HCCA" src="http://resource.onlinetech.com/wp-content/uploads/Mike-Kroon-Exhibiting-HIPAA-Hosting-Solutions-at-HCCA.jpg" alt="Mike Kroon Exhibiting HIPAA Hosting Solutions at HCCA" width="587" height="487" /></a><p class="wp-caption-text">Mike Kroon Exhibiting HIPAA Hosting Solutions at HCCA</p></div>
<p>Stop by, say hello and take a peak at our water front view of the harbor!</p>
<div id="attachment_10925" class="wp-caption alignnone" style="width: 581px"><a href="http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/hcca-view-of-the-harbor/" rel="attachment wp-att-10925"><img class=" wp-image-10925 " title="HCCA View of the Harbor" src="http://resource.onlinetech.com/wp-content/uploads/HCCA-View-of-the-Harbor.jpg" alt="HCCA View of the Harbor" width="571" height="428" /></a><p class="wp-caption-text">HCCA View of the Harbor</p></div>
<p>Try your hand at the HCCA wheel of fortune for your chance to win prizes right around the corner from us.</p>
<div id="attachment_10927" class="wp-caption alignnone" style="width: 438px"><a href="http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/hcca-compliance-institute-wheel-of-fortune/" rel="attachment wp-att-10927"><img class=" wp-image-10927 " title="HCCA Compliance Institute Wheel of Fortune" src="http://resource.onlinetech.com/wp-content/uploads/HCCA-Compliance-Institute-Wheel-of-Fortune.jpg" alt="HCCA Compliance Institute Wheel of Fortune" width="428" height="571" /></a><p class="wp-caption-text">HCCA Compliance Institute Wheel of Fortune</p></div>
<p>The post <a href="http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/">Liveblogging: 2013 Health Care Compliance Association Compliance (HCCA) Institute</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/liveblogging-2013-health-care-compliance-association-compliance-hcca-institute/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 IHIMA: Social Media and Healthcare</title>
		<link>http://resource.onlinetech.com/2013-ihima-social-media-and-healthcare/</link>
		<comments>http://resource.onlinetech.com/2013-ihima-social-media-and-healthcare/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 18:20:46 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[healthcare social media]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[social media strategy]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10910</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19. Social Media and &#8230; <a href="http://resource.onlinetech.com/2013-ihima-social-media-and-healthcare/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-ihima-social-media-and-healthcare/">2013 IHIMA: Social Media and Healthcare</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19.</p>
<p><strong>Social Media and Healthcare</strong><br />
<em>Speaker: Matt LaMond, TranscriptionGear.com, Founded Social Presence back in 2009 </em></p>
<p>With the rapid growth of social there is an overwhelming rise in the amount of information shared among individuals, businesses and organizations. Simply look at the upcoming implementation of EHRs. There are questions and concerns surrounding social media, particularly for those in the healthcare industry who do not have a social media presence and are looking to get involved.</p>
<p>Matt opened up by sharing the most frequent questions he receives in regards to social media from those who do not yet maintain a presence:</p>
<ul>
<li>Does social media really have an influence?</li>
<li>Is the influence of social media good or bad?</li>
<li>Can anyone hop on board and join social media?</li>
</ul>
<p>One of the biggest upsides social media presents to individuals in particular is the ability to resolve issues with national brands promptly through social. No brand or organization wants bad press, and social media offers up a platform for prompt response and resolutions for customers. It can shine a positive light on an organization&#8217;s response time and customer service experience.</p>
<p>However, there are several downsides to social media in terms of privacy and personal information. Before the rise of social media, there was concern over giving out email addresses, phone number and addresses. With the dawn of social media, we don’t think twice about sharing that information any more.</p>
<p>Matt raised awareness on just how much information someone can pull from simple status updates and photos to Facebook. Take someone posting an ultrasound photo to Facebook for example. While someone is probably incredibly excited about sharing that photo innocently enough, that doesn’t mean everyone viewing it will use it innocently enough. Consider this, with that one picture you could potentially have just provided the following information:</p>
<ul>
<li>You will be out of your house for x amount time to deliver the baby</li>
<li>What hospital you will be at in a specific state or town. Same went for the example he gave for a picture someone posted while attending a funeral.</li>
</ul>
<p>Connecting social media and your healthcare organization or business requires a little more caution and due diligence than it would if you were just using it as an individual.</p>
<p>Several keys points raised to consider for any healthcare organization looking to build a social media presence were:</p>
<ul>
<li>The regulation components associated with an online presence and healthcare</li>
<li>Protecting the integrity of yourself, business or organization in the public eye</li>
<li>Protecting the integrity of your patients and their information</li>
<li>Protecting the general population. The most important task to perform before pushing out any information to social media on your organization’s behalf is to review, review, REVIEW. Have multiple set of eyes within your organization read over it before you push it out the door if possible. Once you release the information to the web, it is almost impossible to pull it off without legal action.</li>
</ul>
<p>Big data is one of the major benefits of social media. Through a simple search, you can pull key demographics, improve accessibility to information, disseminate information quickly, identify outbreak trends and educate and enlighten.</p>
