<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Managed Data Center News, Trends, and Commentary</title>
	<atom:link href="http://resource.onlinetech.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://resource.onlinetech.com</link>
	<description>A Guide to Managed Hosting</description>
	<lastBuildDate>Wed, 22 Feb 2012 21:45:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Day 3 &#8211; Liveblogging from HIMSS &#8217;12!</title>
		<link>http://resource.onlinetech.com/day-3-liveblogging-from-himss-12/</link>
		<comments>http://resource.onlinetech.com/day-3-liveblogging-from-himss-12/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 15:54:00 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIMSS 12]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4833</guid>
		<description><![CDATA[We&#8217;re liveblogging from Las Vegas, site of the 12th Annual HIMSS Conference &#38; Exhibition, bringing together over 30,000 healthcare IT professionals and exhibitors. Visit us at booth #13528! For more on the conference, visit HIMSSConference.org. For more about Online Tech’s involvement, including more about HIPAA compliant hosting, visit Online Tech to Exhibit at HIMSS 12. We&#8217;re also in the [...]]]></description>
			<content:encoded><![CDATA[<p><img class=" wp-image-4856 alignright" title="HIMSS 12" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-12.jpg" alt="HIMSS 12" width="218" height="135" /></p>
<p>We&#8217;re liveblogging from Las Vegas, site of the 12th Annual HIMSS Conference &amp; Exhibition, bringing together over 30,000 healthcare IT professionals and exhibitors. Visit us at <strong>booth #13528</strong>!</p>
<ul>
<li>For more on the conference, visit <a href="http://www.himssconference.org/">HIMSSConference.org</a>.</li>
<li>For more about Online Tech’s involvement, including more about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a>, visit <a href="http://www.onlinetech.com/resources/events/seminars/online-tech-to-exhibit-at-himss-12">Online Tech to Exhibit at HIMSS 12</a>.</li>
<li>We&#8217;re also in the <a href="http://onlinebuyersguide.himss.org/profile.asp?VendorId=15268&amp;F_SearchCriteria=online+tech&amp;F_Country=&amp;F_State=&amp;F_CategoryId=&amp;F_City=&amp;F_Zip=">HIMSS Online Buyer&#8217;s Guide</a>.</li>
</ul>
<p><img class="alignleft" style="margin-left: 5px; margin-right: 5px;" title="Twitter Icon" src="http://resource.onlinetech.com/wp-content/uploads/Twitter-Icon.png" alt="Twitter Icon" width="126" height="34" />Tweeting about <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Elinkedin%2Ecom%2Fsignal%2F%3Fkeywords%3D%2523HIMSS&amp;urlhash=yYWy&amp;_t=NUS_UNIU_SHARE-lnk&amp;trk=NUS_UNIU_SHARE-lnk" target="_blank">#HIMSS</a>? Join us in the conversation on <a href="http://twitter.com/#!/OnlineTech">Online Tech’s Twitter</a>.</p>
<p><strong>9:18 A.M. ET &#8211; Pre-sunrise from the Wynn Las Vegas &amp; Encore Resort.</strong></p>
<div id="attachment_4837" class="wp-caption aligncenter" style="width: 499px"><img class=" wp-image-4837 " title="Pre-Sunrise at Wynn" src="http://resource.onlinetech.com/wp-content/uploads/Pre-Sunrise-at-Wynn.jpg" alt="Pre-Sunrise at Wynn" width="489" height="249" /><p class="wp-caption-text">Pre-Sunrise at Wynn</p></div>
<p><strong>11:07 A.M. ET &#8211; Dragon encounter on the way to the HIMSS &#8217;12 conference!</strong></p>
<div id="attachment_4841" class="wp-caption aligncenter" style="width: 353px"><img class=" wp-image-4841  " title="HIMSS 12 Dragon" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS12-Dragon.jpg" alt="HIMSS 12 Dragon" width="343" height="457" /><p class="wp-caption-text">HIMSS 12 Dragon</p></div>
<p><strong>11:07 A.M. ET (8:30 A.M. in Las Vegas) &#8211; Educational session <a href="http://www.himssconference.org/education/SessionDetail.aspx?ID=2696">&#8220;Social Media, Healthcare and Law: Developing a Social Media Policy&#8221;</a> about to begin.</strong> Come to Room Marcello #4502 for the session at HIMSS &#8217;12!</p>
<p>Speakers:</p>
<ul>
<li>Tatiana Melnik, JD, Associate Attorney, Dickinson Wright PLLC</li>
<li>Brian Balow, JD, Member, Dickinson Wright PLLC</li>
</ul>
<div id="attachment_4845" class="wp-caption aligncenter" style="width: 474px"><img class=" wp-image-4845 " title="Social Media and Healthcare Speakers" src="http://resource.onlinetech.com/wp-content/uploads/Social-Media-and-Healthcare-Speakers1.jpg" alt="Social Media and Healthcare Speakers" width="464" height="308" /><p class="wp-caption-text">Social Media and Healthcare Speakers</p></div>
<p><strong>11:37 A.M. ET &#8211; Social Media, Healthcare and the Law presentation by health IT attorneys from Dickinson Wright, Tatiana Melnik and Brian Balow.</strong></p>
<div id="attachment_4848" class="wp-caption aligncenter" style="width: 401px"><img class="size-full wp-image-4848" title="Social Media and Healthcare Presentation" src="http://resource.onlinetech.com/wp-content/uploads/Social-Media-and-Healthcare-Presentation.jpg" alt="Social Media and Healthcare Presentation" width="391" height="293" /><p class="wp-caption-text">Social Media and Healthcare Presentation</p></div>
<p><strong>Big turnout for the Social Media, Healthcare and the Law presentation!</strong></p>
<div id="attachment_4850" class="wp-caption aligncenter" style="width: 500px"><img class=" wp-image-4850 " title="Social Media and Healthcare Crowd" src="http://resource.onlinetech.com/wp-content/uploads/Social-Media-and-Healthcare-Crowd.jpg" alt="Social Media and Healthcare Crowd" width="490" height="367" /><p class="wp-caption-text">Social Media and Healthcare Crowd</p></div>
<p><strong>Standing room only at the Social Media &amp; Healthcare presentation.</strong></p>
<div id="attachment_4852" class="wp-caption aligncenter" style="width: 377px"><img class=" wp-image-4852 " title="Standing Room Only at HIMSS 12" src="http://resource.onlinetech.com/wp-content/uploads/Standing-Room-Only-at-HIMSS-12.jpg" alt="Standing Room Only at HIMSS 12" width="367" height="490" /><p class="wp-caption-text">Standing Room Only at HIMSS 12</p></div>
<p><strong>1:38 P.M. ET &#8211; &#8220;<a href="http://onlinebuyersguide.himss.org/event.asp?VendorId=15484&amp;PPSId=557">Anatomy of a Data Breach</a>&#8221; Knowledge Center Session by Chris Andrews of Kroll now in session @ HIMSS12.</strong></p>
<p>Speaker: Chris Andrews, Certified Forensic Computer Examiner, International Association of Computer Investigative Specialists (CFCE), EnCase Certified Examiner (EnCE)</p>
<div id="attachment_4854" class="wp-caption aligncenter" style="width: 622px"><img class="size-full wp-image-4854" title="Anatomy of a Data Breach" src="http://resource.onlinetech.com/wp-content/uploads/Anatomy-of-a-Data-Breach.jpg" alt="Anatomy of a Data Breach" width="612" height="459" /><p class="wp-caption-text">Anatomy of a Data Breach</p></div>
<p><strong>4:43 P.M. ET &#8211; Learning about governmental investments in e-health from a Danish approach.</strong></p>
<div id="attachment_4899" class="wp-caption aligncenter" style="width: 503px"><a href="http://resource.onlinetech.com/day-3-liveblogging-from-himss-12/danish-investments/" rel="attachment wp-att-4899"><img class=" wp-image-4899 " title="Governmental Investments in E-Health" src="http://resource.onlinetech.com/wp-content/uploads/Danish-Investments.jpg" alt="Governmental Investments in E-Health" width="493" height="382" /></a><p class="wp-caption-text">Governmental Investments in E-Health</p></div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/day-3-liveblogging-from-himss-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliant Clouds</title>
		<link>http://resource.onlinetech.com/hipaa-compliant-clouds/</link>
		<comments>http://resource.onlinetech.com/hipaa-compliant-clouds/#comments</comments>
		<pubDate>Wed, 22 Feb 2012 13:44:08 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[hipaa clouds]]></category>
		<category><![CDATA[hipaa compliant clouds]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[PHI availability]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4824</guid>
		<description><![CDATA[What does the cloud bring to the table for healthcare organizations when it comes to data storage, availability, and ability to meet HIPAA compliance standards? High-capacity storage without CapEx costs – The need for high-capacity storage and computing is high in the healthcare industry, with medical imaging producing large data files (X-rays, CAT scans, MRIs, [...]]]></description>
			<content:encoded><![CDATA[<p>What does the cloud bring to the table for healthcare organizations when it comes to data storage, availability, and ability to meet HIPAA compliance standards?</p>
<ul>
<li><strong>High-capacity storage without CapEx costs</strong> – The need for high-capacity storage and computing is high in the healthcare industry, with medical imaging producing large data files (X-rays, CAT scans, MRIs, etc.). A <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting/high-capacity-hipaa-cloud">high-capacity HIPAA cloud</a> can meet the needs of storage-intensive applications for healthcare companies that also need compliance. <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">Cloud hosting</a> can provide a viable solution without typical hardware requirements.</li>
</ul>
<p>Recommended reading: <em><a href="http://resource.onlinetech.com/key-benefits-of-leasing-vs-building-a-data-center/">Key Benefits of Leasing vs. Building a Data Center</a></em></p>
<ul>
<li><strong>PHI availability and accessibility – </strong>The HIPAA Security Rule requires protected health information is available, meaning “accessible and usable on demand by an authorized person” (HHS.gov). Hosting your data and applications with a third-party requires trust in their ability to provide <a href="http://www.onlinetech.com/company/michigan-data-centers/features/high-availability-server-hosting">high availability</a> services to ensure your data is accessible at all times when requested.</li>
</ul>
<p>Recommended Reading: <em><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-faq#What does HIPAA cover?">HIPAA FAQ: What Does HIPAA Cover?</a></em></p>
<ul>
<li><strong>Cloud disaster recovery for PHI availability – </strong>In the event of a disaster, electronic PHI or e-PHI, needs to be recoverable. The HIPAA Security Rule emphasizes the need to ensure the integrity of e-PHI, meaning that e-PHI “is not altered or destroyed in an unauthorized manner.” Cloud-based disaster recovery can significantly improve your recovery time objectives and is more reliable than traditional disaster recovery methods, including tape backup.</li>
</ul>
<p>Recommended reading: <em><a href="http://resource.onlinetech.com/disaster-recovery-for-hipaa-applications-its-all-about-availability-of-phi/">Disaster Recovery for HIPAA Applications – It’s All About Availability of PHI</a></em></p>
<ul>
<li><strong>Step closer to compliance</strong> – As a covered entity, you need to demonstrate and document compliance and the controls you have in place to achieve HIPAA compliance. An integral part of your compliance lies with the IT controls you have in place – if you partner with an audited, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/packages/cloud-hosting/high-capacity-hipaa-cloud">HIPAA compliant cloud</a> provider, they already have the documented policies they can hand over to help you demonstrate your own company’s compliance to the HHS/ONC. Additionally, business associates are also responsible for meeting compliance standards to prevent a data breach, as a <a href="http://resource.onlinetech.com/business-associates-must-be-hipaa-compliant-by-march-2012/">recent case</a> in which legal action was taken against a business associate exemplifies.</li>
</ul>
<p>But how can you be sure they’ll adhere to these controls when it comes to your data or applications in the cloud? Make sure you sign a business associate agreement (BAA) with your <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA hosting</a> provider outlining their obligations and responsibilities to meet compliance.</p>
<p>Recommended reading: <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider"><em>Five Questions to Ask Your HIPAA Hosting Provider</em></a></p>
<p>References:<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/srsummary.html">HHS.gov Summary of the HIPAA Security Rule</a><br />
<a href="http://healthcareitnews.com/news/6-keys-data-storage?page=0,1">6 Keys to Data Storage</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-compliant-clouds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Day 2 &#8211; Liveblogging from HIMSS &#8217;12!</title>
		<link>http://resource.onlinetech.com/day-2-liveblogging-from-himss-12/</link>
		<comments>http://resource.onlinetech.com/day-2-liveblogging-from-himss-12/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 14:07:04 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud compliance]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[HIMSS 12]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[las vegas]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4796</guid>
		<description><![CDATA[We&#8217;re liveblogging from Las Vegas, site of the 12th Annual HIMSS Conference &#38; Exhibition, bringing together over 30,000 healthcare IT professionals and exhibitors. For more on the conference, visit HIMSSConference.org. For more about Online Tech’s involvement, including more about HIPAA compliant hosting, visit Online Tech to Exhibit at HIMSS 12. Tweeting about #HIMSS? Join us in the conversation on Online Tech’s [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re liveblogging from Las Vegas, site of the 12th Annual HIMSS Conference &amp; Exhibition, bringing together over 30,000 healthcare IT professionals and exhibitors.</p>
<ul>
<li>For more on the conference, visit <a href="http://www.himssconference.org/">HIMSSConference.org</a>.</li>
<li>For more about Online Tech’s involvement, including more about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a>, visit <a href="http://www.onlinetech.com/resources/events/seminars/online-tech-to-exhibit-at-himss-12">Online Tech to Exhibit at HIMSS 12</a>.</li>
</ul>
<p><img class="alignleft" style="margin-left: 5px; margin-right: 5px;" title="Twitter Icon" src="http://resource.onlinetech.com/wp-content/uploads/Twitter-Icon.png" alt="Twitter Icon" width="126" height="34" />Tweeting about <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Elinkedin%2Ecom%2Fsignal%2F%3Fkeywords%3D%2523HIMSS&amp;urlhash=yYWy&amp;_t=NUS_UNIU_SHARE-lnk&amp;trk=NUS_UNIU_SHARE-lnk" target="_blank">#HIMSS</a>? Join us in the conversation on <a href="http://twitter.com/#!/OnlineTech">Online Tech’s Twitter</a>.</p>
<p><strong>Late o&#8217;clock - Play our Las Vegas-centric slideshow below to see the city at its finest, from the Bellagio Fountains to our view of the Las Vegas strip at night.</strong></p>
<p><object width="500" height="400" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.flickr.com/apps/slideshow/show.swf?v=109615" /><param name="flashvars" value="offsite=true&amp;lang=en-us&amp;page_show_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629417183519%2Fshow%2F&amp;page_show_back_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629417183519%2F&amp;set_id=72157629417183519&amp;jump_to=" /><param name="allowfullscreen" value="true" /><embed width="500" height="400" type="application/x-shockwave-flash" src="http://www.flickr.com/apps/slideshow/show.swf?v=109615" flashvars="offsite=true&amp;lang=en-us&amp;page_show_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629417183519%2Fshow%2F&amp;page_show_back_url=%2Fphotos%2Fonlinetech%2Fsets%2F72157629417183519%2F&amp;set_id=72157629417183519&amp;jump_to=" allowfullscreen="true" /></object></p>
<p><center></center><strong>11:33 A.M. &#8211; The HIMSS keynote address is underway &#8211; the co-founder of Twitter, Biz Stone, is speaking next.</strong></p>
<div id="attachment_4810" class="wp-caption aligncenter" style="width: 503px"><img class="wp-image-4810 " title="HIMSS Keynote Speaker" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-Keynote.jpg" alt="HIMSS Keynote Speaker" width="493" height="370" /><p class="wp-caption-text">HIMSS Keynote Speaker</p></div>
<p><strong>11:46 A.M. &#8211; Biz Stone, co-founder of Twitter, speaking at the HIMSS &#8217;12 keynote address!</strong></p>
<div id="attachment_4813" class="wp-caption aligncenter" style="width: 509px"><img class=" wp-image-4813 " title="Biz Stone Twitter Co-Founder" src="http://resource.onlinetech.com/wp-content/uploads/Biz-Stone-Twitter-Founder.jpg" alt="Biz Stone Twitter Co-Founder" width="499" height="286" /><p class="wp-caption-text">Biz Stone Twitter Co-Founder</p></div>
<p>HealthCareITNews.com posted a <a href="http://bit.ly/y82IuI">Twitter recap</a> of Biz Stone&#8217;s keynote:</p>
<blockquote><p>Tuesday’s HIMSS12 Keynote was given by Biz Stone, one of the co-founders of Twitter. Social media is certainly a hot topic at HIMSS12, and Stone explained ways we can refine communication in our businesses.</p></blockquote>
<p><strong>2:10 P.M. &#8211; HIMSS educational session: <a href="http://www.himssconference.org/education/SessionDetail.aspx?ID=2646">Data Center Hosting &#8211; Build, Upgrade or Partner</a></strong></p>
<p>Speakers:</p>
<p>Tanya Freeman, MS<br />
Chief Information Officer, Central Maine Healthcare Corporation</p>
<p>Mr. Denis Tanguay<br />
CIO, Central Maine Healthcare</p>
<div id="attachment_4815" class="wp-caption aligncenter" style="width: 500px"><img class=" wp-image-4815 " title="Data Center Hosting" src="http://resource.onlinetech.com/wp-content/uploads/Data-Center-Hosting.jpg" alt="Data Center Hosting" width="490" height="367" /><p class="wp-caption-text">Data Center Hosting</p></div>
<p><strong>4:30 P.M. &#8211; Listening to a cloud and compliance talk at HIMSS.</strong></p>
<div id="attachment_4819" class="wp-caption aligncenter" style="width: 496px"><img class=" wp-image-4819 " title="Cloud Compliance Talk" src="http://resource.onlinetech.com/wp-content/uploads/Cloud-Compliance.jpg" alt="Cloud Compliance Talk" width="486" height="379" /><p class="wp-caption-text">Cloud Compliance Talk</p></div>
<p><strong>View from the 60th floor (top) of the Wynn Las Vegas &amp; Encore Resort.</strong></p>
<div id="attachment_4821" class="wp-caption aligncenter" style="width: 503px"><img class=" wp-image-4821    " title="Night View from Wynn" src="http://resource.onlinetech.com/wp-content/uploads/View-from-Wynn.jpg" alt="Night View from Wynn" width="493" height="370" /><p class="wp-caption-text">Night View from Wynn</p></div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/day-2-liveblogging-from-himss-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Review Your Server’s Backup Status with OTPortal</title>
		<link>http://resource.onlinetech.com/review-your-servers-backup-status-with-otportal/</link>
		<comments>http://resource.onlinetech.com/review-your-servers-backup-status-with-otportal/#comments</comments>
		<pubDate>Tue, 21 Feb 2012 12:00:17 +0000</pubDate>
		<dc:creator>Kurt Schaldenbrand</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[data backup status]]></category>
		<category><![CDATA[managed dedicated servers]]></category>
		<category><![CDATA[managed servers]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[otbackup]]></category>
		<category><![CDATA[OTPortal]]></category>
		<category><![CDATA[remote server monitoring]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4781</guid>
		<description><![CDATA[As an Online Tech client, you can use OTPortal to easily monitor the backup status of any servers for which you have OTBackup. Login to OTPortal at https://customer.onlinetech.com, open the Systems tab, and check the Devices section. Here you’ll find a color-coded indicator of each server’s backup status; green for good and red for failed. [...]]]></description>
			<content:encoded><![CDATA[<p>As an Online Tech client, you can use OTPortal to easily monitor the backup status of any servers for which you have <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">OTBackup</a>. Login to OTPortal at <a href="https://customer.onlinetech.com/">https://customer.onlinetech.com</a>, open the <em>Systems</em> tab, and check the <em>Devices</em> section.</p>
<div id="attachment_4782" class="wp-caption aligncenter" style="width: 505px"><img class=" wp-image-4782  " title="Backup Devices View" src="http://resource.onlinetech.com/wp-content/uploads/Backup-DevicesView.png" alt="Backup Devices View" width="495" height="356" /><p class="wp-caption-text">Backup Devices View</p></div>
<p>Here you’ll find a color-coded indicator of each server’s backup status; green for good and red for failed. Our engineers constantly monitor backup jobs, and promptly restart backups for failed jobs. A notice that a job has been restarted is normally posted to the <em>Messages</em> section on the <em>Status Dashboard</em>.</p>
<p>To view more information for the last backup job for a given server, click the <em>Device Detail</em> button. The <em>Device Detail</em> page shows the date and time of the most recent backup job, as well as several other details regarding the server.</p>
<div id="attachment_4783" class="wp-caption aligncenter" style="width: 503px"><img class=" wp-image-4783  " title="Backup Messages View" src="http://resource.onlinetech.com/wp-content/uploads/Backup-MessagesView.png" alt="Backup Messages View" width="493" height="275" /><p class="wp-caption-text">Backup Messages View</p></div>
<p>If you would like to add OTBackup for a <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">server</a> that doesn’t already have it, simply click on the <em>Upgrade</em> button for that server. You can easily add additional RAM, CPU, disk storage, SAN space, or OTBackup for any server you have that is managed by Online Tech.</p>
<p>Additional information about OTPortal is available in several training videos, found right on the site itself. If you have specific questions or need help, please contact us at <a href="mailto:support@onlinetech.com">support@onlinetech.com</a>, or by calling 734-213-2020 and selecting Option 3.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/review-your-servers-backup-status-with-otportal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Day 1 &#8211; Liveblogging from HIMSS &#8217;12!</title>
		<link>http://resource.onlinetech.com/liveblogging-from-himss-12/</link>
		<comments>http://resource.onlinetech.com/liveblogging-from-himss-12/#comments</comments>
		<pubDate>Mon, 20 Feb 2012 14:43:34 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIMSS 12]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4746</guid>
		<description><![CDATA[The Online Tech Team has officially landed in Las Vegas for HIMSS &#8217;12, the Annual HIMSS Conference &#38; Exhibition bringing together over 30,000 healthcare IT professionals and exhibitors. For more on the conference, visit HIMSSConference.org. For more about Online Tech&#8217;s involvement, including more about HIPAA compliant hosting, visit Online Tech to Exhibit at HIMSS 12. Tweeting [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" style="margin-left: 10px; margin-right: 10px;" title="HIMSS Gold Corporate Member" src="http://www.onlinetech.com/images/stories/misc/himss%20gold%20corporate%20member.png" alt="HIMSS Gold Corporate Member" width="211" height="69" /></p>
<p>The Online Tech Team has officially landed in Las Vegas for HIMSS &#8217;12, the Annual HIMSS Conference &amp; Exhibition bringing together over 30,000 healthcare IT professionals and exhibitors.</p>
<ul>
<li>For more on the conference, visit <a href="http://www.himssconference.org/">HIMSSConference.org</a>.</li>
<li>For more about Online Tech&#8217;s involvement, including more about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview">HIPAA compliant hosting</a>, visit <a href="http://www.onlinetech.com/resources/events/seminars/online-tech-to-exhibit-at-himss-12">Online Tech to Exhibit at HIMSS 12</a>.</li>
</ul>
<p><img class="alignleft" style="margin-top: 0px; margin-bottom: 0px; margin-left: 5px; margin-right: 5px;" title="Twitter Icon" src="http://resource.onlinetech.com/wp-content/uploads/Twitter-Icon.png" alt="Twitter Icon" width="126" height="34" />Tweeting about <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Elinkedin%2Ecom%2Fsignal%2F%3Fkeywords%3D%2523HIMSS&amp;urlhash=yYWy&amp;_t=NUS_UNIU_SHARE-lnk&amp;trk=NUS_UNIU_SHARE-lnk" target="_blank">#HIMSS</a>? Join us in the conversation on <a href="http://twitter.com/#!/OnlineTech">Online Tech’s Twitter</a>.</p>
<p><strong>9:30 A.M. &#8211; Good Morning, Las Vegas!</strong></p>
<div id="attachment_4747" class="wp-caption aligncenter" style="width: 356px"><img class="wp-image-4747 " title="Good Morning, Las Vegas" src="http://resource.onlinetech.com/wp-content/uploads/Good-Morning-Las-Vegas.jpg" alt="Good Morning, Las Vegas" width="346" height="461" /><p class="wp-caption-text">Good Morning, Las Vegas</p></div>
<p>The strip waking up &#8230; Or more likely going to sleep &#8230;</p>
<p>Off to the HIMSS &#8217;12 pre-workshops!</p>
<p><strong>10:50 A.M. &#8211; Fueling up, registration at the Las Vegas Sands Expo &amp; Convention Center, and starting a CPHIMS educational session at HIMSS 12.</strong></p>
<div id="attachment_4763" class="wp-caption aligncenter" style="width: 522px"><img class=" wp-image-4763  " title="HIMSS 12 Breakfast &amp; Registration" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-Monday.jpg" alt="HIMSS 12 Breakfast &amp; Registration" width="512" height="190" /><p class="wp-caption-text">HIMSS 12 Breakfast &amp; Registration</p></div>
<div id="attachment_4765" class="wp-caption aligncenter" style="width: 506px"><img class=" wp-image-4765      " title="CPHIMS Certification Education Session" src="http://resource.onlinetech.com/wp-content/uploads/Class-Starting.jpg" alt="CPHIMS Certification Education Session" width="496" height="372" /><p class="wp-caption-text">CPHIMS Certification Education Session</p></div>
<p>Looking forward to learning more about <a href="http://www.himss.org/ASP/certification_cphims.asp">CPHIMS</a> (Certified Professional in Healthcare Information and Management Systems) with Ruth Bowen &amp; Susan Wozniak @ HIMSS12!</p>
<p><strong>3:30 P.M. &#8211; Setting up the Online Tech HIPAA Hosting Booth (#</strong><strong>13528) Exhibit.</strong></p>
<div id="attachment_4771" class="wp-caption aligncenter" style="width: 508px"><img class=" wp-image-4771 " title="Online Tech HIPAA Compliant Hosting Booth Setup" src="http://resource.onlinetech.com/wp-content/uploads/Booth-Setup1.jpg" alt="Online Tech HIPAA Compliant Hosting Booth Setup" width="498" height="622" /><p class="wp-caption-text">Online Tech HIPAA Compliant Hosting Booth Setup</p></div>
<div id="attachment_4769" class="wp-caption aligncenter" style="width: 509px"><img class=" wp-image-4769  " title="Booth Unloading and Exhibitor Space" src="http://resource.onlinetech.com/wp-content/uploads/Booth-Unloading.jpg" alt="Booth Unloading and Exhibitor Space" width="499" height="143" /><p class="wp-caption-text">HIMSS Exhibitor Booth Unloading</p></div>
<p><strong>4:40 P.M. &#8211; Our HIMSS hotel!</strong></p>
<div id="attachment_4778" class="wp-caption aligncenter" style="width: 500px"><img class=" wp-image-4778 " title="HIMSS Hotel" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-Hotel.jpg" alt="HIMSS Hotel" width="490" height="343" /><p class="wp-caption-text">HIMSS Hotel</p></div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/liveblogging-from-himss-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gearing Up For HIMSS &#8217;12 in Las Vegas! Online Tech Exhibits HIPAA Hosting Solutions</title>
		<link>http://resource.onlinetech.com/gearing-up-for-himss-12-in-las-vegas-online-tech-exhibits-hipaa-hosting-solutions/</link>
		<comments>http://resource.onlinetech.com/gearing-up-for-himss-12-in-las-vegas-online-tech-exhibits-hipaa-hosting-solutions/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 21:10:56 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIMSS 12]]></category>
		<category><![CDATA[hipaa clouds]]></category>
		<category><![CDATA[hipaa colocation]]></category>
		<category><![CDATA[hipaa compliant clouds]]></category>
		<category><![CDATA[hipaa compliant colocation]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa managed servers]]></category>
		<category><![CDATA[hipaa servers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4709</guid>
		<description><![CDATA[Online Tech is gearing up for the 12th Annual HIMSS Conference &#38; Exhibition in Las Vegas next week, one of the largest healthcare IT conferences in the world. We&#8217;ll be exhibiting our HIPAA compliant hosting solutions for healthcare organizations, healthcare Software-as-a-Service (Saas) and other related organizations at Booth #13528. Stay tuned for some live blogging from our Online [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="margin: 5px;" src="http://www.onlinetech.com/images/stories/misc/himss%20logo.png" alt="" width="272" height="180" />Online Tech is gearing up for the 12th Annual HIMSS Conference &amp; Exhibition in Las Vegas next week, one of the largest healthcare IT conferences in the world.</p>
<p>We&#8217;ll be exhibiting our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> solutions for healthcare organizations, healthcare Software-as-a-Service (Saas) and other related organizations at <strong>Booth #13528. </strong>Stay tuned for some live blogging from our Online Tech reps next week!</p>
<p>Our HIPAA cloud, colocation and managed server packages have just launched! And we&#8217;ve revamped and expanded the HIPAA section of our website. Click below for more details.</p>
<p><a href="index.php?option=com_k2&amp;view=item&amp;layout=item&amp;id=544&amp;Itemid=761"><img src="http://www.onlinetech.com/images/overview/hipaa-cloud-overview.png" alt="HIPAA Cloud Hosting" width="175" height="183" /></a><img src="http://www.onlinetech.com/images/overview/hipaa-managed-servers-overview.png" alt="HIPAA Managed Servers" width="175" height="183" /><img src="http://www.onlinetech.com/images/overview/hipaa-colocation-overview.png" alt="HIPAA Colocation" width="176" height="183" /></p>
<p>We&#8217;re one of the few (perhaps only) 100% HIPAA compliant hosting providers that have undergone an independent audit by a CHP (Certified HIPAA Practitioner) and CHSS (Cerified HIPAA Security Specialist) and can provide a copy of our audit report to clients under NDAs (non-disclosure agreements).</p>
<p>We also sign business associate agreements (BAAs) to clarify our role and responsibilities when it comes to protecting your personal health information (PHI) and breach notification policies.</p>
<div id="attachment_4732" class="wp-caption alignright" style="width: 221px"><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/overview"><img class="wp-image-4732  " title="HIPAA Compliant Hosting Screenshot" src="http://resource.onlinetech.com/wp-content/uploads/HIPAA-Compliant-Hosting-Screenshot.png" alt="HIPAA Compliant Hosting Screenshot" width="211" height="207" /></a><p class="wp-caption-text">HIPAA Compliant Hosting Screenshot</p></div>
<p>Get the facts about HIPAA and what you need to be HIPAA compliant:</p>
<ul>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/100-hipaa-compliant">100% HIPAA Compliant</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/what-is-hipaa-compliance">What is HIPAA Compliance?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-compliant-case-studies">HIPAA Compliant Case Studies</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/who-needs-to-be-hipaa-compliant">Who Needs to be HIPAA Compliant?</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/benefits-of-hipaa-compliant-hosting">Benefits of HIPAA Compliant Hosting</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources: Policies, Procedures and Training Materials</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/hipaa-faq">HIPAA FAQ</a></li>
<li><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/resources/five-questions-to-ask-your-business-associates">Five Questions to Ask Your Business Associates</a></li>
<li><a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider">Five Questions to Ask Your HIPAA Hosting Provider</a></li>
</ul>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/gearing-up-for-himss-12-in-las-vegas-online-tech-exhibits-hipaa-hosting-solutions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Health App Regulations: FDA &amp; HIPAA</title>
		<link>http://resource.onlinetech.com/mhealth-app-regulations-fda-hipaa/</link>
		<comments>http://resource.onlinetech.com/mhealth-app-regulations-fda-hipaa/#comments</comments>
		<pubDate>Fri, 17 Feb 2012 13:53:04 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[FDA]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>
		<category><![CDATA[mHealth]]></category>
		<category><![CDATA[mobile app regulation]]></category>
		<category><![CDATA[mobile health]]></category>
		<category><![CDATA[mobile health apps]]></category>
		<category><![CDATA[ONC]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4691</guid>
		<description><![CDATA[Mobile healthcare and apps, mHealth, is, at times, quite literally a matter of life and death. And from my recent research on the trend, there’s widespread agreement that the industry requires pre-defined standards and strong regulation to 1) protect the quality of patient care; and 2) ensure PHI is secure and handled properly. Yet, being [...]]]></description>
			<content:encoded><![CDATA[<p>Mobile healthcare and apps, mHealth, is, at times, quite literally a matter of life and death. And from my recent research on the trend, there’s widespread agreement that the industry requires pre-defined standards and strong regulation to 1) protect the quality of patient care; and 2) ensure PHI is secure and handled properly.</p>
<p>Yet, being enveloped in the HIPAA realm for some time has skewed my thinking – when I heard about the FDA regulating healthcare apps, I was confused. Instinctually, albeit not intellectually, I’d always thought the FDA provided insight into topics like food poisoning and MSG – not smartphones and apps, or anything technology-related.</p>
<p>However a <a href="http://www.mhimss.org/blog/five-reasons-why-digital-health-technologies-need-fda-oversight">recent blog post</a> by David Lee Scher, MD, opened my eyes to a few reasons why he believes the FDA needs to be the regulatory body of “digital health technologies.” And some reasons why those in the field aren&#8217;t very fond of the organization – he mentions the fact that the FDA slows the approval process for apps annually and raises review fees for device companies, increasing developer frustration over the increased time to market.</p>
<p>One of the points he brings up is the fact that the FDA’s mandate isn’t covered by other related agencies – including the ONC and FCC (broadband access). The ONC, acting on behalf of the HHS, is notorious for enforcing the HIPAA and HITECH compliance laws, yet Scher reduces that to, “oversees EHRs.” A slightly broader perspective might say the ONC oversees the handling of PHI, not just EHRs, since the majority of HIPAA breach cases involved some type of physical theft or loss, as you can see in my infographic breakdown of the <a href="http://resource.onlinetech.com/2011-hipaa-violations-and-audits/">2011 HIPAA violation breach types</a>.</p>
<p>While the FDA should and will be involved in evaluating apps for their ability to improve patient health, they need to make collaboration with the ONC/HHS a priority to test apps for their ability to keep PHI secure. Scher references commentary in <a href="http://p.washingtontimes.com/news/2012/feb/7/fdas-assault-on-mobile-technologies/">The Washington Times</a> by Joel White – White’s position is primarily against FDA app regulation, including the argument that the FDA’s “piecemeal and oftentimes conflicting structure” of regulation raises concerns on how these rules intend to coexist with rules established by other agencies.</p>
<p>White argues a point from a recent State of the Union speech in support of his opinion; “tearing down outdated regulatory structures” allows innovation to flourish and encourages economic growth. Although potentially initially true, I don’t think throwing every regulatory body or law out the window is productive – without mHealth oversight, patient care may decrease significantly in quality with the advent of untested apps released to market, causing more costly and potentially dangerous issues down the road.</p>
<p>A regulatory body may also serve to prevent a flooded healthcare app industry (perhaps prolonging its success) and work to inform consumers of their quality and security when it comes to keeping health records secure.</p>
<p>Ultimately, I think we need a cohesive and productive collaboration between every agency and organization that touches mHealth and a way of streamlining the process to prevent wasted resources and time.</p>
<p><strong>References:</strong><br />
<a href="http://www.mhimss.org/blog/five-reasons-why-digital-health-technologies-need-fda-oversight">Five Reasons Why Digital Health Technologies Need FDA Oversight</a><br />
<a href="http://p.washingtontimes.com/news/2012/feb/7/fdas-assault-on-mobile-technologies/">White: FDA’s Assault on Mobile Technologies</a><strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/mhealth-app-regulations-fda-hipaa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Associates Must Be HIPAA Compliant By March 2012</title>
		<link>http://resource.onlinetech.com/business-associates-must-be-hipaa-compliant-by-march-2012/</link>
		<comments>http://resource.onlinetech.com/business-associates-must-be-hipaa-compliant-by-march-2012/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 13:27:01 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[business associate agreement]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4678</guid>
		<description><![CDATA[While the Department of Health and Human Services (HHS) shows that business associate-related HIPAA breaches were responsible for 62 percent of the total number of patient records breached (as seen in this blog post), there has not been government legal action taken against business associates until recently. Minnesota’s Attorney General is suing a business associate [...]]]></description>
			<content:encoded><![CDATA[<p>While the Department of Health and Human Services (HHS) shows that business associate-related HIPAA breaches were responsible for 62 percent of the total number of patient records breached (as seen in <a href="http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/">this blog post</a>), there has not been government legal action taken against business associates until recently.</p>
<p>Minnesota’s Attorney General is suing a business associate over an unencrypted data breach incident that occurred last year when a laptop containing 23,500 patient records was stolen from the business associate’s car. Accretive Health is a licensed debt collector that also provides a patient analysis service for hospitals.</p>
<p>Part of the reason why they were targeted may be linked to further complexity of the case – not only did Accretive Health suffer from a data breach, but the lawsuit claims they were also accessing and using patient data without the knowledge or consent of patients. One of their services provided the probability of a patient’s hospital admittance and their calculated potential financial worth to the patient’s healthcare provider, all based on perceived risk factors from their personal health information, according to the <a href="http://www.ag.state.mn.us/PDF/Consumer/AccretiveHealth20120119.pdf">claim</a> (PDF).</p>
<p>Another major <a href="http://resource.onlinetech.com/military-healthcare-contractor%E2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/">HIPAA violation case</a> involving a business associate was the Department of Defense’s military healthcare program, in which nearly the exact same incident occurred – a contractor employee left an unencrypted laptop in their car and it was stolen. About 4.9 million patients were affected. A lawsuit was filed by a few of the affected patients, and in the claim, they indicated the need for all contractor employees to be properly trained in how to handle personal health information (PHI).</p>
<p><strong>Modifications to HIPAA Applicability</strong></p>
<p>Are business associates lax on HIPAA compliance because the law has no teeth? That’ll change very soon – according to HealthCareInfoSecurity.com, <strong>March 2012</strong> is the target date to release a final version of the HIPAA modifications and breach notification rule (also known as the Omnibus rule, meaning <em>for all</em> in Latin). And in the proposed version of HIPAA modifications, business associates will be required to comply with the HIPAA standards, as seen in the change to the <strong><a href="http://www.hipaasurvivalguide.com/hipaa-regulations/164-104.php">§164.104 Applicability</a> </strong>rule:</p>
<blockquote><p>When a health care clearinghouse creates or receives protected health information as a business associate of another covered entity, or other than as a business associate of a covered entity, the clearinghouse must comply with <a href="http://www.hipaasurvivalguide.com/hipaa-regulations/164-105.php">§164.105</a> relating to organizational requirements for covered entities, including the designation of health care components of a covered entity.</p></blockquote>
<p><strong>Roadmap to Achieving Compliance</strong></p>
<p>How can a business associate avoid a potential HIPAA violation, subsequent lawsuits and fines? Try the following:</p>
<ul>
<li><strong>Conduct and document an initial risk assessment/analysis</strong> in order to check where your business is at when it comes to implementing HIPAA security safeguards, and where you need to fill in the gaps. This list of the <em><a href="http://resource.onlinetech.com/nine-elements-of-a-hipaa-risk-analysis/">Nine Components of a HIPAA Risk Analysis</a></em> provides a good high-level overview of what you need to include in your document.</li>
<li><strong>Research and understand the HIPAA standards</strong>, and your role in handling PHI. As a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> provider, Online Tech never accesses PHI or data on clients’ servers, we only provide the secure infrastructure necessary to protect sensitive information in a fully compliant environment.</li>
<li><strong>Draft a business associate agreement (BAA)</strong> that clearly defines your role and obligation in handling a client’s sensitive data. Include clauses about contract termination, data ownership and breach notification. <em><a href="http://resource.onlinetech.com/what%E2%80%99s-in-a-business-associate-agreement/">What’s in a Business Associate Agreement?</a> </em>provides a summary of the primary provisions to include in your BAA.</li>
<li><strong>Ideally, invest in an independent HIPAA audit</strong> of your business in order to have the assurance and verification that your policies, procedures and services are in compliance. If you need guidance on which IT components can help you achieve compliance, read our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq#What services from Online Tech help make me compliant?">HIPAA FAQ</a>.</li>
<li><strong>Train all of your employees in HIPAA compliant policies and procedures</strong> as they affect the day-to-day operations of your company and according to the level of security needed by position – an employee that transports sensitive data will need more specific guidelines to stay compliant and prevent a data breach. Document proof of employee training and awareness.</li>
<li><strong>Appoint a Risk Management and Security Officer </strong>position in your company to implement, manage and oversee compliance and ensure everyone is following the documented policies and procedures, preferably someone with a strong technical background.</li>
</ul>
<p>Or are you a covered entity that needs assurance their business associates are handling PHI in a HIPAA compliant manner? Read our E-Tip on the top <em><a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider">Five Questions to Ask Your HIPAA Hosting Provider</a></em>.</p>
<p>References:<br />
<a href="http://www.healthcareinfosecurity.com/articles.php?art_id=4508">March Target for HIPAA Modifications</a><br />
<a href="http://www.ag.state.mn.us/PDF/Consumer/AccretiveHealth20120119.pdf">State of Minnesota vs. Accretive Health, Inc. (PDF)</a><br />
<a href="http://www.startribune.com/local/137678533.html">Minnesota Sues Consulting Firm Over Lost Health Data</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/business-associates-must-be-hipaa-compliant-by-march-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Last Chance: SSAE 16 &amp; SOC Webinar</title>
		<link>http://resource.onlinetech.com/last-chance-ssae-16-soc-webinar/</link>
		<comments>http://resource.onlinetech.com/last-chance-ssae-16-soc-webinar/#comments</comments>
		<pubDate>Tue, 14 Feb 2012 15:09:58 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data center audits]]></category>
		<category><![CDATA[data center standards]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[ssae 16]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4661</guid>
		<description><![CDATA[It&#8217;s your last chance to sign up for our free, informative webinar today at 2 P.M. ET with David Barton, Jon Long and Online Tech&#8217;s Risk Management &#38; Security Officer Jason Yaeger for a discussion to help clarify data center audit standards and assessments. Register for our free webinar Tuesday, February 14, 2012 (today) from 2-3pm ET to discuss [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s your last chance to sign up for our free, informative webinar today at 2 P.M. ET with David Barton, Jon Long and Online Tech&#8217;s Risk Management &amp; Security Officer Jason Yaeger for a discussion to help clarify data center audit standards and assessments.</p>
<p><a href="https://www3.gotomeeting.com/register/665591734"><img class="alignleft" style="margin: 10px;" src="http://www.onlinetech.com/images/stories/misc/soc-logo-150.png" alt="SOC 2" width="150" height="137" />Register for our free webinar</a> <strong>Tuesday, February 14, 2012 (today) from 2-3pm ET</strong> to discuss the differences between AICPA&#8217;s (American Institute of Certified Public Accountants) SOC (Service Organization Controls) audits and reports, other types of audits, and the difference between point-in-time, period of time, self-assesments and independent assessments.</p>
<p><a href="https://www3.gotomeeting.com/register/665591734">Sign up Now!</a></p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p><a href="http://www.uhyadvisors-us.com/"><img class="alignleft" style="margin-top: 10px; margin-bottom: 10px;" title="002e7b8" src="http://www.uhyadvisors-us.com/respics/DavidBarton.jpg" alt="David Barton, CRISC and CISA" width="128" height="160" /></a></p>
<p><strong>David Barton, CRISC, Principal, UHY LLP</strong><br />
David is a Principal and is the practice leader of the Technology Assurance and Advisory Services group at <a href="http://www.uhyadvisors-us.com/">UHY Advisors, Inc.</a> in Atlanta, GA. He is Certified in Risk and Information Systems Controls (CRISC) and received his Certified Information Systems Auditor (CISA) designation in 1988.</p>
<p>With over 25 years practical experience in information systems and technology risk and controls, he is an expert in identifying and reducing information technology risk throughout an organization.</p>
<p>Read David Barton&#8217;s guest blog post on our blog, &#8220;<a href="http://resource.onlinetech.com/socs-and-sass-the-new-standards-for-service-organization-controls-reporting/">SOCs and SASs: The New Standards for Service Organization Controls Reporting</a>.&#8221;</p>
<div>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<div><a href="http://1.bp.blogspot.com/-lTCRuI6N6qY/Tx7jAiKLAXI/AAAAAAAAAIY/3cj-ssvuNV4/s1600/ProfilePicture.jpg"><img class="alignleft" style="margin: 10px;" src="http://www.onlinetech.com/images/stories/misc/jon-long-150.png" alt="jon-long-150" width="120" height="160" /></a><strong>Jon Long, CISA, QSA Senior Audit Manager CompliancePoint</strong><br />
Jon is a Senior Manager and Practice Builder at <a href="http://www.compliancepoint.com/">CompliancePoint</a> as well as an enthusiastic blogger at <a href="http://www.riskassuranceguy.blogspot.com/">The Risk Assurance Guy</a>. He is a Certified Information Systems Auditor (CISA) as well as a Qualified Security Assessor (QSA) in the Payment Card Industry (PCI).</div>
<div>Jon has over 15 years experience in IT, and crossed over into auditing in 2006.  His background enables him to conduct audits from the perspective of having been audited by external auditors.  He is currently championing an audit approach that allows organizations to combine multiple compliance requirements into a single SOC 2 engagement.</div>
<div></div>
<div></div>
<div></div>
<div></div>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
</div>
<p><strong>Jason Yaeger, Risk Management &amp; Security Officer, Online Tech</strong></p>
<p><img class="alignleft" style="margin: 10px;" src="http://www.onlinetech.com/images/stories/people/jason-yeager-160.png" alt="jason-yeager-160" width="115" height="154" /></p>
<p>Jason Yaeger is Online Tech’s Risk Management and Security Officer. In his 3 years at Online Tech, Jason has guided the company through successful completion of many audits, including SAS 70 Type I, SAS 70 Type II, SSAE 16, and HIPAA. In addition to overseeing operations across all of Online Tech’s data centers, Jason is also the Vice President of the Southeast Michigan Chapter of 7&#215;24 Exchange. Prior to Online Tech, Jason was Director of Internet Operations at 20/20 Communications where he spent 8 years developing the company’s wireless and internet initiatives.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/last-chance-ssae-16-soc-webinar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Questions to Ask Your Business Associate: Question #4 Disaster Recovery</title>
		<link>http://resource.onlinetech.com/five-questions-to-ask-your-business-associate-question-4-disaster-recovery/</link>
		<comments>http://resource.onlinetech.com/five-questions-to-ask-your-business-associate-question-4-disaster-recovery/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 15:08:19 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[high availability]]></category>
		<category><![CDATA[hipaa compliant cloud]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4655</guid>
		<description><![CDATA[If disaster strikes, how long will it take before PHI is available again? Part of due diligence is asking yourself and your partners detailed questions about contingency plans in the event of a disaster. HIPAA – The Health Insurance Portability and Accountability Act focuses on three key criteria for handling Protected Health Information (PHI): availability, [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><em><strong>If disaster strikes, how long will it take before PHI is available again?</strong></em></p>
<p>Part of due diligence is asking yourself and your partners detailed questions about contingency plans in the event of a disaster.</p>
</div>
<div>
<p><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a> – The Health Insurance Portability and Accountability Act focuses on three key criteria for handling Protected Health Information (PHI): availability, confidentiality and integrity. Of these, availability often takes second stage to security concerns, but in a real health emergency, is most important to patient health.</p>
<p>Availability means that PHI is always available, accessible and never lost. When a patient arrives at the emergency room at three o’clock in the morning, the electronic health records need to be available so the physician can address the emergency with all of the patient’s records at her fingertips. Patient records in the health care world is no longer a 9-5 job – and one of the main drivers behind electronic health records (EHR) is the portability and availability of patients’ records to health care providers around the clock.</p>
<p>Availability also means that PHI isn’t lost. HIPAA and the HITECH Act make Covered Entities and Business Associates responsible for making sure PHI isn’t lost. For electronic records, this means offsite data backups are imperative and offsite <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> is strongly recommended.</p>
<p>From a computing and application infrastructure point of view, &#8220;availability&#8221; means 2 things:</p>
<ol>
<li><strong>Disaster Prevention</strong> – putting all the tools in place to minimize the probability of an outage in the data center infrastructure, server hardware, software and network connectivity.</li>
<li><strong>Disaster Recovery</strong> – assuring that the applications and data can be recovered and restored in a reasonable timeframe to continue running the business and making patient data available if there is a disaster in the primary data center.</li>
</ol>
<p>Disaster Prevention is typically thought of in terms of “High Availability” – or redundant systems to assure that there is no single point of failure on the delivery of the application or data. Examples of high availability at the data center level include <a href="http://www.onlinetech.com/company/michigan-data-centers/features/high-availability-server-hosting">high availability</a> power delivery through redundant generators, uninterruptible power supplies (UPSs), power distribution units (PDUs), and redundant power supplies in the servers. With high availability power, the failure of any element (generator, UPS, or power supply) does not affect the availability of the application – since the entire infrastructure is redundant.</p>
<p>Redundancy can also be delivered in the cloud server platform. For example, <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">HIPAA compliant cloud</a> servers run on redundant hardware hosts with multiple power supplies, multiple network connections to SANs, redundant controllers and redundant RAID drives. Again, any hardware failure or even complete shutdown of a hardware hosts will not affect the availability of the application and the PHI data.</p>
<p>Disaster Recovery is typically thought of in terms of Recovery Time Objective (RTO) and Recovery Point Objective (RPO). RTO is the amount of time it takes to spin up the servers, network, application and data as a separate data center in the case that the application is shut down from a disaster.</p>
<p>RTOs can range from minutes to weeks depending on the technology selected. RPO is defined as how close to the disaster the data can be recovered, which is tied to how often the data is backed up. If backups are made every night, then the RPO is 24 hours (up to 24 hours of data can be lost). If continuous replication is used, the loss may be as short as a few minutes. The shorter the RTO and RPO, the better.</p>
<p>As a minimum, all HIPAA applications should use <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a>. That way, if the production data center has a disaster or is destroyed, the PHI isn’t lost. The backup should be located a significant distance away to assure the same disaster doesn’t strike both sites. Every region of the country has a recommended best practices for geographic separation; in the Midwest, it&#8217;s at least 50 miles apart.</p>
<p>For critical PHI, a warm site disaster recovery infrastructure is ideal. Warm site disaster recovery means that the entire server environment is replicated including operating systems, applications, data, network and firewall setttings so that it is ready and waiting to take over at a moment&#8217;s notice. Several years ago, warm site disaster recovery was difficult and expensive.</p>
<p>Now, with the advent of cloud computing, disaster recovery has become very cost-effective. For example, DR Now!, Online Tech&#8217;s <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">cloud disaster recovery</a> service, provides offsite, warm site disaster recovery for cloud servers with a four hour RTO that starts at just $99 per server.</p>
<p>When you evaluate meeting HIPAA availability requirements for your health care applications and PHI, ask two key questions:</p>
<ol>
<li>Is your application hosted in a high availability environment where the power infrastructure, servers and network infrastructure can sustain failures without impacting your application and PHI data?</li>
<li>How will your application and PHI data survive a disaster at the production data center? Do you need only to recover your data with offsite backup, or do you need your application and data to be back online in as short a time as possible?</li>
</ol>
<p>How you answer these questions is critical to compliance with the availability criteria of HIPAA and the HITECH Act.</p>
<p>Next week we will look at an organizations security training and knowing where to find your security policy documents.</p>
<p>References:<br />
<a href="http://resource.onlinetech.com/disaster-recovery-for-hipaa-applications-its-all-about-availability-of-phi/">Disaster Recovery for HIPAA Applications &#8211; It&#8217;s All About Availability of PHI</a><br />
<a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">DR Now! Disaster Recovery Cloud</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources: Policies, Procedures and Training Materials</a></p>
<p>For <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA Compliant hosting</a>, call 877.740.5028 or email <a href="mailto:contactus@onlinetech.com">contactus@onlinetech.com</a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/five-questions-to-ask-your-business-associate-question-4-disaster-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Rise of the Healthcare App Industry</title>
		<link>http://resource.onlinetech.com/the-rise-of-the-healthcare-app-industry/</link>
		<comments>http://resource.onlinetech.com/the-rise-of-the-healthcare-app-industry/#comments</comments>
		<pubDate>Fri, 10 Feb 2012 13:53:25 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[mHealth]]></category>
		<category><![CDATA[mobile health]]></category>
		<category><![CDATA[mobile health applications]]></category>
		<category><![CDATA[mobile health IT]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4635</guid>
		<description><![CDATA[The advent of BYOD (Bring Your Own Device) and mobile/portable device use in the healthcare industry (currently coined as ‘mHealth’) is said to increase productivity, streamline processes including medical information collection and transmission, and allows people to work remotely and still have access to critical data and applications. A report by Juniper Research estimates that [...]]]></description>
			<content:encoded><![CDATA[<p>The advent of BYOD (Bring Your Own Device) and mobile/portable device use in the healthcare industry (currently coined as ‘mHealth’) is said to increase productivity, streamline processes including medical information collection and transmission, and allows people to work remotely and still have access to critical data and applications.</p>
<p>A report by Juniper Research estimates that mobile healthcare and medical app downloads will reach 44 million in 2012 and eventually 142 million by 2016.</p>
<p>[<strong>Sidenote</strong>: Although I don’t condone the citing of Wikipedia as reference, it’s worth mentioning the <a href="http://en.wikipedia.org/wiki/MHealth#Applications_in_the_mHealth_Field">mHealth wiki</a> does have a great list of applications for healthcare in the developing world, organized in charts by categories defined by the UN Foundation and Vodafone Foundation, including health education and awareness,  helplines, diagnostic support, treatment support, communication and training for healthcare workers, disease surveillance, remote data collection, epidemic outbreak tracking and more. <a href="http://www.vitalwaveconsulting.com/pdf/mHealth.pdf">mHealth for Development PDF</a>. <strong>Edit</strong>: Forbes also just published a relevant article, <em><a href="http://www.google.com/url?sa=t&amp;rct=j&amp;q=&amp;esrc=s&amp;source=newssearch&amp;cd=3&amp;ved=0CD0QqQIwAg&amp;url=http%3A%2F%2Fwww.forbes.com%2Fsites%2Fmobiledia%2F2012%2F02%2F10%2Fthe-future-of-mhealth-mobile-phones-improve-care-in-developing-world%2F&amp;ei=13A1T4WwHqTg0QGysI20Ag&amp;usg=AFQjCNHrYfW14IWvBJe1jkhvtQW-8sp1oQ">The Future of mHealth: Mobile Phones Improve Care in Developing World</a></em>.]</p>
<p>While there are <a href="http://resource.onlinetech.com/tactical-mobile-device-security-measures-to-meet-hipaa-compliance/">mobile security measures and policies</a> that should be documented and implemented to abide by HIPAA compliance standards for the ultimate goal of protecting personal health information (PHI), healthcare apps have flooded the industry and are here to stay.</p>
<p>Forbes.com published an <a href="http://www.forbes.com/sites/mobiledia/2012/02/09/the-future-of-mhealth-healthcare-apps-to-lower-insurance-costs/">editorial</a> by Mobiledia that suggests <em>“healthcare insurers are using apps to streamline patient-care systems, by connecting with and educating members, and ultimately reining in spiraling costs.”</em></p>
<div id="attachment_4639" class="wp-caption alignleft" style="width: 141px"><img class=" wp-image-4639  " title="Medscape Mobile" src="http://resource.onlinetech.com/wp-content/uploads/Medscape.jpg" alt="Medscape Mobile" width="131" height="241" /><p class="wp-caption-text">Medscape Mobile</p></div>
<p>According to <a href="http://mobihealthnews.com/16200/next-generation-health-it-is-not-anchored-to-a-desk/">Mobihealthnews.com</a>, a healthcare investment firm headed up by former government health IT employees, Health Evolution Partners (HEP), has partnered with Verizon to collaborate on health applications and developments in the mobile health industry.</p>
<p>HEP invests in healthcare startups and partner venture capital firms, providing healthcare facility locators, mobile medication management workflow platforms, e-prescribing services, remote patient visits and more.</p>
<p>So what are some of the most popular health apps being downloaded? <a href="http://www.informationweek.com/news/galleries/healthcare/mobile-wireless/232200263">InformationWeek.com</a> lists Medscape Mobile, the app of the professional medical website as one of the most popular. Medscape offers news alerts, a drug interaction checker, disease, conditions and drug reference and more, including a searchable database of over 400,000 U.S. physicians, pharmacies and hospitals.</p>