<p>Look at the influenza outbreak that occurred late in 2012. Google actually mapped out, based on tweets on the influenza, the location of all outbreaks. See link: <a href="http://healthmap.org/en/">http://healthmap.org/en/</a>. By having access to this kind of information, hospitals could potentially prepare and estimate the number of patients they may see based on location and density of outbreak point.</p>
<p>The breakdown of how America search for health information:</p>
<ul>
<li>34% use social media</li>
<li>46% using health portals</li>
<li>67% using search engines</li>
<li>21% use wikipedia</li>
<li>36 % Want to see what other consumers say about medicine or treatment</li>
</ul>
<p>This is a great example of real people wanting to communicate and know how a treatment worked for another human being.</p>
<p>Matt asked the audience if anyone felt overwhelmed with the amount of information he was throwing out on the scale and magnitude of what social media could for healthcare.  He reminded everyone that no one really knows exactly what they’re doing with social media.</p>
<p>Social media is really a conversation and people you know are already using it to communicate. People are attracted to social media and want to find you, because they are looking for a “person just like them” more than authority figures in business and government. If entering the social media realm, seek to have a dialogue with your consumers. Transparency, honesty, trust and transparency are key components to any successful presence.</p>
<p>Resources for monitoring what is being said about your organization:</p>
<ul>
<li>Technorati.com/watchlist – watches for terms and updates you on what’s happening</li>
<li>Google.com/alerts – email updates for company and keyword alerts.</li>
<li>Yahoo.com – alerts on any occurences of defined terms and names</li>
</ul>
<p>If you find you are gaining bad press, Matt urged the audience to deal with it right away. He stressed that you should draft a response strategy beforehand and back it up with visible action. Best advice for beginning a social media presence? Be consistent and keep it simple.</p>
<p>Related Articles:<br />
<a href="http://resource.onlinetech.com/2013-ihima-meaningful-use/">2013 IHIMA: Meaningful Use</a><br />
<a href="http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/">2013 IHIMA: Corporate Compliance for Healthcare</a><br />
<a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/">Liveblogging: HIPAA Hosting at the Indiana Health Information Management Association Meeting</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-ihima-social-media-and-healthcare/">2013 IHIMA: Social Media and Healthcare</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-ihima-social-media-and-healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 IHIMA: State and Federal Legislative Updates on Healthcare and HITECH</title>
		<link>http://resource.onlinetech.com/2013-ihima-state-and-federal-legislative-updates-on-healthcare-and-hitech/</link>
		<comments>http://resource.onlinetech.com/2013-ihima-state-and-federal-legislative-updates-on-healthcare-and-hitech/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 15:02:26 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa hosting solutions]]></category>
		<category><![CDATA[HITECH]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10901</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19. State and Federal &#8230; <a href="http://resource.onlinetech.com/2013-ihima-state-and-federal-legislative-updates-on-healthcare-and-hitech/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-ihima-state-and-federal-legislative-updates-on-healthcare-and-hitech/">2013 IHIMA: State and Federal Legislative Updates on Healthcare and HITECH</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19.</p>
<p><strong>State and Federal Legislative Update</strong><br />
<em>Speaker: Brian Tabor, VP Government Relations, IHA (Indiana Hospital Assoc.)</em></p>
<p>Brian Tabor addressed the crowd with the latest changes in the Indiana state government with new Gov. Mike Pence ( R ), Lt. Gov. Sue Ellspermann ( R ) and the new Republican majority in the legislative branch and what that means for the bills and legislation currently on the table.</p>
<p>In terms of healthcare, there has been a strong state focus from Indiana and what they are working on in their own backyard in relation to the national healthcare landscape.</p>
<p>Brian works with over 150 state legislators and several agencies to represent hospitals and those with specific roles between the government and hospitals. He noted that it has been key to have senators and representatives who have a background in healthcare. He mentioned Rep. Tim Brown, an ER physician, who handles a lot of the healthcare relations and concerns that pass through the Indiana Legislature and is now Chair of the House Ways and Means Committee.</p>
<p>The biggest issues currently facing those working in hospitals in Indiana in regards to the either new legislation and HITECH are:</p>
<ul>
<li>Renew Hospital Assessment Fee program</li>
<li>Expand coverage – Medicaid expansion, part of affordable care act</li>
<li>Defend against threats – Added regulatory reporting</li>
</ul>
<p>What are they following and advocating? He mentioned that while IT issues are a concern for the state, they fell to the second tier in regards to the issues stated above.</p>
<p>Brian went on to discuss several bills going through the IN legislative branch that could affect healthcare for patients. A few he touched on were:</p>
<p>Children and Hoosier Immunization Regulatory Program (CHIRP); in which, among other provisions, the bill introduced would require ALL providers to report ALL immunizations within 72 hours or face a $1,000 fine.</p>
<p>Senate Bill 272 (INSPECT) &#8211; A proposal that was made during a committee meeting which would require all legend drug prescriptions to be entered into INSPECT. Several concerns have been raised around INSPECT, mainly dealing with patient privacy and confidentiality, but some concerns were raised for the real time reporting and entry of the information collected.</p>
<p>There has been much press lately at a federal level as to examining the strategies that are going to be needed to fully adopt health IT. Five areas where there are questions remaining for some at the federal level focus on the following:</p>
<ul>
<li>    Lack of a clear path to interoperability</li>
<li>    Increased costs of moving to EHR</li>
<li>    Possible lack of oversight</li>
<li>    High risk of patient privacy</li>
<li>    The sustainability of the entire program</li>
</ul>
<p><strong><img class="alignleft" title="Brian Tabor" src="http://www.ihaconnect.org/advocacy/advocacyimages/advocacycontacts/12432.jpg?Width=100" alt="Brian Tabor" width="100" height="150" />Brian C. Tabor, VP Government Relations, IHA (Indiana Hospital Assoc.)</strong></p>
<p>Brian C. Tabor is Vice President of Government Relations at the Indiana Hospital Association. As such, he oversees all of IHA’s state and federal legislative initiatives and health policy development.</p>
<p>Prior to joining IHA in 2008, Tabor worked at the Indiana House of Representatives where he served as the majority caucus policy director. He has worked for and around the Indiana General Assembly for almost 15 years, also serving as a fiscal analyst for the Indiana State Senate. He earned a bachelor’s degree in political science and a master’s degree in agricultural economics from Purdue University.</p>
<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignright" title="HIPAA Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-hipaa.png" alt="HIPAA Compliant Hosting White Paper" width="253" height="115" /></a>For a complete guide to HIPAA <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical</a>, <a href="http://www.onlinetech.com/secure-hosting/administrative-security">administrative</a> and <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical security</a>, read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Hosting white paper</a>. This white paper explores the impact of HITECH and HIPAA on data centers. It includes a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> outsourcing, and vendor selection criteria.</p>
<p>Related Articles:<br />
<a href="http://resource.onlinetech.com/2013-ihima-meaningful-use/">2013 IHIMA: Meaningful Use</a><br />
<a href="http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/">2013 IHIMA: Corporate Compliance for Healthcare</a><br />
<a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/">Liveblogging: HIPAA Hosting at the Indiana Health Information Management Association Meeting</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-ihima-state-and-federal-legislative-updates-on-healthcare-and-hitech/">2013 IHIMA: State and Federal Legislative Updates on Healthcare and HITECH</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-ihima-state-and-federal-legislative-updates-on-healthcare-and-hitech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 IHIMA: Lawsuits by Patients for Unauthorized Disclosure of Protected Health Information (PHI)</title>
		<link>http://resource.onlinetech.com/2013-ihima-lawsuits-by-patients-for-unauthorized-disclosure-of-protected-health-information-phi/</link>
		<comments>http://resource.onlinetech.com/2013-ihima-lawsuits-by-patients-for-unauthorized-disclosure-of-protected-health-information-phi/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 13:31:30 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[protected health information]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10891</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19. This session is &#8230; <a href="http://resource.onlinetech.com/2013-ihima-lawsuits-by-patients-for-unauthorized-disclosure-of-protected-health-information-phi/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-ihima-lawsuits-by-patients-for-unauthorized-disclosure-of-protected-health-information-phi/">2013 IHIMA: Lawsuits by Patients for Unauthorized Disclosure of Protected Health Information (PHI)</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19.</p>
<p>This session is about a lawsuit involving the breach of protected health information (PHI):</p>
<p><strong>The Future is Here: Lawsuits by Patients for Unauthorized Disclosure of Protected Health Information</strong><br />
<em>Speaker: Neal Eggeson, JD</em></p>
<p>Neal gave his opening statement for a lawsuit in which he represented a young man a few years back in Bloomington, IN. His client had been diagnosed with HIV several years before and throughout his entire treatment process had only told 5 people about his status; His mom, doctor, counselor and two partners.</p>
<p>A few years down the road, the young man received a notice from IMA that he was being sued for an unpaid medical bill of roughly $330. His doctor and insurance had never made any mention of the unpaid billed. After looking at the lawsuit document, he noticed that his diagnosis was right there on the page for IMA’s attorney, administrative assistants, courthouse clerical staff and anyone else to see since lawsuits are open public record.</p>
<p>The jury in the case ruled that IMA dropped the ball on protecting private patient information and was charged for a settlement of $1.25 million over a $330 unpaid medical bill simply because it listed the patient’s diagnosis on the claims page.</p>
<p>Neal made it clear that he was not suing IMA for a violation of HIPAA, he was suing because IMA dropped the ball on their duty to protect private patient information.</p>
<p>It was the first lawsuit in the country after implementation of the privacy rule and the first lawsuit in the country to return a seven-figure verdict against the provider for that particular privacy breach.</p>
<p>Always remember, do not assume that:</p>
<ul>
<li>HIPAA’s bar against private causes of action will protect you</li>
<li>The medical community will protect you</li>
<li>That disclosures to your attorneys are protected</li>
</ul>
<p>Read the court case <a href="http://www.in.gov/judiciary/opinions/pdf/05031201jss.pdf">here</a> (PDF).</p>
<p>Related Articles:<br />
<a href="http://resource.onlinetech.com/2013-ihima-meaningful-use/">2013 IHIMA: Meaningful Use</a><br />
<a href="http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/">2013 IHIMA: Corporate Compliance for Healthcare</a><br />