<div id="attachment_4637" class="wp-caption alignright" style="width: 260px"><img class="wp-image-4637 " title="MIM Mobile" src="http://resource.onlinetech.com/wp-content/uploads/MIM-Mobile.png" alt="MIM Mobile" width="250" height="259" /><p class="wp-caption-text">MIM Mobile</p></div>
<p>Another app that received FDA (Food and Drug Administration) 510(K) clearance for security is MIM Mobile, a remote diagnostic imaging tool said to be HIPAA compliant and encrypted for image transfer and storage. The app allows for direct sharing and <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud</a> storage with the app MIMcloud that stores the large images on their phones.</p>
<p>However, there is some opposition to the FDA’s 510(k) clearance process for medical devices, with critics accusing the process of being inherently flawed as it compares new devices to ones already on the market instead of actually proving the security and effectiveness of these devices (<a href="http://www.center4research.org/2011/08/report-medical-devices-lack-evidence-of-safety-and-effectiveness/">National Research Center for Women &amp; Families</a>).</p>
<p>As the mHealth industry grows, app audit standards, security measures and app effectiveness will continue to require endless revisions to improve overall patient healthcare while meeting national healthcare compliance standards set by HIPAA.</p>
<p>Not sure where to start with HIPAA? Find help in our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources: Policies, Procedures and Training Materials</a>.</p>
<p>References:</p>
<p><a href="http://www.forbes.com/sites/mobiledia/2012/02/09/the-future-of-mhealth-healthcare-apps-to-lower-insurance-costs/">The Future of mHealth: Healthcare Apps to Lower Insurance Costs</a><br />
<a href="http://mobihealthnews.com/16200/next-generation-health-it-is-not-anchored-to-a-desk/">Next Generation Health IT Is Not Anchored to a Desk</a><br />
<a href="http://mobihealthnews.com/15029/report-44m-health-app-downloads-in-2012/">Report: 44M Health App Downloads in 2012</a><br />
<a href="http://www.informationweek.com/news/galleries/healthcare/mobile-wireless/232200263">9 Mobile Health Apps Worth a Closer Look</a><br />
<a href="http://www.marketwatch.com/story/mhealth-users-of-remote-health-monitoring-to-reach-3-million-by-2016-smartphones-play-leading-role-2012-02-02">mHealth Users of Remote Health Monitoring to Reach 3 Million by 2016: Smartphones Play Leading Role</a><br />
<a href="http://www.fiercemobilehealthcare.com/story/medical-image-sharing-patients-enabled-new-mim-app/2011-06-01">Medical Image Sharing for Patients Enabled By New MIM App</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/the-rise-of-the-healthcare-app-industry/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliance Concerns with Google</title>
		<link>http://resource.onlinetech.com/hipaa-compliance-concerns-with-google/</link>
		<comments>http://resource.onlinetech.com/hipaa-compliance-concerns-with-google/#comments</comments>
		<pubDate>Wed, 08 Feb 2012 13:51:31 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[google hipaa compliance]]></category>
		<category><![CDATA[google new privacy policy]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4618</guid>
		<description><![CDATA[After reading a blog post about House Representative Mary Bono Mack (R-Calif.) and her concerns about Google’s new privacy policy potentially violating HIPAA compliance standards, I’ve concluded that: Searching for a medical phrase does not make that phrase protected/patient health information (PHI) Users that volunteer search phrases and use Google are consenting to their privacy [...]]]></description>
			<content:encoded><![CDATA[<p>After reading a blog post about House Representative Mary Bono Mack (R-Calif.) and her concerns about Google’s <a href="http://www.google.com/intl/en_us/policies/privacy/preview/">new privacy policy</a> potentially violating <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> standards, I’ve concluded that:</p>
<ul>
<li>Searching for a medical phrase does not make that phrase protected/patient health information (PHI)</li>
<li>Users that volunteer search phrases and use Google are consenting to their privacy policy</li>
<li>It’s unfortunate a House Representative does not understand HIPAA</li>
<li>It’s unfortunate a House Representative does not understand Google or their privacy policy</li>
</ul>
<p>In an interview with USA Today’s Technology Live blog, Mack used an example in which a user searches for cervical cancer on Google, doesn’t log out, and then is tracked across other products online (?). I assume she means the information they collect will influence the ads shown on Google’s Display Network across other sites you may visit.</p>
<p>Google doesn’t store any actual patient health information, such as the kind that a physician might collect in a clinic. SearchEngineLand.com’s <a href="http://searchengineland.com/googles-new-privacy-policy-may-violate-hipaa-congresswoman-says-110053">article</a> cites Google’s new privacy policy, stating:</p>
<blockquote><p>When showing you tailored ads, we will not associate a cookie or anonymous identifier with sensitive categories, such as those based on race, religion, sexual orientation or health.</p></blockquote>
<p>They also state that they require <a href="http://www.google.com/intl/en_us/policies/privacy/preview/faq/#toc-terms-sensitive-info">opt-in consent</a> when it comes to sharing any sensitive personal information. In her interview, Mack also questions the definition of sensitive data, “They are saying that they do not track sensitive data like that. I don’t know who determines what’s sensitive and what’s not. And that’s probably another question on another day and a more extensive hearing.” Perhaps they should go by the Department of Health and Human Services (HHS)’s definition as written in their <a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/summary/index.html">Summary of the Privacy Rule</a>, as they are the leading government agency:</p>
<blockquote><p>The Privacy Rule protects all &#8220;individually identifiable health information&#8221; held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information &#8220;protected health information (PHI).&#8221;12</p>
<p>“Individually identifiable health information” is information, including demographic data, that relates to:</p>
<ul>
<li>the individual’s past, present or future physical or mental health or condition,</li>
<li>the provision of health care to the individual, or</li>
<li>the past, present, or future payment for the provision of health care to the individual,</li>
</ul>
<p>and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual.13  Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number).</p></blockquote>
<p>Yale.edu’s <a href="http://hipaa.yale.edu/guidance/index.html#phi">HIPAA Guide</a> offers more specific identifiers, including medical record number, account number, certificate/license number, web URL, IP addresses, finger or voice prints, etc.</p>
<p>Ultimately, the question remains, how can the Department of Health and Human Services and our government expect HIPAA compliance from healthcare and related organizations if government representatives appear to be unfamiliar with the standards and equally out of touch with technology and the use thereof? While the acts passed in 2009, I think healthcare organizations, business associates and the lawmakers could all benefit from a more in-depth review of the law.</p>
<p>If you&#8217;d like a refresher on HIPAA, our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a> could help.</p>
<p>References:<br />
<a href="http://searchengineland.com/googles-new-privacy-policy-may-violate-hipaa-congresswoman-says-110053">Google’s New Privacy Policy May Violate HIPAA, Congresswoman Says</a><br />
<a href="http://www.google.com/intl/en_us/policies/privacy/preview/">Google Preview: Privacy Policy</a><br />
<a href="http://www.google.com/intl/en_us/policies/privacy/preview/faq/#toc-terms-sensitive-info">Google Preview: Privacy FAQ</a><br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/summary/index.html">HHS’s Summary of the Privacy Rule</a><br />
<a href="http://hipaa.yale.edu/guidance/index.html">Yale.edu’s Health Insurance Portability and Accountability Act Guide</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-compliance-concerns-with-google/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming Webinar: Making Sense of Service Organization Audits</title>
		<link>http://resource.onlinetech.com/webinar-making-sense-of-service-organization-audits/</link>
		<comments>http://resource.onlinetech.com/webinar-making-sense-of-service-organization-audits/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 13:55:04 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data center audits]]></category>
		<category><![CDATA[free webinar]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[ssae 16]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4612</guid>
		<description><![CDATA[Join Online Tech, David Barton and Jon Long for a discussion to help clarify data center audit standards and assessments. Register for our free webinar Tuesday, February 14, 2012 from 2-3pm ET to discuss the differences between AICPA&#8217;s (American Institute of Certified Public Accountants) SOC (Service Organization Controls) audits and reports, other types of audits, and [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Join Online Tech, David Barton and Jon Long for a discussion to help clarify data center audit standards and assessments.</p>
</div>
<div>
<p><a href="https://www3.gotomeeting.com/register/665591734"><img class="alignleft" style="margin-left: 10px; margin-right: 10px;" src="http://www.onlinetech.com/images/stories/misc/soc-logo-150.png" alt="SOC 2" width="150" height="137" />Register for our free webinar</a> <strong>Tuesday, February 14, 2012 from 2-3pm ET</strong> to discuss the differences between AICPA&#8217;s (American Institute of Certified Public Accountants) SOC (Service Organization Controls) audits and reports, other types of audits, and the difference between point-in-time, period of time, self-assesments and independent assessments.</p>
<p><a href="https://www3.gotomeeting.com/register/665591734">Sign up Now!</a></p>
<p>Find more information about <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2 Hosting</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16 Hosting</a> and read about the <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting">differences between SAS 70, SSAE 16 and SOC</a>.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p><a href="http://www.uhyadvisors-us.com/"><img class="alignleft" style="margin-left: 10px; margin-right: 10px;" title="002e7b8" src="http://www.uhyadvisors-us.com/respics/DavidBarton.jpg" alt="David Barton, CRISC and CISA" width="128" height="160" /></a></p>
<p><strong>David Barton, CRISC, Principal, UHY LLP</strong><br />
David is a Principal and is the practice leader of the Technology Assurance and Advisory Services group at <a href="http://www.uhyadvisors-us.com/">UHY Advisors, Inc.</a> in Atlanta, GA. He is Certified in Risk and Information Systems Controls (CRISC) and received his Certified Information Systems Auditor (CISA) designation in 1988.</p>
<p>With over 25 years practical experience in information systems and technology risk and controls, he is an expert in identifying and reducing information technology risk throughout an organization.</p>
<p>Read David Barton&#8217;s guest blog post on our blog, &#8220;<a href="http://resource.onlinetech.com/socs-and-sass-the-new-standards-for-service-organization-controls-reporting/">SOCs and SASs: The New Standards for Service Organization Controls Reporting</a>.&#8221;</p>
<div>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<div><a href="http://1.bp.blogspot.com/-lTCRuI6N6qY/Tx7jAiKLAXI/AAAAAAAAAIY/3cj-ssvuNV4/s1600/ProfilePicture.jpg"><img class="alignleft" style="border-style: initial; border-color: initial; border-image: initial; margin-left: 10px; margin-right: 10px; border-width: 0px;" src="http://1.bp.blogspot.com/-lTCRuI6N6qY/Tx7jAiKLAXI/AAAAAAAAAIY/3cj-ssvuNV4/s200/ProfilePicture.jpg" alt="" width="125" height="126" border="0" /></a><strong>Jon Long, CISA, QSA Senior Audit Manager CompliancePoint</strong><br />
Jon is a Senior Manager and Practice Builder at <a href="http://www.compliancepoint.com/">CompliancePoint</a> as well as an enthusiastic blogger at <a href="http://www.riskassuranceguy.blogspot.com/">The Risk Assurance Guy</a>. He is a Certified Information Systems Auditor (CISA) as well as a Qualified Security Assessor (QSA) in the Payment Card Industry (PCI).</div>
<p>Jon has over 15 years experience in IT, and crossed over into auditing in 2006.  His background enables him to conduct audits from the perspective of having been audited by external auditors.  He is currently championing an audit approach that allows organizations to combine multiple compliance requirements into a single SOC 2 engagement.</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/webinar-making-sense-of-service-organization-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Questions to Ask Your Business Associates: #3 Policies &amp; Technologies</title>
		<link>http://resource.onlinetech.com/five-questions-to-ask-your-business-associates-3-policies-technologies/</link>
		<comments>http://resource.onlinetech.com/five-questions-to-ask-your-business-associates-3-policies-technologies/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 13:35:29 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA audits]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA policies]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[private firewalls]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4605</guid>
		<description><![CDATA[Our third most important question to a Business Associate is: What policies and technologies are used to protect my applications and PHI data? Neither HIPAA nor HITECH call for specific technical measures to assure PHI data is available, accurate and secure. However, there are still basic technologies and practices that indicate a culture of security [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Our third most important question to a Business Associate is:</p>
<p><em><strong>What policies and technologies are used to protect my applications and PHI data?</strong></em></p>
</div>
<div>
<p>Neither HIPAA nor HITECH call for specific technical measures to assure PHI data is available, accurate and secure. However, there are still basic technologies and practices that indicate a culture of security awareness and proficiency. After you review the BA’s independent <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/100-hipaa-compliant">HIPAA audit</a> report, ask about these data security technologies.</p>
<p>In our case, as a hosting provider, the <strong>minimum server security requirements</strong> to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> are:</p>
<ul>
<li>Virtual or Dedicated Firewall</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">Backup</a></li>
<li>Antivirus</li>
<li>OS Patch Management</li>
</ul>
<p><strong>We also recommend:</strong></p>
<ul>
<li>Private Firewall services (either a Virtual or Dedicated Firewall) with VPN for remote access</li>
<li>Separate database and web servers for production</li>
<li>Separate test server (can use one for web and DB but not same as production)</li>
<li>Offsite data backup at the minimum, ideally a warm-site disaster recovery paradigm (easiest for cloud servers)</li>
<li>SSL certificates and HTTPS for all web-based access to PHI (protected health information)</li>
<li>Private IP addresses</li>
</ul>
<p><strong>Is encryption required?</strong><br />
We are asked this repeatedly, and the answer is “No, but it’s a darn good idea.” Encryption is usually handled at the software application level, so if you are working with a Business Associate who is providing software, ask how they address it in the application. If you are putting your own software on a server, you&#8217;ll undoubtedly have taken encryption into account. Encryption requires decryption prior to use which is computationally expensive, so you can’t just encrypt everything on the server. The best tools and methods depend on the application, operating system and usage patterns. Look for the following best practices:</p>
<ul>
<li>Always use SSL for web-based access of any sensitive data (personally identifying or medical information)</li>
<li>Name, SSN, diagnosis, addresses, prognosis etc. and other sensitive information within an EMR (electronic medical records) system should be encrypted in the database using techniques and mechanisms known only to a select few.</li>
<li>Content such as images or scans should be encrypted and contain no personally identifying information.</li>
</ul>
<p><strong>Important HIPAA policies to ask about:</strong></p>
<ul>
<li>Documentation of data management, security, training and notification plans (every employee should have regular HIPAA security training)</li>
<li>Clients should use a password policy for their access</li>
<li>Encrypt PHI data whether it’s in a database or in files on the server</li>
<li>Do not use public FTP (File Transfer Protocol) to move files</li>
<li>Only use VPN (virtual private network) access for remote access</li>
<li>Login retry protection in their application</li>
<li>Documentation of a DR (<a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a>) plan</li>
</ul>
<p>Next week, we’ll talk about important questions to ask about disaster preparedness and how long it will take for you to access your PHI again in the event disaster strikes.</p>
<p>Are you going to HIMSS 12 in Las Vegas, Feb. 20-24? If so, stop by our Booth (#13528) and say hello! Online Tech will be <a href="http://www.onlinetech.com/resources/events/seminars/online-tech-to-exhibit-at-himss-12">exhibiting at HIMSS</a> with our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> solutions for healthcare and related organizations.</p>
<p>References:<br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq#What%20services%20from%20Online%20Tech%20help%20make%20me%20compliant?">What Services From Online Tech Help Make Me Compliant?</a><br />
<a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a><br />
<a href="http://searchhealthit.techtarget.com/tip/How-to-comply-with-the-HIPAA-Security-Rule">SearchHealthIT: How to Comply With the HIPAA Security Rule</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">More HIPAA Resources</a></p>
<p>For <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA Compliant hosting</a>, call 877.740.5028 or email <a href="mailto:contactus@onlinetech.com">contactus@onlinetech.com</a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/five-questions-to-ask-your-business-associates-3-policies-technologies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Federal Mobile Strategy: Increasing Access to Mission-Critical Data &amp; Streamlining IT</title>
		<link>http://resource.onlinetech.com/federal-mobile-strategy-increasing-access-to-mission-critical-data-streamlining-it/</link>
		<comments>http://resource.onlinetech.com/federal-mobile-strategy-increasing-access-to-mission-critical-data-streamlining-it/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 13:44:23 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[federal mobile strategy]]></category>
		<category><![CDATA[IT consumerization]]></category>
		<category><![CDATA[IT industry trends]]></category>
		<category><![CDATA[mobile device security]]></category>
		<category><![CDATA[smartphone security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4579</guid>
		<description><![CDATA[Last August, I wrote a blog post discussing the federal cloud computing initiative launched by then-U.S. CIO Vivek Kundra and his Cloud-First policy developed to motivate agencies to adopt cloud computing projects and reduce overall spending and energy expenditure. On the heels of his endeavor comes a new federal mobile strategy intended to increase productivity [...]]]></description>
			<content:encoded><![CDATA[<p>Last August, I wrote a blog post discussing the <a href="http://resource.onlinetech.com/breakdown-of-federal-cloud-computing/">federal cloud computing</a> initiative launched by then-U.S. CIO Vivek Kundra and his Cloud-First policy developed to motivate agencies to adopt <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> projects and reduce overall spending and energy expenditure. On the heels of his endeavor comes a new federal mobile strategy intended to increase productivity and realize cost-savings.</p>
<div id="attachment_4595" class="wp-caption alignleft" style="width: 315px"><img class=" wp-image-4595    " title="The Mobile Opportunity" src="http://resource.onlinetech.com/wp-content/uploads/The-Mobile-Opportunity.png" alt="The Mobile Opportunity" width="305" height="184" /><p class="wp-caption-text">The Mobile Opportunity</p></div>
<p>The new U.S. CIO (a newly-minted federal position only two-years-old), Steven VanRoekel, has drafted a <a href="http://mobility-strategy.ideascale.com/a/pages/draft-outline">mobile strategy outline</a> to push agencies toward a standardized framework and roadmap to complete implementation. <em></em></p>
<p>In a WhiteHouse.gov <a href="http://www.whitehouse.gov/blog/2012/01/12/mobile-opportunity">blog post</a>, VanRoekel stresses the importance of mobile use with a few key examples and benefits:</p>
<ul>
<li>Realize real estate savings from teleworking</li>
<li>Joint agency programs give employees working from different agencies remote access to mission-critical data from any location</li>
<li>The Army’s mCare App allows remote monitoring of soldiers&#8217; healthcare statuses</li>
<li>The Federal Emergency Management Agency uses mobile Twitter to find victims during an emergency, send out emergency messages and to find out how far the emergency has spread.</li>
</ul>
<p><strong>Social Media for Informed Decisions</strong></p>
<div id="attachment_4587" class="wp-caption aligncenter" style="width: 511px"><img class="wp-image-4587 " title="National Dialogue on The Federal Mobility Strategy" src="http://resource.onlinetech.com/wp-content/uploads/National_Diaglogue.png" alt="National Dialogue on The Federal Mobility Strategy" width="501" height="82" /><p class="wp-caption-text">National Dialogue on The Federal Mobility Strategy</p></div>
<p>In the spirit of social media’s knowledge-sharing ability, the government launched an online forum, the <a href="http://mobility-strategy.ideascale.com/">National Dialogue on The Federal Mobility Strategy</a> to collaborate on ideas and topics they would need to address in the final draft of the mobile strategy. With a thumbs-up and thumbs-down voting system, users could submit concerns around mobile security, disability accessibility, web-to-mobile content portability and more, and vote on which issues take precendence. This lends valuable feedback that VanRoekel  will use to create a final plan for agency implementation.</p>
<p><strong>Mobile Data Security</strong></p>
<p>With the widespread adoption of mobile devices come the concerns around data security. Last August, NIST (The National Institute of Standards and Technology) started a pilot program to test and develop a standardized security protocol for iPhones and iPads, according to an InformationWeek.com <a href="http://www.informationweek.com/news/government/security/231300033">article</a>.</p>
<p>In addition, the Department of Defense (DoD) is developing full-disk encryption for military smartphone data. The DoD has suffered a recent <a href="http://resource.onlinetech.com/department-of-defense%E2%80%99s-cloud-computing-strategy-saving-money-increasing-security/">HIPAA violation</a> when backup tapes with military patient records were stolen last September, calling for an overhaul of their internal processes and stricter security measures.</p>
<p>For a list of tactical mobile device security measures you or your company can implement, read this <a href="http://resource.onlinetech.com/tactical-mobile-device-security-measures-to-meet-hipaa-compliance/">blog post</a>. Another recent post, <a href="http://resource.onlinetech.com/mobile-security-are-most-apps-safe/">Mobile Security: Are Most Apps Safe?</a> explores the privacy of your information on mobile apps.</p>
<p><strong>IT Industry Trends</strong></p>
<p><a href="http://www.cio.com/article/697951/U.S._CIO_Unveils_Mobile_Strategy_for_Federal_Government?page=1&amp;taxonomyId=3133">CIO.com</a> details the federal government’s attempt to move IT progress along through many of the industry’s trends, including the consumerization of IT, migration to the cloud and increasing reliance on mobile devices. Another trend includes streamlining and <a href="http://resource.onlinetech.com/integrating-it-services-cloud-computing-compliance-concerns/">integrating IT services</a> across different departments – by combining email systems, mobile device plans and other systems, costs go down while productivity goes up. I wrote a <a href="http://resource.onlinetech.com/integrating-it-services-cloud-computing-compliance-concerns/">blog post</a> recently about IT process automation and its benefits.</p>
<p>References:<br />
<a href="http://www.whitehouse.gov/blog/2012/01/12/mobile-opportunity">WhiteHouse.Gov: The Mobile Opportunity</a><br />
<a href="http://mobility-strategy.ideascale.com/">National Dialogue on The Federal Mobility Strategy</a><br />
<a href="http://www.informationweek.com/news/government/security/231300033">NIST Tests Ways to Secure iPhones, iPads</a><br />
<a href="http://www.informationweek.com/news/government/mobile/229401618">DARPA To Develop Android, iPhone Encryption</a><br />
<a href="http://www.informationweek.com/news/government/mobile/232400210">VanRoekel Details Government Mobile Strategy at CES</a><br />
<a href="http://www.cio.com/article/697951/U.S._CIO_Unveils_Mobile_Strategy_for_Federal_Government?page=1&amp;taxonomyId=3133">U.S. CIO Unveils Mobile Strategy for Federal Government</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/federal-mobile-strategy-increasing-access-to-mission-critical-data-streamlining-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Megaupload&#8217;s Series of Unfortunate Events</title>
		<link>http://resource.onlinetech.com/megauploads-series-of-unfortunate-events/</link>
		<comments>http://resource.onlinetech.com/megauploads-series-of-unfortunate-events/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 13:54:31 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud storage]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[file-sharing]]></category>
		<category><![CDATA[megaupload]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[servers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4570</guid>
		<description><![CDATA[The recent government shutdown of Megaupload, a massive file-sharing service said to house a substantial amount of copyrighted media, has put into motion a series of unfortunate events and provided valuable lessons learned. Server Data Deletion Megaupload’s servers contained more than 25 petabytes (approximately 25 million gigabytes) of data storage (Mashable.com). While the data includes [...]]]></description>
			<content:encoded><![CDATA[<p>The recent government shutdown of Megaupload, a massive file-sharing service said to house a substantial amount of copyrighted media, has put into motion a series of unfortunate events and provided valuable lessons learned.</p>
<p><strong>Server Data Deletion</strong><br />
Megaupload’s <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">servers</a> contained more than 25 petabytes (approximately 25 million gigabytes) of data storage (<a href="http://mashable.com/2012/01/20/megaupload-sopa-dropbox/">Mashable.com</a>). While the data includes some copyrighted material, a great amount of the data is also legitimate, personal data uploaded by the owners of the content. But the data may be lost forever &#8211; initially, the U.S. Attorney’s Office claims the hosting companies that house Megaupload’s servers have filed a letter stating they may begin deleting data as early Thursday, while more recent reports claim the companies have agreed to wait two weeks before wiping servers.</p>
<p>However, a nonprofit, Electronic Frontier Foundation, just announced they will be partnering with Carpathia Hosting to help the legitimate users retrieve their data with at <a href="http://www.megaretrieval.com/">www.megaretrieval.com</a>.</p>
<p>With at least 50 million users’ data at risk of deletion, one to has to wonder if the right to destroy data without providing a copy to their rightful owners or their client was included in their hosting contract. Make sure you know where your data goes if something happens to your <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud hosting</a> provider or if you decide to terminate your contract. While various articles and blogs on this topic point the finger at the cloud storage industry as a whole, the issue at hand is really more about your service provider’s terms of service and your understanding of them.</p>
<p><strong>No Data Backup</strong><br />
Since Megaupload’s assets and domains were frozen, they’ve been unable to pay for their hosting, bandwidth and system administration services and users cannot access their data to back it up. <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">Offsite backup</a> could have come in handy in this situation. Backing up your data to an offsite <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> would ensure you still have a copy of your files, instead of depending solely on the state of your servers. A law enforcement official claims the site “clearly warned users not to keep a sole copy of material on the site,” according to the <a href="http://online.wsj.com/article/SB10001424052970203806504577181201072864644.html">Wall Street Journal</a>.</p>
<p><strong>File-Sharing Recoil</strong><br />
According to <a href="http://www.pcmag.com/article2/0,2817,2399238,00.asp">PCMag.com</a>, several smaller cloud-based services are changing their services in response to the Megaupload case. FileSonic and Upload.to have disabled their file-sharing functionality, and others are shutting down their affiliate programs. Megaupload paid its users to upload popular files to the site, another point of contention in the case. Many similar file hosting sites have cancelled similar rewards programs.</p>
<p><strong>Hacker Retaliation</strong><br />
Last Thursday, the hacker group Anonymous launched a DDos (denial-of-service) attack on several related websites, taking down those owned by the Department of Justice, FBI, Motion Picture Associate of America (MPAA), the Recording Industry Associate of America (RIAA) and Universal Music Group, according to <a href="http://www.informationweek.com/news/security/attacks/232500183">InformationWeek.com</a>.</p>
<p>As the domino effect of the Megaupload saga continues to play out, other businesses should take note of these lessons learned to take necessary measures to protect themselves and their/their clients data.</p>
<p>References:<br />
<a href="http://www.washingtonpost.com/opinions/megaupload-shows-online-copyright-protection-is-needed/2012/01/20/gIQAT6G8IQ_story.html">Megaupload Shows Online Copyright Protection is Needed</a><br />
<a href="http://www.itbusinessedge.com/cm/blogs/mah/cloud-storage-and-what-smbs-can-learn-from-megauploads-demise/?cs=49626">Cloud Storage and What SMBs Can Learn from Megaupload&#8217;s Demise</a><br />
<a href="http://www.informationweek.com/news/security/attacks/232500183">Anonymous Retaliates for Megaupload Raids: 10 Key Facts</a><br />
<a href="http://www.pcmag.com/article2/0,2817,2399238,00.asp">After Megaupload, Storage Sites Shutter Services</a><br />
<a href="http://www.msnbc.msn.com/id/46190158/ns/technology_and_science-security/#.TygSOsUS0RN">Feds: Megaupload User Data could Be Gone Thursday</a><br />
<a href="http://www.pcworld.com/article/249025/megaupload_users_get_reprieve_on_file_wipe.html">Megaupload Users Get Reprieve on File Wipe</a><br />
<a href="http://online.wsj.com/article/SB10001424052970203806504577181201072864644.html">Megaupload’s Ripple Effect</a><br />
<a href="http://www.cbsnews.com/8301-501465_162-57367613-501465/megaupload-users-plan-to-sue-fbi-over-deleted-files/">Megaupload Users Plan to Sue FBI Over Deleted Files</a><br />
<a href="http://www.google.com/hostednews/ap/article/ALeqM5jQkm-N8qJ3efPbLc8PteCQOaLSKQ?docId=74cfb253f7334d2f998af74883ed5f0f">Nonprofit to Help Megaupload Users Retrieve Data</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/megauploads-series-of-unfortunate-events/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Social Media Might Benefit Health Care and Be Meaningful to Patient Health</title>
		<link>http://resource.onlinetech.com/how-social-media-might-benefit-health-care-and-be-meaningful-to-patient-health/</link>
		<comments>http://resource.onlinetech.com/how-social-media-might-benefit-health-care-and-be-meaningful-to-patient-health/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 17:28:26 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare social media]]></category>
		<category><![CDATA[healthcare social networks]]></category>
		<category><![CDATA[patient care]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4566</guid>
		<description><![CDATA[The subtitle to this blog post should be How Strep Throat Can Lead You to Change Doctors, but there’s a point here about how social media might fill a wide chasm of disconnect between patients and physicians. Maybe I&#8217;m sentimental, but I love the stories my dad tells of being a general practitioner making house [...]]]></description>
			<content:encoded><![CDATA[<p>The subtitle to this blog post should be <em>How Strep Throat Can Lead You to Change Doctors</em>, but there’s a point here about how social media might fill a wide chasm of disconnect between patients and physicians.</p>
<p>Maybe I&#8217;m sentimental, but I love the stories my dad tells of being a general practitioner making house calls along the shores of South Haven, Michigan. I realize there&#8217;s a lot that&#8217;s not practical about this approach today, and advantages for the current system, but every time I sit down at my dad&#8217;s piano, I remember that it was gifted to him by a patient who he took care of for many, many years. (It&#8217;s a classic 8&#8242; grand, so no trivial gift!).</p>
<p>Can you imagine a patient-doctor relationship today that would be so “meaningful” that a patient would make this type of gift to his or her physician? Can you sense the gratitude that this man must have felt towards a doctor who stopped by in the evenings to check on him, attend to his comfort, and take time for a cup of tea with the patient’s worried wife? Can you guess how humbled my dad was to receive that gift?</p>
<p>Bear with me, I am getting to a point about social media &#8230;</p>
<p>Ok, now let’s snap back to today’s reality. How many of you feel a true sense of gratitude towards your health care providers or a solid emotional connection? How well can we really separate our emotional experience with health care from our physical well-being? Feel like this is a bunch of mushy nonsense? Ok, would they know your name if you met in another context? More importantly, does your primary health care provider know you well enough to recognize when you’re not acting yourself and be able to use this observation to make educated decisions and recommendations about your health?</p>
<p>When I think of my local family practice, I get frustrated. Case in point: I was told last year that I had to &#8220;follow protocol&#8221; and &#8220;wait for a nurse to call back&#8221; before getting a basic strep swab. Now, I was on good enough terms with my (then) primary care doctor that if he heard me say &#8220;Hey Doc, my throat&#8217;s on fire and I see these fuzzy white patches on my throat &#8211; can I come in to get a swap culture done?&#8221; I would have been on my way in a heartbeat.</p>
<p>But there was NO chance that I would ever be able to have that 30 second conversation with him due to the current system of administrative screening, followed by nurse screening; making any direct communication with physicians impossible. I had to take the initiative to call back and beg for permission to get a culture after not hearing back for 3 hours. When I compared this experience with what we expect as clients of other industries, I really started scratching my head. Would anyone put up with that at a restaurant, clothing store, Amazon, Zappos, or anywhere else? Of course not.</p>
<p>Dang, I could have TWEETED my request for a strep culture to my doc and it would have taken him 2 seconds to reply &#8220;Come on in.”</p>
<p>I know that my old family practice is following common protocol &#8211; they didn’t invent this model of disservice on their own. And I know that us pesky patients can be quite a handful sometimes if we actually make it through the administrative and all other pre-screening barriers to actually express ourselves directly to our physician. But does this model lead to better health?</p>
<p>If the primary purpose of the doctor-patient relationship is to promote health, prevent disease, and help patients lead healthier (dare I say happier) lives, then wouldn’t a system where we could have direct and ongoing dialogue with our primary care physicians on a regular basis BEFORE we get so sick that we can’t work, be parents or lead our productive lives serve everyone’s interests? (If not, maybe we need a sanity check on incentives and the basis of health care spending &#8211; but that’s a whole other discussion). And maybe, just maybe, this is where social media and better access to our own patient records could fill a gap.</p>
<p>I don&#8217;t pretend to think that FaceBook, LinkedIn, or Twitter can recapture or replace the type of bond I described between my dad and that patient, but many of us ARE connecting on these platforms today. A weird virtual community, granted &#8211; but a community nonetheless. And for those physicians who tire of us question-asking pesky patients, maybe using social media to ask those quick questions (can I please get a strep swab?) would be less intrusive than a phone call or walk-in “interruption.”</p>
<p>If we can get past the security issues (which we can and will as more attention and great minds address it), social media offers a new way for patients and physicians to connect in a more &#8220;meaningful&#8221; way. If we could maintain an ongoing dialogue with those we entrust with our health, I think we&#8217;d see a lot less misdiagnosis, unhappy patients (malpractice lawsuits), stressed out doctors, and unhealthy patients. Heck, as a patient I would subscribe to a service offered by my primary care physician to review my health tweets about exercise, diet, energy level, etc. on a regular basis and reach out with suggestions or concerns! Wouldn’t you?</p>
<p>Despite the fact that I respect, appreciate and genuinely like the physicians at our old family practice, my kids and I are not patients there anymore. There&#8217;s no evidence they miss me or even know we’re gone, despite the fact that we had been there for years. And I’ve never been a difficult patient to deal with &#8211; at all. I talk more with the Nurse Practitioner (who is my daughter’s boyfriend’s mother) about health concerns more than with the primary care physician who is formally listed on my insurance. Why? Because she knows me, I see her at horse shows, and she emails me Maxine jokes. <strong>We are socially connected. I trust her. We have a social context to draw from. </strong>It’s too bad her practice isn’t close enough for a strep swab.</p>
<p>In my desperation to get treated for strep so I could get back to work, I reached out to my former ob-gyn, Elizabeth Shadigian, to see if she knew of a better option than an expensive trip to urgent care. Yep, I used my mobile phone to Google her name, pressed the “Call” button from Google Maps, and within minutes, was actually <strong>connecting directly to her</strong>. Her practice has a <a href="http://womansafehealth.com/">website</a>, and she publishes her email address, <a href="http://www.linkedin.com/in/elizabethshadigian">LinkedIn profile</a>, <a href="http://www.facebook.com/people/Elizabeth-Shadigian/1393021713">FaceBook profile</a>, and <a href="https://twitter.com/WomanSafeHealth">Twitter profile</a> where she posts info about flu clinics, invitations to health-related educational lectures, and fun community events (darn, I missed fountain making class!)</p>
<p>In person, by phone, by email, tweet, FB post, or LinkedIn (um, what … link?), Elizabeth is ready to engage with me about my health in whatever format works for me. Wow. Of course she’s not tweeting anything about my personal health &#8211; come on &#8211; she’s a consummate professional who knows and cares about me! But I have complete confidence that whenever I have a health concern, I can connect with her directly, she will remember who I am, and she knows me well enough to use that context to inform educated recommendations about my health. Wow.</p>
<p>I’m truly grateful for her willingness to communicate openly and directly with me about my health. I wouldn’t go anywhere else and I recommend her practice to EVERYONE who mentions the word “doctor.” Sharing her social media and online information with her patients was a jaw-dropper for me (ever try asking for your primary care physician’s email address? Try it, I dare you). Elizabeth would be a great physician without social media, but the spirit of it reflects direct, engaged, and responsive communication which is great for business, and great for (my) health care.</p>
<p>Related articles:<br />
<a href="http://govhealthit.com/news/3-ways-social-media-transforming-health-care">3 Ways Social Media is Transforming the Doctor-Patient Relationship</a><br />
<a href="http://www.nytimes.com/2011/04/23/health/23doctor.html?_r=1">Family Physician Can’t Give Away Solo Practice</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/how-social-media-might-benefit-health-care-and-be-meaningful-to-patient-health/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Online Tech to Attend IMPACT 2012 Conference on Cloud Computing</title>
		<link>http://resource.onlinetech.com/online-tech-to-attend-impact-2012-conference-on-cloud-computing/</link>
		<comments>http://resource.onlinetech.com/online-tech-to-attend-impact-2012-conference-on-cloud-computing/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 13:57:37 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[automation alley events]]></category>
		<category><![CDATA[michigan business events]]></category>
		<category><![CDATA[michigan technology events]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[private cloud hosting]]></category>
		<category><![CDATA[southeast michigan business]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4440</guid>
		<description><![CDATA[Mike Klein, President and COO of Online Tech, will be speaking about cloud computing at IMPACT 2012 on February 7 in Auburn Hills, Michigan. Featuring sales, marketing, finance, human resources and public sector experts, IMPACT 2012 is an informative networking conference on current economic and technology trends, hosted by Automation Alley. Klein will be speaking at a [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_4443" class="wp-caption alignleft" style="width: 210px"><img class="size-full wp-image-4443" title="IMPACT 2012 Conference" src="http://resource.onlinetech.com/wp-content/uploads/Impact2012.jpg" alt="IMPACT 2012 Conference" width="200" height="186" /><p class="wp-caption-text">IMPACT 2012 Conference</p></div>
<p>Mike Klein, President and COO of Online Tech, will be speaking about <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> at IMPACT 2012 on February 7 in Auburn Hills, Michigan.</p>
<p>Featuring sales, marketing, finance, human resources and public sector experts, IMPACT 2012 is an informative networking conference on current economic and technology trends, hosted by Automation Alley.</p>
<p>Klein will be speaking at a panel discussion, <em>A Day in the Clouds: Is Your Future Cloudy? </em>Moderated by Peter Marsack, VP of Computer Solutions, the panel will cover <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a> definitions, cloud services available and the benefits and costs of the cloud for businesses.</p>
<p>Other panelists include:</p>
<ul>
<li>Mark Farneth, President of Radley Corporation, will discuss the transition from traditional corporate computing to cloud computing, as well as why they use Online Tech for their <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">private cloud hosting</a> services.</li>
<li>Jamie Hamilton, VP of Software Engineering at Quicken Loans</li>
<li>James White, Senior Enterprise Solution Advisor at Secure 24.</li>
</ul>
<p>The <a href="http://www.automationalley.com/page?pageid=a0E60000004E9ma">IMPACT 2012 event overview</a> details what you will gain from attending the conference:</p>
<ul>
<li>Insight from industry leaders on how to navigate business challenges in 2012</li>
<li>Real-world insight on accessing capital and maximizing profitability in your business</li>
<li>Tangible tactics to increase sales and generate revenue</li>
<li>Grow your professional network by connecting with fellow Automation Alley members representing a variety of industries</li>
<li>Tips for creating powerful marketing initiatives the generate sales</li>
<li>Strategies to motivate your employees and create a productive work environment</li>
</ul>
<p><strong>Exhibitors</strong><br />
Various companies and organizations will also be exhibiting at the event, including chambers of commerce, universities, banks, IT vendors and more. View a full list of <a href="http://www.automationalley.com/page?pageid=a0E60000004FqmXEAS">exhibitors</a>.</p>
<p><strong>Registration</strong><br />
Pre-registration and door fees vary, and <a href="http://www.automationalley.com/page?pageid=a0E60000004ED2h">sponsorships</a> are available for exhibitors (includes a vendor booth and admission). <a href="http://www.automationalley.com/a2_nws_eventinfo?id=a086000000CqLFNAA3">Register online</a> for the conference today.</p>
<table width="650" border="0" cellpadding="0">
<tbody>
<tr>
<td valign="top"><strong>Location</strong></td>
<td valign="top"><strong>Contact</strong></td>
</tr>
<tr>
<td valign="top">Centerpoint Marriott</td>
<td valign="top">Automation Alley Resource Center</td>
</tr>
<tr>
<td valign="top">3600 Centerpoint Parkway, Auburn Hills, MI 48341</td>
<td valign="top"><a href="mailto:info@automationalley.com">info@automationalley.com</a></td>
</tr>
<tr>
<td valign="top">February 7, 2012 from 8 a.m. – 5 p.m.</td>
<td valign="top">(800) 427-5100</td>
</tr>
</tbody>
</table>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p style="text-align: left;"><strong>Mike Klein, President, Online Tech</strong></p>
<p style="text-align: left;"><img style="float: left; margin: 0 15px 0 5px;" src="http://www.onlinetech.com/images/stories/people/mike-klein-100.jpg" alt="Mike_Klein_Head_Shot_Thumb" width="100" height="138" /></p>
<p style="text-align: left;">Mike is a serial entrepreneur with more than 30 years of high tech business leadership, technology, and startup experience including CEO of Interlink Networks, Managing Partner of CompanyCrafters, and CEO /Founder of Steeplechase Software, an INC 500 Company which he sold to Schneider Electric. Prior to becoming an entrepreneur, Mike spent the first decade of his career working in sales, strategic marketing, product development at Motorola Semiconductor and Rockwell International.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p><img style="float: left; margin-top: 0px; margin-right: 15px; margin-bottom: 0px; margin-left: 5px;" src="http://www.onlinetech.com/images/stories/misc/automation-alley-logo.jpg" alt="automation-alley-logo" width="100" height="138" /></p>
<p style="text-align: left;"><strong>About Automation Alley</strong></p>
<p style="text-align: left;"><a href="http://www.automationalley.com/">Automation Alley</a>, Michigan&#8217;s largest technology business association, drives growth in Southeast Michigan&#8217;s economy. Automation Alley is a non-profit organization that drives growth and economic development through a collaborative culture that focuses on workforce and business development initiatives. Automation Alley attracts the creators and consumers of diverse technologies from a variety of industries around the world.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 1px;" />
<p style="text-align: left;"><strong>About Radley Corporation</strong></p>
<p style="text-align: left;">Radley is a global ecommerce and data collection software development company that has successfully transitioned from traditional on premise software products to On Demand cloud computing. Mark sits on the Board of Directors at Radley and actively participates in the business planning and product development cycles within the company. Prior to Radley, Mark held several project management, consulting and technical and positions at Compuware Corporation and ADP Network Services.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-to-attend-impact-2012-conference-on-cloud-computing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Questions to Ask Your Business Associate: Question #2 HIPAA Audits</title>
		<link>http://resource.onlinetech.com/five-questions-to-ask-your-business-associate-question-2-hipaa-audits/</link>
		<comments>http://resource.onlinetech.com/five-questions-to-ask-your-business-associate-question-2-hipaa-audits/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 20:32:12 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[business associate agreement]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[HIPAA audits]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4554</guid>
		<description><![CDATA[Following up from last week&#8217;s question #1, the second most important question to ask a Business Associate is: Who performed your independent HIPAA audit and do you provide copies of the audit report? This single question quickly reveals Business Associates who take HIPAA compliance seriously. Business Associates who have invested in an independent HIPAA audit [...]]]></description>
			<content:encoded><![CDATA[<div>
<p>Following up from last week&#8217;s question #1, the second most important question to ask a Business Associate is:</p>
<p><strong><em>Who performed your independent HIPAA audit and do you provide copies of the audit report?</em></strong></p>
</div>
<div>
<p>This single question quickly reveals Business Associates who take <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> seriously.</p>
<p>Business Associates who have invested in an independent HIPAA audit benefit from:</p>
<ul>
<li>objective feedback from a HIPAA expert,</li>
<li>guided improvement of security processes and procedures,</li>
<li>training all of their employees about HIPAA security,</li>
<li>better preparation in the event of a PHI breach.</li>
</ul>
<p>When you see what <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/ocr-audit-requirements-following-a-self-reported-hipaa-breach?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">HHS requests after a PHI breach</a>, you’ll see there’s no way that the requested documentation can be prepared in 10 days. 10 weeks or 10 months would be more appropriate.</p>
<p>Some will argue that the cost of getting an independent HIPAA audit is prohibitive, but compared to the costs of a PHI breach, it’s truly trivial. Consider this: current class action lawsuits seek $1000/patient record breached. When a laptop was stolen from the Massachusetts eHealth Collaborative, 13,687 patient records were taken. There are 2 pending class action lawsuits.</p>
<p><strong>2 lawsuits * 13,687 patient records * $1000/patient record = $27,374,000</strong></p>
<p>Still think investing in an independent HIPAA audit is too expensive or overwhelming? Make sure you outsource health care IT services to Business Associates who are <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/100-hipaa-compliant">independently HIPAA audited</a> and will share a copy of the audit report with you.</p>
<p>Next week we discuss policies and technologies used to protect health care applications and PHI data.</p>
<p>References:</p>
<p><a href="http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">Why Business Associates Should Invest in a HIPAA Audit</a><br />
<a href="http://www.nytimes.com/2011/12/19/technology/as-patient-records-are-digitized-data-breaches-are-on-the-rise.html?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">NY Times Article: Digital Data on Patients Raises Risk of Breaches</a></p>
<p><strong>Related resources:</strong></p>
<p><a href="http://www.onlinetech.com/resources/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">HIPAA, HITECH, BAAs and the Law: Concerns &amp; Best Practices</a><br />
<a href="http://www.onlinetech.com/resources/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance/cost-effective-protection-against-hipaa-enforcement?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">Cost Effective Protection Against HIPAA Enforcement</a><br />
<a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/ocr-audit-requirements-following-a-self-reported-hipaa-breach?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">OCR Audit Requirements Following a Self-Reported HIPAA Breach</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/who-needs-to-be-hipaa-compliant?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">Who Needs to be HIPAA Compliant?</a><br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">HIPAA Resources: Policies, Procedures &amp; Training Materials</a><br />
<a href="http://resource.onlinetech.com/what%e2%80%99s-in-a-business-associate-agreement/?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">What&#8217;s in a Business Associate Agreement?</a><br />
<a href="http://resource.onlinetech.com/hipaa-compliant-it-security-and-best-practices/?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">HIPAA Compliant IT Security and Best Practices</a></p>
<p>For <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting?utm_source=Online+Tech+Mailing+List&amp;utm_campaign=1abf93a92b-HIMSS_eMail_Question_1_1_17_2012&amp;utm_medium=email">HIPAA Compliant hosting</a>, call 877.740.5028 or email <a href="mailto:contactus@onlinetech.com">contactus@onlinetech.com</a>.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/five-questions-to-ask-your-business-associate-question-2-hipaa-audits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Security: Are Most Apps Safe?</title>
		<link>http://resource.onlinetech.com/mobile-security-are-most-apps-safe/</link>
		<comments>http://resource.onlinetech.com/mobile-security-are-most-apps-safe/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 19:45:47 +0000</pubDate>
		<dc:creator>Aaron Riddle</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[mobile data security]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[smartphone data security]]></category>
		<category><![CDATA[smartphone security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4543</guid>
		<description><![CDATA[With smartphones and social media platforms becoming a major means of communication between friends, family and co-workers, we have come to appreciate the evolution of mobile applications. With over 500,000 apps on iPhone, 350,000 on Android and thousands more on other operating systems, there are many different apps out there that offer many different services [...]]]></description>
			<content:encoded><![CDATA[<p>With smartphones and social media platforms becoming a major means of communication between friends, family and co-workers, we have come to appreciate the evolution of mobile applications. With over 500,000 apps on iPhone, 350,000 on Android and thousands more on other operating systems, there are many different apps out there that offer many different services and solutions to its users. In order for these apps to work, they require permissions to use certain features of your phone in order to function. Sometimes, these apps require permissions that ultimately the app doesn’t need.</p>
<div id="attachment_4546" class="wp-caption alignright" style="width: 300px"><img class="wp-image-4546 " title="Pandora App Redistribution of User Information" src="http://resource.onlinetech.com/wp-content/uploads/Pandora-App-Redistribution-of-User-Information.png" alt="Pandora App Redistribution of User Information" width="290" height="354" /><p class="wp-caption-text">Pandora App Redistribution of User Information</p></div>
<p>For example, if you download an app from the Android Market, a screen will appear asking you to accept the permissions of this app having access to certain components and programs on your phone.</p>
<p>Apple takes a similar approach, except they approve permissions before they even put the app on their App Store.</p>
<p>Each of these methods has its pros and cons that may put users in jeopardy. Android puts more reliance on permissions of apps to its users while Apple takes that measure for you, but they are not perfect and some slip through the cracks.</p>
<p>Lookout, a U.S.-based security firm did a study in 2010 and found that over 300,000 apps on both iPhone and Android were stealing user data without user knowledge. Most of those privacy breaches were due to advertisement kits installed on the applications. These kits provide a little extra revenue to developers since information from the app is sent to third-party advertisers and used to target specific ads to its users.</p>
<p>They also pointed out that one specific Android wallpaper app,“Jackeey,” was stealing personal data from its users, including:</p>
<ul>
<li>Location</li>
<li>Phone Number</li>
<li>Voicemail Passwords</li>
</ul>
<p>This information was then sent to a website hosted in China. This particular app was downloaded somewhere between 1.1-4.6 million times.</p>
<p>Here are a couple of precautionary tips when it comes to downloading apps on your phone:</p>
<ul>
<li>Make sure the app is created and distributed by a verified developer. Make your best judgment on what you download.</li>
<li>Review the permissions that the app is requesting from your phone &#8211; does this app really need access to my contacts, location or text messages?</li>
</ul>
<p>There’s a great resource on Wall Street Journal’s <a href="http://blogs.wsj.com/wtk-mobile/">website</a> that has an interactive diagram in which you can see some of the most popular apps on your iPhone and Android (I’m sure there’s a good chance one of these apps is on your phone right now), and how they distribute your information.</p>
<p>For example, Pandora (seen in the photo above) shows that it requires your Phone ID (Red), Location (Purple), and Age/Gender (Blue), and then sends those resources to multiple advertising companies and groups.</p>
<p>Users need to be aware of what apps they are downloading to their phone. To users who are employed with companies that deal with compliance regulations such as <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a> (PHI, EMR) and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI</a> (CHD), it’s even more important due to heavy fines and potential legal action if any of that information is accessed. You don’t want to be that person that costs your company thousands of dollars because you needed the latest wallpaper app, do you?</p>
<p>Sources:<br />
<a href="http://venturebeat.com/2010/07/28/android-wallpaper-app-that-steals-your-data-was-downloaded-by-millions/">Android Wallpaper App That Steals Your Data Was Downloaded By Millions</a><br />
<a href="http://www.cio.com/article/683229/Mobile_App_Security_5_Ways_to_Protect_Your_Smartphone?page=2&amp;taxonomyId=3089">Mobile App Security: 5 Ways To Protect Your Smartphone</a><br />
<a href="http://www.itproportal.com/2010/07/29/300000-mobile-apps-stealing-personal-data/">Mobile Apps Stealing Personal Data</a><br />
<a href="http://blogs.wsj.com/wtk-mobile/">WSJ Interactive Diagram</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/mobile-security-are-most-apps-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disaster Recovery for HIPAA Applications – It’s All About Availability of PHI</title>
		<link>http://resource.onlinetech.com/disaster-recovery-for-hipaa-applications-its-all-about-availability-of-phi/</link>
		<comments>http://resource.onlinetech.com/disaster-recovery-for-hipaa-applications-its-all-about-availability-of-phi/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 18:16:00 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[high availability]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[managed cloud]]></category>
		<category><![CDATA[offsite backup]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4537</guid>
		<description><![CDATA[HIPAA – The Health Insurance Portability and Accountability Act focuses on three key criteria for handling Protected Health Information (PHI):  availability, confidentiality and integrity. This blog post focuses on availability as it applies to HIPAA applications and HIPAA data. Availability means that PHI is always available, accessible and never lost.  When a patient arrives at [...]]]></description>
			<content:encoded><![CDATA[<p>HIPAA – The Health Insurance Portability and Accountability Act focuses on three key criteria for handling Protected Health Information (PHI):  availability, confidentiality and integrity. This blog post focuses on availability as it applies to HIPAA applications and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a> data.</p>
<p>Availability means that PHI is always available, accessible and never lost.  When a patient arrives at the emergency room at three o’clock in the morning, the electronic health records need to be available so the physician can address the emergency with all of the patient’s records at her fingertips.  Patient records in the health care world is no longer a 9-5 job – and one of the main drivers behind electronic health records (EHR) is the portability and availability of patients’ records to health care providers around the clock.</p>
<p>Availability also means that PHI isn’t lost.  HIPAA and the HITECH Act make Covered Entities and Business Associates responsible for making sure PHI isn’t lost.  For electronic records, this means offsite data backups are imperative and offsite disaster recovery is strongly recommended.</p>