<a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/">Liveblogging: HIPAA Hosting at the Indiana Health Information Management Association Meeting</a></p>
<p>The post <a href="http://resource.onlinetech.com/2013-ihima-lawsuits-by-patients-for-unauthorized-disclosure-of-protected-health-information-phi/">2013 IHIMA: Lawsuits by Patients for Unauthorized Disclosure of Protected Health Information (PHI)</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-ihima-lawsuits-by-patients-for-unauthorized-disclosure-of-protected-health-information-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 IHIMA: Meaningful Use</title>
		<link>http://resource.onlinetech.com/2013-ihima-meaningful-use/</link>
		<comments>http://resource.onlinetech.com/2013-ihima-meaningful-use/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 19:35:02 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[meaningful use]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10880</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19. The following session &#8230; <a href="http://resource.onlinetech.com/2013-ihima-meaningful-use/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-ihima-meaningful-use/">2013 IHIMA: Meaningful Use</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19.<br />
<strong></strong></p>
<p>The following session covered meaningful use with healthcare professionals:</p>
<p><strong>Meaningful Use</strong><br />
<em>Speaker: Jeff Short, JD, Hall Render, Killian Heath and Lyman</em></p>
<p>Jeff highlighted the key core objectives that will be coming in every stage of meaningful use. One of the biggest changes to affect healthcare professionals is the change to e-copy and online access found in Stage 1 that will be effective as of 2014.</p>
<p dir="ltr">This change will require that healthcare organizations provide patients with an e-copy of health information upon request. Electronic access to health information must be provided where patients will have the ability to view and download records from online.</p>
<p dir="ltr">Other items in the core set of objectives that Stage 2 will address for eligible hospitals:</p>
<ul>
<li><strong>Demographics</strong>- patient demographics must be stored in EHR’s</li>
<li><strong>Labs</strong> – incorporate lab results for 55% of data you can run reports against</li>
<li><strong>Patient List</strong> – be able to generate patient list by specific condition</li>
<li><strong>Patient access</strong>- provide online access for 55% of patients with 5% actually  accessing it. Can get creative on how patients access it. Could have them fill out something online. Joint community portals</li>
<li><strong>Summary of Care</strong> – provide summary of care of 50% of transition of care and referrals with 10% sent electronically.</li>
</ul>
<p dir="ltr">The heaviest emphasis for a Stage 2 core objective was for security analysis. Hospitals must conduct and review a security analysis and incorporate it into their risk management process. Jeff could not emphasize enough that you HAVE to have a security analysis and it MUST have some rigor to it.</p>
<p dir="ltr">Every single data breach write-up he has read has stated that the hospitals in question said that they had performed a security risk assessment, when they in fact had not. Simply put, performing a security analysis is the right thing to do because it protects your patients’ data. You’re also protecting yourself from the state attorney general. You have to perform the analysis to comply with HIPAA. They are already beginning to write people up for HIPAA violations. Fines are beginning to seven figures now for even minor breaches.</p>
<p dir="ltr">He mentioned that there is some discrepancy between whether or not you have to use an external auditor or whether you can do an internal audit and attest that you have met the requirements. While it is noted that you can do an internal audit, it is simply smarter and safer to have an outside vendor perform your audit.</p>
<div class="wp-caption alignleft" style="width: 132px"><img title="Jeffrey Short" src="http://www.hallrender.com/health_care_law/images/attorney.photos/Short_J.jpg" alt="Jeffrey Short" width="122" height="153" /><p class="wp-caption-text">Jeffrey Short</p></div>
<p dir="ltr"><strong>Jeffrey W. Short, JD, Hall, Render, Killian, Heath &amp; Lyman, P.C.</strong></p>
<p dir="ltr">Jeffrey W. Short advises large and small companies on legal issues relating to computer hardware, computer software, technology, privacy, copyright, trademark, and the Internet. Mr. Short concentrates his practice on information technology and privacy issues relating to health care entities, including hospitals, physician groups, and pharmaceutical companies. Specifically, Mr. Short assists his clients in the procurement of technology by drafting and negotiating the necessary agreements including software development, software licensing, and IT consulting agreements. In addition, Mr. Short has vast experience in the development of protection policies, not only in the technology arena, but also in the areas of intellectual property and the Internet. Mr. Short routinely assists local and national clients on privacy issues including HIPAA compliance. Mr. Short has made numerous speeches relating to HIPAA and technology procurement in health care, including speaking at the 2001 National HIPAA Summit.</p>
<p dir="ltr"><strong>About the Indiana Health Information Management Association</strong><br />
The Indiana Health Information Management Association (IHIMA) is a non-profit healthcare professional association representing over 2,000-credentialed Hoosiers. IHIMA is an affiliate with American Health Information Management Association (AHIMA) as a Component State Association. Our purpose is to commit to excellence in the management of health information for the benefit of patients and providers.</p>
<p>The post <a href="http://resource.onlinetech.com/2013-ihima-meaningful-use/">2013 IHIMA: Meaningful Use</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-ihima-meaningful-use/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2013 IHIMA: Corporate Compliance for Healthcare</title>
		<link>http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/</link>
		<comments>http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 17:32:23 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[corporate compliance]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[IHIMA]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10859</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19. This educational session &#8230; <a href="http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/">2013 IHIMA: Corporate Compliance for Healthcare</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19.</p>
<p>This educational session details dealing with corporate compliance in the healthcare industry.</p>
<p><strong>Elements of an Effective Compliance Program</strong><br />
<em>Speaker: Marsha Shepard, RHIA; Director of Corporate Compliance Memorial Hospital &amp; HCC; Jasper, IN</em></p>
<p dir="ltr">“We all live in compliance as IHIMA professionals,” Marsha pointed out at the beginning of her speech. Throughout the lecture, she repeatedly mentioned that achieving compliance is a team effort and collaboration throughout an organization &#8211; from working internally with everyone from the Board of Director to remotely contracted employees and externally with auditors and consultants.</p>
<p dir="ltr">Compliance is a choice for organizations, but there will be strong consequences for not following. She humored the audience by likening compliance to stopping at a stop sign. Just because the laws are in place to do so, doesn’t mean that an organization or everyone in an organization will comply.</p>
<p dir="ltr">A strong compliance program for any organization should include the following 3 P’s:</p>
<ul>
<li>Provide direction and answers</li>
<li>Prevent, detect and report any unethical or illegal behavior</li>
<li>Promote integrity</li>
</ul>
<p dir="ltr">With <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a> and HITECH, your role as an organization, from a high level perspective, should be to:</p>
<ul>
<li>Remain honest, respectful and ethical throughout your business conduct</li>
<li>Identify and prevent illegal and unethical behavior</li>
<li>Improve quality of care</li>
<li>Develop a culture of reporting without retaliation</li>
<li>Follow compliance policies and procedures</li>
</ul>
<p dir="ltr">Social media has raised flags within the healthcare world in relation to HIPAA. Marsha said she knew of four people who had been turned in for abuse of social media in the hospital environment. With the age of smartphones, there is a huge need for secure apps that allow doctors and staff to share information back and forth in real time, but she cautioned that until the security is in place, “Just because it’s easy, doesn’t mean it’s right.” There needs to be social responsibility and respect in regards to all social media in the healthcare environment.</p>
<p dir="ltr">With all the changes and laws being hurled at healthcare organizations, it can feel like an organization is moving at 100 MPH. If an organization is to achieve compliance, they must slow down.</p>
<p dir="ltr">She laid down five questions that an organization should ask when looking to form a compliance program:</p>
<ul>
<li>Where are you going and why is implementing compliance key for your organization?</li>
<li>What is your organization’s commitment to compliance?</li>
<li>Why is it necessary to adhere to the organization’s policies and procedures as well as applicable laws and regulations?</li>
<li>What duty do employees have to report concerns or misconduct?</li>
<li>Do you know your organization’s compliance program, including reporting and/or mechanisms and the organization’s commitment to non-retaliation?</li>
</ul>
<p dir="ltr">Not all compliance programs are going to be the same and compliance officers may wear many “hats” within their organization. Conducting a risk assessment with an outside auditor or consultant on an annual basis is highly recommended.</p>
<p dir="ltr">To achieve success within any compliance program, the organization should:</p>
<ul>
<li>Know their strengths</li>
<li>Communicate early</li>
<li>Keep a good hand on the situation</li>
<li>Maintain and build trust</li>
</ul>
<p><a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers"><img class="alignright" title="HIPAA Compliant Hosting White Paper" src="http://resource.onlinetech.com/wp-content/uploads/download-hipaa.png" alt="HIPAA Compliant Hosting White Paper" width="252" height="114" /></a>For a complete guide to HIPAA <a href="http://www.onlinetech.com/secure-hosting/technical-security">technical</a>, <a href="http://www.onlinetech.com/secure-hosting/administrative-security">administrative</a> and <a href="http://www.onlinetech.com/secure-hosting/physical-security">physical security</a>, read our <a href="http://www.onlinetech.com/resources/white-papers/hipaa-compliant-data-centers">HIPAA Compliant Hosting white paper</a>. This white paper explores the impact of HITECH and HIPAA on data centers. It includes a description of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> IT architecture, contractual requirements, benefits and risks of <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> outsourcing, and vendor selection criteria.</p>
<p><strong>About the Indiana Health Information Management Association</strong><br />
The Indiana Health Information Management Association (IHIMA) is a non-profit healthcare professional association representing over 2,000-credentialed Hoosiers. IHIMA is an affiliate with American Health Information Management Association (AHIMA) as a Component State Association. Our purpose is to commit to excellence in the management of health information for the benefit of patients and providers.</p>
<p>The post <a href="http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/">2013 IHIMA: Corporate Compliance for Healthcare</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2013-ihima-corporate-compliance-for-healthcare/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Michigan SMBs Need to Create a Disaster Recovery Plan</title>
		<link>http://resource.onlinetech.com/why-michigan-smbs-need-to-create-a-disaster-recovery-plan/</link>