<p>So what does “availability” mean from a computing and application infrastructure?   I like to look at availability from 2 perspectives:</p>
<ol>
<li><strong><em>Disaster Prevention</em></strong> – putting all the tools in place to minimize the probability of an outage in the data center infrastructure, server hardware, software and network connectivity.</li>
<li><strong><em>Disaster Recovery</em></strong> – assuring that the applications and data can be recovered and restored in a reasonable timeframe to continue running the business and making patient data available if there is a disaster in the primary data center.</li>
</ol>
<p>Disaster Prevention is typically thought of in terms of “High Availability” – or redundant systems to assure that there is no single point of failure on the delivery of the application or data.  Examples of <a href="http://www.onlinetech.com/company/michigan-data-centers/features/high-availability-server-hosting">high availability</a> at the data center level include high availability power delivery through redundant generators, uninterruptible power supplies (UPSs), power distribution units (PDUs), and redundant power supplies in the servers.  With high availability power, the failure of any element (generator, UPS, or power supply) does not affect the availability of the application – since the entire infrastructure is redundant.</p>
<p>Redundancy can also be delivered in the cloud server platform.  For example, unlike many public clouds, Online Tech’s <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/managed-cloud">managed cloud servers</a> are running on redundant hardware hosts with multiple power supplies, multiple network connections to SANs, redundant controllers and redundant RAID drives.  Again, any hardware failure or even complete shutdown of a hardware hosts will not affect the availability of the application and the PHI data.</p>
<p><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">Disaster Recovery</a> is typically thought of in terms of Recovery Time Objective (RTO) and Recovery Point Objective (RPO).  RTO is the amount of time it takes to spin up the servers, network, application and data as a separate data center in the case that the application is shut down from a disaster.  RTOs can range from minutes to weeks depending on the technology selected.  RPO is defined as how close to the disaster the data can be recovered, which is tied to how often the data is backed up.  If backups are made every night, then the RPO is 24 hours (up to 24 hours of data can be lost). If continuous replication is used, the loss may be as short as a few minutes.  The shorter the RTO and RPO, the better for most businesses.</p>
<p>As a minimum, we recommend that all HIPAA applications use <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a> for their data.  That way, if the production data center has a disaster or is destroyed, the PHI isn’t lost.  The backup is stored at a second data center that is located a significant distance away to assure the same disaster doesn’t strike both sites.  In the Midwest, for example, best practices dictate a geographic separation of 50 miles between data centers.  Online Tech’s data centers are 53 miles apart on separate power utilities and are interconnected with high speed fiber to assure timely replication between sites.</p>
<p>For critical PHI, we recommend warm site disaster recovery between data centers.  Several years ago, warm site disaster recovery was difficult and expensive to achieve.  However, with the advent of <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud computing</a>, disaster recovery has become very cost-effective.  DR Now!, our <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">cloud disaster recovery</a> service provides offsite disaster recovery for cloud servers with a four hour RTO that starts at just $99 per server.</p>
<p>So when you think about meeting the HIPAA availability requirements for your health care applications and PHI, I’d suggest you think about it in terms of disaster prevention (high availability) and disaster recovery and ask yourself two key questions:</p>
<ol>
<li>Is your application hosted in a high availability environment where the power infrastructure, servers and network infrastructure can sustain failures without impacting your application and PHI data?</li>
<li>How will your application and PHI data survive a disaster in your production data center?  Do you need only to recover your data with offsite backup, or do you need your application and data to be back online in as short a time as possible?</li>
</ol>
<p>How you answer these questions will be critical to how you comply with the availability criteria of HIPAA and the HITECH Act.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/disaster-recovery-for-hipaa-applications-its-all-about-availability-of-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update from Online Tech: Major Initiatives &amp; Investments</title>
		<link>http://resource.onlinetech.com/update-from-online-tech-major-initiatives-investments/</link>
		<comments>http://resource.onlinetech.com/update-from-online-tech-major-initiatives-investments/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 13:00:41 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[disaster recovery in the cloud]]></category>
		<category><![CDATA[hipaa compliant cloud]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[managed cloud computing]]></category>
		<category><![CDATA[mid-michigan data center]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[sox compliant hosting]]></category>
		<category><![CDATA[ssae 16]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4477</guid>
		<description><![CDATA[To Our Valued Clients: Each quarter I like to share with our clients the major initiatives we’re undertaking at Online Tech, and a look at what is in store for the near future. Last year, we grew over 26%, added a new data center, and invested in a number of improvements to our data centers [...]]]></description>
			<content:encoded><![CDATA[<p>To Our Valued Clients:</p>
<p>Each quarter I like to share with our clients the major initiatives we’re undertaking at Online Tech, and a look at what is in store for the near future.</p>
<p>Last year, we grew over 26%, added a new data center, and invested in a number of improvements to our data centers and service offerings.  Some of our 2011 initiatives included:</p>
<ul>
<li>A <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=10fefc47e0&amp;e=a9fb62ad83">$1M investment in our Mid-Michigan data center</a>, including the complete replacement of the Uninterruptible Power Supplies (UPS).  The in-line UPS retrofit was achieved with no downtime and increased the capacity to a full 1 MW at the data center floor.</li>
<li>We remodeled the office and entry areas of the Mid-Michigan data center and now have a kitchen area and conference rooms available for our clients’ use.</li>
<li>We opened a third data center, <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=b3bf6c108f&amp;e=a9fb62ad83">Ann Arbor 2,</a> in the same Avis office park as our Ann Arbor 1 data center was filling up.  The new data center went live in November and adds another 10,000 square feet of raised floor and 300 KW of capacity to our footprint.</li>
<li>We completed our first <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=b71d3f2575&amp;e=a9fb62ad83">SSAE 16 Type II</a> (<a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=cab3b8cf57&amp;e=a9fb62ad83">SOC 1</a>), <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=bb68d69fef&amp;e=a9fb62ad83">SOC 2</a>, <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=f2e019d27d&amp;e=a9fb62ad83">SOC 3</a> and <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=da44aa9c74&amp;e=a9fb62ad83">HIPAA</a> audits and reports last year.  Online Tech was the first data center operator in Michigan to complete its SSAE 16 Type II (SOC 1) audit. We are one of a handful of data centers nationally who invested in a SOC 2 and SOC 3 audit which is much more stringent and focuses on privacy and security controls. We are also one of very few data centers across the country found to be fully HIPAA compliant across all 54 citations of the HITECH act. Online Tech shares audit reports with clients under NDA – every hosting provider should. You can learn more about the latest set of data center audits from this <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=0d4a8f9288&amp;e=a9fb62ad83">blog post</a>.</li>
<li>Our new multi-tenant <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=d0e8ef7ce8&amp;e=a9fb62ad83">managed cloud computing</a> offering was released last year.  Rather than competing against low-end public clouds like Amazon and Rackspace, we designed our managed cloud offering to run mission critical applications.  The uptake of server deployments has ramped very quickly since the product release and allows clients to leverage the flexibility and scalability of the cloud.</li>
<li><a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=4d8571e86b&amp;e=a9fb62ad83">HIPAA compliant cloud</a> – through the design and audit process, both our multi-tenant managed cloud and private cloud offerings are HIPAA audited and <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=3dc98f21ed&amp;e=a9fb62ad83">100% compliant</a>.</li>
<li><a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=0ed82fa440&amp;e=a9fb62ad83">DR Now!</a>  - Last quarter, we introduced the first cost-effective disaster recovery solution for cloud computing.  Our managed and private cloud clients are able to get complete disaster recovery in a second data center with a 4 hour recovery time, starting at $99 per server.  Fast, automatic disaster recovery is one of the demonstrated benefits of deploying cloud computing.</li>
</ul>
<p>It was nice to see so many of you at our Ann Arbor 2 open house last month.  Over the holidays, we were able to take a deep breath and start planning for what we hope will be an exciting 2012.  Some of the plans on our first quarter horizon include:</p>
<ul>
<li>Rolling out a new website.  Along with a cleaner, easier-to-navigate site, we’ve added a number of resources to the new site that you might find helpful, including information on <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=8720a4b427&amp;e=a9fb62ad83">HIPAA compliance</a>, <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=69db7df462&amp;e=a9fb62ad83">PCI compliance</a> and <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=f74be26181&amp;e=a9fb62ad83">SOX compliance</a>.</li>
<li>We are completing our PCI (Processing Card Industry) audit and will be listed on the Visa’s Global Registry of Service Providers.  PCI compliance is required for companies that process, transmit or store credit card data across the Internet.</li>
<li>We are announcing <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=8ba388b069&amp;e=a9fb62ad83">additional fiber optic capability</a> in our <a href="http://onlinetech.us2.list-manage.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=d1ccad13ef&amp;e=a9fb62ad83">Mid-Michigan data center</a> that enhances the connectivity to the Ann Arbor data centers and adds direct fiber connections to additional Internet service providers.</li>
<li>Comcast has just finished installing a fiber connection into the Mid-Michigan data center – to provide cost-effective high-speed data connections from anywhere in Michigan to our data centers.</li>
<li>Finally, if you’re going to be at the February <a href="http://onlinetech.us2.list-manage1.com/track/click?u=60f5b43fc127bc7fffa563394&amp;id=757fd76560&amp;e=a9fb62ad83">HIMSS health care IT conference</a> in Las Vegas, please stop by – we’ll be in booth #13528, where we’ll be discussing our HIPAA audited hosting capabilities. Our HIPAA auditor and one of the foremost legal experts in HIPAA compliance and the HITECH Act will be at our booth to answer your HIPAA questions.</li>
</ul>
<p>We wish all of our clients continued success into the new year and we look forward to continuing to serve your hosting needs.  As always, I welcome your feedback on how we can improve our services and the value we deliver.  Feel free to drop me an e-mail or call anytime.</p>
<p>Best Regards,</p>
<p>Mike Klein<br />
President &amp; Chief Operating Officer<br />
Online Tech Inc.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/update-from-online-tech-major-initiatives-investments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tactical Mobile Device Security Measures to Meet HIPAA Compliance</title>
		<link>http://resource.onlinetech.com/tactical-mobile-device-security-measures-to-meet-hipaa-compliance/</link>
		<comments>http://resource.onlinetech.com/tactical-mobile-device-security-measures-to-meet-hipaa-compliance/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 13:48:23 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[iphone security]]></category>
		<category><![CDATA[mobile device security]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[smartphone security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4505</guid>
		<description><![CDATA[Mobile devices are becoming ubiquitous in the healthcare industry – from quickly filing e-prescriptions to collecting and sending patient health information (PHI) directly to an EHR/EMR (electronic health or medical record) system, the use of smartphones, tablets and other portable devices is changing the quality of patient care for the better across the nation. But [...]]]></description>
			<content:encoded><![CDATA[<p>Mobile devices are becoming ubiquitous in the healthcare industry – from quickly filing e-prescriptions to collecting and sending patient health information (PHI) directly to an EHR/EMR (electronic health or medical record) system, the use of smartphones, tablets and other portable devices is changing the quality of patient care for the better across the nation.</p>
<p>But when it comes to securing your mobile devices and meeting strict <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> standards, physicians and other healthcare professionals may not realize the security precautions they need to take to prevent a data breach and HIPAA violation.</p>
<p>One example of recommended best practices can be found in Yale University’s HIPAA guide for mobile device security (intended for its covered components, such as the Schools of Medicine, Health Services, etc.) including:</p>
<div id="attachment_4525" class="wp-caption alignleft" style="width: 213px"><img class=" wp-image-4525 " title="Smartphone Security" src="http://resource.onlinetech.com/wp-content/uploads/Smartphones.jpg" alt="Smartphone Security" width="203" height="320" /><p class="wp-caption-text">Smartphone Security</p></div>
<ul>
<li><strong>Passwords – </strong>Yale recommends users have a password with a minimum of four characters. They also recommend implementing a lock-out setting after 10 failed attempts to enter a password.<strong></strong></li>
<li><strong>Encryption – </strong>Data must be encrypted at rest and in transit, including backup data.<strong></strong></li>
<li><strong>Message Storage – </strong>The storage limit is capped at 200 messages at one time or 14 days of messages.<strong></strong></li>
<li><strong>Applications</strong> – All applications that create, store, access, send or receive PHI must meet HIPAA security standards. Yale also has a <a href="http://security.yale.edu/sdr/">Security Design Review</a> service that can check out any custom developed apps for compliance (although the website really needs to update its language regarding Application Service Providers and the required <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a> Type II documentation – <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>/<a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-1-hosting">SOC 1</a> have since replaced the SAS 70 standard).<strong></strong></li>
<li><strong>Software – </strong>Apply security updates frequently and use the most recent OS available. <strong></strong></li>
<li><strong>Remote Management and Tracking –</strong> Mobile devices must have a remote deletion and tracking feature or you have to sign up for a service that can wipe it if it is stolen or lost. For the iPhone, that can mean installing the Find My iPhone app. Yale provides a <a href="http://www.yale.edu/its/mobile-technology/erase.html">comprehensive  guide</a> to locating and wiping iPhones, Blackberrys (<a href="http://crackberry.com/great-plural-blackberry-debate">read this, grammar nerds</a>) and other smartphone devices.<strong></strong></li>
<li><strong>No Circumvention – </strong>This refers to protecting the security of mobile devices by prohibiting users from using unauthorized software and hardware, etc.<strong></strong></li>
<li><strong>Wireless – </strong>Yale requires the use of VPN services when using digital cellular to connect to the Yale network and if not using one of Yale’s cell carriers. For Bluetooth™, passwords or PINs are required to secure connections. <strong></strong></li>
<li><strong>Thumb Drives and Other Portable Media Devices – </strong>Storing PHI is prohibited unless the devices meet the Yale encryption standards.<strong></strong></li>
<li><strong>File-Sharing – </strong>Users that need to send or exchange PHI outside of the network have to use a secure file transfer tool, or secure file transfer protocol (SFTP).<strong></strong></li>
<li><strong>Servers – </strong>Naturally Yale recommends using their IT department-owned servers to store all PHI. Their requirements are aligned with the HIPAA breach notification rules that require reports of data breaches if it affects 500 or more patients.<strong></strong></li>
<li><strong>Privacy Filters – </strong>Computer screens that display PHI must have privacy filters installed if they’re viewable by the public. <strong></strong></li>
<li><strong>Device Disposal &#8211; </strong>When upgrading or getting rid of your mobile devices, you must first securely destroy or delete PHI.<strong></strong></li>
<li><strong>Email – </strong>Configuring email accounts to auto-forward to a non-Yale email account is prohibited if the email account may have PHI in its inbox.<strong></strong></li>
</ul>
<p>This is a great start when it comes to documenting and specifying the security measures your organization needs to take, but don’t just copy and paste these policies. Every company has different needs that require a customized plan to keep PHI safe.</p>
<p>Also, not every device is created equal. Last year, <a href="http://www.bgr.com/2011/09/30/major-security-flaw-lets-anyone-bypass-att-samsung-galaxy-s-ii-security-video/">BGR.com</a> found a major security flaw in the security lock design of AT&amp;T’s Samsung Galaxy S II cellphone that left it open to a simple workaround, allowing users to bypass the PIN or unlock feature. If you tap the lock button to wake it, wait for it to time out and go black, then tap the lock button again, the phone is suddenly accessible and the PIN rendered useless.</p>
<p>Make sure you know your device and its features, and deploy similar security measures as found above to stay compliant even on the go.</p>
<p>For more on IT security and best practices, read <a href="http://resource.onlinetech.com/hipaa-compliant-it-security-and-best-practices/">HIPAA Compliant IT Security and Best Practices</a>. Or for more about smartphone security, read <a href="http://resource.onlinetech.com/mobile-security-how-safe-is-your-data/">Mobile Security: How Safe is Your Data?</a></p>
<p>References:<br />
<a href="http://hipaa.yale.edu/guidance/policy.html">Yale University’s HIPAA Security Updates and Reminders</a><br />
<a href="http://www.bgr.com/2011/09/30/major-security-flaw-lets-anyone-bypass-att-samsung-galaxy-s-ii-security-video/">Major Security Flaw Lets Anyone Bypass AT&amp;T Samsun Galaxy S II Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/tactical-mobile-device-security-measures-to-meet-hipaa-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Questions to Ask Your Business Associates: #1 Breach Notification</title>
		<link>http://resource.onlinetech.com/five-questions-to-ask-your-business-associates-1-breach-notification/</link>
		<comments>http://resource.onlinetech.com/five-questions-to-ask-your-business-associates-1-breach-notification/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 15:54:08 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[business associates agreement]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4513</guid>
		<description><![CDATA[How does your BAA (Business Associate Agreement) address breach notification to your clients? We&#8217;re asking ourselves tough questions about HIPAA compliance, and our responsibilities as a trusted Business Associate and hosting partner. #1 What timeframe does your BAA promise clients for PHI breach notification? As a data center hosting partner to hospitals, physician groups, and [...]]]></description>
			<content:encoded><![CDATA[<p>How does your BAA (Business Associate Agreement) address breach notification to your clients? We&#8217;re asking ourselves tough questions about HIPAA compliance, and our responsibilities as a trusted Business Associate and hosting partner.</p>
<h4><strong>#1 What timeframe does your BAA promise clients for PHI breach notification?</strong></h4>
<p>As a data center hosting partner to hospitals, physician groups, and health IT companies, we want to be a trusted Business Associate. We consulted experienced health care attorneys and HIPAA auditors to fully understand our responsibilities. Together we created a Business Associate Agreement (BAA) that reflects HHS requirements for timely breach notifications. We&#8217;ll share the exact language with you below.</p>
<p><strong>Why preparing for PHI breach notification is critical for Business Associates</strong><br />
Speaking from our own experience, Online Tech serves the health care industry with <a href="colocation/overview">colocation</a>, <a href="managed-dedicated-servers/overview">managed servers</a>, <a href="cloud-computing-hosting/packages/private-cloud">private</a> and <a href="cloud-computing-hosting/packages/managed-cloud">managed clouds</a>, and <a href="managed-services/it-disaster-recovery">disaster recovery</a>. A lot of PHI flows through our networks and resides in our servers, clouds, and storage. 62% of the breached records reported to HHS, or 4.4 million, <a href="http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/">involved a Business Associate</a>. The<a href="http://resource.onlinetech.com/prevent-increasing-costs-of-a-data-breach-invest-in-hipaa-hosting/"> costs of a PHI breach</a> to patients, Business Associates, and Covered Entities are high with HHS penalties, and lawsuit damages of $1000 per breached patient record.</p>
<p>Anything short of 100% HIPAA compliance puts any Business Associate, their clients, and their patients at undue risk. We weren&#8217;t comfortable assessing our own state of HIPAA compliance, so we invested in the expertise of independent health IT security specialists, auditors, and attorneys.</p>
<p><strong>What timeframe does Online Tech&#8217;s BAA promise for PHI breach notification?</strong> <strong>?</strong><br />
HHS requires <a href="resources/e-tips/hipaa-compliance/ocr-audit-requirements-following-a-self-reported-hipaa-breach">extensive documentation</a> within 10 days of a PHI breach &#8212; documentation that must be prepared well in advance. Online Tech&#8217;s preparation included an independent risk assessment, remediation, and complete HIPAA audit of all 54 HITECH citations across our company policies, procedures, facilities, and HIPAA security training by Certified HIPAA Security Specialist Joe Dylewski, president of ATMP Solutions. Our BAA was prepared in accordence with HITECH requirements with the help of experienced health care attorneys Brian Balow and Tatiana Melnik from Dickinson Wright.<br />
<strong><a href="secure-hosting/hipaa-compliant-hosting/five-questions-to-ask-your-business-associates/question-1-breach-notification/baa-breach-notification-clause"><br />
Click here for Online Tech&#8217;s BAA Breach Notification Timeframe Clause</a></strong>.</p>
<p>Next week, we&#8217;ll discuss preparing for an independent HIPAA audit and the end deliverables.<strong><br />
</strong></p>
<p><strong>Related resources:</strong><br />
<a href="secure-hosting/hipaa-compliant-hosting/five-questions-to-ask-your-business-associates/question-1-breach-notification/baa-breach-notification-clause">BAA Breach Notification Clause</a><br />
<a href="resources/e-tips/hipaa-compliance/ocr-audit-requirements-following-a-self-reported-hipaa-breach">OCR Audit Requirements Following a Self-Reported HIPAA Breach</a><br />
<a href="secure-hosting/hipaa-compliant-hosting/who-needs-to-be-hipaa-compliant">Who Needs to be HIPAA Compliant? </a><br />
<a href="secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources: Policies, Procedures &amp; Training Materials</a><br />
<a href="resources/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices">HIPAA, HITECH, BAAs and the Law: Concerns &amp; Best Practices</a><br />
<a href="http://resource.onlinetech.com/what%e2%80%99s-in-a-business-associate-agreement/">What&#8217;s in a Business Associate Agreement?</a><br />
<a href="http://resource.onlinetech.com/hipaa-compliant-it-security-and-best-practices/">HIPAA Compliant IT Security and Best Practices</a></p>
<p>For more information on <a href="secure-hosting/hipaa-compliant-hosting">HIPAA Compliant hosting</a>, contact us at 877.740.5028 or <a href="mailto:himss@onlinetech.com">himss@onlinetech.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/five-questions-to-ask-your-business-associates-1-breach-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mass Digitization Threatens the IT Industry</title>
		<link>http://resource.onlinetech.com/mass-digitization-threatens-the-it-industry/</link>
		<comments>http://resource.onlinetech.com/mass-digitization-threatens-the-it-industry/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 13:46:14 +0000</pubDate>
		<dc:creator>Yan Ness</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[Managed Servers]]></category>
		<category><![CDATA[IT industry news]]></category>
		<category><![CDATA[mass digitization]]></category>
		<category><![CDATA[server virtualization]]></category>
		<category><![CDATA[virtual servers]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4509</guid>
		<description><![CDATA[Video, music, classified ads, newspapers, magazines, pictures – all forms of media have been dramatically transformed by their digitization. iTunes, Amazon and all of their various devices have enabled a new business model that created fantastic wealth at the expense of old-guard leaders. This digital transformation was an onslaught that decimated local newspapers, record stores, [...]]]></description>
			<content:encoded><![CDATA[<p>Video, music, classified ads, newspapers, magazines, pictures – all forms of media have been dramatically transformed by their digitization. iTunes, Amazon and all of their various devices have enabled a new business model that created fantastic wealth at the expense of old-guard leaders. This digital transformation was an onslaught that decimated local newspapers, record stores, film production, magazines and many more.</p>
<p>IT professionals claim they dodged this. In fact, they claim they benefit from this. All of this digitization will call for more and more of their expertise. As everyone digitizes everything, the world needs more servers, more storage, more memory, more connectivity, more software and more people who can make it all work.</p>
<p>But I can imagine now a discussion in the decimated old-guard leaders of the newspaper industry.  “The ever-growing and aging population will consume ever-increasing quantities of news.”  They were right that more and more people wanted to consume more and more news content.  But they completely missed that it wouldn’t be in print.  It would be in a new form.  One they didn’t anticipate and that came on faster than they predicted.  Hence they failed to exist.  Their newspaper had been <em>virtualized.</em></p>
<p>IT professionals are right that there will be an ever-increasing demand for digital content.  But they are wrong to assume that means their skills will remain relevant as that happens.  In fact, I predict that many of the IT skills currently in demand will experience a similar trend as those who ran printing presses in the 80s for those same old-guard newspapers.</p>
<p>Why do I think this?  Because the same thing that happened to newspapers is happening to IT equipment. Servers, storage and networks are all being <em>virtualized</em> &#8211; which is exactly what a digital version of a newspaper is.  It’s a <em>virtual newspaper</em>.  And what happens when you <em>virtualize</em> something?  That metamorphosis results in a transformational change.  Transformation is both highly creative but also very destructive.  Once something is <em>virtualized,</em> it can be instantly transported across the globe, instantly searchable, modifiable by software so it can be customized, along with a plethora of other traits.  Those traits add so much value it makes the physical rendition completely obsolete.</p>
<p>Virtualizing a server is essentially digitizing the server hardware. I don’t see any reason why that won’t be as transformational to the IT industry as virtualizing a newspaper was to newspapers or virtualizing photos was to Kodak.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/mass-digitization-threatens-the-it-industry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Guide to PCI Compliance Levels &amp; Merchant Types</title>
		<link>http://resource.onlinetech.com/guide-to-pci-compliance-levels-merchant-types/</link>
		<comments>http://resource.onlinetech.com/guide-to-pci-compliance-levels-merchant-types/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 14:13:20 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliance levels]]></category>
		<category><![CDATA[pci compliance saq]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[pci dss compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci merchants]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4480</guid>
		<description><![CDATA[Do you know what level of PCI (Payment Card Industry) compliance your company falls under? Or even what merchant type best categorizes your payment process? Here’s your guide to the four different levels of PCI compliance as mandated by the major payment card brands, Visa and Mastercard, as well as action items for each: Level [...]]]></description>
			<content:encoded><![CDATA[<p>Do you know what level of PCI (<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Payment Card Industry">Payment Card Industry</a>) compliance your company falls under? Or even what merchant type best categorizes your payment process?</p>
<p>Here’s your guide to the four different <strong>levels of <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliance</a></strong> as mandated by the major payment card brands, Visa and Mastercard, as well as action items for each:</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="73">
<p align="center"><strong>Level 1</strong></p>
</td>
<td valign="top" width="565">Over 6 million Visa and/or Mastercard transactions processed per year. Requires yearly on-site reviews by an internal auditor, and a network scan by an <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Approved Scanning Vendor (ASV)">approved scanning vendor</a> (ASV).</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>Level 2</strong></p>
</td>
<td valign="top" width="565">1 million to 6 million Visa and/or Mastercard transactions processed per year. Must complete a Self-Assessment Questionnaire (SAQ) annually, and requires a network scan with an approved scanning vendor.</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>Level 3</strong></p>
</td>
<td valign="top" width="565">20,000 to 1 million Visa and/or Mastercard e-commerce transactions processed per year. Must complete a Self-Assessment Questionnaire (SAQ) annually, and requires a network scan with an approved scanning vendor.</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>Level 4</strong></p>
</td>
<td valign="top" width="565">Less than 20,000 Visa and/or Mastercard e-commerce transactions processed per year all other companies that process up to 1 million Visa transactions per year. Must complete a Self-Assessment Questionnaire (SAQ) annually, and requires a network scan with an approved scanning vendor.</td>
</tr>
</tbody>
</table>
<p>Now, how do you know which <strong>SAQ (Self-Asssessment Questionnaire)</strong> to fill out? Find which merchant type best fits your company profile:</p>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td width="73">
<p align="center"><strong>A</strong></p>
</td>
<td valign="top" width="565">E-commerce, mail or telephone order merchants that do not store <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/pci-glossary-of-terms#Cardholder Data">cardholder data</a> (CD). All cardholder data functions are outsourced. This does not include face-to-face merchants.</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>B</strong></p>
</td>
<td valign="top" width="565">Merchants that do not store electronic cardholder data. Instead, this applies to merchants that use an imprint machine to copy cardholder information. Also applies to standalone, dial-out terminal merchants.</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>C-VT</strong></p>
</td>
<td valign="top" width="565">Web-based virtual terminal merchants that do not store electronic cardholder data.</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>C</strong></p>
</td>
<td valign="top" width="565">Merchants that use a <a href="http://www.pcicomplianceguide.org/pcifaqs.php#15" target="_blank">payment application system</a> connected to the Internet and do not store electronic cardholder data. If using a software vendor for the payment application system, they must take security measures to ensure the app meets PCI compliance.</td>
</tr>
<tr>
<td width="73">
<p align="center"><strong>D</strong></p>
</td>
<td valign="top" width="565">This includes all of the other merchants that aren’t included in the above categories, including all service providers defined as eligible to complete a SAQ and approved by a payment brand.</td>
</tr>
</tbody>
</table>
<p>You&#8217;ve narrowed down what level and type of merchant you are, so now what? Read up about the 12 requirements to meet PCI Compliance with <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/what-is-pci-compliance">What is PCI Compliance?</a> or watch a webinar on the <a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-detailed-requirements">detailed requirements</a> of PCI compliance.</p>
<p>References:<br />
<a href="https://www.pcisecuritystandards.org/documents/pci_dss_saq_instr_guide_v2.0.pdf" target="_blank">Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire</a><br />
<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/levels-of-pci-compliance"> Levels of PCI Compliance</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/guide-to-pci-compliance-levels-merchant-types/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Goes to Las Vegas for HIMSS 12</title>
		<link>http://resource.onlinetech.com/online-tech-goes-to-las-vegas-for-himss-12/</link>
		<comments>http://resource.onlinetech.com/online-tech-goes-to-las-vegas-for-himss-12/#comments</comments>
		<pubDate>Wed, 18 Jan 2012 13:47:15 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT conference]]></category>
		<category><![CDATA[HIMSS 12]]></category>
		<category><![CDATA[HIMSS 2012]]></category>
		<category><![CDATA[HIPAA audit]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4460</guid>
		<description><![CDATA[Online Tech will be exhibiting in Las Vegas at the 2012 Annual HIMSS Conference &#38; Exhibition, Feb. 20-24 at the Venetian Sands Expo Center. Drawing in more than 30,000 attendees, HIMSS 12 is one of the largest healthcare IT and management systems conferences in the world, bringing healthcare industry professionals and exhibitors together from around [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_4461" class="wp-caption alignleft" style="width: 321px"><img class="size-full wp-image-4461  " title="HIMSS" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-Logo.png" alt="HIMSS" width="311" height="205" /><p class="wp-caption-text">HIMSS</p></div>
<p>Online Tech will be exhibiting in Las Vegas at the 2012 Annual HIMSS Conference &amp; Exhibition, Feb. 20-24 at the Venetian Sands Expo Center.</p>
<p>Drawing in more than 30,000 attendees, HIMSS 12 is one of the largest healthcare IT and management systems conferences in the world, bringing healthcare industry professionals and exhibitors together from around the nation.</p>
<p>Online Tech will be exhibiting its audited <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> solutions for healthcare and related organizations at <strong>Booth #13528</strong>, including:</p>
<ul>
<li><a href="http://www.onlinetech.com/colocation/overview">HIPAA compliant colocation</a> with high availability power and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a> options.</li>
<li><a href="http://www.onlinetech.com/managed-dedicated-servers/overview">HIPAA compliant servers</a> with fully managed services.</li>
<li><a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">HIPAA compliant private clouds</a> with fully managed services.</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">HIPAA compliant disaster recovery</a> with comprehensive cloud-based solutions.</li>
</ul>
<p>Please stop by and <a href="http://www.onlinetech.com/contact">contact us</a> if you’re also planning to be at the show!</p>
<p>A full list of exhibitors providing healthcare IT products and services can be found through the <a href="http://onlinebuyersguide.himss.org/">HIMSS Online Buyers Guide</a>.</p>
<div id="attachment_4462" class="wp-caption alignright" style="width: 343px"><img class="size-full wp-image-4462  " title="Farzad Mostashari, MD, ScM Speaking at HIMSS 11" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS11.png" alt="Farzad Mostashari, MD, ScM Speaking at HIMSS 11" width="333" height="212" /><p class="wp-caption-text">Farzad Mostashari, MD, ScM Speaking at HIMSS 11</p></div>
<p>Featured <a href="http://www.himssconference.org/education/keynoteSpeakers.aspx">keynote speakers</a> include:</p>
<ul>
<li><strong>Biz Stone</strong> - the Co-founder of Twitter will speak on how social media can influence the changing healthcare landscape.</li>
<li><strong>Farzad Mostashari, MD, ScM</strong> – the National Coordinator for Health Information Technology will share top level insight about the latest on healthcare reform.</li>
<li><strong>Donna Brazile</strong> - Renowned Political Strategist and Commentator Vice Chair of Voter Registration and Participation, Democratic National Committee</li>
<li><strong>Dana Perino</strong> - Political Commentator and Former White House Press Secretary</li>
<li><strong>Dan Buettner</strong> - Founder of Blue Zones and World-Renowned Explorer</li>
</ul>
<p>HIMSS 12 will also feature more than 400 educational sessions, networking events, pre-conference workshops, knowledge center sessions and <a href="http://www.himssconference.org/education/symposia.aspx">symposia</a> on the following topics:</p>
<ul>
<li>ICD-10: Is Your Organization Ready?</li>
<li>Accountable Care Organizations (ACOs): Health IT – Connecting Systems, Connecting People, Changing Care</li>
<li>Achieving Meaningful Use: Achieving and Sustaining the Meaningful Use of Health IT – The Go Forward Plan</li>
<li>Clinical Engineering and IT Leadership: Critical Ingredients for Medical Device Connectivity</li>
<li>Health Information Exchange (HIE): The Year of Implementation, Collaboration &amp; Beyond</li>
<li>Nursing Informatics: Nursing Informatics Leadership – Delivering Value with HIT</li>
<li>Physicians’ IT: The Health IT Balancing Act: Managing the CMIO Workload</li>
<li>Performance Measurement and CDS Symposium: Meaningful Use Improves Quality Care</li>
<li>RFID &amp; RTLS in Healthcare: Business and Technical Essentials for Improving Patient Care and Safety</li>
<li>Secondary Use of Data Symposium: Create Value from the Data</li>
</ul>
<p>For more information about the event, visit <a href="http://www.himssconference.org/">www.himssconference.org</a>.</p>
<p><strong>About HIMSS</strong></p>
<p>HIMSS is a cause-based, not-for-profit organization exclusively focused on providing global leadership for the optimal use of information technology (IT) and management systems for the betterment of healthcare. Founded 50 years ago, HIMSS and its related organizations are headquartered in Chicago with additional offices in the United States, Europe and Asia. HIMSS represents more than 38,000 individual members, of which more than two thirds work in healthcare provider, governmental and not-for-profit organizations.</p>
<p>To learn more about HIMSS, please visit <a href="http://www.himss.org/">www.himss.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-goes-to-las-vegas-for-himss-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recent Data Breaches Exemplify the Importance of PCI Compliance</title>
		<link>http://resource.onlinetech.com/recent-data-breaches-affect-pci-compliance/</link>
		<comments>http://resource.onlinetech.com/recent-data-breaches-affect-pci-compliance/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 13:45:04 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2012 data breaches]]></category>
		<category><![CDATA[hosting ecommerce]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant host]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4422</guid>
		<description><![CDATA[Strafor, the latest target of hackers, lost credit cardholder data in December that was released to the public later that month.  The data belonged to thousands of customers, including politicians, military officers, government officials and business executives. Stratfor is a private international affairs research firm that may have not encrypted data before storing it in [...]]]></description>
			<content:encoded><![CDATA[<p>Strafor, the latest target of hackers, lost credit cardholder data in December that was released to the public later that month.  The data belonged to thousands of customers, including politicians, military officers, government officials and business executives.</p>
<p>Stratfor is a private international affairs research firm that may have not encrypted data before storing it in its database, allowing hackers to access and release customer credit card numbers. As a result of lax online security, the firm’s website was taken down and lost a month’s worth of subscriptions – forcing the company to draw on its savings to survive.</p>
<p>The PCI DSS (Payment Card Industry Data Security Standard) is regulated by major industry card-issuers, including VISA, American Express, Discover, MasterCard and JCB International, and applies to companies that accept, store, process and transmit cardholder data.</p>
<p>The second goal of the 12 requirements is to <strong>Protect Cardholder Data</strong>. Within this goal, requirement #3 states the company must protect stored cardholder data, while Requirement #4 explicitly states:</p>
<blockquote><p>Encrypt transmission of cardholder data across open, public networks.</p></blockquote>
<div id="attachment_4434" class="wp-caption aligncenter" style="width: 498px"><img class="size-full wp-image-4434 " title="PCI Requirements" src="http://resource.onlinetech.com/wp-content/uploads/PCI-Requirements.png" alt="PCI Requirements" width="488" height="226" /><p class="wp-caption-text">PCI Requirements</p></div>
<p>Detailed requirements of encryption include using industry best practices to implement strong encryption for authentication and transmission over wireless networks or networks connected to the cardholder data environment. When it comes to outsourcing a hosting solution, your <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliant hosting</a> provider should provide evidence that the network is secure and encrypted.</p>
<p>The provisions also strictly forbid sending unprotected PANs (Primary Account Numbers) by email, instant messaging, chat, etc.</p>
<p>Stratfor’s subsequent steps will be to limit the scope of compliance by outsourcing credit card processing to a vendor. They are also revamping their website, email and internal systems with the help of an Internet security firm.</p>
<p>Zappos, the online shoes and apparel retailer owned by Amazon, most recently suffered a data breach that may affect more than 24 million customers. An internal email to their employees reports that a hacker gained access to their internal network through one of their servers located in Kentucky.</p>
<p>Although they report that no credit card or payment information was accessed, they are urging customers to change passwords on their online accounts. Names, contact information, password hashes and the last four digits of their credit card numbers were accessed. The company has not released any other details about the incident due to the ongoing investigation.</p>
<p>Need more information about PCI compliance? Watch our pre-recorded <a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series">PCI webinar series</a> hosted by Online Tech and led by expert Adam Goslin, co-founder of High Bit Security.</p>
<ul>
<li><a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-overview">PCI Compliance: Overview and First Steps to Success</a></li>
<li><a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-detailed-requirements">PCI Compliance: Detailed Requirements Walkthrough</a></li>
<li><a href="http://www.onlinetech.com/resources/events/webinars/pci-webinar-series/pci-compliance-penetration-testing">PCI Compliance: Penetration Testing and Enhancing Security for Network and Applications</a></li>
</ul>
<p>References:<br />
<a href="https://www.pcisecuritystandards.org/documents/pci_dss_v2.pdf">Payment Card Industry (PCI) Data Security Standard: Requirements and Security Assessment Procedures Version 2.0</a><br />
<a href="http://www.nytimes.com/reuters/2012/01/11/technology/tech-us-stratfor.html?ref=technology">Stratfor Relaunches Web Site in Wake of Attack</a><br />
<a href="http://www.eweek.com/c/a/Security/Zappos-Latest-Company-Hit-by-Data-Breach-581979/">Zappos Latest Company Hit by Data Breach</a><br />
<a href="http://www.databreaches.net/?p=22881">Zappos Hacked; Notifying 24+ Million Zappos.com and 6pm.com Customeres of Breach and to Reset Passwords</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/recent-data-breaches-affect-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Integrating IT Services: Cloud Computing &amp; Compliance Concerns</title>
		<link>http://resource.onlinetech.com/integrating-it-services-cloud-computing-compliance-concerns/</link>
		<comments>http://resource.onlinetech.com/integrating-it-services-cloud-computing-compliance-concerns/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:25:49 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud compliance]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[colocation]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[managed cloud computing]]></category>
		<category><![CDATA[managed cloud hosting]]></category>
		<category><![CDATA[managed dedicated servers]]></category>
		<category><![CDATA[managed hosting]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[private cloud hosting]]></category>
		<category><![CDATA[remote server monitoring]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4402</guid>
		<description><![CDATA[To streamline IT service management and assets, the convergence of technology and processes to better meet business objectives is ideal. It also allows in-house IT teams to spend more time on other endeavors and projects for industry-specific, targeted business growth. A recent survey conducted by IDG Research Services found that more than half of IT [...]]]></description>
			<content:encoded><![CDATA[<p>To streamline IT service management and assets, the convergence of technology and processes to better meet business objectives is ideal. It also allows in-house IT teams to spend more time on other endeavors and projects for industry-specific, targeted business growth.</p>
<p>A recent survey conducted by IDG Research Services found that more than half of IT executives have a limited process automation, meaning they still have several manual processes when it comes to managing their IT assets.</p>
<p>The report also acknowledges that companies with higher levels of process automation and data/process integration are more likely to rate their processes as better when it comes to efficiency, cost-effectiveness and freeing up their IT team’s time.</p>
<p>The survey also reports that companies typically have three or four different installed solutions for monitoring and managing their IT assets and services, with minimal integration and some reported gaps. More than half are working with multiple IT vendors although they report they would prefer not to &#8211; it can be difficult to monitor, integrate and manage all of their needed solutions.</p>
<p>Online Tech’s <a href="http://www.onlinetech.com/managed-services/overview">managed hosting</a> solutions offer comprehensive <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a>, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a>, <a href="http://www.onlinetech.com/managed-services/remote-server-monitoring">remote server monitoring</a> and more for <a href="http://www.onlinetech.com/colocation/overview">colocation</a>, <a href="http://www.onlinetech.com/managed-dedicated-servers/overview">managed dedicated servers</a> and <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud hosting</a> services.</p>
<div id="attachment_4404" class="wp-caption alignleft" style="width: 298px"><img class="size-full wp-image-4404  " title="OTPortal: Client Hosting Portal" src="http://resource.onlinetech.com/wp-content/uploads/otportal-screenshot.png" alt="OTPortal: Client Hosting Portal" width="288" height="258" /><p class="wp-caption-text">OTPortal: Client Hosting Portal</p></div>
<p>Our OTPortal is an easy-to-use, secure <a href="http://www.onlinetech.com/managed-services/client-hosting-portal">client hosting portal</a> designed as an all-inclusive dashboard detailing everything you need to know about your server, from bandwidth to firewall rules.</p>
<p>The portal allows for optimal process, service and asset integration to cut down on the time it takes to manage your IT services, streamlining your business operations and giving you more time to focus on your own company.</p>
<p>The IT convergence report also details some trends that will demand more of IT teams and require more integration. A few notable trends include:</p>
<ul>
<li><strong>Remote access</strong> &#8211; Evolving working habits and schedules means critical applications and data need to be accessible and available nearly 24&#215;7. A fully redundant <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> built for <a href="http://www.onlinetech.com/company/michigan-data-centers/features/high-availability-server-hosting">high availability</a> is ideal since it provides automatic failover and protected power to keep servers up and running.</li>
<li><strong>Full compliance</strong> &#8211; Industry and government regulations such as <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI DSS compliance</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> are demanding IT services to all meet pre-defined standards for optimal security and privacy of sensitive data. Noncompliance can result in major legal and security fines and damage to your business.</li>
<li><strong>Mobile support</strong> &#8211; With the use of personal devices in a work setting come the security concerns around transmitting or storing sensitive data. The issue of integrating and managing mobile applications and data is now a necessity.</li>
<li><strong>Cloud computing</strong> &#8211; Complex IT infrastructures require a computing solution that can support many applications and easily scale up or down as needed. Compliance concerns may be eased with <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">private clouds</a>, while <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/managed-cloud">managed clouds</a> take the burden off of internal IT staff and allow them to focus on other projects.</li>
</ul>
<p>References:<strong id="internal-source-marker_0.5181114471051842"><br />
</strong><a href="http://resources.idgenterprise.com/original/AST-0054439_Numara_WPfin_1117.pdf">The Convergence of IT Operations Management</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/integrating-it-services-cloud-computing-compliance-concerns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Preventing a HIPAA Violation in 2012</title>
		<link>http://resource.onlinetech.com/preventing-a-hipaa-violation-in-2012/</link>
		<comments>http://resource.onlinetech.com/preventing-a-hipaa-violation-in-2012/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 13:38:48 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2012 hipaa compliance]]></category>
		<category><![CDATA[2012 hipaa security]]></category>
		<category><![CDATA[business associate agreements]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violation]]></category>
		<category><![CDATA[mobile data security]]></category>
		<category><![CDATA[mobile security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4380</guid>
		<description><![CDATA[The government’s HIPAA Audit Program has been underway since November 2011, but it is scheduled to continue through the end of 2012. With more awareness and data breaches reported than ever, here are a few areas your company should be sure to evaluate this year in order to reduce your risk of a HIPAA violation. [...]]]></description>
			<content:encoded><![CDATA[<p>The government’s <a href="http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/">HIPAA Audit Program</a> has been underway since November 2011, but it is scheduled to continue through the end of 2012. With more awareness and data breaches reported than ever, here are a few areas your company should be sure to evaluate this year in order to reduce your risk of a HIPAA violation.</p>
<p><strong>Mobile Device Security </strong><br />
The infamous Ponemon Institute study on data breaches reports that 81 percent of healthcare organizations use mobile devices to collect, store and transmit patient data. Yet 49 percent take no security precautions to ensure those devices and patient data are protected, and less than 24 percent use encryption.</p>
<div id="attachment_4381" class="wp-caption alignleft" style="width: 384px"><img class="size-full wp-image-4381 " title="Mobile Device Security" src="http://resource.onlinetech.com/wp-content/uploads/Mobile-Device-Security.jpg" alt="Mobile Device Security" width="374" height="377" /><p class="wp-caption-text">Mobile Device Security</p></div>
<p>According to a Jackson &amp; Coker report, four out of five physicians use smartphones, tablets and other mobile devices and apps in daily practice in order to collect patient data from patient exams and easily enter it into their digital EHR/EMR (electronic health or medical records) systems.</p>
<p>The top three healthcare specialties that use mobile devices most frequently include:</p>
<ul>
<li>40% Emergency department physicians</li>
<li>33% Cardiologists</li>
<li>31% Urologists and Nephrologists</li>
</ul>
<p>However, the use of mobile devices can increase the potential for a HIPAA breach, especially if the device is lost and not protected by a PIN or encrypted – see our previous blog post on <a href="http://resource.onlinetech.com/mobile-security-how-safe-is-your-data/">Mobile Security: How Safe is Your Data?</a> for more information.</p>
<p>Another way to protect sensitive data is to have it removed from devices before being transferred from a healthcare facility. A combination of technical security and establishing proper policies and procedures is important to keep up with HIPAA compliant standards.</p>
<p>Read more about our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq#What services from Online Tech help make me compliant?">recommended security measures</a> to achieve HIPAA compliance and pass an audit, and about the <a href="http://www.onlinetech.com/news/data-center-industry-news/hipaa-compliance/healthcare-industry-is-going-mobile">rise of mobile devices</a> in the healthcare industry.</p>
<p><strong>Business Associate Agreements</strong><br />
To save on capital costs and take advantage of expert knowledge, many turn to professional organizations that offer services to healthcare providers, including data hosting and billing companies. To a covered entity (a physician’s office or hospital collecting patient data), these companies are known as business associates.</p>
<p>But carefully choosing a vendor is extremely important to keeping compliance – business associate-related data breaches topped 62% of total number of patient records breached according to the Dept. of Health and Human Services.</p>
<div id="attachment_4387" class="wp-caption alignright" style="width: 367px"><img class="size-full wp-image-4387" title="Business Associate Agreements" src="http://resource.onlinetech.com/wp-content/uploads/Business-Associate-Agreements.jpg" alt="Business Associate Agreements" width="357" height="270" /><p class="wp-caption-text">Business Associate Agreements</p></div>
<p>How do you know your <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> provider is credible? Ask them if they’re willing to sign a business associate agreement, or BAA, which is a contract that clearly outlines each party’s responsibility when it comes to data protection.</p>
<p>According to an InformationWeek.com article, only a third of organizations transferring patient data externally had signed data-sharing contracts with all of their contractors.</p>
<p>Online Tech signs a BAA with every healthcare client with patient data since we have possible access to or could affect the availability of patient data on their servers in our data centers. Although we <strong>never</strong> access patient or client data, the signed document codifies our commitment to follow HIPAA compliant rules.</p>
<p>Read more about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq#What is a Business Associate (BA)?">business associates</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq#So, tell me more about this Business Associates Agreement?">business associate agreements</a>.</p>
<p><strong>Internal Operations</strong><br />
Check out your own staff and internal operations – often human error or mistrained/not-at-all-trained employees can be the root cause of a HIPAA violation. Those with access privileges can mishandle sensitive data.</p>
<p>In the case of the TRICARE/SAIC military healthcare contractor incident, an employee drove off government property and left their car unattended, during which time a thief made off with 4.9 million patient records on unencrypted backup tapes. A resulting lawsuit points out the DoD’s lack of employee training as one of the major offenses.</p>
<p>A survey report by PricewaterhouseCoopers (PwC) shows that slightly more than half of respondents reported a privacy or security issue in the past two years attributed most incidents to the improper use of patient health information by employees. Employee training on HIPAA policies and procedures as they affect day-to-day operations is key to eliminating any points of weakness within a company.</p>
<p>Online Tech was found to be <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/100-hipaa-compliant">100% HIPAA compliant</a> as a result of our HIPAA audit, and has undergone complete HIPAA employee training in our updated policies and procedures.</p>
<p>Watch our informative webinar, <a href="http://www.onlinetech.com/resources/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance/impact-of-hipaa-compliance-on-business-associates">Impact of HIPAA Compliance on Business Associates</a>, for more information from the perspective of our Director of Operations and Risk Management and Security Officer on the day-to-day operations of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a>.</p>
<p>References:<br />
<a href="http://www.kevinmd.com/blog/2011/06/securing-mobile-deviceshttp:/www.kevinmd.com/blog/2011/06/securing-mobile-devices-healthcare.html-healthcare.html">80% of Doctors Use Mobile Devices At Work</a><br />
<a href="http://www.mdnews.com/news/2012_01/smartphones-to-blame-for-hipaa">Smartphones Partly to Blame for HIPAA Compliance Issues</a><br />
<a href="http://www.informationweek.com/news/healthcare/security-privacy/231602130?itc=edit_in_body_cross">Integrated Security Reduces Health IT Data Breaches</a><br />
<a href="http://searchcompliance.techtarget.com/news/2240113564/Staying-vigilant-key-to-meeting-regulatory-compliance-standards">Staying Vigilant Key to Meeting Regulatory Compliance Standards</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/preventing-a-hipaa-violation-in-2012/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Data Breach Results in Email Marketing Spam</title>
		<link>http://resource.onlinetech.com/data-breach-results-in-email-marketing-spam/</link>
		<comments>http://resource.onlinetech.com/data-breach-results-in-email-marketing-spam/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 13:36:44 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[email marketing spam]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4362</guid>
		<description><![CDATA[Just before the New Year, I received a strange email that appeared to be sent from the New York Times regarding my account. But the email referenced renewing my home delivery subscription, which I don’t have &#8211; I only have an online subscription. A few days later, I received another email apologizing and acknowledging it [...]]]></description>
			<content:encoded><![CDATA[<p>Just before the New Year, I received a strange email that appeared to be sent from the New York Times regarding my account. But the email referenced renewing my home delivery subscription, which I don’t have &#8211; I only have an online subscription. A few days later, I received another email apologizing and acknowledging it had been sent in error.</p>