		<comments>http://resource.onlinetech.com/why-michigan-smbs-need-to-create-a-disaster-recovery-plan/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 14:42:05 +0000</pubDate>
		<dc:creator>Anna Ankenbrand</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[business continuity]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[disaster recovery plan]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[michigan business]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10856</guid>
		<description><![CDATA[<p>Disasters don’t wait until you’re ready.  They can happen at any time and in many ways like natural disasters (tornadoes, earthquakes, and floods), technical issues (hard drive failures, viruses) or humans (deliberate or accidental). And Michigan small and medium-sized companies &#8230; <a href="http://resource.onlinetech.com/why-michigan-smbs-need-to-create-a-disaster-recovery-plan/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/why-michigan-smbs-need-to-create-a-disaster-recovery-plan/">Why Michigan SMBs Need to Create a Disaster Recovery Plan</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p id="internal-source-marker_0.6647019113673375" dir="ltr">Disasters don’t wait until you’re ready.  They can happen at any time and in many ways like natural disasters (tornadoes, earthquakes, and floods), technical issues (hard drive failures, viruses) or humans (deliberate or accidental). And Michigan small and medium-sized companies (SMBs) are at risk.</p>
<p dir="ltr">According to AMI’s 2009 U.S. Small Business Annual Overview study, 70% of small U.S. businesses have experienced a data loss in the past year due to technical or human disasters.   Even with this high percentage of data loss, very few SMBs have disaster recovery plans.  Over half of Symantec’s SMB disaster preparedness survey respondents said that they do not have a disaster recovery plan in place. Surprisingly, 41% respondents said that it never even occurred to them to put a <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery plan</a> together in the first place.</p>
<p dir="ltr"><strong>Why Have a Disaster Recovery Plan?</strong></p>
<p dir="ltr">As a Michigan SMB business owner do you need a disaster recovery or business continuity plan?  You can ask yourself one simple question, “Can my business continue to function without &lt;insert specific software application or system, communication service, data, etc.&gt;?”</p>
<p dir="ltr">The next thing to consider is if it is financially worth using a disaster recovery solution. Ask yourself how much money would you lose if you were down one hour?  One day?  You need to consider the cost of being unable to operate your business over a period of time.  Consider the number of lost transactions and the future loss of customers going elsewhere. Your disaster recovery solution should not be more expensive than the loss from the disaster, unless your business would fail as a result of the outage.</p>
<p dir="ltr">A disaster could have a tremendous financial impact on Michigan SMBs.  This is especially true during a recession when competitors are looking for every opportunity to win your customers.</p>
<p dir="ltr">Financial reasons alone should encourage Michigan SMBs to develop a disaster plan, but there are other reasons as well.</p>
<ul>
<li dir="ltr">
<p dir="ltr"><strong>Competitive Advantage</strong> – Having a disaster recovery plan and solution in place can be a competitive advantage.  For example, you own a Michigan real estate business and you are backing all of your data to an offsite disaster recovery service provider and your competition is not.  Then a disaster occurs.  You would be able to get your business back up and running while your competition would have a much harder time getting back to business.</p>
</li>
<li dir="ltr">
<p dir="ltr"><strong>Reputation</strong> – Even if your Michigan business survives a data loss, there is no guarantee that your reputation would still be intact.  Once a customer loses trust with a business, it is very difficult to get it back or it requires a lot of time and money to regain the trust.  And in today’s competitive marketplace, your competition can easily take your customers from you.</p>
</li>
<li dir="ltr">
<p dir="ltr"><strong>HIPAA, PCI, SOX Compliance</strong> &#8211; Disaster recovery plans are critical to be in compliance with business regulations like <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA</a>, <a href="http://www.onlinetech.com/compliant-hosting/pci-compliant-hosting/overview">PCI</a> and <a href="http://www.onlinetech.com/compliant-hosting/sarbanes-oxley-sox-compliant-hosting">SOX</a>.  Non compliance could result in monetary fines, loss of business licenses and even prison time.  Well documented disaster recovery policies and procedures that are available for customers, vendors, and partners could be the difference of winning or losing your next project.  As one small business owner described it, “We get most of our business from insurance companies. They are very clear about how long we need to keep records and how their customers’ data can and cannot be used. If we didn’t meet these requirements we wouldn’t have their business. It’s just that clear.”</p>
</li>
</ul>
<p dir="ltr"><strong>Example of Data Retention Regulations &amp; Impact of Non-Compliance</strong></p>
<div dir="ltr">
<table>
<colgroup></colgroup>
<tbody>
<tr>
<td>
<p dir="ltr"><strong>Industry</strong></p>
</td>
<td>
<p dir="ltr"><strong>Summary of Regulation</strong></p>
</td>
<td>
<p dir="ltr"><strong>Non Compliance Penalty</strong></p>
</td>
</tr>
<tr>
<td>
<p dir="ltr">Healthcare</p>
</td>
<td>
<div dir="ltr">
<table>
<colgroup></colgroup>
<tbody>
<tr>
<td>
<p dir="ltr">To be HIPAA compliant and to “protect the integrity, availability and confidentiality of medical information, “business must retainhealth records (electronic, written and oral) for a minimum of 6 years.</p>
</td>
</tr>
<tr>
<td></td>
</tr>
</tbody>
</table>
</div>
</td>
<td>
<p dir="ltr">Fines (up to $250,000) &amp; possible imprisonment (up to 10 years).</p>
</td>
</tr>
<tr>
<td>
<p dir="ltr">Financial Services, including Real Estate</p>
</td>
<td>
<p dir="ltr">Retain mortgage loan files must be stored for the life of loan and additional 6-10 years.</p>
</td>
<td>
<p dir="ltr">Fines (up to $100,000 for each violation) &amp; possible imprisonment (up to 5 years).</p>
</td>
</tr>
<tr>
<td>
<p dir="ltr">Real Estate</p>
</td>
<td>
<p dir="ltr">Laws vary by state as well. For example, under California’s Business And Professions Code Section 10148 regulation, real estate companies must retain all listings, deposit slips, checks and other transaction documents for up to 3 years.</p>
</td>
<td>
<p dir="ltr">Fines &amp; possible suspension or revoke of broker&#8217;s license</p>
</td>
</tr>
<tr>
<td>
<p dir="ltr">Financial Services</p>
</td>
<td>
<p dir="ltr">Under SEC Rule 17a, retain all communication for up to 6 years. It also defines the types of records (e.g. emails), how long and what types of media they must be stored on (e.g. nonrewritable media).</p>
</td>
<td>
<p dir="ltr">Fines &amp; possible imprisonment</p>
</td>
</tr>
<tr>
<td>
<p dir="ltr">All industries</p>
</td>
<td>
<p dir="ltr">Following the Fair Labor Standards Act, business must retain employee records related to wages, hours, conditions for 3 years.</p>
</td>
<td>
<p dir="ltr">Fines (up to $10,000). Repeat convictions may apply.</p>
</td>
</tr>
</tbody>
</table>
</div>
<p dir="ltr">Source: Disaster Recovery Planning How Planning for a Disaster Can Save Your Business</p>
<ul>
<li dir="ltr">
<p dir="ltr"><strong>Peace of Mind</strong> – Having a disaster recovery plan and solutions in place will give you a peace of mind.  You can sleep better at night knowing that your business data and systems are protected in the case of a data loss or disaster.</p>
</li>
</ul>
<p dir="ltr"><strong>Data Recovery Solutions for Michigan SMBs</strong></p>
<p dir="ltr">According to a survey that was developed to examine how U.S. small businesses prepare for disasters, 94% of the businesses take steps to backup their financial data. However, six out of 10 of the businesses surveyed said they are only storing their backed up data onsite only.</p>
<p dir="ltr">Although this onsite data storage provides some protection, it has one distinct disadvantage over offsite data storage.  Onsite data can be destroyed in a catastrophic event like a fire in the building, a water main bursting or tornado.  In addition, onsite servers can also be stolen or the collected data could be lost on them.</p>
<p dir="ltr">Using a third party disaster recovery service provider or a <a href="http://www.onlinetech.com/colocation/overview">colocation</a> provider offers Michigan SMBs added protection and the peace of mind in the case of a catastrophic event.</p>
<p dir="ltr">Colocation data centers offers Michigan businesses an alternative to setting up their own disaster recovery site.  With colocation you are setting up your network, servers, data storage, etc. at a third party location.  You still can have control over your servers and other equipment, while reducing costs like power, cooling and personnel.</p>
<p dir="ltr">Using an offsite backup service provider is another option for Michigan businesses.  All of your critical data can be electronically backed up to a traditional, secure <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> facility or by using the cloud. <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">Disaster recovery in the cloud</a> is the most reliable solution that costs less than half of the production environment.</p>
<p dir="ltr">Online Tech clients can also use our most advanced and comprehensive disaster recovery option – <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/san-to-san-replication">SAN-to-SAN Replication</a>.  This offers our clients even faster recovery times and a solution that can failback gracefully to production once the disaster event is over.</p>
<p>Related Articles:<br />
<a href="http://resource.onlinetech.com/using-a-michigan-colocation-provider-for-disaster-recovery/">Using a Michigan Colocation Provider for Disaster Recovery</a><br />
<a href="http://resource.onlinetech.com/five-questions-to-ask-your-disaster-recovery-provider/">Seeking a Disaster Recovery Solution? Five Questions to Ask Your DR Provider</a><br />
<a href="http://resource.onlinetech.com/pci-compliant-disaster-recovery/">PCI Compliant Disaster Recovery</a></p>
<p>The post <a href="http://resource.onlinetech.com/why-michigan-smbs-need-to-create-a-disaster-recovery-plan/">Why Michigan SMBs Need to Create a Disaster Recovery Plan</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/why-michigan-smbs-need-to-create-a-disaster-recovery-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Wins 2013 Corp! DiSciTech Award; Recognized for Michigan Technology Leadership</title>
		<link>http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/</link>
		<comments>http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 14:28:57 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[michigan business awards]]></category>
		<category><![CDATA[michigan technology]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10835</guid>
		<description><![CDATA[<p>Online Tech is the winner of the 2013 Corp! DiSciTech Award, adding to the previous wins in 2010 and 2012. The award recognizes Michigan companies leading the way in digital, science and technology. Find a list of our past awards &#8230; <a href="http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/">Online Tech Wins 2013 Corp! DiSciTech Award; Recognized for Michigan Technology Leadership</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p>Online Tech is the winner of the <a href="https://www.corpmagazine.com/events/corp!-events/corp-events/discitech-awards">2013 Corp! DiSciTech Award</a>, adding to the previous wins in 2010 and 2012. The award recognizes Michigan companies leading the way in digital, science and technology.</p>
<p>Find a list of our past awards by reading about our <a href="http://www.onlinetech.com/company/overview">company</a>, and find out more about our <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data centers</a>. We&#8217;re attending the award ceremony in Auburn Hills, Michigan this morning. The award ceremony features speakers:</p>
<ul>