<div id="attachment_4376" class="wp-caption aligncenter" style="width: 490px"><img class="size-full wp-image-4376 " title="NYTimes Spam Email" src="http://resource.onlinetech.com/wp-content/uploads/NYTimes-Spam-Email.png" alt="NYTimes Spam Email" width="480" height="376" /><p class="wp-caption-text">NYTimes Spam Email</p></div>
<p>But more research reveals that many users received the same email and an earlier statement from the New York Times reported the emails were a result of spam, although they did not directly name the source, according to Gigaom.com. Search Security and the Wall Street Journal reported on a data breach that affected several companies, including J.P. Morgan Chase &amp; Co. and TiVo back in April of last year.</p>
<p>The one common factor between the two separate incidents? All of these companies employ third-party email marketing campaign management by Epsilon Data Management LLC, a division of Alliance Data Systems Corp.</p>
<p>In April, Epsilon reported hackers had breached its system security and accessed names and email addresses, including personal information of more than 40 companies (Search Security reports 150 companies, including major banks, retailers and other firms). The company uses customer information to send targeted email promotions to customers of many ecommerce organizations, including Target, Best Buy, the Home Shopping Network and more.</p>
<p>Gigaom.com’s further research shows that the message was sent by bfio.com, a mail server registered to Epsilon Data Management.</p>
<p>Although no credit cardholder data or bank account numbers were accessed, this is a great concern of many of Epsilon’s clients, considering the financial and ecommerce nature of their industries. While spam emails were the only consequence of this instance, similar data breaches in which more sensitive information is accessed can result in a major <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI</a> or <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a> violation, and significant financial losses.</p>
<p>Read more about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/who-needs-to-be-hipaa-compliant">Who Needs to be PCI Compliant?</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/who-needs-to-be-hipaa-compliant">Who Needs to be HIPAA Compliant?</a> if you’re not sure whether or not your company needs to meet national security standards.</p>
<p>References:<br />
<a href="http://online.wsj.com/article/SB10001424052748704587004576245131531712342.html">Breach Brings Scrutiny</a><br />
<a href="http://searchsecurity.techtarget.com/news/1529593/Massive-Epsilon-email-breach-could-lead-to-email-attacks-spam">Massive Epsilon Email Breach Could Lead to Email Attacks, Spam</a><br />
<a href="http://gigaom.com/2011/12/28/new-york-times-email-spam-epsilon-data-breach/">Update: New York Times Email List Spammed – By the New York Times</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/data-breach-results-in-email-marketing-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Associates: Why Invest in a HIPAA Audit?</title>
		<link>http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/</link>
		<comments>http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 16:02:05 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[HIPAA audits]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4353</guid>
		<description><![CDATA[Could budgeting for an independent HIPAA audit be well worth the investment for business associates? In the event of a HIPAA violation, the numbers for federal penalties, legal and security fees and resulting lawsuits add up to a significant sum that has a serious impact on the bottom line. The annual investment is often worth [...]]]></description>
			<content:encoded><![CDATA[<p>Could budgeting for an independent <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/100-hipaa-compliant">HIPAA audit</a> be well worth the investment for business associates? In the event of a HIPAA violation, the numbers for federal penalties, legal and security fees and resulting lawsuits add up to a significant sum that has a serious impact on the bottom line. The annual investment is often worth it – especially since current statistics show business associate-related breaches were responsible for 62 percent of the total number of patient records breached (HHS.gov).</p>
<p>Business associates (BAs) don&#8217;t always have the mindset that an independent HIPAA audit in advance of a problem is worth budgeting for. And it might be that covered entities (CEs) aren&#8217;t ready to insist that BAs undergo a HIPAA audit in prevention of a future breach. Yet, more patient records are affected by data breaches that involve BAs than those that don&#8217;t, according to current statistics.</p>
<div id="attachment_4354" class="wp-caption aligncenter" style="width: 504px"><img class="size-full wp-image-4354" title="Business Associates - Why Invest in a HIPAA Audit?" src="http://resource.onlinetech.com/wp-content/uploads/Business-Associates-Why-Invest-in-a-HIPAA-Audit.jpg" alt="Business Associates - Why Invest in a HIPAA Audit?" width="494" height="410" /><p class="wp-caption-text">Business Associates - Why Invest in a HIPAA Audit?</p></div>
<p>Even though BAs were only involved in 19% of the total breaches, BA-related HIPAA breaches were responsible for 62% of the total number of patient records breached, or 4.4 million or more patient records breached than those that only involved a CE (from the HHS wall of shame).</p>
<p>With penalty fees averaging $1000/patient record, most BAs would be put out of business for a breach of several hundred records. For example, NYTimes.com wrote about a nonprofit health consultant who has already spent $300,000 in legal and security fees following the theft of an employee&#8217;s laptop that contained 13,687 patient records. Additionally, his company had to deal with the aftermath of notifying and compensating affected patients with free credit monitoring. A separate incident with Sutter Health, a nonprofit health system based in California, is now facing two class-action suits, each seeking $1,000 for each patient record breached.</p>
<p>As the number of reported breaches rise, independent audits are becoming more of a necessity to protect businesses from the growing costs of a breach. According to the <a href="http://www.ponemon.org/blog/post/second-annual-patient-privacy-study-released">Poneman Institute</a>, the number of reported data breaches is up 32 percent this year from last year, costing the healthcare industry an estimated $6.5 billion in 2011.</p>
<p>An audit and an initial risk assessment can help your business pinpoint any areas of weakness in security and privacy policies, practices and procedures. Working with the experts to remedy any issues can make your company more resilient and prepared when it comes to protecting sensitive data and avoiding legal and security fees.</p>
<p>For more on HIPAA violations, business associates and how to stay compliant, watch our webinar on <a href="http://www.onlinetech.com/resources/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices">HIPAA, HITECH, BAAs and the Law: Concerns and Best Practices</a>.</p>
<p>References:</p>
<p><a href="http://www.nytimes.com/2011/12/19/technology/as-patient-records-are-digitized-data-breaches-are-on-the-rise.html?scp=1&amp;sq=data%20breach&amp;st=cse">Digital Data on Patients Raises Risk of Breaches</a><br />
<a href="http://www.ponemon.org/blog/post/second-annual-patient-privacy-study-released">Second Annual Patient Privacy Study Released</a><br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/breachnotificationrule/breachtool.html">Breaches Affecting 500 or More Individuals</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/business-associates-why-invest-in-a-hipaa-audit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Center Standards Cheat Sheet: From HIPAA to SOC 2</title>
		<link>http://resource.onlinetech.com/data-center-standards-cheat-sheet-from-hipaa-to-soc-2/</link>
		<comments>http://resource.onlinetech.com/data-center-standards-cheat-sheet-from-hipaa-to-soc-2/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 15:16:48 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 2]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[ssae 16]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4335</guid>
		<description><![CDATA[With the confusion regarding what audits and auditor reports apply to certain aspects of data center standards, I felt the need to create a basic data center/hosting solution audit cheat sheet to simplify matters. Here’s your comprehensive guide to data center audits and reports. SAS 70 The Statement on Auditing Standard No. 70 was the [...]]]></description>
			<content:encoded><![CDATA[<p>With the confusion regarding what audits and auditor reports apply to certain aspects of data center standards, I felt the need to create a basic data center/hosting solution audit cheat sheet to simplify matters. Here’s your comprehensive guide to data center audits and reports.<br />
<strong></strong></p>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a></strong><br />
The Statement on Auditing Standard No. 70 was the original audit to measure a data center’s financial reporting and recordkeeping controls. Developed by the AICPA (American Institute of CPAs, there two types:</p>
<ul>
<li><strong>Type 1 – </strong>Reports on a company&#8217;s description of their operational controls<strong></strong></li>
<li><strong>Type 2 – </strong>Reports on an auditor&#8217;s opinion on how effective these controls are over a specified period of time (six months)</li>
</ul>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a></strong><br />
The Statement on Standards for Attestation Engagements No. 16 replaced SAS 70 in June 2011. A SSAE 16 audit measures the controls relevant to financial reporting.</p>
<ul>
<li><strong>Type 1</strong> – A data center’s description and assertion of controls, as reported by the company.<strong></strong></li>
<li><strong>Type 2 – </strong>Auditors test the accuracy of the controls and the implementation and effectiveness of controls over a specified period of time.</li>
</ul>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-1-hosting">SOC 1</a></strong><br />
The first of three new Service Organization Controls reports developed by the AICPA, this report measures the controls of a data center as relevant to financial reporting. It is essentially the same as a SSAE 16 audit.</p>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2</a></strong><br />
This report and audit is completely different from the previous. SOC 2 measures controls specifically related to IT and data center service providers. The five controls are security, availability, processing integrity (ensuring system accuracy, completion and authorization), confidentiality and privacy. There are two types:</p>
<ul>
<li><strong>Type 1</strong> – A data center’s system and suitability of its design of controls, as reported by the company.</li>
<li><strong>Type 2 </strong>– Includes everything in Type 1, with the addition of verification of an auditor&#8217;s opinion on the operating effectiveness of the controls.</li>
</ul>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-3-hosting">SOC 3</a></strong><br />
This report includes the auditor’s opinion of SOC 2 components with an additional seal of approval to be used on websites and other documents. The report is less detailed and technical than a SOC 2 report.</p>
<p><em><strong>Recommended Reading:</strong></em><br />
<a href="http://resource.onlinetech.com/a-soc-of-a-different-color-critical-differences-between-soc-2-and-soc-1ssae-16/">A SOC of A Different Color: Critical Differences Between SOC 2 and SOC 1/SSAE 16</a><br />
<a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-ssae-16-and-soc-comparison">What’s the Difference Between SAS 70, SSAE 16 and SOC?</a></p>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a></strong><br />
Mandated by the U.S. Health and Human Services Dept., the Health Insurance Portability and Accountability Act of 1996 specifies laws to secure protected health information (PHI), or patient health data (medical records).</p>
<p>When it comes to data centers, a hosting provider needs to meet HIPAA compliance in order to ensure sensitive patient information is protected.</p>
<p>A HIPAA audit conducted by an independent CHP (Certified HIPAA Practitioner) and CHSS (Certified HIPAA Security Specialist) can provide a documented report to prove a data center operator has the proper policies and procedures in place to provide <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> solutions.</p>
<p>No other audit or report can provide evidence of full HIPAA compliance.</p>
<p><em><strong>Recommended Reading:</strong></em><br />
<a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/five-questions-to-ask-your-hipaa-hosting-provider">Five Questions to Ask Your HIPAA Hosting Provider</a><br />
<a href="http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/">Encrypting Data to Meet HIPAA Compliance</a><br />
<a href="http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/">Detailed 2011-2012 HIPAA Audit Program</a></p>
<p><strong><a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI DSS</a></strong><br />
The Payment Card Industry Data Security Standard was created by the major credit card issuers, and applies to companies that accept, store process and transmit credit cardholder data.</p>
<p>When it comes to data center operators, they should prove they have a PCI compliant environment with an independent audit. They should also know what services can help your company fulfill the <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/what-is-pci-compliance">12 PCI requirements</a>.</p>
<p><em><strong>Recommended Reading:</strong></em><br />
<a href="http://resource.onlinetech.com/pci-compliance-and-virtualization-new-recommendations/">PCI Compliance and Virtualization: New Recommendations</a><br />
<a href="http://resource.onlinetech.com/guide-to-becoming-pci-compliant-build-and-maintain-a-secure-network/">Guide to Becoming PCI Compliant: Build and Maintain a Secure Network</a><br />
<a href="http://resource.onlinetech.com/guide-to-becoming-pci-compliant-protect-cardholder-data/">Guide to Becoming PCI Compliant: Protect Cardholder Data</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/data-center-standards-cheat-sheet-from-hipaa-to-soc-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 5 Must-Read Articles for HIPAA Compliance in 2012</title>
		<link>http://resource.onlinetech.com/top-5-must-read-articles-for-hipaa-compliance-in-2012/</link>
		<comments>http://resource.onlinetech.com/top-5-must-read-articles-for-hipaa-compliance-in-2012/#comments</comments>
		<pubDate>Fri, 06 Jan 2012 12:00:15 +0000</pubDate>
		<dc:creator>Chris Rizzo</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT news]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[hipaa compliance news]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[hipaa compliant resources]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa news]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4281</guid>
		<description><![CDATA[We are now entering the second year of federal health IT incentives and it is more important now than ever to take steps toward achieving HIPAA compliance and implementing an electronic health records (EHR) system. The federal government has already paid out more than $872 million in incentives to Medicaid/Medicare health organizations and individual providers [...]]]></description>
			<content:encoded><![CDATA[<p>We are now entering the second year of federal health IT incentives and it is more important now than ever to take steps toward achieving HIPAA compliance and implementing an electronic health records (EHR) system.</p>
<p>The federal government has already paid out more than $872 million in incentives to Medicaid/Medicare health organizations and individual providers that have adopted a meaningful use EHR system.</p>
<p>Here are 5 must-read articles explaining HIPAA compliance and what it means for your business in 2012:</p>
<ol>
<li><a href="http://www.hfma.org/Templates/InteriorMaster.aspx?id=18980" target=_blank">HIPAA Compliance: Are You Ready for Jan. 1 2012?</a> - This article provides a timeline of important dates in benefits and compliance deadlines.</li>
<li><a href="http://www.forbes.com/sites/ciocentral/2012/01/02/unhealthy-2011-saw-surge-in-hippa-compliance-issues/"target=_blank">Unhealthy: 2011 Saw Surge In HIPAA Compliance Issues</a> – This article reviews HIPAA trends in 2011 showing that health related data is becoming less secure while enforcement is growing more stringent.</li>
<li><a href="http://resource.onlinetech.com/hipaa-health-it-872-million-in-incentives/">HIPAA &amp; Health IT: $872 Million in Incentives</a> - This article explains what you need to do qualify for HIPAA/EHR benefits based on the American Recovery and Reinvestment Act of 2009.</li>
<li><a href="http://www.ama-assn.org/amednews/2011/12/19/bisf1222.htm" target=_blank">Health organizations not prepared for HIPAA audits</a> – This article shows that health organizations are lagging behind regulations and the Dept. of Health and Human Services Offices is already conducting random, on-site audits.</li>
<li><a href="http://resource.onlinetech.com/2012-health-it-spending-trends/">2012 Health IT Spending &amp; Trends</a> – This articles breaks down Health IT spending in major tech investments as well as shows the advantages of virtualization in healthcare.</li>
</ol>
<p>More HIPAA compliance/health IT resources:<br />
<a href="http://www.onlinetech.com/news/data-center-industry-news/hipaa-compliance">Data Center Industry News: HIPAA Compliance</a> - For the latest on Health IT industry news and compliance updates.<br />
<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-compliant-hosting-case-studies"> HIPAA Compliant Case Studies</a> &#8211; Real Companies and Real <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA Hosting</a> Solutions</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/top-5-must-read-articles-for-hipaa-compliance-in-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Use OTPortal to Monitor your Bandwidth Usage at Online Tech</title>
		<link>http://resource.onlinetech.com/use-otportal-to-monitor-your-bandwidth-usage-at-online-tech/</link>
		<comments>http://resource.onlinetech.com/use-otportal-to-monitor-your-bandwidth-usage-at-online-tech/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 11:00:48 +0000</pubDate>
		<dc:creator>Kurt Schaldenbrand</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[add bandwidth]]></category>
		<category><![CDATA[bandwidth usage]]></category>
		<category><![CDATA[client hosting portal]]></category>
		<category><![CDATA[OTPortal]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4309</guid>
		<description><![CDATA[If you’re an Online Tech client, you can easily monitor your monthly bandwidth usage in OTPortal, our client hosting portal. Simply login to OTPortal at https://customer.onlinetech.com and open the Systems Tab. The Bandwidth Usage section gives you a snapshot view of your bandwidth for the current month, as well as the previous few months. For [...]]]></description>
			<content:encoded><![CDATA[<p>If you’re an Online Tech client, you can easily monitor your monthly <a href="http://www.onlinetech.com/resources/white-papers/bandwidth-service">bandwidth</a> usage in OTPortal, our client hosting portal.</p>
<p>Simply login to OTPortal at <a href="https://customer.onlinetech.com/">https://customer.onlinetech.com</a> and open the <em>Systems Tab</em>. The <em>Bandwidth Usage</em> section gives you a snapshot view of your bandwidth for the current month, as well as the previous few months.</p>
<p>For a more detailed view of your usage, click the <em>Real-time Chart</em> button. This will open a page with an interactive graph showing your bandwidth over the past month. On this page, you can easily check your usage over a variety of time periods.</p>
<p>For a concise listing of your bandwidth usage, you can click the <em>History</em> button on the <em>Systems Tab/Bandwidth Usage</em> section. The <em>Bandwidth Usage History</em> page shows a color-coded listing of your usage on a weekly basis, grouped by month. All months or weeks with a green check indicate usage below your contracted limit. Yellow warning icons indicate weeks or months with overages.</p>
<p>If you need to add additional bandwidth to your contract, you can easily do that right in OTPortal.</p>
<ul>
<li>Simply click the <em>Add Bandwidth</em> button on the <em>Systems Tab/Bandwidth Usage</em> section.</li>
<li>A pop-up window will appear where you can specify the amount of bandwidth to add.</li>
<li>Click <em>Add to Cart</em> to begin the ordering process.</li>
<li>If you have the <em>Buyer</em> role in OTPortal, you’ll be able to approve the order immediately. If you don’t have the <em>Buyer</em> role, OTPortal will display the name of the person authorized to approve the order.</li>
</ul>
<p>Additional information about <a href="http://www.onlinetech.com/managed-services/client-hosting-portal">OTPortal</a> is available in several training videos, found right on the site itself. If you have specific questions or need help, please contact us at <a href="mailto:support@onlinetech.com">support@onlinetech.com</a>, or by calling 734-213-2020 and selecting Option 3.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/use-otportal-to-monitor-your-bandwidth-usage-at-online-tech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 5 Must-Read Articles for PCI Compliance in 2012</title>
		<link>http://resource.onlinetech.com/top-5-must-read-articles-for-pci-compliance-in-2012/</link>
		<comments>http://resource.onlinetech.com/top-5-must-read-articles-for-pci-compliance-in-2012/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 19:02:51 +0000</pubDate>
		<dc:creator>Chris Rizzo</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[pci compliant news]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[pci dss compliant news]]></category>
		<category><![CDATA[pci dss hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4297</guid>
		<description><![CDATA[Protecting your clients’ personal data has always been important element of trust between a company and its customers. When dealing with electronic transactions, it becomes an issue of card issuers not only trying to instill trust in payments done online, but protect themselves against fraud and losses due to fraud. While there haven’t been too [...]]]></description>
			<content:encoded><![CDATA[<p>Protecting your clients’ personal data has always been important element of trust between a company and its customers. When dealing with electronic transactions, it becomes an issue of card issuers not only trying to instill trust in payments done online, but protect themselves against fraud and losses due to fraud.</p>
<p>While there haven’t been too many changes to PCI DSS compliance in the last year, it is important to keep up with all of the standards because your business depends on it.</p>
<p>Here are 5 must-read articles explaining <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliance</a> and what it means for your business in 2012:</p>
<ol>
<li><a href="http://searchcloudsecurity.techtarget.com/tutorial/PCI-and-cloud-computing-Cloud-computing-compliance-guide" target=_blank">PCI and Cloud Computing: Cloud Computing Compliance Guide</a> – This article explains what you need to know about PCI compliance with <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud providers</a>, web security in the cloud, and log management.</li>
<li><a href="http://resource.onlinetech.com/simplifying-pci-compliance-with-tokenization/" >Simplifying PCI Compliance with Tokenization</a> – This article takes you through the latest update on PCI DSS compliant standards, tokenization, and its impact on the scope of the guidelines.</li>
<li><a href="http://resource.onlinetech.com/principles_of_pci_compliance/" ">The Six Principles of PCI Compliance</a> – Second in a series on PCI compliance, this article explains the six objectives of PCI DSS, what to look for in a <a href="http://www.onlinetech.com/company/michigan-data-centers">PCI compliant data center</a>, and how to maintain PCI compliance for your company.</li>
<li><a href="http://searchcloudsecurity.techtarget.com/news/2240036974/PCI-virtualization-report-cites-challenges-with-PCI-compliance-in-the-cloud" target=_blank">PCI Virtualization Report Cites Challenges with PCI Compliance in the Cloud</a> – This article describes the virtualization guidance by the PCI Security Standards Council (PCI SSC) and shows while cloud-based compliance can be challenging, it is possible with the right hardware and policies.</li>
<li><a href="http://resource.onlinetech.com/fend-off-hackers-with-pci-compliant-hosting-virtual-private-firewall-security/" >Fend Off Hackers with PCI Compliant Hosting &amp; Virtual Private Firewall Security</a> – This article sums up the history of hacking attacks in 2010 and how ICS and IPS can help identify and protect against security breaches.</li>
</ol>
<p>More PCI compliant resources:<br />
<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/levels-of-pci-compliance">Levels of PCI Compliance</a> - Do you know what level your business falls under when it comes to meeting PCI compliance? Details on the standards and requirements by company size and transactions.<br />
<a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting/what-is-pci-compliance">What is PCI Compliance?</a> &#8211; Find details on the 12 requirements of PCI compliance.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/top-5-must-read-articles-for-pci-compliance-in-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Keeping an Eye on Your Online Tech Services with OTPortal</title>
		<link>http://resource.onlinetech.com/keeping-an-eye-on-your-online-tech-services-with-otportal/</link>
		<comments>http://resource.onlinetech.com/keeping-an-eye-on-your-online-tech-services-with-otportal/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 18:36:41 +0000</pubDate>
		<dc:creator>Kurt Schaldenbrand</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[client hosting portal]]></category>
		<category><![CDATA[OTPortal]]></category>
		<category><![CDATA[remote server management]]></category>
		<category><![CDATA[remote server monitoring]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4290</guid>
		<description><![CDATA[Online Tech clients can stay up-to-date on the status of their services by using OTPortal, our client hosting portal that allows you to monitor your servers remotely. Simply login at https://customer.onlinetech.com. Immediately after logging in, you will be on the Status page, which gives you a quick overview of what’s happening at Online Tech. The [...]]]></description>
			<content:encoded><![CDATA[<p>Online Tech clients can stay up-to-date on the status of their services by using OTPortal, our client hosting portal that allows you to monitor your servers remotely.</p>
<p>Simply login at <a href="https://customer.onlinetech.com/">https://customer.onlinetech.com</a>. Immediately after logging in, you will be on the <em>Status</em> page, which gives you a quick overview of what’s happening at Online Tech.</p>
<p>The <em>Messages</em> section shows you a customized view of OTTalk, our internal communications tool. Online Tech Operations staff uses OTTalk to keep each other, and you, the client, updated on what’s happening in the data centers and with your account.</p>
<p>If you have our <a href="http://www.onlinetech.com/managed-services/remote-server-monitoring">OTMonitor</a> service, the status of your monitored servers and devices is displayed in the <em>OTMonitor</em> section, directly below the Messages section. If you have a dedicated or <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud server</a> with Online Tech, you automatically have OTMonitor. For <a href="http://www.onlinetech.com/colocation/overview">colocation</a> clients, OTMonitor is optional.</p>
<p>Also included on the <em>Status</em> page is the <em>Support Requests</em> section, showing a color coded listing of your support tickets. A ticket that has been submitted, but not yet acknowledged by Online Tech support staff is shaded red. Tickets that are being worked on are yellow. Those that are completed are shaded green. You can click the <em>Open</em> button (the white arrow on the small round button) to view the details of any ticket.</p>
<p>Below <em>Support Requests</em> is the <em>News from OT</em> section. Here you’ll find information on <a href="http://www.onlinetech.com/resources/events/webinars">upcoming webinars</a> and other announcements from Online Tech. Additional information about OTPortal is available in several training videos, found right on the site itself. If you have specific questions or need help, please contact us at <a href="mailto:support@onlinetech.com">support@onlinetech.com</a>, or by calling 734-213-2020 and selecting Option 3.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/keeping-an-eye-on-your-online-tech-services-with-otportal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Review and Request Firewall Rule Changes with OTPortal, Our Client Portal</title>
		<link>http://resource.onlinetech.com/review-and-request-firewall-rule-changes-with-otportal-our-client-portal/</link>
		<comments>http://resource.onlinetech.com/review-and-request-firewall-rule-changes-with-otportal-our-client-portal/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 16:17:28 +0000</pubDate>
		<dc:creator>Kurt Schaldenbrand</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[client server portal]]></category>
		<category><![CDATA[client server support]]></category>
		<category><![CDATA[firewall rule changes]]></category>
		<category><![CDATA[firewall rules]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4275</guid>
		<description><![CDATA[Provided to every client at no cost, OTPortal&#8217;s feature-rich dashboard delivers self-service, on-demand access to server monitoring, management and customer support, 24 hours a day and 7 days a week. With historical records of current and past order forms, Internet bandwidth and support tickets, managing your account is a simple undertaking. As an Online Tech [...]]]></description>
			<content:encoded><![CDATA[<p>Provided to every client at no cost, OTPortal&#8217;s feature-rich dashboard delivers self-service, on-demand access to server monitoring, management and customer support, 24 hours a day and 7 days a week.</p>
<p>With historical records of current and past order forms, Internet bandwidth and support tickets, managing your account is a simple undertaking.</p>
<p>As an Online Tech client, you can use OTPortal to easily see any firewall rules you have on our firewall. Login to OTPortal at <a href="https://customer.onlinetech.com/">https://customer.onlinetech.com</a>, open the <em>Systems</em> tab, then scroll down to the Firewall Rules section.</p>
<p>Here you’ll find a listing of your firewall rules. If you need to contact an Online Tech Support engineer regarding any of your rules, you’ll need to reference the ID and Sequence numbers.</p>
<p>To request a change, including adding a new rule, click the <em>Request Firewall Change</em> button. A new window will pop-up prompting you for details on the change. Fill in any of the fields on the page, or simply describe the change you would like to have made, and an engineer will contact you for further information. Click <em>Submit</em>, and your request will be entered as a new support ticket in OTPortal, where you can track it on the <em>Status</em> page.</p>
<p>Additional information about <a href="http://www.onlinetech.com/managed-services/client-hosting-portal">OTPortal</a> is available in several training videos, found right on the site itself. If you have specific questions or need help, please contact us at <a href="mailto:support@onlinetech.com">support@onlinetech.com</a>, or by calling 734-213-2020 and selecting Option 3.</p>
<p>View more <a href="http://www.onlinetech.com/managed-services/client-hosting-portal">OTPortal features</a> in order to take full advantage of our custom client portal system.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/review-and-request-firewall-rule-changes-with-otportal-our-client-portal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>$999/Hour for An Amazon Cloud Server?</title>
		<link>http://resource.onlinetech.com/999hour-for-an-amazon-cloud-server/</link>
		<comments>http://resource.onlinetech.com/999hour-for-an-amazon-cloud-server/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 10:00:56 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[amazon ec2 cloud]]></category>
		<category><![CDATA[amazon server prices]]></category>
		<category><![CDATA[amazon spot pricing]]></category>
		<category><![CDATA[amazon web services]]></category>
		<category><![CDATA[aws]]></category>
		<category><![CDATA[cloud servers]]></category>
		<category><![CDATA[high availability clouds]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4266</guid>
		<description><![CDATA[Would you pay $999 per hour for a cloud server? Apparently, Amazon’s EC2 cloud servers spiked to $999.99 per hour when their supply was recently constrained.  The high bidder paid close to $1000 per hour and others got bumped off of their servers. One month’s use of the server at this price would cost a [...]]]></description>
			<content:encoded><![CDATA[<p>Would you pay $999 per hour for a cloud server? Apparently, Amazon’s EC2 cloud servers spiked to $999.99 per hour when their supply was recently constrained.  The high bidder paid close to $1000 per hour and others got bumped off of their servers.</p>
<p>One month’s use of the server at this price would cost a ridiculous $729,992.70 &#8211; more than the cost to purchase an entire mainframe and host it in a high-end <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> for 5 years. Admittedly, it is a far-fetched scenario for the spot demand for Amazon cloud servers to stay that high for an entire month, but it raises some interesting questions about the predictability and usability of the Amazon cloud.</p>
<p>I found this <a href="https://forums.aws.amazon.com/thread.jspa?threadID=76964">discussion thread</a> on the Amazon Cloud forum to be both informative and puzzling.</p>
<p>This left me with a couple of takeaway points:</p>
<ol>
<li>The Amazon cloud isn’t as straight-forward to use as mission critical <a href="http://www.onlinetech.com/cloud-computing-hosting/overview">cloud servers</a> that companies like <a href="http://www.onlinetech.com/">Online Tech</a> offer.  To use Amazon, you have to design your software around their architecture, availability zones, etc.</li>
<li>The basic on-demand model charges by a complex set of computation factors such as CPU clock hours, I/O requests, API requests and others – all of which are very difficult to predict in an application.  Amazon posted <a href="http://www.slideshare.net/AmazonWebServices/predicting-costs-on-aws">this slide deck</a> to encourage you to “model, measure, monitor, multiply and master”- the cost model associated with the Amazon cloud. Looking at the slide deck had me walking away less confident that I was able to model the pricing without an engineering investment to figure it out.</li>
<li>While the on-demand model is complex enough, the spot market pricing for Amazon EC2 instances is even less predictable, as the forum post discusses.</li>
</ol>
<p>At the end of the day, it’s difficult to be convinced that this is truly “spot market” pricing when only one party controls the supply side of the market. I’m left with the feeling that playing the spot market for Amazon cloud servers is like gambling against the house – only one party is truly in a position to win.</p>
<p>While this may sound like I’m slamming Amazon as a competitor, the reality is that we rarely compete.  Amazon has different goals, market and business plan for their cloud servers than we do. Users design to the Amazon cloud to leverage the automation capability, and thus need to buy into their system architecture. Clients leverage our easy-to-use, <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">high availability cloud</a> servers for mission critical applications that they want to run over the long haul.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/999hour-for-an-amazon-cloud-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Department of Defense’s Cloud Computing Strategy: Saving Money &amp; Increasing Security</title>
		<link>http://resource.onlinetech.com/department-of-defense%e2%80%99s-cloud-computing-strategy-saving-money-increasing-security/</link>
		<comments>http://resource.onlinetech.com/department-of-defense%e2%80%99s-cloud-computing-strategy-saving-money-increasing-security/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 18:51:34 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cloud computing security]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[data center security]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[federal cloud computing]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violation]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4256</guid>
		<description><![CDATA[The 2012 National Defense Authorization Act (NDAA) recently passed by Congress includes a section on data centers and servers, concerning the IT industry and cloud hosting providers (Section 2867). What do the provisions call for? A plan to reduce the resources needed for servers and data centers. The components of the plan include a reduction [...]]]></description>
			<content:encoded><![CDATA[<p>The 2012 National Defense Authorization Act (<a href="http://www.rules.house.gov/Media/file/PDF_112_1/legislativetext/HR1540conf.pdf">NDAA</a>) recently passed by Congress includes a section on <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> and servers, concerning the IT industry and cloud hosting providers (Section 2867).</p>
<p>What do the provisions call for?<br />
A plan to reduce the resources needed for servers and data centers. The components of the plan include a reduction in:</p>
<ul>
<li>Square feet of floor space</li>
<li>Power and cooling utilities</li>
<li>Investments in capital infrastructure (measured in cost per megawatt of data storage)</li>
<li>Number of applications</li>
<li>Full-time personnel/cost of labor</li>
</ul>
<p>The provisions also call for a performance plan that measures and sets standards for server and data center operations, including the implementation of a strategy for the following:</p>
<ul>
<li>Desktop, laptop and mobile device virtualization</li>
<li><a href="http://www.onlinetech.com/cloud-computing-hosting/overview">Cloud computing</a> transitions for lower costs and greater security</li>
<li>Use of cloud computing and data center security services managed by the private sector</li>
<li>Reporting standards to measure data center infrastructure aspects, including space, power, cooling, age, cost, capacity, efficiency, etc.</li>
</ul>
<p>The section also calls for reports from the CIO on the division’s cost-savings as a result of transitioning to cloud computing to be presented to Congress in March of each fiscal year, starting in 2012 and reoccurring through 2016. Hopefully a close analysis of investments and the resulting numbers/reduction of security breaches will provide a more comprehensive framework for annual cloud computing and data center re-strategizing to continue the advancement of the DoD’s IT infrastructure and operations.</p>
<p>Back in August, I blogged about the <a href="http://resource.onlinetech.com/breakdown-of-federal-cloud-computing/">federal cloud computing strategy</a> proposed by CIO Vivek Kundra with intentions of allocating $20 billion of the total $80 billion IT budget for cloud computing migration alone. The goal is similar to the DoD’s NDAA strategy – consolidate and reduce data center and energy expenditure. Kundra’s Federal Cloud Computing Strategy (<a href="http://www.cio.gov/documents/Federal-Cloud-Computing-Strategy.pdf">official document</a>) outlines the cloud as a fundamental shift in IT and offers case studies and more guidance for cloud migration.</p>
<p>Data breaches may have prompted the NDAA’s new security provisions and attention to standardized data center and server practices. The DoD suffered a major <a href="http://resource.onlinetech.com/military-healthcare-contractor%E2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/">HIPAA violation</a> in September when stolen backup tapes exposed 4.9 million patients and their health records. A resulting lawsuit filed fines of $1,000 per individual, totaling to $4.9 billion. One order among the 11 in the lawsuit requires defendants “set up proper systems and procedures to maintain the privacy of protected information.”</p>
<p><a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms#Healthcare Insurance">HIPAA</a>, the Health Insurance Portability and Accountability Act of 1996, sets the standards for protecting sensitive <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms#Protected Health Information">patient data</a> that is stored, processed or transferred by healthcare organizations and other companies that deal with patient information. The law specifies that healthcare organizations should implement and follow certain policies and practices in order to preserve the integrity, confidentiality and availability of data.</p>
<p>For more about HIPAA and to find out if/how your company is affected by the law, read our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>. Or if you’re interested in learning more about cloud computing security, watch an informative video or read the transcript of <a href="http://www.onlinetech.com/resources/wiki/cloud-computing/private-cloud-security-how-your-data-security-changes-in-the-cloud">Private Cloud Security: How Your Data Security Changes in the Cloud</a> presented by our Director of Operations, Jason Yaeger.</p>
<p>References:<br />
<a href="http://www.rules.house.gov/Media/file/PDF_112_1/legislativetext/HR1540conf.pdf">National Defense Authorization Act for Fiscal Year 2012</a> (PDF)<br />
<a href="http://www.internetevolution.com/author.asp?section_id=1647&amp;doc_id=237174&amp;f_src=internetevolution_gnews">New DoD Plan Could Be Big Boost for Clouds</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/department-of-defense%e2%80%99s-cloud-computing-strategy-saving-money-increasing-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2012 Health IT Spending &amp; Trends</title>
		<link>http://resource.onlinetech.com/2012-health-it-spending-trends/</link>
		<comments>http://resource.onlinetech.com/2012-health-it-spending-trends/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 14:18:53 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2011 health IT trends]]></category>
		<category><![CDATA[2012 health IT trends]]></category>
		<category><![CDATA[cloud computing healthcare]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[healthcare information technology]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4244</guid>
		<description><![CDATA[The healthcare IT market is rapidly growing and expected to continue through 2016. Here’s a look at 2012 health IT spending trends and a review of 2011. Nearly 90 percent of healthcare IT decision-makers are planning significant investments in hardware, software and other solutions within the next six months. A study by CDW IT Monitor [...]]]></description>
			<content:encoded><![CDATA[<p>The healthcare IT market is rapidly growing and expected to continue through 2016. Here’s a look at 2012 health IT spending trends and a review of 2011.</p>
<p>Nearly 90 percent of healthcare IT decision-makers are planning significant investments in hardware, software and other solutions within the next six months. A study by CDW IT Monitor reveals the spending habits and plans of certain key corporate industries within the IT sector &#8211; including healthcare, manufacturing and retail industries.</p>
<p>Within the IT budget, the report lists the major tech investments that were put off in 2011 and slated for actualization in 2012, including:</p>
<ul>
<li>PCs (60%)</li>
<li>Security (55%)</li>
<li><a href="http://www.onlinetech.com/cloud-computing-hosting/overview">Cloud Computing</a> (50%)</li>
<li>Virtualization (41%)</li>
<li>Mobility (39%)</li>
</ul>
<p>Research firm BCC (Business Communications Company) estimates that the total clinical healthcare IT market is projected to grow from $7.4 billion in 2011 to nearly $17.5 billion in 2016 &#8211; increasing at a compound annual growth rate (CAGR) of 18.7 percent over the next five years.</p>
<p>A study of the clinical healthcare technologies market shares from 2010-2016 show a projected growth in the dedicated hardware spend, growing from 28.7 percent in 2011 to 34.2 percent in 2016.</p>
<p>Additionally, government IT consultants and research subsidiary Deltek issued a report on the federal health IT market from 2011-2016 predicting that the federal health IT spending budget will increase from $4.5 billion this year to $6.5 billion in 2016 &#8211; showing a growth of 7.5% year over year for the next five.</p>
<p>With this growth comes an improved hiring outlook to support IT investments &#8211; 20 percent of IT management plan to hire staff within the next six months. In addition to hiring, some companies may take advantage of outsourcing IT or hosting solutions for its cost-effectiveness, professional management and support.</p>
<p><strong>2011 Health IT Trends -To Continue in 2012?</strong><br />
In a review of 2011 health IT trends, SearchHealthIT.com lists cloud computing and health data privacy and security (<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a>) as #4 and #5 on their Top 10 Health IT Trends of 2011. Another SearchHealthIT article suggests that healthcare companies start out with server virtualization by testing their noncritical applications (ones that don’t affect patients) in the cloud first, then advancing to accommodate a <a href="http://www.onlinetech.com/cloud-computing-hosting/packages/private-cloud">private cloud</a>.</p>
<p>Other advantages of virtualization in healthcare include:</p>
<ul>
<li><strong>Interoperability</strong> &#8211; Virtualization can help when it comes to combining patient data information into one system to allow for information exchange and patient access, also known as EMR (electronic medical records) or EHR (electronic health records) systems.</li>
<li><strong>Remote access</strong> &#8211; Virtual desktop deployment without hardware dependence can allow healthcare employees and physicians to manage business applications from many different mobile devices, increasing the immediacy and streamlining of patient care by increasing access.</li>
<li><strong>Compliance</strong> &#8211; A solid disaster recovery plan is recommended to comply with HIPAA compliance regulations. When it comes to disaster recovery, virtualization allows for faster network replication from an offsite location or data center, which in turn effects data recovery times and accuracy.</li>
</ul>
<p>A white paper by Thomson Reuters, <a href="http://healthcare.thomsonreuters.com/thought-leadership/testimony/WP_6_15_10.pdf">A Path to Eliminating $3.6 Trillion in Wasteful Healthcare Spending</a>, outlines strategies to improve and streamline healthcare organization business processes and systems to lower healthcare costs and wasteful spending. Among the strategies include systems improvements and care coordination, including the goal to better link providers &#8211; the paper suggests that healthcare organizations build EMR systems to create increased and efficient connectivity among provider.</p>
<p>Get more details on <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> and recommended IT solutions to help your healthcare organization meet compliance.</p>
<p>References:<br />
<a href="http://searchhealthit.techtarget.com/healthitexchange/healthitpulse/show-me-the-money-federal-health-it-budget-to-skyrocket/?track=NL-1598&amp;ad=858437&amp;asrc=EM_NLT_15874185&amp;uid=13145113">Show Me the Money: Federal Health IT Budget to Skyrocket</a><br />
<a href="https://fedfocus08.input.com/corp/library/detail.cfm?ItemID=15639">Federal Health Information Technology Market 2011-2016</a><br />
<a href="http://www.bccresearch.com/report/HLC048A.html">BCC Research Market Forecasting Report: Healthcare Information Systems</a><br />
<a href="http://searchhealthit.techtarget.com/tip/How-virtualization-implementation-catalyzes-private-cloud-growth">How Virtualization Implementation Catalyzes Private Cloud Growth</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2012-health-it-spending-trends/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Safeguards Part 1: Administrative &amp; Assigned Security Responsibility</title>
		<link>http://resource.onlinetech.com/hipaa-safeguards-part-1-administrative-assigned-security-responsibility/</link>
		<comments>http://resource.onlinetech.com/hipaa-safeguards-part-1-administrative-assigned-security-responsibility/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 13:56:16 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA administrative safeguards]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa safeguards]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4228</guid>
		<description><![CDATA[The NIST (National Institute of Standards and Technology) provides an introductory resource guide for implementing HIPAA (Health Insurance Portability and Accountability Act) Security Rule, including handy tables that breakdown the safeguards that covered entities and business associates need to abide by if they handle PHI, or ePHI (electronic protected health information). This multi-part series on [...]]]></description>
			<content:encoded><![CDATA[<p>The NIST (National Institute of Standards and Technology) provides an introductory resource guide for implementing HIPAA (Health Insurance Portability and Accountability Act) Security Rule, including handy tables that breakdown the safeguards that covered entities and business associates need to abide by if they handle PHI, or ePHI (electronic protected health information).</p>
<p>This multi-part series on HIPAA safeguards and compliance includes a detailed description of key activities and questions you can ask yourself as a checklist to ensure you meet the standards. The safeguards include:</p>
<ul>
<li><strong>Administrative Safeguards</strong>, Security Management Process (164.308(a)(1))</li>
<li><strong>Assigned Security Responsibility, </strong>Identifying a Security Official (164.308(a)(2))</li>
<li><strong>Workforce Security</strong>, Implementing Workplace Policies and Procedures(164.308(a)(3))</li>
<li><strong>Information Access Management</strong>,  Implementing Policies and Procedures for Access Authorization (164.308(a)(4))</li>
<li><strong>Security Awareness and Training, </strong>Implementing Security Awareness and Training<strong> </strong>(164.308(a)(5))</li>
</ul>
<p>The first part in this series describes the Administrative Safeguards that include implementing company policies and procedures related to security controls to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a>.</p>
<p><strong>Administrative Safeguards (164.308(a)(1))</strong></p>
<ul>
<li><strong>Identify Information Systems with PHI</strong>
<ul>
<li><strong><em>Action</em></strong>: Identify information systems, hardware and software used to collect, store, process or transmit PHI. Review your business functions to verify ownership and control of your information system components.</li>
<li><strong><em>Ask yourself</em></strong>: Do you take regular inventory of your hardware and software (including removable media and remote access devices)? Is your system configuration documented? And have you identified your information type/use and how sensitive your information is?</li>
</ul>
</li>
<li><strong>Conduct A Risk Assessment</strong>
<ul>
<li><strong><em>Action:</em> </strong>Conduct a thorough assessment of any potential risks and vulnerabilities of PHI, and follow a standard risk assessment methodology (see <a href="http://csrc.nist.gov/publications/nistpubs/800-66-Rev1/SP-800-66-Revision1.pdf">Appendix E: Risk Assessment Guidelines, Page E-1</a>).<strong></strong></li>
<li><strong><em>Ask yourself:</em></strong> What are the current and planned controls? Is your facility or your data hosting facility in a region prone to natural disasters? Has hardware and software been checked for enabled security settings?<strong><em></em></strong></li>
</ul>
</li>
<li><strong>Implement a Risk Management Program<em></em></strong>
<ul>
<li><strong><em>Action:</em></strong> Implement security measures to comply with 164.306(a).<strong><em></em></strong></li>
<li><strong><em>Ask yourself:</em></strong> Do your current safeguards protect the confidentiality, integrity and availability of PHI, including anticipated threats or hazards to the security/integrity of PHI? Have you checked this compliance against your policies and procedures?<strong><em></em></strong></li>
</ul>
</li>
<li><strong>Acquire IT Systems and Services<em></em></strong>
<ul>
<li><strong><em>Action:</em> </strong>Implement technology, hardware, software and services as needed to protect PHI – match your IT solution to your environment and take into consideration how sensitive the data is, your security policies, procedures and standards, and the resources you have available for operation, maintenance and training.<strong><em></em></strong></li>
<li><strong><em>Ask yourself: </em></strong>How will the new security controls work within your existing IT infrastructure? Have you done a cost-benefit analysis of investment vs. identified security risks? Has a staff training strategy been developed?<strong><em></em></strong></li>
</ul>
</li>
<li><strong>Create and Deploy Policies &amp; Procedures<em></em></strong>
<ul>
<li><strong><em>Action:</em></strong> Implement new risk mitigation controls by department, including management, operational and technical. When creating your policies, establish roles and responsibilities per control for certain individuals or departments.<strong><em></em></strong></li>
<li><strong><em>Ask yourself:</em></strong> Do you have a documented plan for system security and a formal contingency plan? What’s your employee communication plan? And are the policies and procedures reviewed and updated when major changes take place in your company or as needed?<strong><em></em></strong></li>
</ul>
</li>
<li><strong>Develop and Implement a Sanction Policy<em></em></strong>
<ul>
<li><strong><em>Action: </em></strong>Create a policy that addresses any employee offenses that compromise the HIPAA regulations and safety/privacy of PHI, including reprimands, termination, etc.<strong><em></em></strong></li>
<li><strong><em>Ask yourself:</em></strong> Is there a documented and formal process in place addressing PHI and system misuse, abuse and fraud? Have employees been alerted about policies regarding sanctions for the misuse and disclosure of PHI? <strong><em></em></strong></li>
</ul>
</li>
<li><strong>Develop and Deploy the Information System Activity Review Process<em></em></strong>
<ul>
<li><strong><em>Action: </em></strong>Implement procedures to review records of system activity, like audit logs, access reports and security incident tracking reports.<strong><em></em></strong></li>
<li><strong><em>Ask yourself:</em></strong> How often will reviews occur and results analyzed, and who will be responsible for it? Where will audit information reside?<strong><em></em></strong></li>
</ul>
</li>
<li><strong>Develop Appropriate Standard Operating Procedures<em></em></strong>
<ul>
<li><strong><em>Action: </em></strong>Figure out what kind of audit data and monitoring you need to derive exception reports.<strong><em></em></strong></li>
<li><strong><em>Ask yourself:</em></strong> How will exception reports or logs be reviewed, and where will monitoring reports be filed and maintained?<strong><em></em></strong></li>
</ul>
</li>
<li><strong>Implement the Information System Activity Review and Audit Process<em></em></strong>
<ul>
<li><strong><em>Action: </em></strong>Activate review process and begin auditing/logging activity.<strong><em></em></strong></li>
<li><strong><em>Ask yourself:</em></strong> What needs to be implemented to assess the effectiveness of the review process? What’s the review process revision plan when needed?</li>
</ul>
</li>
</ul>
<p>If you found this guide useful, check back soon for other HIPAA safeguard descriptions and guides. Or if you need other resources, read our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA Hosting FAQ</a> or our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a>.</p>
<p>References:<br />
<a href="http://csrc.nist.gov/publications/nistpubs/800-66-Rev1/SP-800-66-Revision1.pdf">NIST’s Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-safeguards-part-1-administrative-assigned-security-responsibility/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Security: How Safe is Your Data?</title>
		<link>http://resource.onlinetech.com/mobile-security-how-safe-is-your-data/</link>
		<comments>http://resource.onlinetech.com/mobile-security-how-safe-is-your-data/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 20:44:52 +0000</pubDate>
		<dc:creator>Aaron Riddle</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[mobile phone security]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[smartphone security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4218</guid>
		<description><![CDATA[According to a recent Gartner study, smartphones accounted for 297 million (19%) of the 1.6 billion mobile phones sold in 2010. That’s 72.1% more smartphone sales than in 2009 and it doesn’t appear to be slowing down for 2011 and beyond. The advancements that have been made in the mobile market have been nothing more [...]]]></description>
			<content:encoded><![CDATA[<p>According to a recent Gartner study, smartphones accounted for 297 million (19%) of the 1.6 billion mobile phones sold in 2010. That’s 72.1% more smartphone sales than in 2009 and it doesn’t appear to be slowing down for 2011 and beyond. The advancements that have been made in the mobile market have been nothing more than unbelievable. Your phone is not only a means of verbal communication, but an email-checking, web-browsing multimedia device. With that however, more and more of our personal information becomes increasingly vulnerable with all of these new features.</p>
<p>A lot of sensitive information is easily accessible on our phones these days, especially with the trend of using personal devices in workplace environments. Corporate emails, social media accounts, and bank apps are on our phones to check at our own convenience on a daily basis with most of our passwords saved on each account for easy access. What would happen if SOMEONE ELSE had access to that kind of information? To YOUR personal information? To YOUR company’s sensitive information?</p>
<p>If your company stores, transmits or processes PHI (Protected Health Information) or CHD (Cardholder Data), you need to be aware of the dangers of that data landing in the wrong hands due to poor mobile phone security. Not only that, but both <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a> and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI</a> compliance regulations assign large fines and penalties in the event of a data breach.</p>
<div id="attachment_4220" class="wp-caption alignleft" style="width: 217px"><img class="size-full wp-image-4220 " title="Smartphone Pin Screenshot" src="http://resource.onlinetech.com/wp-content/uploads/photo.png" alt="Smartphone Pin Screenshot" width="207" height="311" /><p class="wp-caption-text">Smartphone Pin Screenshot</p></div>
<p>Take this incident as an example &#8211; back in February 2011, my smartphone fell out of my pocket into the snow and I was unable to find it after an hour or so of digging. One month rolls by and someone had called in to say they found it in the snow. Fortunately, that person turned it in, but that’s not always how these types of stories end. Someone could have picked up my phone, and if I had no type of security measures in place, they would have had immediate access to ALL of my sensitive information.</p>
<p>The only thing that kept me safe from somebody accessing all of my personal information was implementing a PIN on my phone. Without it, ANYONE could have had access to anything I had stored on my phone within a few minutes of finding it. Bank accounts, confidential emails, personal information on social sites&#8230;the possibilities are endless.</p>
<p>However, there is even opposition from some consumers on putting these kinds of security measures into place! A study by Confident Technologies showed that 44% of smartphone users said it was too much of a hassle to lock their phone with a PIN or password, and 30% said they weren’t too worried about security. Yes, it can be a pain to enter your PIN or password every time you access your phone, but it’s worth it in the long run in order to avoid a situation in which your sensitive data could be accessed and misused.</p>
<p>Despite consumer response, mobile security is still getting better as some companies are starting to offer services that wipe phones remotely and even locate them via GPS if they are lost or stolen. However, we as consumers need to implement our own security measures to ensure our information is in the right hands and above all, safe and secure.</p>
<p>Sources:<br />
<a href="http://www.informationweek.com/blog/mobility/231700155">Most Consumers Don’t Lock Mobile Phone Via PIN</a><br />
<a href="http://www.informationweek.com/blog/230600092">10 Combinations Dominate iPhone Passwords</a><br />
<a href="http://www.email-marketing-reports.com/wireless-mobile/smartphone-statistics.htm">Smartphone Statistics and Market Share</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/mobile-security-how-safe-is-your-data/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A SOC of A Different Color: Critical Differences Between SOC 2 and SOC 1/SSAE 16</title>
		<link>http://resource.onlinetech.com/a-soc-of-a-different-color-critical-differences-between-soc-2-and-soc-1ssae-16/</link>
		<comments>http://resource.onlinetech.com/a-soc-of-a-different-color-critical-differences-between-soc-2-and-soc-1ssae-16/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 17:59:27 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[sarbanes-oxley compliance]]></category>
		<category><![CDATA[sas 70 audit]]></category>