<li>Jennifer Kluge, Publisher, Corp! Magazine</li>
<li>Sharon Miller, Vice Chancellor of External Affairs</li>
<li>Hajj Fleming, Personal Brand Strategist, President and Founder, Brand Camp University</li>
<li>Emcee: Matt Roush, WWJ Newsradio 950</li>
</ul>
<div id="attachment_10841" class="wp-caption alignnone" style="width: 470px"><a href="http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/2013-corp-discitech-awards/" rel="attachment wp-att-10841"><img class="wp-image-10841 " title="2013 Corp! DiSciTech Awards" src="http://resource.onlinetech.com/wp-content/uploads/2013-Corp-DiSciTech-Awards.jpg" alt="2013 Corp! DiSciTech Awards" width="460" height="816" /></a><p class="wp-caption-text">2013 Corp! DiSciTech Awards</p></div>
<p>Matt Roush, Tech Editor of GLITR (Great Lakes Innovation and Technology Report) Emcees the DiSciTech awards:</p>
<div id="attachment_10844" class="wp-caption alignleft" style="width: 581px"><a href="http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/matt-roush-at-the-discitech-awards/" rel="attachment wp-att-10844"><img class=" wp-image-10844 " title="Matt Roush at the DiSciTech Awards" src="http://resource.onlinetech.com/wp-content/uploads/Matt-Roush-at-the-DiSciTech-Awards.jpg" alt="Matt Roush at the DiSciTech Awards" width="571" height="322" /></a><p class="wp-caption-text">Matt Roush at the DiSciTech Awards</p></div>
<p>The post <a href="http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/">Online Tech Wins 2013 Corp! DiSciTech Award; Recognized for Michigan Technology Leadership</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-wins-2013-corp-discitech-award/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Liveblogging: HIPAA Hosting at the Indiana Health Information Management Association Meeting</title>
		<link>http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/</link>
		<comments>http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/#comments</comments>
		<pubDate>Thu, 18 Apr 2013 13:14:05 +0000</pubDate>
		<dc:creator>Courtney Noonan</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[health IT conference]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[IHIMA]]></category>
		<category><![CDATA[indiana health]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=10822</guid>
		<description><![CDATA[<p>Online Tech is exhibiting HIPAA hosting solutions at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, Changing Times with IHIMA, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19. Check our blog &#8230; <a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/">Continue reading <span class="meta-nav">&#8594;</span></a></p><p>The post <a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/">Liveblogging: HIPAA Hosting at the Indiana Health Information Management Association Meeting</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="HIPAA Compliant Cloud" src="http://www.onlinetech.com/images/packages/packages-hipaa-cloud.png" alt="HIPAA Compliant Cloud" width="170" height="170" />Online Tech is exhibiting <a href="http://www.onlinetech.com/compliant-hosting/hipaa-compliant-hosting/overview">HIPAA hosting solutions</a> at booth #9 at the Indiana Health Information Management Association (IHIMA) 2013 Annual Meeting, <em><strong>Changing Times with IHIMA</strong></em>, held at the Indianapolis Marriott Downtown, in Indianapolis, IN on April 17-19.</p>
<p>Check our blog for updates over the next few days as we liveblog some of the most compelling health IT educational sessions.</p>
<p>The Annual Meeting features sessions on corporate compliance, accountable care organizations (ACOs), disclosure of protected health information, HIPAA/security final rule updates and more.</p>
<p>Our HIPAA hosting solutions for healthcare and related organizations include:</p>
<ul>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/colocation">HIPAA compliant colocation</a> with high availability power and offsite backup options.</li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/managed-servers">HIPAA compliant dedicated servers</a> with fully managed services.</li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting">HIPAA compliant private clouds</a> with fully managed services.</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">HIPAA compliant disaster recovery</a> with comprehensive cloud-based solutions.</li>
</ul>
<p><strong>About the Indiana Health Information Management Association</strong><br />
The Indiana Health Information Management Association (IHIMA) is a non-profit healthcare professional association representing over 2,000-credentialed Hoosiers. IHIMA is an affiliate with American Health Information Management Association (AHIMA) as a Component State Association. Our purpose is to commit to excellence in the management of health information for the benefit of patients and providers.</p>
<hr />
<p>The conference is just getting started. Everyone is setting up and grabbing Starbucks. Opening ceremony and exhibitor introductions begin at 8:30. Education sessions start at noon. Will be blogging about <em><strong>Corporate Compliance</strong></em> by Marsha Shepard, RHIA. Stay tuned!</p>
<div id="attachment_10824" class="wp-caption alignnone" style="width: 423px"><a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/online-tech-ihima/" rel="attachment wp-att-10824"><img class=" wp-image-10824 " title="Online Tech's Bill Ryan at IHIMA - Exhibiting HIPAA Hosting Solutions" src="http://resource.onlinetech.com/wp-content/uploads/Online-Tech-IHIMA.jpg" alt="Online Tech's Bill Ryan at IHIMA - Exhibiting HIPAA Hosting Solutions" width="413" height="551" /></a><p class="wp-caption-text">Online Tech&#8217;s Bill Ryan at IHIMA &#8211; Exhibiting HIPAA Hosting Solutions</p></div>
<p>The post <a href="http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/">Liveblogging: HIPAA Hosting at the Indiana Health Information Management Association Meeting</a> appeared first on <a href="http://resource.onlinetech.com">Managed Data Center News</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/liveblogging-hipaa-hosting-at-the-indiana-health-information-management-association-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