		<category><![CDATA[sas 70 data centers]]></category>
		<category><![CDATA[sas 70 hosting]]></category>
		<category><![CDATA[soc 1 hosting]]></category>
		<category><![CDATA[soc 1 report]]></category>
		<category><![CDATA[soc 2 audit]]></category>
		<category><![CDATA[soc 2 hosting]]></category>
		<category><![CDATA[soc 2 report]]></category>
		<category><![CDATA[sox compliant hosting]]></category>
		<category><![CDATA[ssae 16 audit]]></category>
		<category><![CDATA[ssae 16 data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4204</guid>
		<description><![CDATA[If you’re in a business that needs to meet Sarbanes-Oxley compliance, you probably know by now that the SAS 70 report expired earlier this year and was replaced with the SSAE 16 attestation. SSAE 16 is a lot like SAS 70, but adds an attestation set forth and signed by a company’s management that confirms [...]]]></description>
			<content:encoded><![CDATA[<p>If you’re in a business that needs to meet Sarbanes-Oxley compliance, you probably know by now that the <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a> report expired earlier this year and was replaced with the SSAE 16 attestation. <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a> is a lot like SAS 70, but adds an attestation set forth and signed by a company’s management that confirms that the described controls are in place and functional.</p>
<p>You might have known that SSAE 16 is also called <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-1-hosting">SOC 1</a>. It’s just an alternative label for exactly the same thing.</p>
<p>And this might lead you to believe that the <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2</a> audit report is closely related to SOC 1 … but this couldn’t be further from the truth. The “little” difference between SOC 1 and SOC 2 amounts to a significant difference to companies who are using the reports as part of their due diligence to research prospective vendors. SOC 2 finally addresses the industry need for a consistent set of criteria against which companies can be measured and compared.</p>
<p><strong>Oh, you didn’t know that SAS 70, SSAE 16/SOC 1 were arbitrary measurements?</strong> It goes something like this &#8211; before an auditor steps foot into a company to be audited, the company gets to decide what they want to be audited on. It’s like getting to say what questions you want on your final exam. Companies are likely to specify those controls that are in their sweet spot, and that they know they will pass. Companies are likely to omit controls that are weak and ineffective.</p>
<p>What’s worse is that there&#8217;s no consistency in audit scope. Some companies specify a mere handful of controls to be audited, while others document exhaustive procedures that they are audited and reported on. Even though any company that passes a SAS 70 or SSAE 16/SOC 1 audit can claim Sarbanes-Oxley (SOX) compliance, only a detailed scrutiny of the independent audit report will reveal what the company has elected to have audited, and the auditor’s opinion. No two SAS 70 or SSAE 16/SOC 1 reports are the same! See the problem?</p>
<p>But wait, it still gets worse for companies who are using SAS 70 or SSAE 16/SOC 1 reports as due diligence for vendor selection. By definition, SAS 70 and SSAE 16/SOC 1 review financial and accounting controls of a service provider. So, when you review one of those reports, you’re getting confirmation that they keep their books well. While this may be one measure of honesty, wouldn’t you really care about the processes that you will be hiring them for? For example, if you were evaluating Online Tech as a hosting provider, would you rather see an independent audit report about our financial and administrative procedures, or an independent audit report about how we control the privacy, security, availability, integrity and confidentiality of our data center facilities and server hosting solutions?</p>
<p><strong>This is where the SOC 2 audit and report comes in.</strong> Don’t be fooled into thinking that SOC 2 is a next level up from SOC 1. SOC 2 is a COMPLETELY different species. Here’s why. SOC 2 is the first and only audit and report that sets a pre-defined, consistent set of criteria specifically around the services that a company provides. That means that when you read and compare the SOC 2 reports from two different companies, you can finally compare apples to apples. And what’s even better, you get to compare the processes directly related to the services they will be providing you. While SAS 70 and SSAE 16/SOC 1 are designed to measure financial controls, the SOC 2 audit is designed to measure Service Organization Controls related to:</p>
<ol>
<li><strong>Security</strong></li>
<li><strong>Availability</strong></li>
<li><strong>Processing Integrity</strong></li>
<li><strong>Confidentiality</strong></li>
<li><strong>Privacy</strong></li>
</ol>
<p>Alright, so you get that SOC 2 is a completely different audit than SOC 1. Ready for the next “gotcha”? There are actually two types of SOC 2 audits: a <strong>Type I</strong> and <strong>Type II</strong>. Just like in SAS 70 and SSAE 16/SOC 1, the Type I report just means that the company has stated that the controls are in place and functional. The Type II report is the real measurement and auditor validation that the stated controls actually ARE in place and actually ARE working. Put this all together, and the net is, you want to compare vendors who will share a copy of the independent <strong>SOC 2 Type II</strong> report.</p>
<p><strong>Some cautionary tales: not all companies that position themselves to have “compliant solutions” are really independently audited.</strong> How do you know? Ask for a copy of the independent audit report. Expect that these will only be shared under an NDA (Non-Disclosure Agreement), but that’s fair considering that these reports describe the heart and soul of how a service organization runs its business. You might find that some companies won’t even provide their independent audit reports under NDA. Big warning sign. If a service-oriented company refuses to share their audit reports with a prospective customer, it’s impossible for you to prove to your board, shareholders, customers and regulators that you did your own due diligence. And for some industries, the stakes are too high to take this kind of a chance.</p>
<p>If you want an objective, relevant measure of how your vendor will be able to provide a secure, available, confidential and private solution of integrity, there is only one independent audit report to ask for: <strong>SOC 2 Type II</strong>. At the end of the day in our industry, when investors and clients want proof that a data center is going to be able to meet SLA obligations for server, data, and application uptime, they need to know that the processes and controls around security, availability, processing integrity, confidentiality and privacy are rock solid – not that a data center’s financial controls have passed review.</p>
<p>More references:</p>
<p><a href="http://resource.onlinetech.com/soc-1-soc-2-soc-3-report-comparison/">SOC Report Comparison</a><br />
<a href="http://www.aicpa.org/">American Institute of CPAs</a><br />
<a href="http://www.uhyadvisors-us.com/">UHY Advisors</a><br />
<a href="http://itcontrolsfreak.wordpress.com/">Principal of UHY Advisors, David Barton’s blog</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/a-soc-of-a-different-color-critical-differences-between-soc-2-and-soc-1ssae-16/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare IT Priorities: Comprehensive EHRs with Simple Implementation and Low Maintenance</title>
		<link>http://resource.onlinetech.com/healthcare-it-priorities-comprehensive-ehrs-with-simple-implementation-and-low-maintenance/</link>
		<comments>http://resource.onlinetech.com/healthcare-it-priorities-comprehensive-ehrs-with-simple-implementation-and-low-maintenance/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 13:28:02 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[EHR]]></category>
		<category><![CDATA[EMR]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4197</guid>
		<description><![CDATA[In order to achieve federal meaningful use requirements, the top planned IT projects include purchasing or upgrading their EMR or EHR software (58 percent). According to a recent InformationWeek.com survey of business technology professionals at physician practices, hospitals, healthcare centers and other healthcare providers, other IT projects include adopting an e-prescribing system (25 percent) and [...]]]></description>
			<content:encoded><![CDATA[<p>In order to achieve federal meaningful use requirements, the top planned IT projects include purchasing or upgrading their EMR or EHR software (58 percent). According to a recent InformationWeek.com survey of business technology professionals at physician practices, hospitals, healthcare centers and other healthcare providers, other IT projects include adopting an e-prescribing system (25 percent) and adopting public or private cloud computing (26 percent).</p>
<p>Forty-one percent of respondents reported the need to upgrade infrastructure, networking, Internet technology/web portals and storage in order to comply with meaningful use requirements. Meaningful use refers to the CMS’s (Centers for Medicare &amp; Medicaid Services) requirements for using EHR systems, including the required use in a meaningful and effectual manner, such as e-prescribing, clinical quality measures and others.</p>
<p>When asked about what percentage of their annual IT budget would be spent on EMR or EHR systems this year, 20 percent reported they’d be spending 21 to 30 percent of their budget, while 10 percent will spend 31 to 40 percent of their total budget.</p>
<p>Although an unsurprising 54 percent reported the expense as the top barrier to adopting an electronic medical record system, the second reason was due to negative reactions to using new systems and processes from doctors and other clinicians (30 percent), echoing the government’s concern in the healthcare industry’s technical advancements.  The third barrier is the lack of time (25 percent) and fourth is the potential for disruption in patient care and other processes while implementing systems (24 percent).</p>
<p>When it came to priority ranking of EMR system criteria, the first two included the interoperability/integration within their existing infrastructure (57 percent) and upfront costs (45 percent). However, the third most important criteria was the ease of ongoing maintenance (34 percent), suggesting a number of healthcare professionals and organizations may not have the time or resources required to maintain and upgrade systems.</p>
<p>Another survey statistic that supports the desire for easy system implementation is the 60 percent of respondents that have or will be implementing a comprehensive system from a single vendor, as opposed to the 11 percent that choose to implement a combination of homegrown apps and third-party systems.</p>
<p>The survey also notes the 31 percent of healthcare providers that claim their systems already comply with meaningful use requirements – the article suggests that while these systems may be certified from their vendors as compliant, the healthcare organizations have a responsibility to integrate the system into their existing infrastructure and develop processes that also need to be compliant (this includes employee training). The confusion around owning a compliant technology or system vs. actually being a compliant organization is a common one in the healthcare industry.</p>
<p>Another example of owning or outsourcing a compliant solution vs. actual compliance includes HIPAA compliance. Healthcare providers seeking a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> solution or <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a> to house their patients’ sensitive protected health information (PHI) often believe they can merely purchase a package to meet HIPAA compliance.</p>
<p>However, there is no HIPAA audited or compliant package that can guarantee your organization is automatically compliant – the healthcare organization is still independently responsible for their policies, procedures and staff training to prepare for passing a potential HIPAA audit. While you can buy tools to help you achieve compliance, you cannot bypass the security precautions that can lead to a data breach or leak. With human error often topping the list as a cause of HIPAA violations, it’s important to take the time to teach and implement best security practices for ultimate prevention. Still have HIPAA questions? Head over to our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>!</p>
<p>What’s next when it comes to health IT plans in the next upcoming two years? Sixty-two percent are planning or evaluating patient web access to their personal health records, and 58 percent are looking to implement business intelligence tools for analyzing medical data.</p>
<p>References:</p>
<p><a href="https://www.cms.gov/EHRIncentivePrograms/30_Meaningful_Use.asp">CMS EHR Meaningful Use Overview</a><br />
<a href="http://reports.informationweek.com/abstract/105/5934/Healthcare/research-healthcare-it-priorities-survey.html?cid=iwk_well_Analytics_Administration_Systems&amp;ticket=ST-1225263-GnFxADeoq591Yvh4e3Xc-login.techweb.com">InformationWeek’s Research: Healthcare IT Priorities Survey</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/healthcare-it-priorities-comprehensive-ehrs-with-simple-implementation-and-low-maintenance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Sum of All Fears: From Vulnerability to Exploit, the Importance of Patch Management</title>
		<link>http://resource.onlinetech.com/the-sum-of-all-fears-from-vulnerability-to-exploit-the-importance-of-patch-management/</link>
		<comments>http://resource.onlinetech.com/the-sum-of-all-fears-from-vulnerability-to-exploit-the-importance-of-patch-management/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 15:05:16 +0000</pubDate>
		<dc:creator>Zachary Zeid</dc:creator>
				<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[duqu]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[patch management]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[server security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4189</guid>
		<description><![CDATA[Why is patch management so important? If your servers aren’t updated and managed properly, your data and applications are left vulnerable to hackers, identity thieves and other malicious attacks against your systems. And when it comes to sensitive data and national industry compliance standards, such as HIPAA and PCI DSS compliance, your company can’t afford [...]]]></description>
			<content:encoded><![CDATA[<p>Why is patch management so important? If your servers aren’t updated and managed properly, your data and applications are left vulnerable to hackers, identity thieves and other malicious attacks against your systems.</p>
<p>And when it comes to sensitive data and national industry compliance standards, such as <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a> and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI DSS compliance</a>, your company can’t afford to suffer a data breach or theft, as the fines and estimated financial loss per data breach record continues to rise each year.</p>
<p><iframe src="http://www.youtube.com/embed/4aBE6o0oDlo" frameborder="0" width="560" height="315"></iframe></p>
<p>The above video was a concept exploit of the recent vulnerability MS11-83.  The theory behind MS11-83 is that you can send specially crafted UDP packets to a target machine and gain access to it, whether the port is closed or not.</p>
<p>By comparison, the much talked about Stuxnet variant “Duqu” uses a Win32k TrueType font parsing engine vulnerability to inject itself into target machines.  Unlike MS11-83, Duqu is a real-world example of the exploit that has the ability to cause considerable damage and spread itself by embedding itself into Microsoft Word documents sent as email attachments or even USB keys.</p>
<p>In each of these cases these vulnerabilities are known, and fixes have been released (though in Duqu’s case, there is only a temporary patch), and have been disseminated down to WSUS servers and individual computers worldwide.  While MS11-083 has been patched within a week, Duqu was detected in the middle of October, with Microsoft releasing an advisory three weeks later.  This exemplifies the importance of immediate patch management.  One can little afford to not keep their public facing servers up-to-date with the latest patches.</p>
<p>Security is a paramount concern of clients, but so is the stability of your IT operations. Clients often mix and match patching levels to balance these two concerns. At Online Tech, we offer three different levels of patch management, notify clients of outstanding updates waiting to be applied, and offer any assistance with patch installation to ensure comprehensive security measures are implemented accurately and timely.</p>
<p>References:</p>
<p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-083">Microsoft Security Bulletin MS11-083 &#8211; Critical</a><br />
<a href="http://support.microsoft.com/kb/2639658">Microsoft Security Advisory: Vulnerability in TrueType Font Parsing Could Allow Elevation of Privileges</a><br />
<a href="http://youtu.be/4aBE6o0oDlo">JFY: ms11-083</a><br />
<a href="http://www.computerworld.com/s/article/9221498/Duqu_exploits_same_Windows_font_engine_patched_last_month_Microsoft_confirms">Duqu Exploits Same Windows Font Engine Patched Last Month, Microsoft Confirms</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/the-sum-of-all-fears-from-vulnerability-to-exploit-the-importance-of-patch-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Revenue, Supply &amp; Demand: Effects of the 2011 Hard Drive Shortage</title>
		<link>http://resource.onlinetech.com/revenue-supply-demand-effects-of-the-2011-hard-drive-shortage/</link>
		<comments>http://resource.onlinetech.com/revenue-supply-demand-effects-of-the-2011-hard-drive-shortage/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 14:14:30 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[data center news]]></category>
		<category><![CDATA[hard drive shortage]]></category>
		<category><![CDATA[IT companies]]></category>
		<category><![CDATA[IT industry news]]></category>
		<category><![CDATA[thailand floods]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4180</guid>
		<description><![CDATA[The recent hard drive shortage caused by this year’s extreme Thailand floods is said to continue its major impact through 2013, according to market research firm IDC and reported by ComputerWorld.com. The hard drive shortage is being felt around the world as IT vendors, computer system merchants and consumers are all affected. While initial recovery [...]]]></description>
			<content:encoded><![CDATA[<p>The recent hard drive shortage caused by this year’s extreme Thailand floods is said to continue its major impact through 2013, according to market research firm IDC and reported by ComputerWorld.com. The hard drive shortage is being felt around the world as IT vendors, computer system merchants and consumers are all affected. While initial recovery was estimated to occur within the first three months of 2012, complete recovery may take longer.</p>
<p>According to TechRadar.com, the shortage has dramatically increased prices to as much as 150 percent, due primarily to the closure of many manufacturing plants. In addition, Digitimes reports an estimated 70 million HDD shortage for laptops and desktop computers in the fourth quarter of 2011. While computer and laptop demand is currently at 180 million, there are reportedly only enough hard drives available for 110-130 million.</p>
<p>Even Apple is feeling it – estimated shipping times have increased significantly from 1 to 3 days to 5 to 7 weeks for customized iMac products with 2TB hard drives, according to AppleInsider.com. Intel recently reported its Q4 revenue will fall from $13.7 billion to $14.7 billion due to the lack of hard drive supply, which has trickled down from fewer personal computers and servers to fewer semiconductors.</p>
<p>However, a recent NYTimes.com article highlights the potential opportunity the shortage has presented for the company: Intel is now looking to push sales of solid-state hard drives, the type used in ultrabooks (MacBook Air-like devices). The company’s future venture includes research to add touch screens to ultrabook devices, similar to tablets.</p>
<p>ComputerWorld.com reports that a rep from Lenovo, a Chinese multinational computer manufacturing company, has stated that PC orders are being placed for a supply that doesn’t exist. Their solution includes replacing unavailable drives for a different, “off-spec” drive. And even after swapping drives, customers will have to wait an extra 45-60 days.</p>
<p>The company hit hardest by the Thailand floods is Western Digital, the largest producer of hard drives, with an estimated 75 percent of its production shut down temporarily.</p>
<p>While Gartner reports the worldwide disk storage market growth in Q2 of 2011 is up nearly 12 percent from last year, as well as the disk market storage market for external <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> deployment up 56 percent from 2010, only time will tell what the major impacts on revenue will be in the next two years.</p>
<p>Sources:<br />
<a href="http://www.computerworld.com/s/article/9222522/Impact_of_hard_drive_shortage_to_linger_through_2013?taxonomyId=19">Impact of Hard Drive Shortage to Linger Through 2013</a><br />
<a href="http://www.nytimes.com/2011/12/13/technology/intel-lowers-forecast-on-shortages.html?_r=1&amp;ref=technology">Intel Sees Opportunity in Shortage of Drives</a><br />
<a href="http://www.appleinsider.com/articles/11/12/02/2tb_hard_drive_shortage_hits_apples_bto_imacs_with_5_7_week_wait.html">2TB Hard Drive Shortage Hits Apple’s BTO iMacs with 5-7 Week Wait</a><br />
<a href="http://www.techradar.com/news/computing-components/storage/hard-drive-shortage-pushes-prices-up-150--1044021">Hard Drive Shortage Pushes Prices Up 150%</a><br />
<a href="http://www.computerworld.com/s/article/9220745/Floods_forces_shutdown_of_Western_Digital_s_Thailand_plants">Floods Forces Shutdown of Western Digital’s Thailand Plants</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/revenue-supply-demand-effects-of-the-2011-hard-drive-shortage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why is a PCI Compliant Environment So Expensive?</title>
		<link>http://resource.onlinetech.com/why-is-a-pci-compliant-environment-so-expensive/</link>
		<comments>http://resource.onlinetech.com/why-is-a-pci-compliant-environment-so-expensive/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 18:59:06 +0000</pubDate>
		<dc:creator>Yan Ness</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[pci compliance pricing]]></category>
		<category><![CDATA[pci compliant environment]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[pci compliant technology]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[pci pentration testing]]></category>
		<category><![CDATA[web access firewall]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4169</guid>
		<description><![CDATA[Because it’s worth it. It’s the one that really helps an executive sleep at night. We’ve done HIPAA, SAS 70, SSAE 16, SOC 1/SOC 3 audits, but PCI DSS does the deepest dive, by far. PCI includes source code reviews, requires custom penetration testing and well-documented procedures, policies and change management processes. PCI is also [...]]]></description>
			<content:encoded><![CDATA[<p>Because it’s worth it. It’s the one that really helps an executive sleep at night.</p>
<p>We’ve done <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-1-hosting">SOC 1</a>/<a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-3-hosting">SOC 3</a> audits, but PCI DSS does the deepest dive, by far. PCI includes source code reviews, requires custom penetration testing and well-documented procedures, policies and change management processes.</p>
<p>PCI is also very prescriptive about the technology you must deploy, compared to other compliance standards. For example, HIPAA requires you to logically secure data, but it doesn’t specifically state the use of a firewall. The PCI audit specifically states that you must use a firewall and numerous other technologies to logically protect cardholder data. It’s those prescriptive solutions that drive up the cost of passing an audit. Here’s an explanation of Web Access Firewall (WAF) and the Annual Penetration Testing:</p>
<ul>
<li><strong>Web Access Firewall </strong>– This is a piece of software that watches the web activity to and from your website in order to prevent nefarious activity. This software actually looks at the web page, not the network traffic, and does pattern matching to make sure credit card numbers are not displayed etc. Deploying a WAF requires someone familiar with both the PCI rules and your application. That person then writes a configuration that tells the WAF how to examine the application’s web pages to check for sensitive credit cardholder data. Every time the programmers make a change to the application, the WAF configuration has to be updated. It’s an expensive tool that requires an expert to use. It can cost thousands to tens of thousands of dollars per year to license and maintain the technology for a PCI application.</li>
<li><strong>Annual Penetration Testing </strong>– PCI requires an internal and external penetration test each year, and after any major change to the application. These tests use both technology and manual review of the application source code to assure there are no threats to sensitive cardholder data.The technology consists of a scanner that examines the ports and attempts various attacks such as SQL injection on the application. Similar to WAF, the scanner has to be custom-configured based on the application. The external test is designed from outside the network.  The internal test is done from inside the network, which is where a hacker may be attacking your application.</li>
</ul>
<p>PCI also requires file integrity monitoring to ensure configuration files are not nefariously modified, SSL certificates to secure web traffic and dual-factor authentication for administrators. All of these technologies require staff to research, select, install, configure, monitor and maintain the increasing TCO (Total Cost of Ownership) of PCI.</p>
<p>But it’s worth it. In today’s world, data <em>is </em>your business. You can’t operate without it, so we welcome the protections prescribed by PCI regulations in order to provide <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliant hosting</a>.</p>
<p>PCI also requires a robust and complete suite of documentation, procedures, policies and change management which further increase the TCO. But that’s for another blog entry…</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/why-is-a-pci-compliant-environment-so-expensive/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Efficient Auditing at Online Tech</title>
		<link>http://resource.onlinetech.com/efficient-auditing-at-online-tech/</link>
		<comments>http://resource.onlinetech.com/efficient-auditing-at-online-tech/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 18:11:20 +0000</pubDate>
		<dc:creator>Yan Ness</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data center audits]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[midwest data centers]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[SOC 1]]></category>
		<category><![CDATA[SOC 3]]></category>
		<category><![CDATA[ssae 16]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4159</guid>
		<description><![CDATA[We’ve completed a number of audits over the years. Each audit results in a report such as HIPAA, SAS 70, SSAE 16, SOC 1/SOC 3 and PCI.  It’s extremely expensive to do these audits well. The obvious costs are the auditors, but you can’t overlook the staff time and technology. We estimate it takes a few hundred hours [...]]]></description>
			<content:encoded><![CDATA[<p>We’ve completed a number of audits over the years. Each audit results in a report such as <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a>, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-1-hosting">SOC 1</a>/<a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-3-hosting">SOC 3</a> and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI</a>.  It’s extremely expensive to do these audits well. The obvious costs are the auditors, but you can’t overlook the staff time and technology. We estimate it takes a few hundred hours of staff time for each audit, and we regularly automate many functions.</p>
<p>This obviously doesn’t scale well enough for us. We have multiple <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> and plan to add more throughout the Midwest.  To deliver our promise of <em><a href="http://www.onlinetech.com/secure-hosting">compliant computing</a></em> for as many environments as possible, we had to find an industry-leading, unique and highly efficient method for performing these and other audits.</p>
<p>We hired a nationally-known auditing firm to develop a one-of-a-kind <em>super audit</em>. This super audit is a super-set of all of the audits with the redundant items removed. As a result, we now have one very large audit throughout the year that can be used to generate a full suite of reports: HIPAA, PCI, SSAE 16, etc. The result? We spend less time while experiencing less intrusion, resulting in a better audit.</p>
<p>We then looked at the body of audit points to identify a number of automation opportunities and turned them over to our development team. They added various tools to <a href="https://customer.onlinetech.com/CustomerLogin.aspx">OTPortal</a> such as the Walkthrough Manager and the Firewall Rule Change Manager to simplify and automate many of the functions the audit requires. We gave our auditors access to these systems to make it easier for them to audit without having to visit our data centers and to save staff time.</p>
<p>Our investment in the super audit and automation allows us to deliver audited, compliant hosting much more cost-effectively than many companies are able to achieve themselves.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/efficient-auditing-at-online-tech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Risk Assessments to Achieve PCI Compliance in the Cloud</title>
		<link>http://resource.onlinetech.com/risk-assessments-to-achieve-pci-compliance-in-the-cloud/</link>
		<comments>http://resource.onlinetech.com/risk-assessments-to-achieve-pci-compliance-in-the-cloud/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 15:23:27 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud computing security]]></category>
		<category><![CDATA[pci cloud security]]></category>
		<category><![CDATA[pci clouds]]></category>
		<category><![CDATA[pci compliant hosting]]></category>
		<category><![CDATA[PCI DSS compliance]]></category>
		<category><![CDATA[pci dss compliant hosting]]></category>
		<category><![CDATA[PCI hosting]]></category>
		<category><![CDATA[pci private clouds]]></category>
		<category><![CDATA[pci public clouds]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4150</guid>
		<description><![CDATA[One of the main concerns with cloud computing is security &#8211; when it comes to national industry security compliance standards such as PCI DSS or HIPAA, additional precautions must be taken in order to protect confidential data during transmission. While PCI compliance calls for very specific requirements to protect customer cardholder data, it is possible [...]]]></description>
			<content:encoded><![CDATA[<p>One of the main concerns with <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> is security &#8211; when it comes to national industry security compliance standards such as PCI DSS or <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a>, additional precautions must be taken in order to protect confidential data during transmission. While PCI compliance calls for very specific requirements to protect customer cardholder data, it is possible to remain compliant while using the cloud.</p>
<p>The PCI Security Council (PCI SSC) recently <a href="http://resource.onlinetech.com/pci-compliance-and-virtualization-new-recommendations/">released</a> a set of guidelines and recommendations on configuring virtualized environments to meet PCI requirements in June. The council acknowledges there is no one-size-fits-all hosting solution that allows all businesses to meet the PCI requirements, but they do address potential new risks that may be associated with virtualization technology.</p>
<p>According to Onestopclick.com’s article on <em>PCI Compliance and the Public Cloud</em>, some experts suggest using a separate secure server for transactions while using a cloud platform for other business operations. However, the PCI SSC suggests some public clouds have certain characteristics that may introduce challenges in defining scope and responsibilities when it comes to meeting PCI compliance, including the fact that the hosted entity may have limited knowledge of other tenants in their hosted environment and limited control over CHD storage. In a <a href="http://www.onlinetech.com/cloud-computing-hosting/private-cloud-hosting-packages">private cloud</a>, dedicated hardware provides more security and control by allowing the tenant to know where their data lives.</p>
<p>As a result, the PCI SSC states the burden of PCI compliance falls upon the cloud provider and their own controls and assessment of their own environment’s compliance. When searching for a <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliant hosting</a> provider and solution, merchants should review which controls are in place to meet the requirements, what is included in the scope of their assessment and details of what is not covered, and what is ultimately the merchant’s own responsibility.</p>
<p>The PCI SSC also recommends conducting a <strong>risk assessment</strong> of their virtual environments to comply with PCI standards, including the following key elements:</p>
<ul>
<li><strong>Define the Environment</strong><br />
Components, physical security/site details, traffic flow, component visibility, virtual and physical hardware components, etc.</li>
<li><strong>Identify Threats</strong><br />
One example is new types of malicious code or logical attacks targeting virtual components (hypervisor) or unsecured communication channels between shared hardware components.</li>
<li><strong>Identify Vulnerabilities</strong><br />
While the PCI SSC acknowledges vulnerabilities may result from the complexity of virtualization layers, shared environments and lack of visibility, they also point out that vulnerabilities are not limited to technical issues &#8211; mistrained staff, operational processes errors, lack of control monitoring and more can be responsible for a point of weakness.</li>
<li><strong>Evaluate and Address Risk</strong><br />
With all threats, vulnerabilities and environmental aspects considered, a risk assessment’s ultimate goal is to determine if any additional controls (on top of existing PCI compliance requirements) need to be implemented to protect CHD and avoid a PCI compliance breach.</li>
</ul>
<p>For more on PCI compliance, see our prerecorded <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/pci-webinar-series">PCI compliance webinar series</a>, including a <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/pci-webinar-series/item/223">PCI overview</a>, <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/pci-webinar-series/item/224">detailed PCI requirements</a> and <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/item/225-pci-compliance-penetration-testing-and-enhancing-security-for-network-and-applications">PCI penetration testing</a> and enhancing network and application security, led by a PCI compliance expert, Adam Goslin of High Bit Security.</p>
<p>Sources:<br />
<a href="http://security.onestopclick.com/topic/193/512/pci-compliance-and-the-public-cloud.html">PCI Compliance and the Public Cloud</a><br />
<a href="https://www.pcisecuritystandards.org/documents/Rth87Wp/Virtualization_InfoSupp_v2.pdf">Information Supplement: PCI DSS Virtualization Guidelines</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/risk-assessments-to-achieve-pci-compliance-in-the-cloud/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Encrypting Data to Meet HIPAA Compliance</title>
		<link>http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/</link>
		<comments>http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 13:50:52 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data encryption]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant data centers]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4140</guid>
		<description><![CDATA[To address the question of whether or not to use data encryption when it comes to meeting HIPAA compliance and keeping patient health information (PHI) protected, let’s revisit the Health Insurance Portability and Accountability Act of 1996 (HIPAA): A covered entity must, in accordance with §164.306… Implement a mechanism to encrypt and decrypt electronic protected [...]]]></description>
			<content:encoded><![CDATA[<p>To address the question of whether or not to use data encryption when it comes to meeting HIPAA compliance and keeping patient health information (PHI) protected, let’s revisit the Health Insurance Portability and Accountability Act of 1996 (HIPAA):</p>
<blockquote><p>A covered entity must, in accordance with §164.306… Implement a mechanism to encrypt and decrypt electronic protected health information.&#8221; (45 CFR § 164.312(a)(2)(iv))</p></blockquote>
<p>If you choose not to encrypt data, the HIPAA Security Rule states you must implement an equivalent solution to meet the regulatory requirement. The law leaves encryption open to interpretation since covered entities vary when it comes to network and network usage, depending on the type and size of business.</p>
<p>While HIPAA and HITECH address the security and privacy of PHI with more of a policy and procedures-oriented approach with no strict parameters for what type of technology to use, encryption is typically considered a best practice when it comes to protecting sensitive data.</p>
<p>A few recommendations when it comes to data encryption:</p>
<ul>
<li>Don’t use public FTP (File Transfer Protocol) if you need to transfer patient data to and from payers or other business associates.</li>
<li>To err on the safe side would be to combine two methods of encryption &#8211; send encrypted files over an encrypted connection.</li>
<li>When it comes to remote access to applications and data in cases of telecommuting or working from remote locations, use a VPN (Virtual Private Network). This network creates a temporary encrypted connection that only exists during the time of use.</li>
<li>Always use SSL (Secure Sockets Layer) for web-based access to any sensitive data.</li>
<li>Keeping sensitive data on a portable device is not recommended &#8211; it is better to store your data in an offsite location with a secure environment, such as a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> with the proper physical and network security in place to protect PHI and prevent a data breach. This is a lesson learned as shown by the case of the <a href="http://resource.onlinetech.com/sutter-health-hipaa-breach-lessons-learned/">Sutter Health HIPAA breach</a> due to a stolen unencrypted desktop PC. An audited <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> solution can also offer greater protection with additional security measures such as a virtual or dedicated firewall, backup, antivirus and OS patch management.</li>
<li>However, if a portable device needs to be encrypted due to stored sensitive information, file/folder level encryption and full disk encryption (FDE) are both options to keep data safe while stored locally.</li>
<li>When it comes to mobile devices that store data including CD’s, DVD’s, USBs, iPods and Blackberry’s, encryption of the data on the device can help protect against a HIPAA breach. Other options include putting in place a policy for mobile device use and PHI storage, limiting certain data from being stored on the devices, or implementing access controls to the device, including password protection.</li>
<li>Data at rest needs to be encrypted as well &#8211; this includes data stored on disk drives, backup tapes, or servers since they can be accessed from remote locations and in the physical location if not properly locked/secured.</li>
<li>Following the NIST (National Institute of Standards and Technology) standard, called the Advanced Encryption Standard (AES) for encryption is considered another best practice.</li>
<li>Other methods that can help you determine if you need encryption include completing a HIPAA risk assessment, performing a gap analysis to find out what you’re missing in your current security environment, and developing and documenting solutions to become more resilient to the risk of a data breach.</li>
</ul>
<p>Find out more about the <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/benefits-of-hipaa-compliant-hosting">Benefits of HIPAA Compliant Hosting</a> and basic definitions in our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a>. Get examples of HIPAA training, privacy policies, procedures and forms from established HIPAA compliant medical centers and universities in our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA Resources</a> section.</p>
<p>Sources:<br />
<a href="http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf">Advanced Encryption Standard (AES)</a><br />
<a href="http://www.hipaacow.org/Docs/Encryption%20Whitepaper%207.7.10.doc">Encryption White Paper (.doc)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/encrypting-data-to-meet-hipaa-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is your organization HIPAA-ready for 2012?</title>
		<link>http://resource.onlinetech.com/is-your-organization-hipaa-ready-for-2012/</link>
		<comments>http://resource.onlinetech.com/is-your-organization-hipaa-ready-for-2012/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 14:44:49 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA audits]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4130</guid>
		<description><![CDATA[How close are you to being completely HIPAA-ready for 2012? Back in August, I blogged about the upcoming 2011 HIPAA Violations and Audits, and news of the government’s $9.2 million contract with auditing firm KPMG to complete 150 on-site audits of covered entities by December 2012. The OCR officially launched its HIPAA Audit Program, starting in [...]]]></description>
			<content:encoded><![CDATA[<p>How close are you to being completely HIPAA-ready for 2012?</p>
<p>Back in August, I blogged about the upcoming <a href="http://resource.onlinetech.com/2011-hipaa-violations-and-audits/">2011 HIPAA Violations and Audits</a>, and news of the government’s $9.2 million contract with auditing firm KPMG to complete 150 on-site audits of covered entities by December 2012.</p>
<p>The OCR officially launched its HIPAA Audit Program, starting in November 2011.</p>
<p>If you&#8217;re not even close to being HIPAA-ready and need <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> guidance, check out our <a href="http://resource.onlinetech.com/tag/hipaa-compliance/">HIPAA compliance blog category</a>, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>, or watch our recent <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">HIPAA webinars</a> to get educated on what you need to be HIPAA compliant.</p>
<p><iframe src="http://polls.linkedin.com/vote/159701/gmrbl" frameborder="0" marginwidth="0" marginheight="0" scrolling="no" width="300" height="250"></iframe></p>
<p>Take our Linkedin poll (it&#8217;s only one question).</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/is-your-organization-hipaa-ready-for-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2011 Ann Arbor Data Center Open House</title>
		<link>http://resource.onlinetech.com/2011-ann-arbor-data-center-open-house/</link>
		<comments>http://resource.onlinetech.com/2011-ann-arbor-data-center-open-house/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 14:17:21 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[ann arbor michigan data center]]></category>
		<category><![CDATA[michigan data center]]></category>
		<category><![CDATA[online tech events]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4100</guid>
		<description><![CDATA[Thank you to everyone that attended our 2011 Ann Arbor Open House! For photos of presenters, data center tours and more, view the OT Flickr. All photographs taken by Noah Wolff of our Online Tech Operations team. View the complete slideshow. View more photos! Our newest Ann Arbor data center is a 19,500 square foot [...]]]></description>
			<content:encoded><![CDATA[<p>Thank you to everyone that attended our 2011 Ann Arbor Open House! For photos of presenters, data center tours and more, view the <a href="http://www.flickr.com/photos/onlinetech/sets/72157628294670005/">OT Flickr</a>. All photographs taken by Noah Wolff of our Online Tech Operations team. <a href="http://www.flickr.com/photos/onlinetech/sets/72157628294670005/show/">View the complete slideshow</a>.</p>
<div id="attachment_4101" class="wp-caption aligncenter" style="width: 490px"><img class="size-full wp-image-4101  " title="Online Tech CEO Yan Ness" src="http://resource.onlinetech.com/wp-content/uploads/IMG_6142.jpg" alt="Online Tech CEO Yan Ness" width="480" height="320" /><p class="wp-caption-text">Online Tech CEO Yan Ness</p></div>
<div class="mceTemp mceIEcenter">
<div id="attachment_4242" class="wp-caption aligncenter" style="width: 494px"><img class="size-full wp-image-4242  " title="Ann-Arbor-Data-Center-Tours" src="http://resource.onlinetech.com/wp-content/uploads/Ann-Arbor-Data-Center-Tours1.png" alt="Ann Arbor Data Center Tours" width="484" height="360" /><p class="wp-caption-text">Ann Arbor Data Center Tours</p></div>
<div id="attachment_4118" class="wp-caption aligncenter" style="width: 498px"><img class="size-full wp-image-4118  " title="2011 Ann Arbor Data Center Open House" src="http://resource.onlinetech.com/wp-content/uploads/2011-Ann-Arbor-Data-Center-Open-House.png" alt="2011 Ann Arbor Data Center Open House" width="488" height="358" /><p class="wp-caption-text">2011 Ann Arbor Data Center Open House</p></div>
<p style="text-align: left;">View <a href="http://www.flickr.com/photos/onlinetech/sets/72157628294670005/">more photos</a>!</p>
<p style="text-align: left;">Our newest Ann Arbor data center is a 19,500 square foot facility with 10,000 square feet of 12″ raised floor and high availability Internet connectivity. With diversified utility and network feeds, our data center is perfect for production and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> projects.</p>
<p style="text-align: left;">Like our other data centers, our Ann Arbor, <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> is independently audited and found to be <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/sas-70-data-centers">SAS 70</a>, <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/ssae-16-data-centers">SSAE 16</a>, <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/soc-2-data-centers">SOC 2 &amp; SOC 3</a> and <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant</a>. Visit <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor Data Center</a> for detailed specifications on the power, network infrastructure, security, and cooling capacity.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2011-ann-arbor-data-center-open-house/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How a HIPAA Breach Can Negatively Impact Your Business</title>
		<link>http://resource.onlinetech.com/how-a-hipaa-breach-can-negatively-impact-your-business/</link>
		<comments>http://resource.onlinetech.com/how-a-hipaa-breach-can-negatively-impact-your-business/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 19:43:50 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[hipaa data breach]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>
		<category><![CDATA[offsite backup]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4088</guid>
		<description><![CDATA[According to the Ponemon Institute’s 2011 Benchmark Study on Patient Privacy and Data Security, data security breaches cost the U.S. healthcare industry an estimated $6.5 billion a year, up 10 percent from last year. About 29 percent of the providers reported that one consequence of data breaches was medical identity theft. The major causes of [...]]]></description>
			<content:encoded><![CDATA[<p>According to the Ponemon Institute’s 2011 Benchmark Study on Patient Privacy and Data Security, data security breaches cost the U.S. healthcare industry an estimated $6.5 billion a year, up 10 percent from last year. About 29 percent of the providers reported that one consequence of data breaches was medical identity theft.</p>
<p>The major causes of healthcare data breaches include lost or stolen devices (nearly 50 percent), third party/business associate mistakes (46 percent) and unintentional employee actions.</p>
<p>The prevalence of business associates as the source of a data breach highlights the importance of vetting your vendors thoroughly for <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> – although passing a HIPAA audit of their own does not make your organization completely compliant, it does mean your data hosting solution and provider has the proper technology, policies and procedures in place to protect your company from a data breach.</p>
<p>The use of mobile devices in the healthcare industry is another contributor to data loss – while 80 percent are using them to gather, transmit and store patient information, half of them are not securing them.</p>
<p>How can your organization secure sensitive protected health information (PHI) during transfer, storage and transmittal? Online Tech recommends data encryption, virtual or dedicated firewalls, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a> and antivirus to meet HIPAA/HITECH standards and keep data safe.</p>
<p>The study also reports that fifty-five percent of respondents agreed that concerns about the ongoing HIPAA audits enforced by OCR and the onsite investigations have affected changes in their patient data privacy and security policies and procedures.</p>
<div id="attachment_4089" class="wp-caption aligncenter" style="width: 572px"><img class="size-full wp-image-4089  " title="Negative Impacts of Data Breach" src="http://resource.onlinetech.com/wp-content/uploads/Negative-Impacts-of-Data-Breach.png" alt="Negative Impacts of Data Breach" width="562" height="435" /><p class="wp-caption-text">Negative Impacts of Data Breach</p></div>
<p>What are the consequences of a data breach that healthcare organizations must suffer?</p>
<ul>
<li>81% Diminished productivity and lost time</li>
<li>78% Brand or reputation diminishment</li>
<li>75% Loss of patient goodwill</li>
<li>Potential result of consequences: patient churn, representing an average loss of $113,400 per customer/patient, an increase from $107,580 from last year’s study.</li>
</ul>
<p>How are these data breaches discovered?</p>
<ul>
<li>51% Employees</li>
<li>43% Audit/Assessment</li>
<li>35% Patient compliant</li>
</ul>
<p>Although investing in the proper HIPAA compliant technology, policies and procedures can be a costly, time-consuming process, the study also shows that healthcare organization are at risk of non-compliance, based on their current practices. The study also shows a significant financial loss and other serious consequences that can negatively impact business survival.</p>
<p>Need more HIPAA hosting information and recommended best practices to meet compliance? Answer questions like <em>What services from Online Tech help make me compliant?</em> and <em>What’s the best way to encrypt PHI?</em> in our informative <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>. Or read up on a few <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-compliant-hosting-case-studies">HIPAA hosting case studies</a> that detail real companies with real HIPAA challenges, and their solutions that helped them be successful today.</p>
<p>Sources:<br />
Second Annual Benchmark Study on Patient Privacy &amp; Data Security, Ponemon Institute<br />
<a href="http://www.darkreading.com/insider-threat/167801100/security/attacks-breaches/232200606/healthcare-data-in-critical-condition.html">Healthcare Data in Critical Condition</a><br />
<a href="http://www.fiercehealthit.com/story/health-data-breaches-cost-65b-annually/2011-12-01">Health Data Breaches Cost $6.5 Billion Annually</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/how-a-hipaa-breach-can-negatively-impact-your-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Last Chance to RSVP: PCI, HIPAA &amp; Cloud Presentations</title>
		<link>http://resource.onlinetech.com/last-chance-to-rsvp-pci-hipaa-cloud-presentations/</link>
		<comments>http://resource.onlinetech.com/last-chance-to-rsvp-pci-hipaa-cloud-presentations/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 14:57:51 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud compliance]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[michigan data center]]></category>
		<category><![CDATA[PCI compliance]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4081</guid>
		<description><![CDATA[Last Chance: RSVP to attend Online Tech&#8217;s New Ann Arbor, Michigan Data Center Open House &#8211; Friday (tomorrow) 3-7pm! Aside from ongoing data center tours, refreshments and wine, you&#8217;ll get the latest on IT compliance from a Certified HIPAA Practitioner (CHP), a health IT and HIPAA compliance attorney and PCI compliance experts. Come with questions [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_4082" class="wp-caption aligncenter" style="width: 590px"><img class="size-full wp-image-4082" title="Online Tech Open House" src="http://resource.onlinetech.com/wp-content/uploads/Online-Tech-Open-House.png" alt="Online Tech Open House" width="580" height="355" /><p class="wp-caption-text">Online Tech Open House</p></div>
<p>Last Chance: RSVP to attend Online Tech&#8217;s New Ann Arbor, <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan Data Center</a> Open House &#8211; <strong>Friday (tomorrow) 3-7pm</strong>!</p>
<p>Aside from ongoing data center tours, refreshments and wine, you&#8217;ll get the latest on IT compliance from a Certified HIPAA Practitioner (CHP), a health IT and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> attorney and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliance</a> experts. Come with questions for the Q&amp;A session about your own company or organization and get advice from industry professionals.</p>
<p>Interested in <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a>, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> and cloud security? We&#8217;ll have VMware experts speaking on cloud compliance, Dell reps presenting EqualLogic: Fully Loaded with vSphere 5, and an introduction to Online Tech&#8217;s latest <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">cloud-based disaster recovery</a> solution, DR Now!</p>
<p>Stay for an hour or four &#8211; <a href="http://www.onlinetech.com/openhouse">RSVP</a> and reserve a seat at one of our presentations today. Get the address &amp; details <a href="http://www.onlinetech.com/openhouse">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/last-chance-to-rsvp-pci-hipaa-cloud-presentations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Physician Use of EMR/EHR Statistics</title>
		<link>http://resource.onlinetech.com/physician-use-of-emrehr-statistics/</link>
		<comments>http://resource.onlinetech.com/physician-use-of-emrehr-statistics/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 14:46:23 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[EHR]]></category>
		<category><![CDATA[ehr statistics]]></category>
		<category><![CDATA[electronic health records]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR]]></category>
		<category><![CDATA[emr statistics]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4075</guid>
		<description><![CDATA[Despite the federal push for healthcare organizations to adopt effective, meaningful use EMRs/EHRs by 2014 to replace paper records, the latest statistics from the National Ambulatory Medical Care Survey (NAMCS) show that physicians are lagging in implementing a viable system at their practices. In 2010, only 10.1 percent of office-based physicians have a fully functional [...]]]></description>
			<content:encoded><![CDATA[<p>Despite the federal push for healthcare organizations to adopt effective, meaningful use EMRs/EHRs by 2014 to replace paper records, the latest statistics from the National Ambulatory Medical Care Survey (NAMCS) show that physicians are lagging in implementing a viable system at their practices.</p>
<p>In 2010, only 10.1 percent of office-based physicians have a fully functional EMR/EHR system in place, up 32 percent in 2009. Nearly 25 percent have adopted a basic system, showing a minor increase from the 22 percent in 2009. Additionally, 50 percent of office-based physicians have any type of EMR/EHR system, although not fully functional.</p>
<div id="attachment_4076" class="wp-caption aligncenter" style="width: 538px"><img class="size-full wp-image-4076 " title="NAMCS Survey Results" src="http://resource.onlinetech.com/wp-content/uploads/NAMCS-Survey-Results.png" alt="NAMCS Survey Results" width="528" height="312" /><p class="wp-caption-text">NAMCS Survey Results</p></div>
<p>According to the scholarly publication by the National Center for Health Statistics accompanying the survey, ‘fully functional’ is defined as systems with the following basic functionalities:</p>
<ul>
<li>Patient demographic information</li>
<li>Patient problem lists</li>
<li>Clinical notes</li>
<li>Orders for prescriptions</li>
<li>Viewing laboratory and imaging results</li>
<li>Medical history and follow-up</li>
<li>Orders for tests</li>
<li>Prescription and test orders sent electronically</li>
<li>Drug interactions or contraindications warnings</li>
<li>Highlighting out-of-range test levels</li>
<li>Electronic images returned</li>
<li>Reminders for guideline-based interventions</li>
</ul>
<p>The need for EMR/EHR awareness and technical support is growing at a rapid pace, demanding more clinical IT staff training and additional resources. With the advent of electronic systems, data protection and security concerns become paramount, as the Department of Health and Human Services has indicated with its latest investment in <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> enforcement and scheduled, ongoing HIPAA audits.</p>
<p>Find out more about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/who-needs-to-be-hipaa-compliant">who needs to be HIPAA compliant</a>. Or, answer all your health IT, HIPAA and HITECH questions with our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>.</p>
<p>Source:<br />
<a href="http://www.cdc.gov/nchs/data/hestat/emr_ehr_09/emr_ehr_09.pdf">Electronic Medical Record/Electronic Health Record Use By Office-based Physicians: United States, 2009 and Preliminary 2010 State Estimates</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/physician-use-of-emrehr-statistics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech Speaks at Data Security Seminar</title>
		<link>http://resource.onlinetech.com/online-tech-speaks-at-data-security-seminar/</link>
		<comments>http://resource.onlinetech.com/online-tech-speaks-at-data-security-seminar/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 13:19:53 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[data breach security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HITECH]]></category>
		<category><![CDATA[PCI compliance]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4052</guid>
		<description><![CDATA[Online Tech’s COO and President Mike Klein will be speaking at the Data Security Seminar hosted by the Kapnick Insurance Group on data security at Kapnick Insurance Group’s Ann Arbor office. Seminar and presentation topics include data and intellectual property safety, what to do if it is compromised, how much a data breach will cost, [...]]]></description>
			<content:encoded><![CDATA[<p>Online Tech’s COO and President Mike Klein will be speaking at the Data Security Seminar hosted by the Kapnick Insurance Group on data security at Kapnick Insurance Group’s Ann Arbor office.</p>
<div id="attachment_4053" class="wp-caption alignleft" style="width: 280px"><img class="size-full wp-image-4053  " title="kapnick-logo" src="http://resource.onlinetech.com/wp-content/uploads/kapnick-logo.png" alt="Kapnick Insurance Group" width="270" height="92" /><p class="wp-caption-text">Kapnick Insurance Group</p></div>
<p>Seminar and presentation topics include data and intellectual property safety, what to do if it is compromised, how much a data breach will cost, and what companies can do to adequately protect themselves from a data breach.</p>
<p><strong>Other panel topics to be discussed include:</strong></p>
<ul>
<li>What to do after you’ve been hacked</li>
<li>How to comply with numerous federal regulations, such as <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a>, HITECH, <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliance</a> and state laws governing breach notification rules</li>
</ul>
<p>The data security panel discussion is open to the public, and will be held December 12, 2011 from 7-9:30pm. Kapnick Insurance Group’s office is located at:</p>
<p>1201 Briarwood Circle<br />
Ann Arbor, MI 48108<br />
<strong></strong></p>
<p><strong>Other panel discussion participants include:</strong></p>
<ul>
<li>Mark Ford, <em>Privacy and Security Consultant</em> of <strong>Deloitte Touche</strong></li>
<li>Joseph Dylewski, <em>HIPAA Expert and Consultant</em> of <strong>ATMP Solutions</strong></li>
<li>Adam Goslin, <em>IT Security Services/PCI Consultant</em> of <strong>High Bit Security</strong></li>
<li>Stephan Tupper, <em>Attorney</em></li>
<li>Dykema Gossett, <em>Privacy Practice Leader</em></li>
</ul>
<p>The panel will be moderated by Stewart Nelson, Account Executive of Kapnick Insurance Group, and a Q&amp;A session will be held after the initial panel discussion.</p>
<p>Who should attend? The data security panel discussion is suited for business owners, executives, managers and IT professionals from any company that store sensitive information or data.</p>
<p>For bios, contact information and driving directions, visit the <a href="http://events.r20.constantcontact.com/register/event?llr=t75hhncab&amp;oeidk=a07e53gvxczbd8ca7f6">panel discussion registration</a>.</p>
<p>Watch an informative video on <strong><em><a href="http://www.onlinetech.com/resources/cloud-computing-wiki/private-cloud-security-how-your-data-security-changes-in-the-cloud">Private Cloud Security: How Your Data Security Changes in the Cloud</a>, </em></strong>or view a <a href="http://www.onlinetech.com/cloud-computing-hosting/managed-cloud-hosting/managed-cloud-vs-public-cloud">comparison</a> of a <a href="http://www.onlinetech.com/cloud-computing-hosting/managed-cloud-hosting">managed cloud</a> vs. a public cloud when it comes to security and other benefits.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-speaks-at-data-security-seminar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EMR Market Trends: Cloud Computing and Economics</title>
		<link>http://resource.onlinetech.com/emr-market-trends-cloud-computing-and-economics/</link>
		<comments>http://resource.onlinetech.com/emr-market-trends-cloud-computing-and-economics/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 15:37:06 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[EMR adoption rates]]></category>
		<category><![CDATA[EMR cloud computing]]></category>
		<category><![CDATA[EMR deployment]]></category>
		<category><![CDATA[EMR market trends]]></category>
		<category><![CDATA[EMR outsourcing]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA compliance]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=4044</guid>
		<description><![CDATA[According to Accenture’s study of healthcare software, hardware and services companies, the global market for EMR systems is expected to reach $19.7 billion in 2013, with North America experiencing a 9.7 percent growth from 2011 to 2013. When asked how critical the global EMR markets are to their company’s long-term and short-term strategy, 71 percent [...]]]></description>
			<content:encoded><![CDATA[<p>According to Accenture’s study of healthcare software, hardware and services companies, the global market for EMR systems is expected to reach $19.7 billion in 2013, with North America experiencing a 9.7 percent growth from 2011 to 2013.</p>
<p>When asked how critical the global EMR markets are to their company’s long-term and short-term strategy, 71 percent recognized the EMR markets as a short term growth opportunity and 100 percent view them as a growth opportunity in the long term.</p>
<p>The survey anticipates four major trends that will have the greatest impact on EMR growth:</p>
<ul>
<li>Nearly 71 percent rate government incentives as a driver behind effective health IT adoption.</li>
<li>The survey notes a shortage of clinical IT specialists will also contribute to the transition to outsourcing and cloud-based EMR solutions. The EMR systems will require more clinically trained IT resources.</li>
<li>Health system networking will also create the largest challenge, due to the large variety of geographic regions.</li>
<li>Another major issue that will affect the pace of EMR adoption is global economic recovery.</li>
</ul>
<p>The connection between government funding and outsourcing is the need for increasing support costs and lack of IT resources &#8211; hospitals in North America are barely able to offset the costs of adopting and supporting EMR systems, even with incentives. As a result, healthcare companies are turning to outsourced and cloud solutions to reduce overall costs.</p>
<p>While the survey recognizes the capability of cloud computing to reduce costs, increase efficiency and help with EMR deployment, it also quotes an IDC survey stating 54 percent of organizations are still researching and evaluating the cloud, while 21 percent are actually using the cloud for applications. Despite slow adoption rates, the survey shows an expected overall increase in spending on clinical IT over the next five years.</p>
<p>A major inhibitor of EMR adoption include concerns around security and data sharing. Knowing where your data resides and maintaining control is important when it comes to reducing security risks. It’s important to review your contracts with your <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud hosting</a> provider to ensure you’re following <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a> practices for optimal protected health information (PHI) security.</p>
<p>Get more information about cloud security from our E-Tip, <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing/top-5-tips-for-cloud-computing-security">Top 5 Tips for Cloud Computing Security</a> &#8211; one tip is to invest in dedicated hardware and increased IT security measures, such as managed firewalls, and intrusion detection and prevention systems. Not sure what <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> should entail? Check out our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a> for answers.</p>
<p>Source:<br />
<a href="http://www.accenture.com/SiteCollectionDocuments/PDF/Accenture_EMR_Markets_Whitepaper_vfinal.pdf">Accenture’s Overview of International EMR/EHR Markets</a> (PDF)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/emr-market-trends-cloud-computing-and-economics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming Data Center Events: Ann Arbor Open House</title>
		<link>http://resource.onlinetech.com/upcoming-data-center-events-ann-arbor-open-house/</link>
		<comments>http://resource.onlinetech.com/upcoming-data-center-events-ann-arbor-open-house/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 19:30:39 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[Ann Arbor data center]]></category>
		<category><![CDATA[cloud compliance]]></category>
		<category><![CDATA[cloud computing event]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[comcast]]></category>
		<category><![CDATA[dell]]></category>
		<category><![CDATA[disaster recovery in the cloud]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[michigan data center]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[VMware]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3999</guid>
		<description><![CDATA[If you&#8217;re around the Ann Arbor or Detroit area, stop by our open house Friday, December 2, 2011 from 3-7 p.m. at our newest Ann Arbor data center to celebrate and take advantage of a great information-sharing and networking opportunity for those interested in learning about the latest developments in the IT and compliance industries. The [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_4024" class="wp-caption aligncenter" style="width: 564px"><img class="size-full wp-image-4024   " title="Ann Arbor 2 Data Center" src="http://resource.onlinetech.com/wp-content/uploads/Ann-Arbor-2-Data-Center.jpg" alt="Ann Arbor 2 Data Center" width="554" height="227" /><p class="wp-caption-text">Ann Arbor 2 Data Center</p></div>
<p>If you&#8217;re around the Ann Arbor or Detroit area, stop by our open house <strong>Friday</strong>, <strong>December 2, 2011</strong> from <strong>3-7 p.m.</strong> at our newest <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor data center</a> to celebrate and take advantage of a great information-sharing and networking opportunity for those interested in learning about the latest developments in the IT and compliance industries.</p>
<p>The event will include presentations from Dell, Comcast and VMware representatives, as well as <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliance</a> and <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> industry experts. Q&amp;A sessions will follow, as well as data center tours and complimentary wine, cheese and desserts. Also, don&#8217;t miss the presentation launch of our latest <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">cloud disaster recovery</a> product, DR Now!</p>
<p><strong>Open House Agenda</strong></p>
<table border="0" cellspacing="5" cellpadding="5" align="left">
<tbody>
<tr>
<td><strong>3:30</strong></td>
<td><em><strong>PCI Compliance - </strong></em>High Bit Security</td>
</tr>
<tr>
<td><strong>4:00</strong></td>
<td><em><strong>Comcast Metro Ethernet - </strong></em>Comcast</td>
</tr>
<tr>
<td><strong>4:30</strong></td>
<td><em><strong>HIPAA &amp; HITECH - </strong></em>Dickinson-Wright/ATMP Group</td>
</tr>
<tr>
<td><strong>5:00</strong></td>
<td><em><strong>Surviving a Disaster: Lessons Learned - </strong></em>Steven Gold</td>
</tr>
<tr>
<td><strong>5:45</strong></td>
<td><em><strong>DR Now! Cloud Disaster Recovery - </strong></em>Online Tech</td>
</tr>
<tr>
<td><strong>6:00</strong></td>
<td><em><strong>Cloud Compliance &amp; Security - </strong></em>VMWare</td>
</tr>
<tr>
<td><strong>6:30</strong></td>
<td><em><strong>EqualLogic: Fully Loaded with vSphere 5 - </strong></em>Dell</td>
</tr>
</tbody>
</table>
<p>Please RSVP to reserve a ticket and <a href="http://www.onlinetech.com/contact">contact</a> us for more information. For event details, data center address and RSVP form, please visit our <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center/ann-arbor-2-open-house">registration page</a>. Reserve individual presentation seats and customize your schedule to do the following:</p>
<ul>
<li>Tour the Data Center</li>
<li>Ask Dell about EqualLogic SANs &amp; servers</li>
<li>Ask VMWare about <a href="http://www.onlinetech.com/cloud-computing-hosting">Cloud Computing</a> &amp; Cloud Security</li>
<li>Ask Comcast about Metro Ethernet and other business services</li>
<li>Learn about HIPAA compliance from a CHSS (Certified HIPAA Security Specialist) /CHP (Certified HIPAA Practitioner) and Health IT Attorney</li>
<li>Learn about PCI compliance and penetration testing</li>
<li>Learn about <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT Disaster Recovery</a> options</li>
</ul>
<p>Our newest Ann Arbor data center is a 19,500 square foot facility with 10,000 square feet of 12&#8243; raised floor and high availability Internet connectivity. With diversified utility and network feeds, our data center is perfect for production and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> projects.</p>
<p>Like our other data centers, our Ann Arbor, <a href="http://www.onlinetech.com/company/michigan-data-centers">Michigan data center</a> is independently audited and found to be <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/sas-70-data-centers">SAS 70</a>, <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/ssae-16-data-centers">SSAE 16</a>, <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/soc-2-data-centers">SOC 2 &amp; SOC 3</a> and <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant</a>. Visit <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Ann Arbor Data Center</a> for detailed specifications on the power, network infrastructure, security, and cooling capacity.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/upcoming-data-center-events-ann-arbor-open-house/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sutter Health HIPAA Breach: Lessons Learned</title>
		<link>http://resource.onlinetech.com/sutter-health-hipaa-breach-lessons-learned/</link>
		<comments>http://resource.onlinetech.com/sutter-health-hipaa-breach-lessons-learned/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 16:01:09 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2011 HIPAA breaches]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[HIPAA violation]]></category>
		<category><![CDATA[sutter health hipaa breach]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3992</guid>
		<description><![CDATA[The Sutter Health HIPAA breach of 3.3 million patient demographic data from 1995 to January 2011 was recently reported &#8211; and an additional 943,000 patients from the Sutter Medical Foundation were also affected (both demographic and medical diagnosis data). Twenty-one total healthcare providers were also affected. Sutter Health is a not-for-profit network of doctors, hospitals [...]]]></description>
			<content:encoded><![CDATA[<p>The Sutter Health HIPAA breach of 3.3 million patient demographic data from 1995 to January 2011 was recently reported &#8211; and an additional 943,000 patients from the Sutter Medical Foundation were also affected (both demographic and medical diagnosis data). Twenty-one total <a href="http://www.sutterhealth.org/noticeforpatients/list-of-providers.html">healthcare providers</a> were also affected. Sutter Health is a not-for-profit network of doctors, hospitals and care providers.</p>
<p>A couple key points and lessons learned are noted:</p>
<p><strong>Encryption</strong>: the breach was a result of physical theft at the Sutter Medical Foundation’s administrative offices. A rock used to break the window allowed a thief to make off with an unencrypted desktop computer housing a patient database of information (although the company was in the process of encrypting their data at the time of theft, starting primarily with hand-held devices). Encryption is viewed as a common and recommended best practice in cases of sensitive data storage, and is a must for HIPAA covered entities.</p>
<p><strong>Data Storage</strong>: Keeping a large amount of protected health information (PHI) unencrypted and easily accessible on a desktop computer is not considered the most secure form of data storage. As I blogged about in early August (see <a href="http://resource.onlinetech.com/2011-hipaa-violations-and-audits/">2011 HIPAA Violations infographic</a>), HHS.gov records show the most common type of HIPAA violations by number of instances is due to physical theft (49 percent). <a href="http://www.onlinetech.com/cloud-computing-hosting">Cloud computing</a>, whether the <a href="http://www.onlinetech.com/cloud-computing-hosting/private-cloud-hosting-packages">private cloud</a> or the <a href="http://www.onlinetech.com/cloud-computing-hosting/managed-cloud-hosting">managed cloud</a>, can offer increased security with the use of firewalls, Intrusion Detection and Protection Systems (IDS/IPS), access authentication and more.</p>
<p><strong>Patient notification</strong>: Although the data theft was stolen over the weekend of October 15, the patients and the public were not <a href="http://www.sutterhealth.org/noticeforpatients/">notified</a> until a month later (last Wednesday). In addition, according to ModernHealthCare.com, a Sutter Health spokeswoman is not planning to notify the 3.3 million affected patients directly, and some patients might not receive notice by mail until early next month.</p>
<p>Earlier this year, the <a href="http://resource.onlinetech.com/lost-military-backup-tapes-results-in-hipaa-violation-affecting-4-9-million/">TRICARE/SAIC HIPAA breach</a> affected a record 4.9 million military patients of the San Antonio area &#8211; the stolen military backup tapes were also unencrypted.</p>
<p>HIPAA compliance is a result of a combination of technology, policies and procedures &#8211; if you’re uncertain about what <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> for your protected health information (PHI) should entail, see our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a> for more answers.</p>
<p><a href="http://www.modernhealthcare.com/article/20111117/NEWS/311179957/sutter-health-stolen-computer-contained-info-on-4-2-million#">Sutter Health: Stolen Computer Contained Info on 4.2 Million</a><br />
<a href="http://www.huffingtonpost.com/2011/11/18/medical-record-theft_n_1101235.html">Medical Record Theft at Sutter Health Part of Wider Problem</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/sutter-health-hipaa-breach-lessons-learned/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>CMS Announces HIPAA 5010 Enforcement Deadline Extension</title>
		<link>http://resource.onlinetech.com/cms-announces-hipaa-5010-enforcement-deadline-extension/</link>
		<comments>http://resource.onlinetech.com/cms-announces-hipaa-5010-enforcement-deadline-extension/#comments</comments>
		<pubDate>Fri, 18 Nov 2011 17:10:17 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[hipaa 5010 deadline]]></category>
		<category><![CDATA[hipaa 5010 enforcement]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3981</guid>
		<description><![CDATA[The Centers for Medicare &#38; Medicaid Services (CMS) announced Thursday the extension of the HIPAA 5010 deadline &#8211; enforcement will begin March 31, 2012 instead of the January 1, 2012. This gives HIPAA covered entities (any healthcare organization that processes, stores or transfers any type of patient health information, PHI) an extra three months to prepare [...]]]></description>
			<content:encoded><![CDATA[<p>The Centers for Medicare &amp; Medicaid Services (CMS) <a href="http://www.cms.gov/ICD10/Downloads/CMSStatement5010EnforcementDiscretion111711.pdf">announced</a> Thursday the extension of the HIPAA 5010 deadline &#8211; enforcement will begin March 31, 2012 instead of the January 1, 2012. This gives HIPAA covered entities (any healthcare organization that processes, stores or transfers any type of patient health information, PHI) an extra three months to prepare for the full transition to the HIPAA 5010 upgrade.</p>
<p>The deadline extension comes in the wake of a recent survey by the Medical Group Management Association (MGMA) as reported by HealthcareITNews.com which found that only 4.5 percent of respondents would rate their 5010 implementation as fully complete. This discrepancy between time before the original deadline and the actuality of HIPAA covered entity readiness called for action, and the CMS responded with news of the enforcement delay.</p>
<p>The specific office that handles HIPAA compliance enforcement is the Office of E-Health Standards and Services (OESS), within the U.S. Department of Health and Human Services (HHS). The CMS press release reports that the OESS will continue to accept HIPAA 5010 complaints during the three month period, but enforcement will not begin until after March 31.</p>
<p>However, no penalties will be applied between January and March if the covered entity takes corrective action to resolve complaints, or shows a good faith effort toward HIPAA compliance.</p>
<p>The OESS also urges HIPAA covered entities to contact and schedule the compliance upgrade with their trading partners on a timely basis to meet the new enforcement deadline. This is also a good time to check with your third-party hosting provider if they are providing <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> services to avoid any upcoming penalties (see <a href="http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/">2011-2012 HIPAA Audits Have Begun: Are You Ready to Prove HIPAA Compliance?</a> for information and tips on the ongoing HIPAA audit schedule and process).</p>
<p>The American Medical Assocation (AMA) also provides a preparatory fact sheet on planning and tactically implementing HIPAA 5010 on a schedule, which you can find on my other blog post, <a href="http://resource.onlinetech.com/hipaa-5010-deadline-approaching-taking-steps-toward-implementation/">HIPAA 5010 Deadline Approaching: Taking Steps toward Implementation</a>.</p>
<p>The CMS provides more resources on ICD-10 (standards for diagnosis and inpatient procedure coding) and HIPAA 5010 on their <a href="http://www.cms.gov/ICD10/">site</a>. This handy <a href="http://www.cms.gov/ICD10/Downloads/w5010BasicsFctSht.pdf">fact sheet</a> (PDF) from CMS also provides a summary of the upgraded standards (although the deadline portion still needs to be updated).</p>
<p>Source:<br />
<a href="http://www.ihealthbeat.org/articles/2011/11/17/cms-to-delay-enforcement-of-hipaa-5010-transaction-sets.aspx">CMS To Delay Enforcement of HIPAA 5010 Transaction Sets</a><br />
<a href="http://www.cms.gov/ICD10/Downloads/CMSStatement5010EnforcementDiscretion111711.pdf">CMS Press Release: Announcing 90-Day Period of Enforcement Discretion for Compliance with New HIPAA Transaction Standards</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cms-announces-hipaa-5010-enforcement-deadline-extension/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Media, Healthcare IT and HIPAA Law: 2011 Update</title>
		<link>http://resource.onlinetech.com/social-media-healthcare-it-and-hipaa-law-2011-update/</link>
		<comments>http://resource.onlinetech.com/social-media-healthcare-it-and-hipaa-law-2011-update/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 17:17:18 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2011 hipaa breach]]></category>
		<category><![CDATA[2011 hipaa violation]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violations]]></category>
		<category><![CDATA[HITECH breach]]></category>
		<category><![CDATA[social media]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3948</guid>
		<description><![CDATA[Tatiana Melnik and Brian Balow from Dickinson Wright have shared a presentation on Social Media, Healthcare and the Law: 2011 Update from their Midwest HIMSS Fall Technology Conference 2011 breakout session. The 84-page, highly informative presentation includes social media updates and respective legal issues, as well as advice on revisions to social media policies – [...]]]></description>
			<content:encoded><![CDATA[<p>Tatiana Melnik and Brian Balow from Dickinson Wright have shared a presentation on <em><strong>Social Media, Healthcare and the Law: 2011</strong></em><strong> <em>Update</em></strong> from their Midwest HIMSS Fall Technology Conference 2011 breakout session.</p>
<div id="attachment_3965" class="wp-caption alignleft" style="width: 240px"><img class="size-full wp-image-3965 " title="Legal Issues with Social Media" src="http://resource.onlinetech.com/wp-content/uploads/Legal-Issues-with-Social-Media.png" alt="Legal Issues with Social Media" width="230" height="172" /><p class="wp-caption-text">Legal Issues with Social Media</p></div>
<p>The 84-page, highly informative presentation includes social media updates and respective legal issues, as well as advice on revisions to social media policies – and a plethora of HIPAA breach statistics and advice on how to stay<a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting"> HIPAA compliant</a>.</p>
<p>Other presentation highlights include:</p>
<ul>
<li>Statistics on the general use of YouTube, Facebook, Twitter and blogs by hospitals and healthcare</li>
<li>Specific protected health information (PHI) leak incidents as a direct result of using social media in Midwest states, including Iowa, Michigan, Minnesota and Wisconsin</li>
<li>Certain incidents that prompt the Department of Justice or Attorneys’ General to prosecute</li>
<li>FBI cases specifically associated with HIPAA violations</li>
<li>Appeals, settlements and status of ongoing HIPAA breach lawsuits</li>
<li>Statistics on HIPAA complaints and the OCR’s role (either requiring corrective actions by covered entities or cases in which the OCR found no violation)</li>
<li>Most common HIPAA complaint issues</li>
<li>A basic overview of who is under HITECH breach obligations and required actions</li>
<li>2011 HIPAA breach facts and Midwest statistics by state</li>
<li>The cost per HIPAA breach record according to breach type, and how it’s changed from 2009-2010</li>
<li>Formulating a social media policy – who it protects, why it’s important to have, and how to maintain and enforce the policies</li>
<li>Links to more resources and examples of established policies and best practices from clinics and medical centers</li>
</ul>
<p>Download or view the PDF presentation, <a href="http://resource.onlinetech.com/presentations/Social-Media-Healthcare-and-the-Law-2011-Update.pdf" target="_blank">Social Media, Healthcare and the Law: 2011 Update.</a></p>
<p>Melnik also recently discussed the legal implications of BAAs (Business Associate Agreements) when patient information is shared, processed or stored between companies in <em><strong><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance/sharing-phi-data-legal-implications-of-baas-a-avoiding-hipaa-pitfalls">Sharing PHI Data? Legal Implications of BAAs &amp; Avoiding HIPAA Pitfalls</a></strong></em>, the third HIPAA webinar in a webinar series hosted by Online Tech, <em><strong><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">A to Z to Achieving HIPAA Compliance</a>.</strong></em></p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 2px;" />
<p><img style="float: left; margin: 0 15px 0 5px;" src="http://www.onlinetech.com/images/stories/people/tatiana-melnik-100.jpg" alt="Brian_Foley_Head_Shot_Thumb" width="100" height="150" /></p>
<p><strong>Tatiana Melnik, Attorney, Dickinson Wright PLLC</strong></p>
<p>Tatiana Melnik is an attorney with the <a href="http://www.dickinsonwright.com/">Dickinson Wright law firm</a> where her practice focuses on information technology, healthcare information technology, intellectual property and privacy issues. Ms. Melnik sits on the Michigan Bar Information Technology Law Council, the Automation Alley Information Technology Committee, and is a Managing Editor of the Nanotechnology Law &amp; Business Journal.</p>
<p>Ms. Melnik holds a JD from the University of Michigan Law School, and a BS in Information Systems and BBA in International Business, both from the University of North Florida. Ms. Melnik regularly writes and speaks on issues surrounding healthcare information technology.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 2px; margin-top: 20px;" />
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/social-media-healthcare-it-and-hipaa-law-2011-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why It’s More Essential Than Ever To Have A Disaster Recovery Plan In Place</title>
		<link>http://resource.onlinetech.com/why-it%e2%80%99s-more-essential-than-ever-to-have-a-disaster-recovery-plan-in-place/</link>
		<comments>http://resource.onlinetech.com/why-it%e2%80%99s-more-essential-than-ever-to-have-a-disaster-recovery-plan-in-place/#comments</comments>
		<pubDate>Wed, 16 Nov 2011 16:55:34 +0000</pubDate>
		<dc:creator>Aaron Riddle</dc:creator>
				<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[cold site DR]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[SAN-to-SAN replication]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3944</guid>
		<description><![CDATA[No company is exempt from a disaster. Google has had outages in their Docs, Gmail, and other applications that have affected millions of users who use their services on an everyday basis. In April 2011, Sony was attacked when hackers got access to over 77 million users’ personal information, including credit card numbers through its [...]]]></description>
			<content:encoded><![CDATA[<p>No company is exempt from a disaster. Google has had outages in their Docs, Gmail, and other applications that have affected millions of users who use their services on an everyday basis.</p>
<p>In April 2011, Sony was attacked when hackers got access to over 77 million users’ personal information, including credit card numbers through its PSN Network.</p>
<p>Big or small, it’s inevitable that your company will experience some sort of disaster in its lifetime. However, having a plan in place can determine if you’ll be operational after the fact.</p>
<p>Here are some IT disaster recovery statistics:</p>
<ul>
<li>Less than 50% of all organizations have a business continuity plan in place.</li>
<li>43% of companies that do have a business continuity plan do not test it annually.</li>
<li>50% of businesses experiencing a computer outage will be forced to close within five years.</li>
<li>90% of businesses losing data from a disaster are forced to shut down within two years.</li>
</ul>
<p>There are many different kinds of disaster recovery options (Onsite/<a href="http://www.onlinetech.com/managed-services/offsite-backup">Offsite Backup</a>, Cold/Warm/Hot Site DR, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/san-to-san-replication">SAN-to-SAN Replication</a>, <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">DR Now!</a>) that can accommodate organizational needs. Each one of these options have their pros and cons, but having any sort of option in place is better than no option at all.</p>
<p>Disasters can come in a multitude of ways. Hurricanes, earthquakes, and tornadoes are just a few kinds of natural disasters that could strike your business at anytime without warning. Although utilizing <a href="http://www.onlinetech.com/colocation/michigan-colocation">Michigan Colocation</a> is a viable option for its location and decreased risk of these kind of disasters, having a disaster recovery plan in place is still very essential.</p>
<p>When a disaster hits any company, time is of the essence and it’s critical to make sure that your company is sticking to the plan that you have in place. Those first few hours, minutes and  seconds are essential to a company and you need to have professionals and procedures in place to prevent any sort of disaster from getting out of hand.</p>
<p>We live in a world where technology is significantly shaping the way we do business. With our heavy reliance on technology, companies need to have a <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT Disaster Recovery</a> plan in place to ensure that your company will be able to survive any sort of disaster and stay afloat.</p>
<div>
<p>For more information, check out one of our recent webinars with Steven Gold of SJG Consultants on <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/how-a-small-incident-turns-into-a-major-disaster">How a Small Incident Turns Into a Major Disaster</a>.</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/why-it%e2%80%99s-more-essential-than-ever-to-have-a-disaster-recovery-plan-in-place/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Midwest HIMSS 2011 Live Blogging</title>
		<link>http://resource.onlinetech.com/midwest-himss-2011-live-blogging/</link>
		<comments>http://resource.onlinetech.com/midwest-himss-2011-live-blogging/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 12:00:03 +0000</pubDate>
		<dc:creator>April Sage</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIMSS]]></category>
		<category><![CDATA[live blogging]]></category>
		<category><![CDATA[Midwest HIMSS conference]]></category>
		<category><![CDATA[technology conference]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3894</guid>
		<description><![CDATA[Tweeting about #HIMSS? Join us in the conversation on Online Tech&#8217;s Twitter. Day 1: Monday, November 14, 2011 9:15 AM - After a tailgating party last night &#8211; complete with games, flatscreens, and great tailgating food, this morning&#8217;s early morning jog through downtown Indianapolis got the HIMSS Midwest Conference off to a healthy start. The first play of [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><img class="alignleft size-full wp-image-3936" title="Twitter Icon" src="http://resource.onlinetech.com/wp-content/uploads/Twitter-Icon.png" alt="Twitter Icon" width="126" height="34" />Tweeting about <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Elinkedin%2Ecom%2Fsignal%2F%3Fkeywords%3D%2523HIMSS&amp;urlhash=yYWy&amp;_t=NUS_UNIU_SHARE-lnk&amp;trk=NUS_UNIU_SHARE-lnk" target="_blank">#HIMSS</a>? Join us in the conversation on <a href="http://twitter.com/#!/OnlineTech">Online Tech&#8217;s Twitter</a>.</p></blockquote>
<p><strong>Day 1: Monday, November 14, 2011</strong></p>
<p><strong>9:15 AM</strong> - After a tailgating party last night &#8211; complete with games, flatscreens, and great tailgating food, this morning&#8217;s early morning jog through downtown Indianapolis got the HIMSS Midwest Conference off to a healthy start.</p>
<p>The first play of the day now in session: <em>Beyond Meaningful Use—Transforming our Healthcare System,</em> presented by C. Martin Harris, MD, CIO and Chairman of the Cleveland Clinic.</p>
<p><strong>11:50 AM</strong> - Dr. Martin Harris, head of Cleveland Clinic, shared the most expensive type of healthcare mistake at Midwest <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Elinkedin%2Ecom%2Fsignal%2F%3Fkeywords%3D%2523HIMSS&amp;urlhash=yYWy&amp;_t=NUS_UNIU_SHARE-lnk&amp;trk=NUS_UNIU_SHARE-lnk" target="_blank">#HIMSS</a> : incomplete medical records.</p>
<p><strong>Day 2: Tuesday, November 15, 2011</strong></p>
<p><strong>10:14 AM</strong> - Check out Online Tech&#8217;s <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> solutions at Booth 57 (complimentary coffee available!):</p>
<div id="attachment_3925" class="wp-caption aligncenter" style="width: 503px"><img class="size-full wp-image-3925    " title="Midwest HIMSS OT Booth" src="http://resource.onlinetech.com/wp-content/uploads/Midwest-HIMSS-OT-Booth.jpg" alt="Midwest HIMSS OT Booth" width="493" height="370" /><p class="wp-caption-text">Midwest HIMSS Online Tech Booth</p></div>
<p><strong>10:48 AM</strong> - Mike Kroon and Bill Ryan of Online Tech deep in conversation at the Midwest HIMSS conference:</p>
<div id="attachment_3929" class="wp-caption aligncenter" style="width: 522px"><img class="size-full wp-image-3929 " title="Midwest HIMSS Conversation" src="http://resource.onlinetech.com/wp-content/uploads/Midwest-HIMSS-Conversation.png" alt="Midwest HIMSS Conversation" width="512" height="382" /><p class="wp-caption-text">Midwest HIMSS Conversation</p></div>
<p><strong>11:15 AM</strong> - Online Tech Sponsors the 2011 Midwest HIMSS Fall Technology conference:</p>
<div id="attachment_3940" class="wp-caption aligncenter" style="width: 519px"><img class="size-full wp-image-3940  " title="Online Tech Sponsors Midwest HIMSS" src="http://resource.onlinetech.com/wp-content/uploads/Online-Tech-Sponsors-Midwest-HIMSS.png" alt="Online Tech Sponsors Midwest HIMSS" width="509" height="378" /><p class="wp-caption-text">Online Tech Sponsors 2011 Midwest HIMSS Fall Technology Conference</p></div>
<p><strong>11:30</strong> &#8211; Learning about <em>Social Media, Healthcare, &amp; the Law</em> @ <a href="http://www.linkedin.com/redirect?url=http%3A%2F%2Fwww%2Elinkedin%2Ecom%2Fsignal%2F%3Fkeywords%3D%2523HIMSS&amp;urlhash=yYWy&amp;_t=NUS_UNIU_SHARE-lnk&amp;trk=NUS_UNIU_SHARE-lnk" target="_blank">#HIMSS</a> Indy w/ attorneys Brian Balow &amp; Tatiana Melnik.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/midwest-himss-2011-live-blogging/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Six Steps to Transition to the Private Cloud</title>
		<link>http://resource.onlinetech.com/six-steps-to-transition-to-the-private-cloud/</link>
		<comments>http://resource.onlinetech.com/six-steps-to-transition-to-the-private-cloud/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 11:00:03 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[IT disaster recovery plan]]></category>
		<category><![CDATA[managed cloud computing]]></category>
		<category><![CDATA[managed cloud hosting]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[private cloud hosting]]></category>
		<category><![CDATA[SAN]]></category>
		<category><![CDATA[SAN-SAN replication]]></category>
		<category><![CDATA[transitioning to the cloud]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3759</guid>
		<description><![CDATA[When a company decides they want to transition to a private cloud, there are a few important steps they need to take to get started: In-house vs. outsource – The first step is to decide if you want to keep your IT in-house or outsource your IT services to a managed cloud or data center [...]]]></description>
			<content:encoded><![CDATA[<p>When a company decides they want to transition to a <a href="http://www.onlinetech.com/cloud-computing-hosting/private-cloud-hosting-packages">private cloud</a>, there are a few important steps they need to take to get started:</p>
<ol>
<li><strong>In-house vs. outsource</strong> – The first step is to decide if you want to keep your IT in-house or outsource your IT services to a <a href="http://www.onlinetech.com/cloud-computing-hosting/managed-cloud-hosting">managed cloud</a> or data center provider. If you have difficulty deciding, first answer &#8211; Do you have the expertise or experience with virtualization to do it yourself, or would it be best to outsource to a specialized company?</li>
<li><strong>Determine IT costs and plan</strong> – Weigh your company’s current strategic IT mission and plan, cost, and the security and resiliency need for your applications. This is critical to the next two steps, when determining your server and platform specs.</li>
<li><strong>Review specs of your host server </strong>– Decide on a uniform processor speed, since parity in all of your host server boxes is important. While it’s easy to add more RAM or a new processor, adding or replacing local disk can be more complex.</li>
<li><strong>Review specs of your virtualization platform </strong>– Do you want the comfort of using a well-known brand name such as VMware, or do you need something more affordable like Microsoft’s Hyper-V? Consider your IT budget.</li>
<li><strong>Consider using a SAN (Storage Area Network) </strong>– If you consolidate all of your data on your virtual servers to a single storage platform, you’ll have the capability to move virtual servers from one box to another, allowing for optimal use of your server resources. You can monitor, configure and manage automatically; as well as enable automatic failover to another host should one host fail.</li>
<li><strong>Implement an IT disaster recovery plan </strong>– Determine what level of disaster protection your data needs – consider <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a> in a separate location in the event that something happens to your primary site. If you’ve chosen an outsourced private cloud, your provider may have a cost-effective <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/comprehensive-disaster-recovery">cloud disaster recovery</a> plan available. <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/san-to-san-replication">SAN-to-SAN replication</a> can also deliver fast recovery times and failback to production.</li>
</ol>
<p>While setting up the cloud, whether a managed or a private cloud, the most important fact is your cloud doesn’t have to be built in one day – you always have the flexibility to customize, scale up or down, and add hosts to align with company demand. The great part about a cloud is the ability to grow without replacing old hardware or wasting capital.</p>
<p>Consider taking the first few steps to adopting the cloud to realize cost savings, fast server deployment, and disaster recovery options.</p>
<p>Get more details on <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing/the-road-to-the-private-cloud-how-to-make-the-transition">The Road to the Private Cloud: How to Make the Transition</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/six-steps-to-transition-to-the-private-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What’s Your 2012 IT Disaster Recovery Plan?</title>
		<link>http://resource.onlinetech.com/what%e2%80%99s-your-2012-it-disaster-recovery-plan/</link>
		<comments>http://resource.onlinetech.com/what%e2%80%99s-your-2012-it-disaster-recovery-plan/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 15:52:28 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[2012 disaster recovery plan]]></category>
		<category><![CDATA[2012 IT disaster recovery]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[disaster recovery plan]]></category>
		<category><![CDATA[IT disaster recovery plan]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[private cloud computing]]></category>
		<category><![CDATA[private cloud hosting]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3902</guid>
		<description><![CDATA[Do you think you’re ready for a disaster to hit in the upcoming year? Can your business survive the impact, and are you prepared to recover all of your applications and data quickly and accurately? Most businesses just don’t think it’ll happen to them &#8211; when in actuality, disasters happen more often than we think. [...]]]></description>
			<content:encoded><![CDATA[<p>Do you think you’re ready for a disaster to hit in the upcoming year? Can your business survive the impact, and are you prepared to recover all of your applications and data quickly and accurately?</p>
<p>Most businesses just don’t think it’ll happen to them &#8211; when in actuality, disasters happen more often than we think. A study by research firm Forrester dispels the myth that disaster declarations are rare occurrences with the statistic that 27 percent of companies had declared at least one disaster during the past five years, in a Global Disaster Recovery Preparedness Online Survey.</p>
<div id="attachment_3903" class="wp-caption aligncenter" style="width: 515px"><img class="size-full wp-image-3903 " title="Disaster Declarations" src="http://resource.onlinetech.com/wp-content/uploads/Disaster-Declarations.jpg" alt="Disaster Declarations" width="505" height="370" /><p class="wp-caption-text">Disaster Declarations</p></div>
<p>Although 73 percent had no declarations of disaster, 14 percent declared one disaster event in the past five years, and 5 percent experienced more than five disasters. These companies had to not only declare a disaster, but they also had to recover operations at their recovery site.</p>
<p>Another myth the Forrester study dispels is the idea that natural disasters, like hurricanes, tornadoes and earthquakes, are the most common cause of downtime for a company. In actuality, power, IT and network failures are the most common causes.</p>
<p>The survey question asked, “What was the cause of your most significant disaster declaration(s) or major business disruption?” The respondents attributed downtime to<strong> power failure, IT hardware failure, network failure, IT software failure and human error</strong> as the top five most common causes, while floods, other, hurricanes, fires, etc. ranked lower on the list.</p>
<div id="attachment_3904" class="wp-caption aligncenter" style="width: 515px"><img class="size-full wp-image-3904 " title="Causes of Downtime" src="http://resource.onlinetech.com/wp-content/uploads/Causes-of-Downtime.jpg" alt="Causes of Downtime" width="505" height="391" /><p class="wp-caption-text">Causes of Downtime</p></div>
<p>If your disaster can be attributed to things you can control, like choosing a more reliable IT company to host your critical data and applications with, then it may be worth the initial investment. Symantec’s 2011 SMB Disaster Preparedness Survey estimates the average cost of downtime for a small-to-medium business is $12,500 per day.</p>
<p><strong>What can you do to be prepared for a costly disaster in 2012?</strong></p>
<p><strong>Problem: Power Failures</strong><br />
<strong>Solution</strong>: Partner with an IT company that has a N+1 or redundant power infrastructure to avoid a power failure. Check to see if your data center provider has backup power sources &#8211; a pooled UPS, battery and generator power systems can be effective against outages.</p>
<p><strong>Problem: IT Hardware &amp; Software Failure</strong><br />
<strong>Solution</strong>: What causes hardware and software failure? While many factors play a part, lack of maintenance or improper maintenance of your hardware can lead to failures and downtime. Often you or your IT staff might not be able to pay full attention to all of the necessary upgrades, patches and fixes in a timely manner if you’re busy focusing on your applications or other business goals. Handing over the reins to a certified, experienced IT support team that devote their days to managing your servers can be the simple (and effective) solution.</p>
<p><strong>Problem: Network Failure</strong><br />
<strong>Solution</strong>: Protect against network failure by choosing a quality, fully replicated network infrastructure design. Ask your IT company how often and closely they manage their networks &#8211; while the setup and design can be quality, the support provided is also important to ensure high availability of your data and applications.</p>
<p>Hosting your data at a company that offers multiple Internet providers (ISPs) with diverse entry paths can also help eliminate network downtime. In the event of a disaster, the network will automatically failover between providers to ensure you’re always connected without server interruptions.</p>
<p><strong>Problem: Human Error</strong><br />
<strong>Solution:</strong> It happens. But why not cut down on it as much as possible by outsourcing your hosting project to a team of certified professionals that are dedicated to providing unlimited, 24&#215;7 support? Make sure your data center hosting provider has an asset and change management system that can track and record all changes and corrective actions to the network, servers and OS so you can keep tabs on your server maintenance. Or, use a remote server monitoring system to have complete visibility into your server(s) status.</p>
<p>In addition to investing smart, your company needs a comprehensive <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> plan in place. Choose a plan that is affordable and reliable with a fast recovery time &#8211; beware of traditional disaster recovery plans that require error-prone tape backup.</p>
<p><strong>The Complete Solution: Disaster Recovery in the Cloud</strong></p>
<p>Disaster recovery in the cloud is the latest and most reliable solution that also happens to cost less than half of the production environment. It’s considered more reliable because the entire hosted cloud (including servers, software, network configuration and security) are replicated to an offsite disaster recovery cloud.</p>
<p>Plus, it’s faster &#8211; recovering your servers, apps and data into a cold site environment is entirely replaced by only a few clicks to spin up the replicated servers. Online Tech’s <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">disaster recovery cloud</a> solution (DR Now!) has a warranted 4 hour recovery time objective, specifying the worst case availability in case of a disaster. Our <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a> and <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a> audited data centers prove we follow standardized processes to cut down on human error and power, network, hardware and software failure.</p>
<p>Don’t gamble with your chances of declaring a disaster and potentially losing critical data and applications &#8211; protect your company by making an educated investment in an updated 2012 disaster recovery plan.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/what%e2%80%99s-your-2012-it-disaster-recovery-plan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming HIPAA and Health IT Event: 2011 Midwest HIMSS Fall Technology Conference</title>
		<link>http://resource.onlinetech.com/upcoming-hipaa-and-health-it-event-2011-midwest-himss-fall-technology-conference/</link>
		<comments>http://resource.onlinetech.com/upcoming-hipaa-and-health-it-event-2011-midwest-himss-fall-technology-conference/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 20:49:00 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA conferences]]></category>
		<category><![CDATA[HIPAA events]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3881</guid>
		<description><![CDATA[This Sunday, Online Tech is heading down to Indiana for the Midwest HIMSS Fall Technology Conference to join hundreds of healthcare and health IT professionals for breakout sessions, keynote speakers and vendor exhibits. As a conference sponsor, we’ll be representing our HIPAA compliant hosting solutions and joining the discussion on Building a Winning Team &#8211; Strategies [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_3882" class="wp-caption aligncenter" style="width: 548px"><img class="size-full wp-image-3882" title="HIMSS 10" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-10.png" alt="HIMSS 10" width="538" height="357" /><p class="wp-caption-text">HIMSS 10</p></div>
<p>This Sunday, Online Tech is heading down to Indiana for the Midwest HIMSS Fall Technology Conference to join hundreds of healthcare and health IT professionals for breakout sessions, keynote speakers and vendor exhibits.</p>
<div>
<p>As a conference sponsor, we’ll be representing our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> solutions and joining the discussion on <em>Building a Winning Team &#8211; Strategies for Healthcare IT Success</em> (stop by Booth 57 for coffee!).</p>
<p>Keynote speakers include the U.S. Department of Health and Human Services Chief Technology Officer (CTO), Todd Park, and several other CIO’s and leading healthcare IT professionals.</p>
<p>Dickinson Wright Attorney Tatiana Melnik will be leading a breakout session on <em>Social Media, Healthcare and the Law: 2011 Update</em> Tuesday, November 15 at 11AM. Watch Melnik’s most recent HIPAA webinar, <em><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance/sharing-phi-data-legal-implications-of-baas-a-avoiding-hipaa-pitfalls">Sharing PHI Data? Legal Implications of BAAs &amp; Avoiding HIPAA Pitfalls</a></em>, hosted by Online Tech.</p>
</div>
<div>
<p>The conference is hosted by the Healthcare Information and Management Systems Society (HIMSS), one of the 49 affiliated chapters of HIMSS, a not-for-profit organization intended to provide a forum to discuss emerging healthcare IT issues.</p>
<p>HIMSS represents 53 chapters across the U.S., Canada and India, and the Midwest HIMSS represents the chapters of Chicago, Indiana, Iowa, Michigan, Minnesota and Wisconsin.</p>
<p>For more information: <a href="http://www.falltechnologyconference2011.com/">Midwest HIMSS conference site</a> or view the <a href="http://www.falltechnologyconference2011.com/PlaybookFINAL.pdf">Conference Playbook</a> (pdf).</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/upcoming-hipaa-and-health-it-event-2011-midwest-himss-fall-technology-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Study on Cloud Computing Security: Managing Firewall Risks</title>
		<link>http://resource.onlinetech.com/study-on-cloud-computing-security-managing-firewall-risks/</link>
		<comments>http://resource.onlinetech.com/study-on-cloud-computing-security-managing-firewall-risks/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 12:00:00 +0000</pubDate>
		<dc:creator>Steve VanTil</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cloud computing security]]></category>
		<category><![CDATA[cloud firewall risk]]></category>
		<category><![CDATA[cloud firewall security]]></category>
		<category><![CDATA[cloud firewalls]]></category>
		<category><![CDATA[cloud port security]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[dedicated cloud security]]></category>
		<category><![CDATA[hybrid cloud security]]></category>
		<category><![CDATA[managed cloud security]]></category>
		<category><![CDATA[private cloud security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3826</guid>
		<description><![CDATA[A recent cloud computing security study conducted by the Poneman Institute and sponsored by Dome9 reveals that 67 percent of IT professionals claim their organization is left vulnerable to hackers due to lax cloud port and firewall security. Fifty-two percent of respondents rated their organization’s overall cloud server security management as fair (27 percent) or [...]]]></description>
			<content:encoded><![CDATA[<p>A recent <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing security</a> study conducted by the Poneman Institute and sponsored by Dome9 reveals that 67 percent of IT professionals claim their organization is left vulnerable to hackers due to lax cloud port and firewall security. Fifty-two percent of respondents rated their organization’s overall cloud server security management as fair (27 percent) or poor (25 percent).</p>
<p>In addition, 54 percent of respondents to the study said their IT staff had no knowledge about the potential risks of open firewall ports in their cloud environments. These significant statistics show a major lack of security concerns among IT personnel that ultimately affect clients’ data and applications in the cloud.</p>
<p>Even more alarming are the 42 percent of the respondents that fear they wouldn’t know if their data or applications on their cloud were actually compromised or if a data breach occurred, involving an open port on a cloud server.</p>
<div id="attachment_3873" class="wp-caption aligncenter" style="width: 578px"><img class="size-full wp-image-3873 " title="Cloud Security-Managing Firewall Risks" src="http://resource.onlinetech.com/wp-content/uploads/Cloud-Security-Managing-Firewall-Risks.jpg" alt="Cloud Security: Managing Firewall Risks" width="568" height="424" /><p class="wp-caption-text">Cloud Security: Managing Firewall Risks</p></div>
<p>The study “Cloud Security: Managing Firewall Risks” analyzed responses from IT and IT security professionals working in the U.S. that use hosted or cloud servers (dedicated or virtual private servers). And these aren’t novice IT personnel – on average, the respondents had more than 10 years of experience and almost half worked at organizations with 5,000 employees across the globe. The majority of the respondents reported that their organizations used both public and <a href="http://www.onlinetech.com/cloud-computing-hosting/hybrid-cloud-hosting">hybrid clouds</a>.</p>
<p>Transparency is also a prevailing issue. The study reports that 36 percent of respondents claim their organizations cannot manage access or generate reports efficiently, while 29 percent say they manage access through the cloud provider’s tools but can’t see any access reports.</p>
<p><strong>My response  and advice to cloud users, as the Senior Systems Engineer at Online Tech:</strong></p>
<p>Cloud security is and will always be a hot topic. Firewall rules and public cloud management ports are the major concern. If you are educated in what the cloud provider has in place, you can better determine their existing standards for security. Ask before you buy is the best thing you can do. With Online Tech, our dedication to transparency means every client can always see what open firewall ports they have through our client portal. The firewall rules are there for the client to both view and audit.</p>
<p>The client can request for firewall rules to be opened or closed after viewing them through our portal, meaning anything you need to block can be blocked. Port scans can be run from the outside to help you verify this as well. It is always a good idea to do port scans and secure your cloud servers as much as possible. Online Tech also has a built-in intrusion detection system to help identify and block attacks to your cloud server. You don’t want to be guessing here, and at Online Tech, we know this is important.</p>
<p>When it comes to management ports, it is all secured with SSL or VPNs. All staff access is segmented and protected via strict VPN and firewall rules. The least privilege and SSAE 16 standard processes that we have in place hold us accountable when it comes to staff access. Data traffic to SANs is on a private segment and can never be accessed from the outside.</p>
<p>If you have cloud security concerns, ask and you shall receive. This will help you make informed decisions and assess any potential risks.</p>
<p>Read our article on <a href="http://www.onlinetech.com/resources/cloud-computing-wiki/item/38-cloud-computing-security">Cloud Computing Security</a> and access our <a href="http://www.onlinetech.com/resources/cloud-computing-wiki/item/38-cloud-computing-security">Cloud Computing Wiki</a> for more information.</p>
<p>Sources:<br />
<a href="http://www.net-security.org/secworld.php?id=11882">Managing Firewall Risks in the Cloud</a><br />
<a href="http://cloudtimes.org/cloud-security-managing-firewall-risks/">Cloud Security: Managing Firewall Risks</a><br />
<a href="http://www.mitechnews.com/articles.asp?id=13826">Cloud Computing Study: 67 Percent of Companies Vulnerable to Hack</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/study-on-cloud-computing-security-managing-firewall-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2011-2012 HIPAA Audits Have Begun: Are You Ready to Prove HIPAA Compliance?</title>
		<link>http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/</link>
		<comments>http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 18:34:02 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2011 hipaa audits]]></category>
		<category><![CDATA[2012 hipaa audits]]></category>
		<category><![CDATA[hipaa audit process]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[OCR hipaa audit program]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3862</guid>
		<description><![CDATA[Back in August, I blogged about the upcoming 2011 HIPAA Violations and Audits, and news of the government’s $9.2 million contract with auditing firm KPMG. Now that the OCR has officially launched its HIPAA Audit Program, even more relevant information has been released: Who: Every covered entity and business associate is eligible (although the program [...]]]></description>
			<content:encoded><![CDATA[<p>Back in August, I blogged about the upcoming <a href="http://resource.onlinetech.com/2011-hipaa-violations-and-audits/">2011 HIPAA Violations and Audits</a>, and news of the government’s $9.2 million contract with auditing firm KPMG. Now that the OCR has officially launched its HIPAA Audit Program, even more relevant information has been released:</p>
<ul>
<li><strong></strong><strong>Who</strong>: Every covered entity and business associate is eligible (although the program site states that “Business Associates will be included in future audits,” suggesting they won’t be addressed in this audit). HHS.gov states that the OCR may consider covered individual and organizational providers of health services, health plans of sizes and functions, and healthcare clearinghouses may be considered as well.<strong><br />
</strong></li>
<li><strong>What</strong>: OCR is piloting a program to perform up to 150 audits of covered entities to assess privacy and security compliance.</li>
<li><strong>Why</strong>: To satisfy the American Recovery and Reinvestment Act of 2009 (ARRA) Section 13411 of the HITECH Act and to check compliance with HIPAA Privacy and Security Rules and Breach Notification standards.</li>
<li><strong>When</strong>: November 2011-December 2012.</li>
</ul>
<p><strong>Three Steps to the HIPAA Audit Process</strong></p>
<ol>
<li>Staged in a three-step process, the first step was developing audit protocols.</li>
<li>The second step will be the initial wave of audits in November 2011. This step will help shape how the rest of the audits will be conducted.</li>
<li>Finally, the third step will be the full range of conducted audits.</li>
</ol>
<p><strong>How Will the Audit Program Work?</strong></p>
<ol>
<li>Entities selected for an audit will be notified by the OCR and will have to provide documentation of privacy and security compliance efforts.</li>
<li>Every audit requires a <em><strong>site visit</strong></em> and an <em><strong>audit report</strong></em>.</li>
<li>Site visits will include interviews with key personnel and general observation of processes and operations to help determine compliance.</li>
<li>After the site visit, auditors will give the entity a draft report showing how the audit was conducted, audit findings, and what actions the entity is taking in response to the findings.</li>
<li>Before the report is finalized, the entity has a chance to discuss concerns and describe corrective actions taken to address those concerns.</li>
<li>Final OCR report will include the steps the entity has taken to resolve compliance issues and describe the best practices of the entity.</li>
</ol>
<p><strong>Simplified Audit Schedule</strong></p>
<div id="attachment_3863" class="wp-caption aligncenter" style="width: 472px"><img class="size-full wp-image-3863 " title="2011-2012 HIPAA Audit Timeline" src="http://resource.onlinetech.com/wp-content/uploads/HIPAA-Audit-Timeline.jpg" alt="2011-2012 HIPAA Audit Timeline" width="462" height="260" /><p class="wp-caption-text">2011-2012 HIPAA Audit Timeline</p></div>
<p><strong>What is the OCR Planning to Get From These Audits?</strong><br />
The OCR will use the audit reports to determine what types of technical assistance needs to be developed and what types of correction action are most effective.</p>
<p><strong>Need More HIPAA Guidance?</strong><br />
If you’re not sure if your hosting solution is <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a>, or if your patient health information (PHI) is being secured in a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a>, check out the <a href="http://resource.onlinetech.com/five-questions-to-ask-your-hipaa-hosting-provider/">Five Questions to Ask Your HIPAA Hosting Provider</a> to get informed.</p>
<p>Looking for more information on the latest HIPAA ongoings? Check our <a href="http://resource.onlinetech.com/tag/hipaa-compliance/">HIPAA compliance blog category</a>, <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>, or watch our recent <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">HIPAA webinars</a> to get educated on what you need to be HIPAA compliant.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2011-2012-hipaa-audits-have-begun-are-you-ready-to-prove-hipaa-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What’s in a Business Associate Agreement?</title>
		<link>http://resource.onlinetech.com/what%e2%80%99s-in-a-business-associate-agreement/</link>
		<comments>http://resource.onlinetech.com/what%e2%80%99s-in-a-business-associate-agreement/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 15:30:30 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[business associate agreement]]></category>
		<category><![CDATA[hipaa business associates]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3855</guid>
		<description><![CDATA[You’re a covered entity (your company processes, stores or transfers any type of patient information), and you’re outsourcing your HIPAA hosting services to a third party (an IT vendor, a billing company, etc.). But before you can do that, you need to sign a business associate agreement (BAA) with your business associate (BA), according to [...]]]></description>
			<content:encoded><![CDATA[<p>You’re a covered entity (your company processes, stores or transfers any type of patient information), and you’re outsourcing your <a href="file://othqdc01/Desktops/tpham/My%20Documents/index.php?option=com_k2&amp;view=item&amp;id=215&amp;Itemid=209">HIPAA hosting</a> services to a third party (an IT vendor, a billing company, etc.).</p>
<p>But before you can do that, you need to sign a business associate agreement (BAA) with your business associate (BA), according to the HIPAA Privacy Rule. But what’s in a business associate agreement contract?</p>
<p>The U.S. Department of Health and Human Resources (HHS) has a sample business associate contract available on its site listing all the provisions for those that are curious.</p>
<p>While this shouldn’t be copied precisely and is more of a guide than a complete document, it does offer insight into the general terms that a BAA should address, with the addition of customized provisions specific to certain companies’ needs.</p>
<p>A summary of the primary provisions include:</p>
<ul>
<li><strong>Obligations and Activities of Business Associate</strong>
<ul>
<li>No use or disclosure of protected health information (PHI) unless it’s permitted or required by law.</li>
<li>Must use proper safeguards to prevent use or disclosure of PHI.</li>
<li>Mitigation in the event of a data breach.</li>
<li>Must report any use or disclosure of PHI.</li>
<li>Ensures others (subcontractors) agree to the same BAA.</li>
<li>Allows CE access PHI.</li>
<li>Must create documented HIPAA policies and procedures.</li>
<li>Document any PHI disclosures.</li>
</ul>
</li>
<li><strong>Permitted Users and Disclosures by Business Associate</strong></li>
<li>
<ul>
<li>Specifies when BA can use or disclose PHI on behalf of the CE.</li>
</ul>
</li>
<li><strong>Specific Use and Disclosure Provisions (if applicable)</strong>
<ul>
<li>When or why a BA would disclose or use any PHI, to report law violations, with CE permission, or to provide any kind of data aggregation reports to the CE).<strong></strong></li>
</ul>
</li>
<li><strong>Obligations of Covered Entity</strong>
<ul>
<li>The CE will notify the BA of any changes in permission (including restrictions or revocation) of the individual to use or disclose PHI.<strong></strong></li>
</ul>
</li>
<li><strong>Permissible Requests by Covered Entity</strong>
<ul>
<li>Terms and effective dates<strong></strong></li>
<li>How PHI will be handled after termination (returned or destroyed)<strong></strong></li>
<li>Reasons for termination</li>
</ul>
</li>
</ul>
<p>If you’re a covered entity, protect your company and your patients/clients by signing a thorough BAA. As a best practice recommended for HIPAA compliance, it will only strengthen your ability to pass a HIPAA audit, should the auditors come to your door.</p>
<p>Have other questions about compliance and BAAs? Read our <a href="file://othqdc01/Desktops/tpham/My%20Documents/index.php?option=com_k2&amp;view=item&amp;id=367&amp;Itemid=491">HIPAA FAQ</a> to find answers about BAs, hosting and agreements.</p>
<p>Source:<br />
<a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractprov.html">Business Associate Contracts</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/what%e2%80%99s-in-a-business-associate-agreement/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>What to Look for in a Colocation Hosting Provider</title>
		<link>http://resource.onlinetech.com/what-to-look-for-in-a-colocation-hosting-provider/</link>
		<comments>http://resource.onlinetech.com/what-to-look-for-in-a-colocation-hosting-provider/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 20:24:14 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Colocation]]></category>
		<category><![CDATA[colocation hosting]]></category>
		<category><![CDATA[hipaa compliant colocation]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[michigan data centers]]></category>
		<category><![CDATA[pci compliant colocation]]></category>
		<category><![CDATA[sas 70 colocation]]></category>
		<category><![CDATA[soc 2 colocation]]></category>
		<category><![CDATA[soc 3 colocation]]></category>
		<category><![CDATA[ssae 16 colocation]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3832</guid>
		<description><![CDATA[When you need space, power and bandwidth and an ideal data center to house your servers, there are certain aspects you should consider while researching colocation hosting providers. Get informed in order to make the smart decision for optimal server uptime, security and service. An Ideal Location                                       You need an ideal location for server colocation [...]]]></description>
			<content:encoded><![CDATA[<p>When you need space, power and bandwidth and an ideal data center to house your servers, there are certain aspects you should consider while researching <a href="http://www.onlinetech.com/colocation">colocation hosting</a> providers. Get informed in order to make the smart decision for optimal server uptime, security and service.</p>
<p><strong>An Ideal Location                                       </strong></p>
<p>You need an ideal location for server colocation – if you’re concerned about uptime and server safety at all, you’ll need to find a data center located in a geographic region with minimal risk of natural disasters and overheating.</p>
<div id="attachment_3833" class="wp-caption alignright" style="width: 282px"><img class="size-full wp-image-3833  " title="Michigan Colocation Cool Climate" src="http://resource.onlinetech.com/wp-content/uploads/Michigan-Colocation-Cool-Climate.gif" alt="Michigan Colocation Offers Cool Climate" width="272" height="166" /><p class="wp-caption-text">Michigan Colocation Offers Cool Climate</p></div>
<p>Data center efficiency also helps reduce operational costs. Facebook recently built one of their data centers near the Arctic Circle to take advantage of a climate that offers natural cooling resources. <a href="http://www.onlinetech.com/colocation/michigan-colocation">Michigan colocation</a> is also ideal for its low risk of earthquakes, tornadoes, hurricanes, natural disasters, as well as its long winters – only four months have temperatures that average over 60 degrees Fahrenheit.</p>
<p><strong>24&#215;7 Technical Support</strong></p>
<p>To ensure your servers are up and running, you need unlimited and responsive 24&#215;7 technical support from a team of certified, experienced engineers. Managed server monitoring is also important to alert your staff and your colocation hosting provider staff of any potential server issues. Your colocation provider should also offer a troubleshooting and remediation service to identify root causes of any problems and for quick resolution.</p>
<p><strong>Full Redundancy </strong></p>
<p>A colocation facility with redundant Internet service providers (ISPs), uninterruptible power, and a well-designed network infrastructure will provide a quality environment to ensure a high level of uptime. Choosing a <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a> with multiple ISPs allows for automatic failover between providers should one provider be unavailable for any reason. N+1 power with UPS, battery and generator power systems can help protect your servers against outages and power spikes to avoid service disruptions.</p>
<p><strong>Security</strong></p>
<div id="attachment_3835" class="wp-caption alignleft" style="width: 160px"><img class="size-full wp-image-3835 " title="SOC Logo" src="http://resource.onlinetech.com/wp-content/uploads/SOC-Logo.png" alt="SSAE 16 &amp; SOC Audited Colocation" width="150" height="137" /><p class="wp-caption-text">SSAE 16 &amp; SOC Audited Colocation</p></div>
<p>Ask your colocation hosting provider if they’re <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a>, Type II and <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a> audited, and if they have a <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2</a> or <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-3-hosting">SOC 3</a> report. This is a good indicator that your provider has the standardized processes and procedures to protect your data. If you need a <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliant</a> environment (for customer credit cardholder data) or <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> (for patient health information), then you also need to ask your provider if they have the appropriate technology and procedures in place to meet compliance standards.</p>
<p>Ask if your provider has been audited to meet compliance by an auditor to protect against a potential data breach, requiring the use of firewalls, IDS (Intrusion Detection System), IPS (Intrusion Protection System), physical and logical security, etc.</p>
<p><strong>Easily Scalable</strong></p>
<p>Choose a provider that makes it easy for you to add more servers and services, like bandwidth. If your company suddenly needs room to grow, make sure your colocation hosting provider has the sufficient space, resources and business longevity to support your company’s future needs.</p>
<p><strong>Server Transparency</strong></p>
<p>For easy access and visibility into the status of your servers, your colocation hosting provider should have some type of <a href="http://www.onlinetech.com/managed-services/remote-server-monitoring">remote server monitoring</a> system to allow you to login and check your Internet bandwidth, order forms, support tickets, CPU usage, and other information to help keep your servers running optimally. This type of monitoring system allows you to have more control over your servers even if you can’t be at the data centers as well as access to your hosting provider’s tech team for their support.</p>
<p>Read more about the <a href="http://www.onlinetech.com/colocation/benefits-of-server-colocation">Benefits of Michigan Colocation</a>, or our E-Tip on <a href="http://www.onlinetech.com/resources/e-tips/michigan-colocation/michigan-colocation-making-long-distance-colocation-easy">Michigan Colocation: Making Long Distance Colocation Easy</a>.</p>
<p>Source:<br />
<a href="http://www.tomshardware.com/news/facebook-data-center-green-energy-power-consumption,13843.html">Facebook Builds Data Center Near Arctic Circle</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/what-to-look-for-in-a-colocation-hosting-provider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outage Affects North America and Europe</title>
		<link>http://resource.onlinetech.com/outage-affects-north-america-and-europe/</link>
		<comments>http://resource.onlinetech.com/outage-affects-north-america-and-europe/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 13:52:31 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[internet service outage]]></category>
		<category><![CDATA[juniper networks]]></category>
		<category><![CDATA[juniper routers]]></category>
		<category><![CDATA[level 3 communications]]></category>
		<category><![CDATA[router outage]]></category>
		<category><![CDATA[time warner outage]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3798</guid>
		<description><![CDATA[Yesterday morning, Time Warner Cable experienced “a large but brief Internet outage” affecting most of their service areas, as they reported via Twitter. Supplying high speed data services to nearly 9.7 million residential and commercial customers, the outages were reported in Washington D.C., Los Angeles, San Francisco, Raleigh, N.C., Dallas and New York &#8211; and [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday morning, Time Warner Cable experienced “a large but brief Internet outage” affecting most of their service areas, as they reported via Twitter. Supplying high speed data services to nearly 9.7 million residential and commercial customers, the outages were reported in Washington D.C., Los Angeles, San Francisco, Raleigh, N.C., Dallas and New York &#8211; and right here in Michigan.</p>
<div id="attachment_3799" class="wp-caption aligncenter" style="width: 574px"><img class="size-full wp-image-3799" title="Time Warner Outage Tweet" src="http://resource.onlinetech.com/wp-content/uploads/Time-Warner-Tweet.png" alt="Time Warner Outage Tweet" width="564" height="273" /><p class="wp-caption-text">Time Warner Outage Tweet</p></div>
<p>Online Tech experienced an issue with our own Internet service from one of our many providers between 9-9:30 AM EST, and the outage affected only a small portion of the traffic coming to and from the data centers. Our operations team also received reports of a blip in a few of our clients’ service, but never received any alerts from both Online Tech’s internal and external monitoring systems. Additionally, it could not be traced back to our equipment.</p>
<p>Then we found out the outage affected nearly everyone. The outage affected multiple service providers and appeared to have occurred sometime after 6 AM PT, and is said to be resolved according to Time Warner Cable’s tweet.</p>
<p>Even the U.K. appears to have been hit with the “global outage,” according to <a href="http://www.silicon.com/technology/networks/2011/11/07/global-outage-takes-down-sites-and-services-across-the-internet-39748193/">Silicon.com</a> &#8211; their own publishing site was affected, in addition to bit.ly, CBS interactive, and RIM’s Blackberry service. An article by <a href="http://www.businessinsider.com/weird-the-internet-just-died-for-about-30-seconds-around-the-country-2011-11">BusinessInsider.com</a> reports the outage lasted approximately 30 seconds, although some on Twitter <a href="http://www.theblaze.com/stories/did-you-lose-your-internet-this-morning-you-werent-the-only-one/internet-outage-tweet-4/">claim nearly 20 minutes of downtime</a>, as reported by TheBlaze.com.</p>
<p>According to <a href="http://www.theregister.co.uk/2011/11/07/global_net_outage/">TheRegister.CO.UK</a>, some of the outages were a result of a problem with firmware in Juniper Network routers that corrupted BGP, or border gateway protocol, tables. Level 3 Communications, Time Warner’s transit provider, is reported to have housed the routers. According to Silicon.com, the outage has also affected other networks running Juniper routers with the majority of them seeing their devices core dump and reload. Level 3 has <a href="http://www.fierceiptv.com/story/time-warner-cable-outage-traced-level-3-router-glitch/2011-11-07">issued a statement</a>:</p>
<blockquote><p>&#8220;Shortly after 9 a.m. ET today, our network experienced temporary service interruptions across North America and Europe apparently due to a router software issue,&#8221; Level 3 said in a statement. &#8220;It has been reported that a similar issue may have affected other carriers as well. Our technicians worked quickly to address the issue and service is now fully restored.&#8221;</p></blockquote>
<p>Juniper Networks has also acknowledged the routers had to be restarted when they crashed while performing a BGP update. They are offering a software fix and are currently working with their customers for deployment.</p>
<p>Time Warner Cable’s <a href="http://twitter.com/#!/TWCableHelp">twitter</a> is addressing individual issues, asking users to direct message them with their account information for assistance.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/outage-affects-north-america-and-europe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Webinar: Sharing PHI Data? Legal Implications of BAAs &amp; Avoiding HIPAA Pitfalls</title>
		<link>http://resource.onlinetech.com/free-webinar-sharing-phi-data-legal-implications-of-baas-avoiding-hipaa-pitfalls/</link>
		<comments>http://resource.onlinetech.com/free-webinar-sharing-phi-data-legal-implications-of-baas-avoiding-hipaa-pitfalls/#comments</comments>
		<pubDate>Mon, 07 Nov 2011 16:18:39 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[BAA]]></category>
		<category><![CDATA[business associate agreement]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA webinar]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[protected health information]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3790</guid>
		<description><![CDATA[Last chance to sign up for the last webinar of our three-part HIPAA webinar series, starting at 2PM ET tomorrow! Online Tech is hosting a series of free educational webinars titled “A to Z to Achieving HIPAA Compliance” running October 25 – November 8, 2011. This webinar series is helpful for healthcare organizations that interact with patient [...]]]></description>
			<content:encoded><![CDATA[<div><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance"><img title="HIPAA Compliant Webinar Series" src="http://resource.onlinetech.com/wp-content/uploads/hipaa_series_webinar_banner.gif" alt="HIPAA Compliant Webinar Series" width="560" height="192" /></a></div>
<p>Last chance to sign up for the last webinar of our three-part HIPAA webinar series, starting at 2PM ET tomorrow!</p>
<p>Online Tech is hosting a series of free educational webinars titled <strong>“A to Z to Achieving HIPAA Compliance”</strong> running October 25 – November 8, 2011. This webinar series is helpful for healthcare organizations that interact with patient information or vendors of covered entities that need guidance on becoming <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a>.</p>
<div id="attachment_3473">
<div id="attachment_3475" class="wp-caption alignleft" style="width: 110px"><img class="size-full wp-image-3475 " title="Tatiana Melnik" src="http://resource.onlinetech.com/wp-content/uploads/tatiana-melnik-100.jpg" alt="Tatiana Melnik" width="100" height="150" /><p class="wp-caption-text">Tatiana Melnik</p></div>
<p><strong>Tuesday, 11/08/11 @ 2pm ET: Sharing PHI Data? Legal Implications of BAAs &amp; Avoiding HIPAA Pitfalls</strong></p>
</div>
<p>For the third webinar of the series, special guest speaker Tatiana Melnik will cover legal implications of BAAs (Business Associate Agreement) when patient information is shared, processed, or stored between companies. “Sharing PHI Data? Legal Implications of BAAs &amp; Avoiding HIPAA Pitfalls” will start at 2 p.m. ET on Tuesday, November 8, 2011.</p>
<p>As an attorney with the Dickinson Wright law firm, Melnik’s practice focuses on information technology, healthcare information technology, and intellectual property and privacy issues. In addition to being a member of the Michigan Bar Information Technology Law Council and Automation Alley Information Technology Committee, Melnik holds a JD from the University of Michigan Law School and a BS in Information Systems and BBA in International Business from the University of North Florida. Melnik presents at the upcoming Midwest HIMSS conference in November and at the Annual HIMSS conference in February.</p>
<p><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">Register</a> today &#8211; we encourage you to submit your questions about HIPAA compliance in advance for consideration during the webinar by emailing <a href="mailto:contactus@onlinetech.com?subject=Security%20Webinar%20Series%20Question">contactus@onlinetech.com</a>.</p>
<p>If you&#8217;re looking for more HIPAA resources, try this list of <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA policies, procedures and training materials</a>, or read our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/free-webinar-sharing-phi-data-legal-implications-of-baas-avoiding-hipaa-pitfalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Key Benefits of Leasing vs. Building a Data Center</title>
		<link>http://resource.onlinetech.com/key-benefits-of-leasing-vs-building-a-data-center/</link>
		<comments>http://resource.onlinetech.com/key-benefits-of-leasing-vs-building-a-data-center/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 13:39:27 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Colocation]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[benefits of leasing data center]]></category>
		<category><![CDATA[build data center]]></category>
		<category><![CDATA[buy data center]]></category>
		<category><![CDATA[capex]]></category>
		<category><![CDATA[colocation]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[opex]]></category>
		<category><![CDATA[outsource IT]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3765</guid>
		<description><![CDATA[So your company is expanding and growing at a rapid rate, and the demand requires more space, power and cooling &#8211; what do you do? Build a new data center, or buy (lease, or outsource your IT needs to a different provider). Research firm Forrester conducted interviews of IT professionals to analyze the economics of [...]]]></description>
			<content:encoded><![CDATA[<p>So your company is expanding and growing at a rapid rate, and the demand requires more space, power and cooling &#8211; what do you do? Build a new <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a>, or buy (lease, or outsource your IT needs to a different provider).</p>
<p>Research firm Forrester conducted interviews of IT professionals to analyze the economics of data centers and the classic build vs. buy conundrum that arises when it comes time to provision for additional capacity, IT infrastructure and operations.</p>
<div id="attachment_3774" class="wp-caption alignleft" style="width: 402px"><img class="size-full wp-image-3774 " title="Ann Arbor Michigan Data Center" src="http://resource.onlinetech.com/wp-content/uploads/Ann-Arbor-Michigan-Data-Center1.png" alt="Ann Arbor Michigan Data Center" width="392" height="173" /><p class="wp-caption-text">Online Tech&#39;s New Ann Arbor Michigan Data Center</p></div>
<p><strong>Leasing a Data Center (Colocation)</strong><br />
What kind of advantages are associated with <a href="http://www.onlinetech.com/colocation">colocation</a> that you don’t get with building a data center? Forrester reports that there are very few upfront costs, and most of the expenditure is operational, not capital.</p>
<ul>
<li>More predictable expenditure model with costs that increase consistently over the life of the data center</li>
<li>Flexible &#8211; additional capacity can be scaled up as needed, no wasted extra capacity or build outs needed</li>
<li>More accessible to space and power through a provider’s purchasing power</li>
<li>Experienced and certified professionals lend their expertise of running a data center with high efficiency and high availability.</li>
</ul>
<p><strong>Building a Data Center</strong><br />
What kind of advantages are associated with building your own data center that you can’t get when you choose colocation? Mainly control:</p>
<ul>
<li>Complete control over an operating environment, including access, temperature, etc.</li>
<li>Low risk of losing your lease</li>
<li>Ability to leverage and share existing space</li>
</ul>
<p><strong>What kind of upfront costs are associated with building your own data center?</strong><br />
The detailed and practical costs of building your own data center include a fair amount of capital and upfront costs. But there are other often overlooked costs that add up quickly:</p>
<ul>
<li><strong>Upfront planning, design and commissioning</strong> &#8211; ranging from 20-25 percent of total upfront construction cost.</li>
<li><strong>Base building shell and property</strong> &#8211; only applicable if you’re not starting with an existing building. According to the Forrester report, the estimated cost of building the data center shell plus physical security $200 per square foot.</li>
<li><strong>Fire suppression and detection</strong> &#8211; ranging from $20-60,000 to purchase agents, equipment and to install systems &#8211; including early smoke detection systems, FM-200, inert gas blends, etc.</li>
<li><strong>Building permits and local taxes</strong> &#8211; while these costs vary from region to region, a moderate national estimate is $70 per square foot in building permits and taxes.</li>
<li><strong>Data center infrastructure</strong> &#8211; includes purchasing and installing mechanical equipment and electrical equipment, ranging from $7-20,000 per kW of IT load.</li>
<li><strong>Network connection cost</strong> &#8211; you’ll have to pay for fiber on-site, which could run you $10,000 per mile, varying by many other factors.</li>
<li><strong>Power</strong> &#8211; this expense accounts for 70-80 percent of the total costs of running a data center, and is also highly variable by region.</li>
<li><strong>Data center staffing</strong> &#8211; around-the-clock monitoring, on-site maintenance and equipment optimization requires a dedicated and responsive operations staff, and accounts as the second largest expense after power.</li>
<li><strong>Annual facility and infrastructure maintenance</strong> &#8211; a more unpredictable cost of a data center ranging from 3-5 percent of the initial construction cost. Repairs and additions are expected around the third year of operation.</li>
</ul>
<p>Find out more about Online Tech&#8217;s newest <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">Michigan data center</a>, offering <a href="http://www.onlinetech.com/colocation/michigan-colocation">Michigan colocation</a> and other IT services.</p>
<p>Source:<br />
<a href="http://www.romonet.com/files/download/pdf/Build%20Or%20Buy_%20The%20Economics%20Of%20Data%20Center%20Facilities.pdf">Build or Buy? The Economics of Data Center Facilities</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/key-benefits-of-leasing-vs-building-a-data-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Business Associate’s Role in HIPAA Violations</title>
		<link>http://resource.onlinetech.com/the-business-associate%e2%80%99s-role-in-hipaa-violations/</link>
		<comments>http://resource.onlinetech.com/the-business-associate%e2%80%99s-role-in-hipaa-violations/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 15:06:48 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[HIPAA breaches]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa training]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[protected health information]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3730</guid>
		<description><![CDATA[Of the 345 incidents reported by HHS and listed on their site under Breaches Affecting 500 or More Individuals, 74 involved a business associate (21 percent). An increasing number of recent HIPAA violations are caused or involve a business associate – the Stanford Hospital breach was due to improper disclosure of PHI, and the TRICARE/SAIC [...]]]></description>
			<content:encoded><![CDATA[<p>Of the 345 incidents reported by HHS and listed on their site under Breaches Affecting 500 or More Individuals, 74 involved a business associate (21 percent).</p>
<p>An increasing number of recent HIPAA violations are caused or involve a business associate – the Stanford Hospital breach was due to improper disclosure of PHI, and the TRICARE/SAIC incident was due to the theft of unencrypted backup tapes out of the trunk of an employee’s car.</p>
<div id="attachment_3732" class="wp-caption aligncenter" style="width: 515px"><img class="size-full wp-image-3732 " title="Business Associates HIPAA Violations" src="http://resource.onlinetech.com/wp-content/uploads/Business-Associates-HIPAA-Violations.jpg" alt="Business Associates HIPAA Violations" width="505" height="378" /><p class="wp-caption-text">Business Associates and HIPAA Violations</p></div>
<p>While most of the incidents were isolated – meaning different business associates are involved with each individual company, a few repeats were evident. Med Assets made up for 9.5 percent of the breaches reported with a business associate involved, meaning they affected 6 different companies listed.</p>
<p>Two separate incidents affected multiple covered entities – one set affected 4 different healthcare organizations and the other affected 3 different covered entities.</p>
<p>This data makes apparent the level of preparedness that business associates have when it comes to HIPAA security policies, procedures and training. When employees are improperly trained, they leave the business vulnerable to data theft, loss, hacking and/or simple security negligence within the IT environment, putting covered entities at great risk for a HIPAA violation and accompanying fines.</p>
<p>And when one IT vendor is responsible for PHI from many different hospitals, just one incident can have a significant damaging effect on an exponential amount of patients.</p>
<p>If you are outsourcing your data hosting, put research into finding a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> provider who is audited by a CHP (Certified HIPAA Practitioner) and CHSS (Certified HIPAA Security Specialist). Note, this doesn’t make your company HIPAA compliant, or any less responsible for implementing your own policies and procedures, but it does mean you have taken an active role in researching your vendors to prevent a data breach.</p>
<p>If you need more guidance on HIPAA policies, procedures and training materials, visit our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA resources</a> section today.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/the-business-associate%e2%80%99s-role-in-hipaa-violations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Understanding the Data Center Market in Secondary Cities &amp; Beyond</title>
		<link>http://resource.onlinetech.com/understanding-the-data-center-market-in-secondary-cities-beyond/</link>
		<comments>http://resource.onlinetech.com/understanding-the-data-center-market-in-secondary-cities-beyond/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 17:12:24 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[colocation]]></category>
		<category><![CDATA[data center market]]></category>
		<category><![CDATA[IMN]]></category>
		<category><![CDATA[secondary markets]]></category>
		<category><![CDATA[tier 1 market]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3743</guid>
		<description><![CDATA[I’m looking forward to attending the IMN (Information Management Network) conference next week in Los Angeles, California to join the discussion on the growing demand for data centers and colocation, as well as the threats and opportunities that cloud computing brings to the market. The 2011 IMN conference “Fall Forum on Financing, Investing &#38; Real [...]]]></description>
			<content:encoded><![CDATA[<p>I’m looking forward to attending the IMN (Information Management Network) conference next week in Los Angeles, California to join the discussion on the growing demand for <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> and <a href="http://www.onlinetech.com/colocation">colocation</a>, as well as the threats and opportunities that <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> brings to the market.</p>
<div id="attachment_3747" class="wp-caption alignright" style="width: 343px"><img class="size-full wp-image-3747 " title="IMN Conference 2011" src="http://resource.onlinetech.com/wp-content/uploads/IMN-Conference-2011.png" alt="IMN Conference 2011" width="333" height="144" /><p class="wp-caption-text">IMN Conference 2011</p></div>
<p>The 2011 IMN conference “Fall Forum on Financing, Investing &amp; Real Estate Development for Data Centers” will be held at the Hyatt Regency Century Plaza next Wednesday and Thursday.</p>
<p>I was selected to moderate and speak at a five-person panel discussion on “Understanding the Data Center Market in Secondary Cities &amp; Beyond,” a discussion on the differences between Tier 1 data center markets such as New York, Chicago and L.A. and secondary markets found in Michigan, Iowa and Nebraska.</p>
<div id="attachment_3750" class="wp-caption alignleft" style="width: 237px"><img class="size-full wp-image-3750" title="IMN: Information Management Network" src="http://resource.onlinetech.com/wp-content/uploads/IMN-Logo.png" alt="IMN: Information Management Network" width="227" height="123" /><p class="wp-caption-text">IMN: Information Management Network</p></div>
<p>Each of the panel members, including CEOs and a Business Development Manager, will speak to their experiences with their home markets and the market dynamics they’ve witnessed. The panel will provide a discussion of the differences of the growing secondary and tertiary markets and the market dynamics of Tier 1 cities, as seen through the eyes of data center operators in the secondary markets.</p>
<p>The panel also intends to touch on advantages and disadvantages, data center requirements, buyer profiles and community impact in a secondary market.</p>
<p>The second annual IMN data center conference brings together senior executives from some of the most prominent data center owners, tenants, investors, capital and service providers, each with different perspectives on the evolving data center market.</p>
<p>Other topics at the conference include:</p>
<ul>
<li>Tiering &amp; Redundancy: How Important are they in the Data Center Environment of Today?</li>
<li>Demand Capacity Forecasting on a Facility/Entity Level</li>
<li>Data Center Bankruptcy &amp; the Impact on the Tenant</li>
<li>Measuring how Much Tax, Power &amp; Other Incentives are Really Worth?</li>
<li>Power Rates, Build Times, Volatility, Contracts &amp; Pricing</li>
<li>Data Center CAPX &amp; TCO</li>
<li>Carrier Neutrality Vs. Bundled Services</li>
<li>Modular Data Centers</li>
</ul>
<p>See the IMN conference agenda schedule <a href="http://www.imn.org/Conference/IMN-Real-Estate-Development-for-Data-Centers-Conference/Agenda.html">here</a> for more detailed information.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/understanding-the-data-center-market-in-secondary-cities-beyond/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cold Site DR is Dead. Long Live Cloud-Based Disaster Recovery!</title>
		<link>http://resource.onlinetech.com/cold-site-dr-is-dead-long-live-cloud-based-disaster-recovery/</link>
		<comments>http://resource.onlinetech.com/cold-site-dr-is-dead-long-live-cloud-based-disaster-recovery/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 12:00:06 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[cloud computing disaster recovery]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[cloud RTO]]></category>
		<category><![CDATA[cold site disaster recovery]]></category>
		<category><![CDATA[disaster recovery cloud]]></category>
		<category><![CDATA[disaster recovery in the cloud]]></category>
		<category><![CDATA[disaster recovery times]]></category>
		<category><![CDATA[recovery time objectives]]></category>
		<category><![CDATA[RTO]]></category>
		<category><![CDATA[SAN storage]]></category>
		<category><![CDATA[tape backup]]></category>
		<category><![CDATA[tapeless backup]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3696</guid>
		<description><![CDATA[A decade ago, companies like SunGard grew very quickly by selling a solution most of us would call “cold site disaster recovery.” In essence, SunGard compiled a number of physical servers and compute capabilities, then leased these servers to many companies to be used in case of a disaster on a first-come, first-served basis. SunGard [...]]]></description>
			<content:encoded><![CDATA[<p>A decade ago, companies like SunGard grew very quickly by selling a solution most of us would call “cold site disaster recovery.” In essence, SunGard compiled a number of physical servers and compute capabilities, then leased these servers to many companies to be used in case of a disaster on a first-come, first-served basis.</p>
<p>SunGard built facilities in cities around the country such as Chicago and Philadelphia where users could converge when a disaster struck their primary data center. By loading their applications onto the DR servers and mainframes, users could attempt to recover their operations from “cold” servers.</p>
<p>These cold servers were bare metal servers – no operating system, no applications, no patches and no data. Once the tape backups and the IT recovery team finally arrive at the recovery site, the system recovery begins the time-consuming process of loading the system from the tapes. And as if that isn’t hard enough, <a href="http://resource.onlinetech.com/why-consider-online-backup-storage-over-traditional-tape-storage/">tape backup is notoriously unreliable</a>. Tapes have high failure rates when it comes to trying to read a tape from a different tape reader than it was written from.  It’s not unusual for tape readers to need recalibration just to recover the data on the tapes for DR purposes.</p>
<p>The typical cold site would allow for a 48 hour pre-scheduled annual disaster recovery test. Unfortunately, most of the users I’ve spoken with were unable to recover their entire system during the test window due to the time-consuming task of system recovery.  This leaves the remaining untested part of the DR plan tied to the “hope and pray” strategy – not a particularly comforting position to be in for a mission critical IT infrastructure.</p>
<p><strong>Cold site DR is dead.</strong></p>
<p>With the increasing demands for 7&#215;24 IT availability, recovery time requirements have dramatically shrunk over the last decade. While 10 years ago, a 3-5 day disaster recovery time was acceptable, most businesses are now demanding 1-4 hour recovery times given their heavy dependency on their digital infrastructure and electronic assets. This requires an entirely new disaster recovery strategy.</p>
<p>Fortunately, fundamental shifts have taken place over the last decade that makes it far easier and more cost-effective to achieve significantly faster disaster recovery times. Faster, more cost-effective Internet connectivity, point-to-point networks, more cost-effective SAN storage and the advent of <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> have changed the rules for disaster recovery.</p>
<p>One of the most significant advantages to cloud computing is what the cloud delivers in terms of disaster recovery. <a href="http://resource.onlinetech.com/disaster-recovery-in-cloud-computing/">Cloud Computing delivers faster recovery times</a> and multi-site availability at a fraction of the cost of conventional cold site disaster recovery.</p>
<p>Cloud computing virtualization delivers a very different approach to disaster recovery. The entire cloud server, including the operating system, applications, patches and data is encapsulated into a single software bundle or virtual server. This entire virtual server can be replicated to an offsite data center and spun up in a disaster recovery cloud in a matter of minutes.</p>
<p>Since cloud servers are hardware independent, the operating system, applications, patches and data are safely and accurately replicated between data centers, removing the burden of reloading each component of the server. This dramatically reduces cloud server recovery times compared to conventional disaster recovery in which physical servers need to be loaded with the OS and application software, then patched to the last configuration used in production – all before the data can be restored.</p>
<p>Cloud-based disaster recovery delivers warm site recovery times more cost-effectively and without the drawbacks of conventional cold site DR approaches. It also enables much faster recovery point objectives (RPOs) &#8211; eliminating the risk of data loss when failing over the DR servers.</p>
<p>With cloud-based DR, the server replication is dramatically accelerated and network replication becomes the critical path to recovery, including IP address mapping, firewall rules &amp; VLAN configuration. Solutions like Online Tech’s <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">DR Now!</a> cloud-based disaster recovery not only replicates the servers between data centers, but also replicates the entire network configuration in a way that recovers the network as quickly as the backed up cloud servers.</p>
<p>Cloud-based DR delivers a set of benefits that make it difficult to look back at cold site DR with any sense of nostalgia. Long live cloud-based disaster recovery!</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cold-site-dr-is-dead-long-live-cloud-based-disaster-recovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Disclosure in the Public Cloud</title>
		<link>http://resource.onlinetech.com/data-disclosure-in-the-public-cloud/</link>
		<comments>http://resource.onlinetech.com/data-disclosure-in-the-public-cloud/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 13:19:37 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[data disclosure]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[public cloud safety]]></category>
		<category><![CDATA[public cloud security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3721</guid>
		<description><![CDATA[Do you know who has control of your data? Take precaution when you decide to put your data on the public cloud hosted by Google or Amazon. A recent Wall Street Journal article reports statistics from Google’s Transparency Report, a new effort to disclose a limited amount of information regarding government requests for user data [...]]]></description>
			<content:encoded><![CDATA[<p>Do you know who has control of your data? Take precaution when you decide to put your data on the public cloud hosted by Google or Amazon. A recent Wall Street Journal <a href="http://blogs.wsj.com/digits/2011/10/25/google-reports-surge-in-government-requests-for-user-data/">article</a> reports statistics from Google’s Transparency Report, a new effort to disclose a limited amount of information regarding government requests for user data and requests for content removal.</p>
<p>According to the report, U.S. government requests for Google user and account data rose 29 percent when comparing the first six months of 2011 to the previous six months. A total of 5,950 user data requests from January to June 2011 affected 11,057 individual users and accounts. In addition, requests to remove content from Google products increased 70 percent – and in response, Google complied with 63 percent of those requests.</p>
<div id="attachment_3725" class="wp-caption aligncenter" style="width: 530px"><img class="size-full wp-image-3725" title="Data Disclosure in the Public Cloud" src="http://resource.onlinetech.com/wp-content/uploads/Data-Disclosure-in-the-Public-Cloud.jpg" alt="Data Disclosure in the Public Cloud" width="520" height="487" /><p class="wp-caption-text">Data Disclosure in the Public Cloud</p></div>
<p>This raises the question of who has the ability to access, or grant access to your data hosted in a public cloud environment. Can the government simply call up Google or Amazon, submit a request for information and receive your data, whether confidential or not?</p>
<p>The Wikileaks incident back in December 2010 is a good example of government influence on hosting providers. The prolific theft and dissemination of classified cables detailing confidential government activities brought attention not only to the data, but the data host – Amazon EC2 servers. The official Amazon statement claims they kicked Wikileaks off of their servers due to a violation of terms of service, citing the fact that Wikileaks did not own or control rights to their information hosted on the cloud. Yet the question remains, would Amazon have shut them down if there wasn’t strong government opposition?</p>
<p>Trusting your critical business data and applications to the public cloud requires a public cloud provider to uphold certain service terms when it comes to granting access to your data. In a shared environment, do you really know where your data lives and who controls it? And is it worth taking the risk in order to take advantage of a utility pricing model?</p>
<p>Sources:<br />
<a href="http://blogs.wsj.com/digits/2011/10/25/google-reports-surge-in-government-requests-for-user-data/">Google Reports Surge in Government Requests for User Data</a><br />
<a href="http://www.google.com/transparencyreport/governmentrequests/">Google Transparency Report: Government Requests</a><br />
<a href="http://www.google.com/transparencyreport/governmentrequests/removals/">Google Transparency Report: Content Removal Requests</a><br />
<a href="http://www.informationweek.com/news/cloud-computing/software/228500230">Why Did Amazon Web Services Shut Down WikiLeaks?</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/data-disclosure-in-the-public-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA 5010 Deadline Approaching: Taking Steps toward Implementation</title>
		<link>http://resource.onlinetech.com/hipaa-5010-deadline-approaching-taking-steps-toward-implementation/</link>
		<comments>http://resource.onlinetech.com/hipaa-5010-deadline-approaching-taking-steps-toward-implementation/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 16:36:41 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2011 hipaa compliance]]></category>
		<category><![CDATA[hipaa 5010]]></category>
		<category><![CDATA[hipaa billing]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[hipaa FAQ]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[medical billing]]></category>
		<category><![CDATA[new hipaa standards]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3687</guid>
		<description><![CDATA[All covered entities need to meet the latest version of HIPAA, 5010, by January 1, 2012. The latest set of standards aim to upgrade the regulation of all electronic transmissions of healthcare transactions including eligibility, claim status, referrals, claims and remittances. Why is this deadline so important? Transactions not using HIPAA 5010 will be rejected, [...]]]></description>
			<content:encoded><![CDATA[<p>All covered entities need to meet the latest version of HIPAA, 5010, by <strong>January 1, 2012</strong>. The latest set of standards aim to upgrade the regulation of all electronic transmissions of healthcare transactions including eligibility, claim status, referrals, claims and remittances.</p>
<div id="attachment_3608" class="wp-caption alignright" style="width: 260px"><img class="size-full wp-image-3608" title="HIPAA 5010" src="http://resource.onlinetech.com/wp-content/uploads/HIPAA-5010.gif" alt="HIPAA 5010" width="250" height="84" /><p class="wp-caption-text">HIPAA 5010</p></div>
<p><strong>Why is this deadline so important?</strong> Transactions not using HIPAA 5010 will be rejected, resulting in rejected claims and cash flow interruptions.</p>
<p><strong>HIPAA 5010 history: </strong>The regulation was created in 2009 &#8211; level I compliance was effective by December 2010, and level II compliance was effective by December 2011.</p>
<ul>
<li><strong>Level I compliance</strong>: &#8220;that a covered entity can demonstrably create and receive compliant transactions, resulting from the compliance of all design/build activities and internal testing.&#8221;</li>
<li><strong>Level II compliance</strong>: &#8220;that a covered entity has completed end-to-end testing with each of its trading partners, and is able to operate in production mode with the new versions of the standards.&#8221;</li>
</ul>
<p>While the HHS allows the use of both the existing standards (2010A1 and 5.1) and the new standards, (5010 and D.0) for the time being, that fact will change come next year. The final deadline for all covered entities to fully comply with the latest HIPAA standard 5010 is January 1, 2012.</p>
<p><strong>Who is required to upgrade? </strong>Physicians, hospitals, payers, clearinghouses, pharmacies and dentists are included. Software vendors also need to upgrade their products to support HIPAA 5010.</p>
<p>The new HIPAA 5010 version strives to clarify usage to remove ambiguity, create consistency across transactions, support NPI regulation and remove data content no longer used.</p>
<p>To make it easier for organizations and individuals to conduct a gap analysis, the CMS (Centers for Medicare and Medicaid Services) has documents available for download comparing old HIPAA standards to new HIPAA standards, side-by-side, including professional claims, institutional claims, remittance, claim status, eligibility and more. These can be found in the Electronic Billing &amp; EDI Transactions &gt; <a href="https://www.cms.gov/electronicbillingeditrans/18_5010d0.asp">5010 D.0 HIPAA Standards</a>.</p>
<p><strong>Who’s actually prepared for the 5010 switch? </strong>While the newest version of HIPAA has been around for a while, not everyone appears to be ready for the full switch. The Medical Group Management Associate (MGMA) announced a request for a HIPAA 5010 contingency plan from the Department of Health and Human Services (HHS), calling on the department to not penalize health plans that only meet the most critical data content requirements, and not the full list of requirements.<strong></strong></p>
<p>This request comes on the coattails of a MGMA study, as reported by HealthcareITNews.com, that reveals only 4.5 percent of respondents rate their 5010 implementation as fully complete, while 50 percent rate it as between 26 and 99 percent complete, and 40 percent rate it as less than 25 percent complete.</p>
<p><strong>What steps should you take toward HIPAA 5010 implementation? </strong>The American Medical Association (AMA) provides a preparatory fact sheet on planning and tactically implementing HIPAA 5010 in time for the January 1, 2012 deadline:</p>
<ol>
<li><strong>Impact Analysis </strong>– Conduct an internal impact analysis to determine how much of a change the switch to 5010 will have on your current business practices and systems.<strong></strong></li>
<li><strong>Contact your Vendors, Payers, Billing Service and Clearinghouse </strong>– Contact vendors for specific details regarding system upgrades, and ask them about when they expect their upgrades to be completed, and when they’ll be able to accept 5010 transactions.<strong></strong></li>
<li><strong>Installation of Vendor Upgrades</strong> – Schedule the system upgrades according to your vendor’s readiness, and ensure the installation of upgrades is complete.<strong></strong></li>
<li><strong>Internal Testing and Staff Training</strong> – Once upgrades are completed, conduct internal testing of your systems to ensure you can generate and handle the 5010 transactions. Leave a margin of time for issue resolution and staff training on the new system.<strong></strong></li>
<li><strong>External Testing with Clearinghouse, Billing Service and Payers</strong> – Contact your vendors to conduct external testing with them to ensure you can send and receive transactions properly.<strong></strong></li>
<li><strong>Make the Switch to 5010 </strong>– After completing external testing, you may switch to using only 5010 transactions.<strong></strong></li>
</ol>
<p>For more HIPAA guidance, check out <a href="http://www.onlinetech.com/resources/e-tips/hipaa-compliance/tips-for-passing-a-hipaa-audit">Tips for Passing a HIPAA Audit</a> or sign up for our ongoing, free webinar series, <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">A to Z to Achieving HIPAA Compliance</a>. Or if you have other questions, check out our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a>.</p>
<p>Sources:<br />
<a href="https://www.cms.gov/electronicbillingeditrans/18_5010d0.asp">CMS 5010 D.0 Electronic Billing &amp; EDI Transaction</a><br />
<a href="http://www.aapc.com/icd-10/hipaa-5010-implemenation.aspx">HIPAA 5010 Implementation</a><br />
<a href="http://www.healthcareitnews.com/news/hipaa-5010-contingency-plan-needed-says-mgma">HIPAA 5010 Contingency Plan Needed, Says MGMA</a><br />
<a href="http://www.ama-assn.org/ama1/pub/upload/mm/399/hipaa-5010-timeline.pdf">Preparing for the Next Version of HIPAA Standards: January 1, 2012 Compliance Date</a> (pdf)</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-5010-deadline-approaching-taking-steps-toward-implementation/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Free Webinar: Impact of HIPAA Compliance on Business Associates</title>
		<link>http://resource.onlinetech.com/free-webinar-impact-of-hipaa-compliance-on-business-associates/</link>
		<comments>http://resource.onlinetech.com/free-webinar-impact-of-hipaa-compliance-on-business-associates/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 14:12:41 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[achieving hipaa compliance]]></category>
		<category><![CDATA[business associates]]></category>
		<category><![CDATA[free hipaa webinar]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa security]]></category>
		<category><![CDATA[HIPAA webinar]]></category>
		<category><![CDATA[risk management]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3669</guid>
		<description><![CDATA[Don&#8217;t miss our second HIPAA webinar of a three-part series starting at 2PM ET tomorrow &#8211; there&#8217;s still time to register! Online Tech is hosting a series of free educational webinars titled “A to Z to Achieving HIPAA Compliance” running October 25 – November 8, 2011. This webinar series is helpful for operations employees of business associate [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignnone" style="width: 570px"><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance"><img class=" " title="HIPAA Compliant Webinar Series" src="http://resource.onlinetech.com/wp-content/uploads/hipaa_series_webinar_banner.gif" alt="HIPAA Compliant Webinar Series" width="560" height="192" /></a><p class="wp-caption-text">HIPAA Compliant Webinar Series</p></div>
<p>Don&#8217;t miss our second HIPAA webinar of a three-part series starting at 2PM ET tomorrow &#8211; there&#8217;s still time to register!</p>
<p>Online Tech is hosting a series of free educational webinars titled <strong>“A to Z to Achieving HIPAA Compliance”</strong> running October 25 – November 8, 2011.</p>
<p>This webinar series is helpful for operations employees of business associate organizations that would like more guidance on becoming <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a>.</p>
<div id="attachment_3473">
<div class="wp-caption alignleft" style="width: 110px"><img title="Jason Yaeger" src="http://www.onlinetech.com/images/stories/people/jason-yaeger-100.jpg" alt="Jason Yaeger" width="100" height="150" /><p class="wp-caption-text">Jason Yaeger</p></div>
<p><strong>Tuesday, 11/01/11 @ 2PM ET: Impact of HIPAA Compliance on Business Associates – Changes to Company Policies and Day-to-Day Operations</strong></p>
</div>
<p>The second webinar of the series, “Impact of HIPAA Compliance on Business Associates – Changes to Company Policies and Day-to-Day Operations” features Online Tech’s Risk Management Officer and Security Officer, Jason Yaeger and his experience guiding a company through a HIPAA audit. Yaeger will discuss the impact of HIPAA compliance on his role, company policies, and day-to-day operations for employees of a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> tomorrow at 2PM ET.</p>
<p><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">Register</a> today &#8211; we encourage you to submit your questions about HIPAA compliance in advance for consideration during the webinar by emailing <a href="mailto:contactus@onlinetech.com?subject=Security%20Webinar%20Series%20Question">contactus@onlinetech.com</a>. If you need more HIPAA resources, browse our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-faq">HIPAA FAQ</a> or get more information about <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/free-webinar-impact-of-hipaa-compliance-on-business-associates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What’s Missing From Most Cloud-Based Disaster Recovery?  Network Replication</title>
		<link>http://resource.onlinetech.com/what%e2%80%99s-missing-from-most-cloud-based-disaster-recovery-network-replication/</link>
		<comments>http://resource.onlinetech.com/what%e2%80%99s-missing-from-most-cloud-based-disaster-recovery-network-replication/#comments</comments>
		<pubDate>Fri, 28 Oct 2011 12:53:05 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[cloud-based disaster recovery]]></category>
		<category><![CDATA[it disaster recovery]]></category>
		<category><![CDATA[network replication]]></category>
		<category><![CDATA[server replication]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3661</guid>
		<description><![CDATA[I’ve written several blog posts on how cloud computing changes disaster recovery. One of the most significant advantages to cloud computing is how it makes disaster recovery more cost-effective and lowers the bar for deploying comprehensive DR plans across a company’s entire IT infrastructure. Cloud computing delivers faster recovery times and multi-site availability at a fraction [...]]]></description>
			<content:encoded><![CDATA[<p>I’ve written several blog posts on <a href="http://resource.onlinetech.com/disaster-recovery-in-cloud-computing/">how cloud computing changes disaster recovery</a>. One of the most significant advantages to cloud computing is how it makes disaster recovery more cost-effective and lowers the bar for deploying comprehensive DR plans across a company’s entire IT infrastructure. <a href="http://www.onlinetech.com/cloud-computing-hosting">Cloud computing</a> delivers faster recovery times and multi-site availability at a fraction of the cost of conventional disaster recovery.</p>
<p>Apparently, we’re not the only company seeing the benefits for cloud-based DR. There have been several recent announcements of cloud-based DR – where you can ship a copy of your virtual server image offsite to be run in a cloud server should you declare a disaster.</p>
<p>Nice approach if you’re trying to replicate a single stand-alone server.  But what’s missing from these server replication models for DR?</p>
<p>For most enterprise or more complex server configurations, the network configuration, firewall rules, VLANs and VPNs are a critical part of the infrastructure that needs to be recovered in a disaster.</p>
<p>Recovering a replicated cloud server is great leap forward. It removes a ton of work from reinstalling the operating system, applications, patches and data on a new server, and gets the server up and running quickly by turning on the replicated cloud server.</p>
<p>But without replicating the entire network and security configuration, the solution falls short. Before the recovery site can go live, the network configuration needs to be fully replicated at the DR site. This means that copies of the VLAN configuration, firewall rules, and VPN configurations all need to be available and put in place before the DR site can go live.</p>
<p>Rapid recovery time objectives (RTOs) can only be achieved if the entire server and network infrastructure are replicated at the DR site and stay in lockstep with the production site as configuration changes are made.</p>
<p>At Online Tech, we’ve spent a lot of time developing a solution we call DR Now!  <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/drnow">DR Now!</a> replicates the entire hosted cloud, including servers, software, network and security to a separate offsite <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> cloud without any programming or special configuration. We can do this because we manage the production cloud servers and DR cloud servers at both sites.</p>
<p>So when you’re considering the benefits of cloud computing for disaster recovery, keep in mind that DR is not just about replicating the cloud server between data center sites. It requires careful consideration on how the entire compute infrastructure is replicated between data centers – including the entire network and security configuration.</p>
<p>For more resources on this topic, read our E-Tip, <a href="http://www.onlinetech.com/resources/e-tips/disaster-recovery/benefits-of-disaster-recovery-in-cloud-computing">Benefits of Disaster Recovery in Cloud Computing</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/what%e2%80%99s-missing-from-most-cloud-based-disaster-recovery-network-replication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Five Questions to Ask Your HIPAA Hosting Provider</title>
		<link>http://resource.onlinetech.com/five-questions-to-ask-your-hipaa-hosting-provider/</link>
		<comments>http://resource.onlinetech.com/five-questions-to-ask-your-hipaa-hosting-provider/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 13:05:18 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[HIPAA audits]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[hipaa compliant data center]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa hosting provider]]></category>
		<category><![CDATA[hipaa questions]]></category>
		<category><![CDATA[HIPAA violation]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3614</guid>
		<description><![CDATA[With the litany of HIPAA breaches caused by business associates/IT vendors in the news lately, covered entities need to be more proactive when it comes to vetting their HIPAA hosting provider. Protecting confidential patient health information and preventing a HIPAA violation should be the top IT goal of all healthcare organizations, individual providers and software [...]]]></description>
			<content:encoded><![CDATA[<p>With the litany of HIPAA breaches caused by business associates/IT vendors in the news lately, covered entities need to be more proactive when it comes to vetting their <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> provider.</p>
<p>Protecting confidential patient health information and preventing a HIPAA violation should be the top IT goal of all healthcare organizations, individual providers and software vendors. But hosting your critical data and applications with a provider requires trust and confidence in their ability to meet HIPAA compliance requirements.</p>
<p>What questions should you, as covered entity, ask your <a href="http://www.onlinetech.com">HIPAA hosting provider</a>?</p>
<ol>
<li><strong>Have you been independently audited by a Certified HIPAA Practitioner (CHP) and Certified HIPAA Security Specialist (CHSS)?</strong> To verify your data center operator and hosting solutions are truly HIPAA compliant, they need to be 100% compliant across all 54 HIPAA citations and 136 audited components. Although covered entities need to assess their own policies and procedures to become HIPAA compliant, partnering with a HIPAA compliant IT vendor will greatly improve your chances of passing a HIPAA audit.</li>
<li><strong>What particular IT services meet HIPAA compliant security standards for protecting PHI?</strong> Your HIPAA hosting provider should be able to answer this question with specific answers that detail recommended IT services – a private firewall, either virtual or dedicated, with VPN for remote access; data encryption following NIST standards; separate database and web servers for production, etc.<strong></strong></li>
<li><strong>Do you have documented policies and procedures? </strong>Make sure you know your hosting provider’s policies when it comes to a data breach – they are required by law as a BA (Business Associate) to notify covered entities in a timely manner, and covered entities are required to notify affected individuals within 10 days. Not following these deadlines and procedures can result in costly lawsuits.</li>
<li><strong>Are your employees trained? </strong>The recent <a href="http://resource.onlinetech.com/military-healthcare-contractor%E2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/">military healthcare contractor HIPAA violation</a> was attributed to an employee transporting PHI off of government property and leaving backup tapes unattended in the trunk of a car. The recent lawsuit states that their employees were either not properly trained or completely untrained in HIPAA compliant security procedures. HIPAA requires all employees to be trained in the proper security practices, including policies, physical security, logical security, risk response and reporting, passwords/workstation use, data protection and more.</li>
<li><strong>Do you have a thorough BAA (Business Associates Agreement) with documented and communicated policies? </strong>Under HIPAA’s standards for penalties, the lack of a BAA implies negligence, which may fall under Willful Neglect – fines ranging from $10,000 to $50,000 for each incident and potential criminal charges. A BAA can also be valuable to define how the data is handled after service termination; a sample BAA from HHS.gov includes a provision requiring the BA to return or destroy all PHI received from the covered entity, emphasizing that the BA shouldn’t keep any copies of the PHI. If you don’t sign a well-thought out BAA with your hosting provider, they can potentially keep your data on file long after you leave them.<strong></strong></li>
</ol>
<div>
<p>Don’t take chances with serious penalties and make sure your hosting provider can provide sufficient answers to protect patient data and protect against a HIPAA violation. Need to answer more questions about HIPAA? Find out what a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> can provide for your company.</p>
</div>
<p>Sources:</p>
<p><a href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/contractprov.html">Business Associate Contracts</a><strong></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/five-questions-to-ask-your-hipaa-hosting-provider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Tech to Attend HIMSS Midwest Fall Technology Conference 2011</title>
		<link>http://resource.onlinetech.com/online-tech-to-attend-himss-midwest-fall-technology-conference-2011/</link>
		<comments>http://resource.onlinetech.com/online-tech-to-attend-himss-midwest-fall-technology-conference-2011/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 12:43:53 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[healthcare information technology]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[HIMSS]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3554</guid>
		<description><![CDATA[Online Tech will be attending the Midwest HIMSS Fall Technology Conference in Indianapolis, Indiana on November 13-15, 2011, hosted by the Midwest Area HIMSS (Healthcare Information and Management Systems Society). The conference theme is Building a Winning Team – Strategies for Healthcare IT Success with several keynote speakers and breakout sessions focusing on the topics of [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_3569" class="wp-caption alignleft" style="width: 320px"><img class="size-full wp-image-3569  " title="HIMSS Fall Technology Midwest Conference" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS-Fall-Technology-Midwest-Conference.jpg" alt="HIMSS Fall Technology Midwest Conference" width="310" height="94" /><p class="wp-caption-text">HIMSS Fall Technology Midwest Conference</p></div>
<p>Online Tech will be attending the <strong><a href="http://www.falltechnologyconference2011.com/">Midwest HIMSS Fall Technology Conference</a> </strong>in Indianapolis, Indiana on November 13-15, 2011, hosted by the Midwest Area HIMSS (Healthcare Information and Management Systems Society).</p>
<p>The conference theme is <em>Building a Winning Team – Strategies for Healthcare IT Success </em>with several keynote speakers and breakout sessions focusing on the topics of clinical, technology and business healthcare.</p>
<p><strong>Todd Park</strong>, CTO of the U.S. Department of Health and Human Services, will be speaking on <em>Improving Healthcare through Technology Innovation.</em></p>
<p>Park co-founded a health IT company, Athenahealth in 1997. Prior to Athenahealth, he served as a management consultant with Booz Allen &amp; Hamilton, focusing on healthcare strategy, technology and operations. Park also volunteered at the Center for American Progress focusing on health IT and health reform policy.</p>
<p>Other keynote speakers include:</p>
<ul>
<li><strong>C. Martin Harris</strong>, M.D., M.B.A., FHIMSS; CIO of the IT Division of the Cleveland Clinic and Chair of HIMSS Board of Directors will speak on <em>Beyond Meaningful use – Transforming our Healthcare System</em>.</li>
<li><strong>Chuck Christian</strong>, FCHIME, FHIMSS; CIO of the Good Samaritan Hospital in Vincennes, Indiana, and 2011 HIMSS CIO of the Year will speak on <em>Building a Winning Team for HIT Success.</em></li>
<li><strong>Nina M. Antoniotti</strong>, R.N., M.B.A., Ph.D.; Program Director of Marshfield Clinic’s Telehealth Network and past President of the American Telemedicine Association will speak on <em>HIT and Accountable Care – the Role for Telehealth.</em></li>
</ul>
<p>In addition to keynote speaker presentations, the conference will feature a large exhibition area for healthcare IT professionals and vendors, and serves as a great networking opportunity to share new technology and information on technology regulations, such as HIPAA compliance standards. Since Online Tech serves a number of healthcare and healthcare software organizations with <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> solutions (see our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-compliant-hosting-case-studies">HIPAA compliant case studies</a>), we&#8217;ll have our own booth at the exhibition (stop by if you&#8217;re around!).</p>
<div id="attachment_3582" class="wp-caption aligncenter" style="width: 442px"><img class="size-full wp-image-3582" title="HIMSS (Healthcare Information and Management Systems Society)" src="http://resource.onlinetech.com/wp-content/uploads/HIMSS.jpg" alt="HIMSS (Healthcare Information and Management Systems Society)" width="432" height="288" /><p class="wp-caption-text">HIMSS (Healthcare Information and Management Systems Society)</p></div>
<p>Founded 50 years ago, <strong>HIMSS</strong> is a not-for-profit organization focused on providing global leadership for the optimal use of IT and management systems to improve healthcare. With 50 chapters across the U.S., Canada and India and more than 38,000 individual members, HIMSS strives to be a local forum for healthcare system professionals.</p>
<p>Members consist of hospital and clinical organizations, IT system vendors, physicians, nurse and medical informatics professionals and more. Online Tech is a member of the Midwest HIMSS, which includes Michigan, Indiana, Illinois and Ohio chapters.</p>
<p>Online Tech recently passed a HIPAA audit by a Certified HIPAA Practitioner (CHP) and Certified HIPAA Security Specialist (CHSS) and was found to be 100% compliant across all 54 HIPAA citations and 136 audited components. That means we can verify we provide <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> in our <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a> with our <a href="http://www.onlinetech.com/cloud-computing-hosting/private-cloud-hosting-packages">private clouds</a>, <a href="http://www.onlinetech.com/colocation">colocation</a>, <a href="http://www.onlinetech.com/managed-dedicated-servers">managed dedicated servers</a> and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> solutions, for a variety of healthcare organizations and healthcare software companies.</p>
<p>Sources:<br />
<a href="http://www.falltechnologyconference2011.com/">Fall Technology Conference 2011</a><br />
<a href="http://www.himss.org/ASP/index.asp">HIMSS</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/online-tech-to-attend-himss-midwest-fall-technology-conference-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protecting Data with Cloud Computing Service Contracts</title>
		<link>http://resource.onlinetech.com/protecting-data-with-cloud-computing-service-contracts/</link>
		<comments>http://resource.onlinetech.com/protecting-data-with-cloud-computing-service-contracts/#comments</comments>
		<pubDate>Tue, 25 Oct 2011 12:59:12 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Information Technology Tips]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cloud compliance]]></category>
		<category><![CDATA[cloud computing contracts]]></category>
		<category><![CDATA[cloud security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[hipaa cloud]]></category>
		<category><![CDATA[hipaa compliant cloud]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3525</guid>
		<description><![CDATA[Data security and intellectual property rights in cloud computing are issues that should be addressed prior to signing with a cloud computing provider – outlining the agreements in a contract will help protect your company and your (or your clients’) data. The terms outlined in the JISC Legal’s Cloud Computing and the Law guide bring [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_3540" class="wp-caption alignright" style="width: 184px"><img class="size-full wp-image-3540" title="Cloud Security" src="http://resource.onlinetech.com/wp-content/uploads/Cloud-Security.png" alt="Cloud Security" width="174" height="121" /><p class="wp-caption-text">Cloud Security</p></div>
<p>Data security and intellectual property rights in <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> are issues that should be addressed prior to signing with a cloud computing provider – outlining the agreements in a contract will help protect your company and your (or your clients’) data. The terms outlined in the JISC Legal’s Cloud Computing and the Law guide bring up a few critical points that may be overlooked by companies seeking a cloud contract:</p>
<p><strong>Contract Termination </strong>– Do you know what happens to your data when you decide to leave your cloud provider for whatever reason? While a normal contract outlines the duration, renewal and steps by either party (client and provider) in order to terminate the service, it’s important to know where your data goes after you leave your cloud provider, especially if you are storing sensitive information such as health records.</p>
<p>Can you reliably account for their actions after you cancel services with your cloud provider, knowing that they have a copy of your (or your clients’) data?</p>
<p>This brings us to:</p>
<p><strong>Possession of Data on Termination</strong> – The right to have your data returned after contract termination is one key, if not obvious, term that should be detailed in your cloud computing service contract.</p>
<p>Another critical term is the length of time that a cloud provider will keep the data available for retrieval. This can become an issue if a client isn’t aware of the time period and subsequently can’t access their data after termination. It can also be an issue if sensitive data is mishandled after your service agreement is no longer effective and security isn’t upheld.</p>
<p>Leaking or misuse of protected health information (PHI) can mean major federal penalties under HIPAA compliant security standards as enforced by HITECH, and one reason to seek a <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> cloud solution provided by an audited data center operator. A HIPAA-trained IT staff will never access your protected health information.</p>
<p>The best way to ensure your data is protected is to know who controls it, which includes:</p>
<p><strong>Who Has Access to Your Data</strong> – As your data hosting provider and in accordance with national data compliance regulations; they should not have any reason to be accessing your confidential information hosted on their servers. If your cloud provider is outsourcing any services to a third party, you should also be aware of their access controls and ability to touch your data.</p>
<p><strong>Deletion of Data </strong>– Another important term of your contract is if and how data will be deleted from the cloud provider’s environment. Do you know if your data is still deemed your property, or does your cloud provider claim the rights after you use their hosting environment? Be sure to outline a permanent deletion procedure with your cloud provider when drafting your contract.</p>
<p>When it comes to data control and security, you need to do your part in being vigilant about your <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud hosting</a> contract terms to protect the access and right to your data.</p>
<p>Read the <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing/top-5-tips-for-cloud-computing-security">Top 5 Tips for Cloud Computing Security</a> for more on cloud computing security.</p>
<p>Sources:<br />
<a href="http://www.jisclegal.ac.uk/ManageContent/ManageContent/tabid/243/ID/2141/User-Guide-Cloud-Computing-Contracts-SLAs-and-Terms-Conditions-of-Use-31082011.aspx#2.1._Data_Protection">New Toolkit: Cloud Computing and the Law from JISC Legal</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/protecting-data-with-cloud-computing-service-contracts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Webinar: Cost-Effective Protection Against HIPAA Enforcement</title>
		<link>http://resource.onlinetech.com/free-webinar-cost-effective-protection-against-hipaa-enforcement/</link>
		<comments>http://resource.onlinetech.com/free-webinar-cost-effective-protection-against-hipaa-enforcement/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 19:28:14 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cost-effective hipaa]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA violation]]></category>
		<category><![CDATA[HIPAA webinar]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3522</guid>
		<description><![CDATA[Don&#8217;t miss our first HIPAA webinar of a three-part series starting at 2PM ET tomorrow! Online Tech is hosting a series of free educational webinars titled “A to Z to Achieving HIPAA Compliance” running October 25 – November 8, 2011. This webinar series is helpful for healthcare organizations that interact with patient information or vendors of covered [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignnone" style="width: 570px"><img title="HIPAA Compliant Webinar Series" src="http://resource.onlinetech.com/wp-content/uploads/hipaa_series_webinar_banner.gif" alt="HIPAA Compliant Webinar Series" width="560" height="192" /><p class="wp-caption-text">HIPAA Compliant Webinar Series</p></div>
<p>Don&#8217;t miss our first HIPAA webinar of a three-part series starting at 2PM ET tomorrow!</p>
<p>Online Tech is hosting a series of free educational webinars titled <strong>“A to Z to Achieving HIPAA Compliance”</strong> running October 25 – November 8, 2011. This webinar series is helpful for healthcare organizations that interact with patient information or vendors of covered entities that need guidance on becoming <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a>.</p>
<div id="attachment_3473"><img class="alignleft" title="Speaker Joe Dylewski" src="http://resource.onlinetech.com/wp-content/uploads/joe-dylewski-100.jpg" alt="Speaker Joe Dylewski" width="100" height="138" /><strong>Tuesday, 10/25/11 @ 2pm ET: Cost-Effective Protection Against HIPAA Enforcement</strong></div>
<p>In the first webinar of the series, special guest speaker Joe Dylewski will discuss HIPAA enforcement and penalties in the event of a HIPAA violation and how to avoid a HIPAA breach using the most cost-effective methods.</p>
<p>Dylewski, a Certified HIPAA Security Specialist (CHSS) and Certified HIPAA Professional (CHP), has twenty-three years of IT professional experience with eight years spent exclusively in the healthcare industry. Serving as a former Healthcare IT Services Practice Director, Dylewski is now the current President of the ATMP (Applied Technology Methods and Practices) Group, offering HIPAA risk assessments and HIPAA compliance remediation solutions.</p>
<p><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">Register</a> today &#8211; we encourage you to submit your questions about HIPAA compliance in advance for consideration during the webinar by emailing <a href="mailto:contactus@onlinetech.com?subject=Security%20Webinar%20Series%20Question">contactus@onlinetech.com</a>.</p>
<p>If you&#8217;re looking for more HIPAA resources, try this list of <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA policies, procedures and training materials</a>, or read our <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-glossary-of-terms">HIPAA Glossary of Terms</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/free-webinar-cost-effective-protection-against-hipaa-enforcement/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Upward Trend of Consumer Use of EHRs; Slower Trend of Meaningful Use Attestation</title>
		<link>http://resource.onlinetech.com/upward-trend-of-consumer-use-of-ehrs-slower-trend-of-meaningful-use-attestation/</link>
		<comments>http://resource.onlinetech.com/upward-trend-of-consumer-use-of-ehrs-slower-trend-of-meaningful-use-attestation/#comments</comments>
		<pubDate>Mon, 24 Oct 2011 13:37:00 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[EHR]]></category>
		<category><![CDATA[electronic health records]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[Health technology]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[meaningful use]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3499</guid>
		<description><![CDATA[A study of consumer digital health trends reports 56 million U.S. consumers have accessed their medical information stored on an electronic health record (EHR) system, while 26 percent of U.S. adults have used their mobile phones to access health information in the past year. The Cybercitizen Health U.S. 2011 study by Manhattan Research surveyed nearly [...]]]></description>
			<content:encoded><![CDATA[<p>A study of consumer digital health trends reports 56 million U.S. consumers have accessed their medical information stored on an electronic health record (EHR) system, while 26 percent of U.S. adults have used their mobile phones to access health information in the past year.</p>
<p>The Cybercitizen Health U.S. 2011 study by Manhattan Research surveyed nearly 9,000 U.S. consumers in Q3 2011 about their digital health habits and found an additional 41 million users are interested in accessing EHR systems.</p>
<p>However, 141 million have reported not accessing their medical records via EHR systems, consisting of mainly an older, less educated and less technologically-inclined demographic. This group is less likely to use the Internet or have smartphones or tablets.</p>
<p><strong>Mobile Phone EHR/EMR Use Increases</strong></p>
<p>Yet over a quarter of U.S. adults used mobile phones for health information or tools last year, doubling from 12 percent in 2010. Eight percent of consumers have used prescription drug refill or reminder services on their cell phones, compared to only 3 percent in 2010. The growing use of technology to access health records shows a strong need to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a>, the standardized security and privacy regulations designed to protect health data.</p>
<ul>
<li>(Need more guidance on how to become HIPAA compliant? Sign up for our <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">free HIPAA webinar series</a>, from Oct. 25-Nov 8).</li>
</ul>
<p><strong>Medical Graduates Show Favorable EHR/EMR Use</strong></p>
<p>The rapidly growing trend of a younger population using technology more aptly and for health-related tasks is not only consumer-based – new healthcare industry graduates are using EHR/EMRs during medical residence training and are highly motivated to continue to do so.</p>
<p>A 2010 National Physician Survey from Canada reported 79 percent of medical residents had used or been exposed to electronic medical records to collect or access patient clinical notes during training.</p>
<p>In addition, 82 percent of family medicine residents and 75 percent of residents in other specialties expect to use EMRs for clinical notes instead of paper when they enter into practice. As the CanadianEMR.ca blog predicts, there may be a high likelihood that current practices won’t be able to attract new graduates for employment unless they have an EMR in place.</p>
<div id="attachment_3504" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-3504" title="EMR Experience and Expectations" src="http://resource.onlinetech.com/wp-content/uploads/EMR-Experience-and-Expectations.jpg" alt="EMR Experience and Expectations" width="500" height="326" /><p class="wp-caption-text">EMR Experience and Expectations</p></div>
<p><strong>Current Meaningful Use Attestation Lagging       </strong></p>
<p>By contrast, current healthcare organizations and individual providers have been slower when it comes to meeting meaningful use attestation standards. Although a total of 114644 are registered in an EHR system, only 8303 actually meet meaningful use standards and qualify for federal incentives.</p>
<p>A recent report from Frost &amp; Sullivan, U.S. Hospital EHR Market, 2009-2016, shows that total EHR market revenues are expected to peak at $6.5 billion in 2012 due to new licensing and upgrades to hospital systems. This is a significant increase since 2009, when the EHR market earned revenues were at $973.2 million.</p>
<p>But with the trend of both healthcare consumers and young health industry graduates showing strong use and inclination toward EHR/EMRs, it’s predicted the rest of the established practices will need to play catch up in order to stay in the game.</p>
<p>Sources:</p>
<p><a href="http://manhattanresearch.com/News-and-Events/Press-Releases/ehr-consumer-online-medical-records">56 Million U.S. Consumers Access Medical Information From Electronic Health Records</a><br />
<a href="http://blog.canadianemr.ca/canadianemr/2011/10/new-graduates-highly-motivated-to-use-emrs.html">New Graduates Highly Motivated to Use EMRs</a><br />
<a href="http://www.frost.com/prod/servlet/press-release.pag?docid=244644384&amp;ctxixpLink=FcmCtx3&amp;ctxixpLabel=FcmCtx4">Accepting the Inevitable, U.S. Hospitals Significantly Ramp up Use of Electronic Health Records, Finds Frost &amp; Sullivan</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/upward-trend-of-consumer-use-of-ehrs-slower-trend-of-meaningful-use-attestation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Michigan Colocation Can Benefit Your Business</title>
		<link>http://resource.onlinetech.com/how-michigan-colocation-can-benefit-your-business/</link>
		<comments>http://resource.onlinetech.com/how-michigan-colocation-can-benefit-your-business/#comments</comments>
		<pubDate>Thu, 20 Oct 2011 13:10:11 +0000</pubDate>
		<dc:creator>Aaron Riddle</dc:creator>
				<category><![CDATA[Michigan Colocation]]></category>
		<category><![CDATA[colocation hosting]]></category>
		<category><![CDATA[colocation in michigan]]></category>
		<category><![CDATA[Michigan colocation]]></category>
		<category><![CDATA[outsourcing IT]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3441</guid>
		<description><![CDATA[Choosing where to store your data, whether internally or to an outside hosting provider, is a very important decision for any company these days. In addition, your IT staff is becoming more and more important as technology becomes more of a factor in how we do business. They’re not only worrying about keeping client data [...]]]></description>
			<content:encoded><![CDATA[<p>Choosing where to store your data, whether internally or to an outside hosting provider, is a very important decision for any company these days. In addition, your IT staff is becoming more and more important as technology becomes more of a factor in how we do business.</p>
<p>They’re not only worrying about keeping client data secure and network infrastructure up among its employees, but also trying to maintain business applications internally. Allocating some of those responsibilities from your IT staff could really benefit you and your IT staff in the long run.</p>
<div id="attachment_3450" class="wp-caption aligncenter" style="width: 571px"><img class="size-full wp-image-3450" title="Michigan: Ideal Location for Colocation and Data Centers" src="http://resource.onlinetech.com/wp-content/uploads/dc-poster-national.gif" href="http://www.onlinetech.com/colocation/michigan-colocation" alt="Michigan: Ideal Location for Colocation and Data Centers" alt="Michigan Colocation" width="561" height="561" /><p class="wp-caption-text">Michigan: Ideal Location for Colocation and Data Centers</p></div>
<p>Here are three reasons on how <a title="Michigan Colocation" href="http://www.onlinetech.com/colocation/michigan-colocation">Michigan Colocation</a> can benefit your business:</p>
<p>1. <strong>Location</strong> &#8211; Michigan is considered one of the best states in the country for <a title="Colocation Services" href="http://www.onlinetech.com/colocation/colocation-services">Colocation Services</a>. Why is it one of the best? Here are some facts:</p>
<ul>
<li><strong>Cool Climate</strong> &#8211; Michigan is primarily cool for most of the year, with only 4 months out of the year being over 60 degrees. This results in free cooling for most of the year and more cost-effective data centers.</li>
<li><strong>Low Risk of Tornadoes, Hurricanes, &amp; Earthquakes</strong> &#8211; Michigan has never experienced a hurricane, is highly unlikely to experience downtime from any seismic activity due to its location, and faces a significantly lower amount of tornadoes than most of the United States.</li>
<li><strong>Few Natural Disasters</strong> &#8211; From 1980 to 2009, Michigan had one of the fewest number of natural disasters that resulted in over $1 billion in damage.</li>
</ul>
<p>2. <strong>Readily Available Support</strong> &#8211; Outsourcing to a Michigan Colocation provider gives you the option of having a support team in charge of your <a title="Managed Dedicated Servers" href="http://www.onlinetech.com/managed-dedicated-servers">managed dedicated servers</a>, saving your IT team time and most importantly, money. By paying an outside provider for their services, you’re not paying for power, space for your servers, air conditioning and extra IT staff in your company. Now you can you put that extra time and money into other areas of your business.</p>
<p>3. <strong>Security &amp; Peace of Mind</strong> &#8211; When you choose a Michigan Colocation provider, you are providing your data to a company whose main goal is to secure your data and keep your company up and running. They live and breathe security and they take it very seriously when it comes to your data. Depending on what your company does, you may also have to follow strict policies, procedures and compliance regulations (<a title="HIPAA Compliant Hosting" href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA</a>, <a title="PCI Compliant Hosting" href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI</a>, <a title="SOX Compliant Hosting" href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting">SOX</a>) with the data you have stored, and those can be steep hurdles to climb to achieve those standards. Not having those standards can result in major fines to your company.</p>
<p>Having a peace of mind that your data is secure and that your applications or website have 100% uptime is a good feeling for any business executive. Achieving that on your own is another story. It is definitely possible, but you’ll be putting a lot of time and resources into getting it done. Why not save that time and invest in a Michigan Colocation provider that can tailor to your business needs and can guarantee that your data is secure and always up and running? It becomes a Win-Win situation for both parties.</p>
<p>Want more information on Michigan Colocation? Check out our E-Tips where you can check out our <a title="Managed Colocation Guide" href="http://www.onlinetech.com/resources/e-tips/michigan-colocation/managed-colocation-guide">Managed Colocation Guide</a>, and find out <a title="What To Expect From Your Managed Colocation Provider" href="http://www.onlinetech.com/resources/e-tips/michigan-colocation/what-to-expect-from-your-managed-colocation-provider">What To Expect From Your Managed Colocation Provider</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/how-michigan-colocation-can-benefit-your-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliant IT Security and Best Practices</title>
		<link>http://resource.onlinetech.com/hipaa-compliant-it-security-and-best-practices/</link>
		<comments>http://resource.onlinetech.com/hipaa-compliant-it-security-and-best-practices/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 16:10:01 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[free hipaa webinars]]></category>
		<category><![CDATA[free webinars]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA audits]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa IT]]></category>
		<category><![CDATA[hipaa security]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3468</guid>
		<description><![CDATA[If you collect, process, store or transmit protected health information (PHI), including medical records, you will need to be able to pass a HIPAA audit to meet HIPAA compliance. To meet security safeguards, certain technologies and procedures are recommended in the industry, even if not specifically outlined by HIPAA standards. The rules and regulations in [...]]]></description>
			<content:encoded><![CDATA[<p>If you collect, process, store or transmit protected health information (PHI), including medical records, you will need to be able to pass a HIPAA audit to meet HIPAA compliance. To meet security safeguards, certain technologies and procedures are recommended in the industry, even if not specifically outlined by HIPAA standards.</p>
<p>The rules and regulations in the Code of Federal Regulations (CFR) that pertain to HIPAA dictate that Online Tech, as a business that deals with clients’ PHI, must:</p>
<ol>
<li>Protect the availability, integrity and confidentiality of PHI</li>
<li>Have Business Associate Agreements (BAAs) with clients who have PHI</li>
<li>Report any violations of PHI misuse to the OCR (the Office of Civil Rights that audits, fines and charges companies and individuals for HIPAA violations).</li>
</ol>
<p>We deploy all of the following <strong>technology</strong> internally that helped us pass our own HIPAA audit, and allows us to offer <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> solutions in our <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a> (we also happen to offer and recommend these services to our clients that need to be HIPAA compliant):</p>
<ul>
<li>Private Firewall services (either a Virtual or Dedicated Firewall) with VPN for remote access</li>
<li><a href="http://www.onlinetech.com/cloud-computing-hosting/managed-cloud-hosting">Managed Cloud Server</a> (good to ensure high availability and access to data and applications)</li>
<li>Separate database and web servers for production</li>
<li>Separate test server (while the same for web and database, it is not the same for production)</li>
<li><a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">Offsite backup</a> at a minimum, although <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> is better</li>
<li>SSL certificates and HTTPS for all web-based access to PHI (to ensure secure connections)</li>
<li>Set up private IP addresses</li>
<li>Encryption – best practice to do while it is stored in the database and especially in transport. PHI should be encrypted to the NIST standard, <a href="http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf">Advanced Encryption Standard</a> (AES).</li>
</ul>
<p>HIPAA compliance is about more than just deploying the right technology; it’s also about your own policies and procedures. What are some <strong>best practices</strong> for your company to do to meet HIPAA compliance?</p>
<ul>
<li>Documentation – write out data management, security, employee training and notification plans.</li>
<li>Implement a password policy.</li>
<li>Don’t use public FTP (File Transfer Protocol) to move your files.</li>
<li>Only use VPN access for remote access.</li>
<li>Implement login retry protection in your application.</li>
<li>Document a tested and detailed disaster recovery plan to recover data in the event of a disaster.</li>
</ul>
<p>If you still have questions about HIPAA compliance, <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">register</a> for our educational webinar series on achieving HIPAA compliance.</p>
<p>We encourage you to submit your questions about HIPAA compliance and the auditing process in advance for consideration during the webinar by emailing <a href="mailto:contactus@onlinetech.com?subject=Security%20Webinar%20Series%20Question">contactus@onlinetech.com</a>.</p>
<div id="attachment_3469" class="wp-caption aligncenter" style="width: 570px"><img class="size-full wp-image-3469" title="HIPAA Webinar Series: A to Z to Achieving HIPAA Compliance" src="http://resource.onlinetech.com/wp-content/uploads/hipaa_series_webinar_banner.gif" alt="HIPAA Webinar Series: A to Z to Achieving HIPAA Compliance" width="560" height="192" /><p class="wp-caption-text">HIPAA Webinar Series: A to Z to Achieving HIPAA Compliance</p></div>
<p>Online Tech is hosting a three-part series of free educational webinars titled <strong>“A to Z to Achieving HIPAA Compliance”</strong> running October 25 – November 8, 2011. This webinar series is helpful for healthcare organizations that interact with patient information or vendors of covered entities that need guidance on becoming <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a>.<strong><br />
</strong></p>
<div id="attachment_3473" class="wp-caption alignleft" style="width: 110px"><img class="size-full wp-image-3473" title="Speaker Joe Dylewski" src="http://resource.onlinetech.com/wp-content/uploads/joe-dylewski-100.jpg" alt="Speaker Joe Dylewski" width="100" height="138" /><p class="wp-caption-text">Speaker Joe Dylewski</p></div>
<p><strong>10/25/11 @ 2pm ET: Cost-Effective Protection Against HIPAA Enforcement</strong></p>
<p>In the first webinar of the series, special guest speaker Joe Dylewski will discuss HIPAA enforcement and penalties in the event of a HIPAA violation and how to avoid a HIPAA breach using the most cost-effective methods.</p>
<p>Dylewski, a Certified HIPAA Security Specialist (CHSS) and Certified HIPAA Professional (CHP), has twenty-three years of IT professional experience with eight years spent exclusively in the healthcare industry. Serving as a former Healthcare IT Services Practice Director, Dylewski is now the current President of the ATMP (Applied Technology Methods and Practices) Group, offering HIPAA risk assessments and HIPAA compliance remediation solutions.</p>
<div id="attachment_3474" class="wp-caption alignleft" style="width: 110px"><img class="size-full wp-image-3474" title="Speaker Jason Yaeger" src="http://resource.onlinetech.com/wp-content/uploads/jason-yaeger-100.jpg" alt="Speaker Jason Yaeger" width="100" height="150" /><p class="wp-caption-text">Speaker Jason Yaeger</p></div>
<p><strong>11/01/11 @ 2pm ET: Impact of HIPAA Compliance on Business Associates – Changes to Company Policies and Day-to-Day Operations</strong></p>
<p>The second webinar of the series features Online Tech’s Risk Management Officer and Security Officer, Jason Yaeger and his experience guiding a company through a HIPAA audit. Yaeger will discuss the impact of HIPAA certification on his role, company policies, and day-to-day operations for employees of a HIPAA compliant data center.</p>
<div id="attachment_3475" class="wp-caption alignleft" style="width: 110px"><img class="size-full wp-image-3475" title="Speaker Tatiana Melnik" src="http://resource.onlinetech.com/wp-content/uploads/tatiana-melnik-100.jpg" alt="Speaker Tatiana Melnik" width="100" height="150" /><p class="wp-caption-text">Speaker Tatiana Melnik</p></div>
<p><strong>11/08/11 @ 2pm ET: Sharing PHI Data? Legal Implications of BAAs &amp; Avoiding HIPAA Pitfalls</strong></p>
<p>For the third webinar of the series, special guest speaker Tatiana Melnik will cover legal implications of BAAs (Business Associate Agreement) when patient information is shared, processed, or stored between companies.</p>
<p>As an attorney with the Dickinson Wright law firm, Melnik’s practice focuses on information technology, healthcare information technology, and intellectual property and privacy issues. In addition to being a member of the Michigan Bar Information Technology Law Council and Automation Alley Information Technology Committee, Melnik holds a JD from the University of Michigan Law School and a BS in Information Systems and BBA in International Business from the University of North Florida. Melnik presents at the upcoming Midwest HIMSS conference in November and at the Annual HIMSS conference in February.</p>
<p>Get more information and <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/webinar-series-a-to-z-to-achieving-hipaa-compliance">sign up</a> today.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-compliant-it-security-and-best-practices/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cloud Computing Market Trends: Video Interview</title>
		<link>http://resource.onlinetech.com/cloud-computing-market-trends-video-interview/</link>
		<comments>http://resource.onlinetech.com/cloud-computing-market-trends-video-interview/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 11:00:35 +0000</pubDate>
		<dc:creator>Mike Klein</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Online Data Storage]]></category>
		<category><![CDATA[cloud computing interview]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[high availability cloud computing]]></category>
		<category><![CDATA[online tech interview]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3412</guid>
		<description><![CDATA[TMCnet.com inteviews Mike Klein, COO of Online Tech, about his presentation at MSPWorld&#8217;s 2011 ITEEXPO in Austin, TX, as well as about the emerging trends of cloud computing in the market. Three key focuses include: Mission critical applications and the need for high availability cloud computing; How disaster recovery changes significantly in the cloud computing [...]]]></description>
			<content:encoded><![CDATA[<p>TMCnet.com inteviews Mike Klein, COO of Online Tech, about his presentation at MSPWorld&#8217;s 2011 ITEEXPO in Austin, TX, as well as about the emerging trends of <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> in the market.</p>
<p>Three key focuses include:</p>
<ul>
<li>Mission critical applications and the need for <a href="http://www.onlinetech.com/cloud-computing-hosting/private-cloud-hosting-packages/high-availability-private-cloud">high availability cloud computing</a>;</li>
<li>How <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> changes significantly in the cloud computing world; and</li>
<li>Regulatory compliance including <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> and <a href="http://www.onlinetech.com/secure-hosting/pci-compliant-hosting">PCI compliance</a>, and how to support these standards in the cloud.</li>
</ul>
<p style="text-align: center;"><iframe src="http://www.tmcnet.com/tmc/videos/videoiframe.aspx?vid=5215&amp;width=450&amp;height=270" frameborder="0" scrolling="no" width="450" height="270"></iframe></p>
<p>Get more information on cloud computing with Online Tech&#8217;s <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing">Cloud Computing E-Tips</a>, or find Online Tech <a href="http://www.onlinetech.com/resources/news-a-events/in-the-news">In the News</a>.</p>
<p>Read the <a href="http://www.onlinetech.com/resources/news-a-events/events/seminars/item/360-cloud-computing-market-trends-video-interview">full video transcript</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cloud-computing-market-trends-video-interview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Military Healthcare Contractor’s HIPAA Breach Followed by $4.9 Billion Lawsuit</title>
		<link>http://resource.onlinetech.com/military-healthcare-contractor%e2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/</link>
		<comments>http://resource.onlinetech.com/military-healthcare-contractor%e2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/#comments</comments>
		<pubDate>Tue, 18 Oct 2011 12:53:42 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[2011 hipaa violation]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[disaster recovery in the cloud]]></category>
		<category><![CDATA[HIPAA breach]]></category>
		<category><![CDATA[HIPAA violation]]></category>
		<category><![CDATA[offsite backup]]></category>
		<category><![CDATA[tape backup]]></category>
		<category><![CDATA[tricare]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3423</guid>
		<description><![CDATA[If you’ve been following the TRICARE HIPAA breach of PHI reported at the end of September, you’ll know that 4.9 million people were affected by the loss of data backup tapes under the Defense Department’s military healthcare program. Now a $4.9 billion lawsuit seeking class action status for those affected individuals hangs over the offenders’ [...]]]></description>
			<content:encoded><![CDATA[<p>If you’ve been following the TRICARE <a href="http://resource.onlinetech.com/lost-military-backup-tapes-results-in-hipaa-violation-affecting-4-9-million/">HIPAA breach</a> of PHI reported at the end of September, you’ll know that 4.9 million people were affected by the loss of data backup tapes under the Defense Department’s military healthcare program. Now a $4.9 billion lawsuit seeking class action status for those affected individuals hangs over the offenders’ heads, seeking $1,000 for each affected individual.</p>
<p>The affected individuals that filed the lawsuit include a military spouse, her two children and an Air Force veteran. The suit specifically targets Secretary Leon Panetta for violating the Federal Administrative Procedures Act and the Federal Privacy Act of 1974. While the data breach is a clear HIPAA violation, the <a href="http://www.justice.gov/opcl/privacyact1974.htm">Privacy Act of 1974</a> details the code of fair information practices that controls the storage, use, maintenance and dissemination of information by federal agencies, meaning the Department of Defense is also held liable for more than just a HIPAA fine.</p>
<div id="attachment_3428" class="wp-caption aligncenter" style="width: 530px"><img class="size-full wp-image-3428 " title="TRICARE HIPAA Breach &amp; Lawsuit" src="http://resource.onlinetech.com/wp-content/uploads/TRICARE-HIPAA-Breach.jpg" alt="TRICARE HIPAA Breach &amp; Lawsuit" width="520" height="503" /><p class="wp-caption-text">TRICARE HIPAA Breach &amp; Lawsuit</p></div>
<p>At the time the incident was reported, details had not yet been released as an investigation was underway. Now the data breach appears to be attributed to physical theft – the backup tapes with PHI records dating from 1992 to 2011 were stolen out of the back of a car of a SAIC employee (Science Applications International Corp. &#8211; TRICARE’s contractor and business associate that provided <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/offsite-backup">offsite backup</a>, storage and data security for the military insurance carrier, and also reported the breach).</p>
<p>Physical theft proves to be one of the most reoccurring causes of HIPAA breaches thus far, according to HHS data on HIPAA violations and as represented in an <a href="http://resource.onlinetech.com/2011-hipaa-violations-and-audits/">earlier blog post</a>. Another factor that may have contributed is the type of backup the military contractor chose – tape backup. Considered a more traditional disaster recovery method, tape backup is highly error-prone and time-consuming, and, apparently, at risk for physical theft and subsequent HIPAA breaches.</p>
<p>One alternative is <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery/comprehensive-disaster-recovery">cloud disaster recovery</a>, which can improve accuracy and recovery time objectives (RTO), and can be secured with encryption, logging, vulnerability and penetration testing, etc. to ensure your data is safely backed up. Virtualization also eliminates the possibility of physical data theft, as exemplified by the SAIC loss of backup tapes.</p>
<p>Among the 11 orders in the lawsuit, three include concerns around data security practices, systems and procedures:</p>
<ul>
<li><em>Prohibiting defendants from transporting any confidential records by non-secure means and unless the records are properly encrypted. </em>– Transporting tape backup records in the trunk of a car may fall under ‘non-secure means.’</li>
<li><em>Requiring defendants to set up proper systems and procedures to maintain the privacy of protected information.</em> – Refers to implementing HIPAA compliant policies and procedures.</li>
<li><em>Prohibiting defendants and SAIC from transferring any records until an independent expert panel finds that adequate information security has been established.</em> – Similar to Online Tech’s recent HIPAA audit by an independent CHP (Certified HIPAA Professional) and CHSS (Certified HIPAA Security Specialist) to prove our fully <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant hosting</a> and <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data centers</a> can provide proper data security for organizations that need to protect PHI.</li>
</ul>
<p>Still concerned about HIPAA compliance and cloud security? Watch the webinar <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/modern-security-standards-series/new-solutions-for-security-and-compliance-in-the-cloud">New Solutions for Security and Compliance in the Cloud</a> to learn more. Or read our E-Tip, <a href="http://www.onlinetech.com/resources/e-tips/disaster-recovery/benefits-of-disaster-recovery-in-cloud-computing">Benefits of Disaster Recovery in Cloud Computing</a> and watch our webinar, <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/modern-security-standards-series/hipaa-compliance-in-the-cloud-a-in-the-data-center">HIPAA Compliance in the Cloud &amp; in the Data Center</a> to make an informed decision on your disaster recovery options.</p>
<p>Sources:<br />
<a href="http://www.justice.gov/opcl/privacyact1974.htm">USDOJ: OPCL: Privacy Act of 1974</a><br />
<a href="http://www.healthdatamanagement.com/news/breach-tricare-notification-hipaa-privacy-43404-1.html">TRICARE Hit with $4.9 Billion Suit Following Breach</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/military-healthcare-contractor%e2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disaster Recovery in the Cloud: Online Tech at 7&#215;24 Exchange&#8217;s 2011 Fall Conference</title>
		<link>http://resource.onlinetech.com/disaster-recovery-in-the-cloud-online-tech-at-7x24-exchanges-2011-fall-conference/</link>
		<comments>http://resource.onlinetech.com/disaster-recovery-in-the-cloud-online-tech-at-7x24-exchanges-2011-fall-conference/#comments</comments>
		<pubDate>Mon, 17 Oct 2011 15:01:16 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[cloud computing for disaster recovery]]></category>
		<category><![CDATA[cloud disaster recovery]]></category>
		<category><![CDATA[disaster recovery]]></category>
		<category><![CDATA[disaster recovery in the cloud]]></category>
		<category><![CDATA[it disaster recovery]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3394</guid>
		<description><![CDATA[Online Tech’s CEO Yan Ness has been selected to speak at 7&#215;24 Exchange’s Fall Conference “Leveraging Innovation” in Phoenix, Arizona. According to 7x24exchange.org, the conference is designed for IT, data center, and disaster recovery professionals, network/telecommunication managers, computer technologists, facility or building managers, supervisors and engineers, vendors, consultants and anyone concerned with uninterrupted access to critical [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_3395" class="wp-caption alignleft" style="width: 284px"><img class="size-full wp-image-3395 " title="Leveraging Innovation" src="http://resource.onlinetech.com/wp-content/uploads/Leveraging-Innovation.jpg" alt="Leveraging Innovation" width="274" height="97" /><p class="wp-caption-text">Leveraging Innovation</p></div>
<p>Online Tech’s CEO Yan Ness has been selected to speak at 7&#215;24 Exchange’s <a href="http://www.7x24exchange.org/fall11/index.html">Fall Conference</a> “Leveraging Innovation” in Phoenix, Arizona.</p>
<p>According to 7x24exchange.org, the conference is designed for IT, <a href="http://www.onlinetech.com/company/michigan-data-centers">data center</a>, and <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">disaster recovery</a> professionals, network/telecommunication managers, computer technologists, facility or building managers, supervisors and engineers, vendors, consultants and anyone concerned with uninterrupted access to critical information.</p>
<p>The <a href="http://www.7x24exchange.org/fall11/ed_sessions.html#mondaybreakoutc">breakout session</a> is titled “The Cloud and the Availability Spectrum.” Ness will discuss the challenges that companies face when choosing to adopt either the cloud or a disaster recovery plan, as well as share a case study of Online Tech&#8217;s own migration to cloud disaster recovery:</p>
<blockquote><p><em>The potential of <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> to reduce recovery time and achieve better utilization of resources dedicated to disaster recovery has tantalizing appeal for businesses wanting to improve their resilience.</em></p>
<p><em>The problem is, expectations are often misaligned with the selected technologies or the path of getting from the current infrastructure to one that is truly capable of both failover and failback in the event of an actual disaster.</em></p>
<p><em>Progressing companies are often forced to learn painful lessons by piloting new systems: cloud first or disaster recovery first? Is there a path that can embrace both? How do we find out what we don’t know to ask?</em></p>
<p><em>Yan Ness from Online Tech shares the questions, challenges, and solutions generated during Online Tech’s own migration from “offsite backup” to true Active-Active availability with a cloud/disaster recovery infrastructure capable of continuity in a meaningful, realistic manner.</em></p></blockquote>
<div id="attachment_3396" class="wp-caption alignright" style="width: 343px"><img class="size-full wp-image-3396" title="The Cloud and The Availability Spectrum: Disaster Recovery in the Cloud" src="http://resource.onlinetech.com/wp-content/uploads/The-Cloud-and-The-Availability-Spectrum.png" alt="The Cloud and The Availability Spectrum: Disaster Recovery in the Cloud" width="333" height="248" /><p class="wp-caption-text">The Cloud and The Availability Spectrum: Disaster Recovery in the Cloud</p></div>
<p>7&#215;24 is a leadership collective for professionals that design, build, use and maintain mission-critical enterprise information infrastructures. Read our recent <a href="http://www.onlinetech.com/resources/news-a-events/press-releases/2011/online-tech-shares-cloud-strategies-for-disaster-recovery-at-7x24-exchange-fall-conference">press release</a> for more information about Ness’s presentation and the conference.</p>
<p>Or read one of our E-Tips on the <a href="http://www.onlinetech.com/resources/e-tips/disaster-recovery/benefits-of-disaster-recovery-in-cloud-computing">Benefits of Disaster Recovery in Cloud Computing</a> and how the cloud changes conventional disaster recovery. Watch a webinar on <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/cloud-computing-for-backup-a-dr-series/disaster-recovery-in-the-cloud-san-to-san-replication">Disaster Recovery in the Cloud &#8211; SAN to SAN Replication</a> for a more technical overview.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/disaster-recovery-in-the-cloud-online-tech-at-7x24-exchanges-2011-fall-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Invests in Cloud Computing Data Center</title>
		<link>http://resource.onlinetech.com/apple-invests-in-cloud-computing-data-center/</link>
		<comments>http://resource.onlinetech.com/apple-invests-in-cloud-computing-data-center/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 16:07:50 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[apple cloud data center]]></category>
		<category><![CDATA[apple icloud]]></category>
		<category><![CDATA[cloud computing news]]></category>
		<category><![CDATA[cloud data center]]></category>
		<category><![CDATA[cloud hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3378</guid>
		<description><![CDATA[With the release of iCloud on Wednesday, Apple has been dipping in the cloud computing pool recently with significant ongoing investments – in 2009, the company announced plans to spend billions of dollars on a data center in North Carolina over the course of nine years to support future projects. Asmyco.com reports the total spend [...]]]></description>
			<content:encoded><![CDATA[<p>With the release of iCloud on Wednesday, Apple has been dipping in the <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> pool recently with significant ongoing investments – in 2009, the company announced plans to spend billions of dollars on a data center in North Carolina over the course of nine years to support future projects.</p>
<div id="attachment_3379" class="wp-caption alignright" style="width: 249px"><img class="size-full wp-image-3379 " title="Apple Cloud Data Center" src="http://resource.onlinetech.com/wp-content/uploads/Apple-Cloud-Data-Center.jpg" alt="Apple Cloud Data Center" width="239" height="206" /><p class="wp-caption-text">Apple Cloud Data Center</p></div>
<p><a href="http://www.asymco.com/2011/10/14/the-down-payment-on-icloud/">Asmyco.com</a> reports the total spend to have hit $1 billion last December, while the down payment for the 500,000 square foot cloud data center is estimated at $750 million.</p>
<p>With over a billion spent on cloud computing costs, including servers, storage equipment, personnel, R&amp;D, bandwidth and more, Apple has been investing aggressively to keep iTunes, Apps, iCloud and its other cloud-based services on par with demand.</p>
<p>However, the NYTimes.com <a href="http://bits.blogs.nytimes.com/2011/10/13/customers-run-into-trouble-in-the-icloud/?ref=technology">Bits blog</a> reports numerous error messages while using the new iCloud software designed to sync multimedia across numerous devices. The problems are attributed to a major spike in traffic and simultaneous downloading of the new software update, but similar issues occurred during the first few weeks of the MobileMe launch several years ago.</p>
<div id="attachment_3380" class="wp-caption aligncenter" style="width: 576px"><img class="size-full wp-image-3380 " title="Apple Cloud Data Center Spending" src="http://resource.onlinetech.com/wp-content/uploads/Apple-Cloud-Data-Center-Spending.jpg" alt="Apple Cloud Data Center Spending" width="566" height="419" /><p class="wp-caption-text">Apple Cloud Data Center Spending</p></div>
<div id="attachment_3382" class="wp-caption alignright" style="width: 156px"><img class="size-full wp-image-3382 " title="iCloud Icon" src="http://resource.onlinetech.com/wp-content/uploads/iCloud-Icon.png" alt="iCloud Icon" width="146" height="214" /><p class="wp-caption-text">iCloud Icon</p></div>
<p>Will Apple’s iCloud introduce serious competition to Gmail, Google Docs, or Google Sync? The iCloud is Apple-only, meaning it doesn’t support a wide variety of Windows or other brand devices. Google Sync does allow you to use different devices, including Windows, Android, Blackberry, Noki and Apple devices. This difference could affect a wider audience, save the group of primarily only-Apple users.</p>
<p>Apple’s iCloud is consumer-facing, but what about cloud computing for businesses? Read more about the <a href="http://www.onlinetech.com/resources/e-tips/cloud-computing/what-are-the-benefits-of-private-cloud-computing-for-businesses">Benefits of Cloud Computing for Businesses</a> to find out how the cloud is cost-effective, flexible and customizable to adapt to business needs.</p>
<p>Sources:<br />
<a href="http://bits.blogs.nytimes.com/2011/10/13/customers-run-into-trouble-in-the-icloud/?ref=technology">Customers Run Into Trouble in the iCloud</a><br />
<a href="http://www.asymco.com/2011/10/14/the-down-payment-on-icloud/">The Down Payment on iCloud</a><br />
<a href="http://9to5mac.com/2011/10/14/apple-already-spent-750-million-on-the-icloud-building-alone/">Apple Already Spent $750 million on the iCloud Building Alone?</a><br />
<a href="http://www.datacenterknowledge.com/archives/2011/10/14/report-apple-has-spent-750m-on-idatacenter/">Report: Apple Has Spent $750m on iDataCenter</a><br />
<a href="http://www.ausbt.com.au/icloud-for-business-travellers-your-essential-guide">iCloud for Business Travellers</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/apple-invests-in-cloud-computing-data-center/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA &amp; Health IT: $872 Million in Incentives</title>
		<link>http://resource.onlinetech.com/hipaa-health-it-872-million-in-incentives/</link>
		<comments>http://resource.onlinetech.com/hipaa-health-it-872-million-in-incentives/#comments</comments>
		<pubDate>Fri, 14 Oct 2011 13:05:41 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[EHR incentives]]></category>
		<category><![CDATA[electronic health records]]></category>
		<category><![CDATA[health IT incentives]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HITECH]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3357</guid>
		<description><![CDATA[The national EHR incentive program is rapidly changing healthcare operations, and as a result, an increasing awareness of health IT is accelerating the need to meet HIPAA compliance requirements for security and privacy. Since the establishment of the meaningful use program on January 1, 2011, the federal government has paid out more than $872 million [...]]]></description>
			<content:encoded><![CDATA[<p>The national EHR incentive program is rapidly changing healthcare operations, and as a result, an increasing awareness of health IT is accelerating the need to meet <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> requirements for security and privacy.</p>
<p>Since the establishment of the meaningful use program on January 1, 2011, the federal government has paid out more than $872 million in incentives to Medicaid/Medicare health organizations and individual providers that have adopted a meaningful use electronic health records (EHR) system.</p>
<p>While a total of 114644 organizations and individual providers are registered in an EHR system, only 8303 meet the meaningful use standards for attestation.</p>
<p>What is meaningful use? The Centers for Medicare &amp; Medicaid Services (CMS) website lists three main components form the American Recovery and Reinvestment Act of 2009:</p>
<ol>
<li>The use of a certified EHR in a meaningful manner, such as e-prescribing.</li>
<li>The use of certified EHR technology for electronic exchange of health information to improve quality of healthcare.</li>
<li>The use of certified EHR technology to submit clinical quality and other measures.</li>
</ol>
<div id="attachment_3358" class="wp-caption aligncenter" style="width: 530px"><img class="size-full wp-image-3358" title="Health IT Incentives" src="http://resource.onlinetech.com/wp-content/uploads/Health-IT-Incentives.jpg" alt="HIPAA and Health IT Incentives" width="520" height="554" /><p class="wp-caption-text">HIPAA and Health IT Incentives</p></div>
<p>The EHR incentive program website provides a timeline of useful dates related to upcoming payments and deadlines:</p>
<p><strong>November 30, 2011</strong> – Last day for eligible hospitals and critical access hospitals to register and attest to receive an Incentive Payment for Federal fiscal year (FY) 2011.</p>
<p><strong>December 31, 2011</strong> – Reporting year ends for eligible professionals.</p>
<p><strong>February 29, 2012</strong> – Last day for eligible professionals to register and attest to receive an Incentive Payment for calendar year (CY) 2011.</p>
<p>Find more resources for <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA policies, procedures and training</a> materials to help your organization achieve <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a>.</p>
<p>Sources:</p>
<p><a href="http://www.modernhealthcare.com/article/20111012/NEWS/310129986/cms-872-million-in-it-incentives-paid?AllowView=VW8xUmo5Q21TcWJOb1gzb0tNN3RLZ0h0MWg5SVgra3NZRzROR3l0WWRMZmFWUHdERWxiNUtpQzMyWmFyNW40WUpiU25iUlF5MUE1QnRUM2FBZnM5anlLYnFKeXhYSks4UStZVEJLc0cwckxxYWFUNHBzeFRZc0k9#">CMS: $872 Million in IT Incentives Paid</a></p>
<p><a href="http://www.hhs.gov/news/press/2010pres/09/20100910a.html">New Funds Support Rural Hospitals’ Switch to Electronic Health Records</a></p>
<p><a href="https://www.cms.gov/ehrincentiveprograms/30_Meaningful_Use.asp">CMS EHR Meaningful Use Overview</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-health-it-872-million-in-incentives/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Benefits of Managed Dedicated Servers</title>
		<link>http://resource.onlinetech.com/benefits-of-managed-dedicated-servers/</link>
		<comments>http://resource.onlinetech.com/benefits-of-managed-dedicated-servers/#comments</comments>
		<pubDate>Wed, 12 Oct 2011 13:29:48 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Managed Servers]]></category>
		<category><![CDATA[fully managed dedicated servers]]></category>
		<category><![CDATA[fully managed servers]]></category>
		<category><![CDATA[managed dedicated servers]]></category>
		<category><![CDATA[managed servers]]></category>
		<category><![CDATA[server hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3327</guid>
		<description><![CDATA[When it comes to conducting a cost-benefit analysis of hosting your servers with a third party versus maintaining your own servers, take note that benefits lie primarily in security, support, reliability and scalability. Leaving IT up to the experts can save you time and money better spent on growing your business. Security - Quality data centers [...]]]></description>
			<content:encoded><![CDATA[<p>When it comes to conducting a cost-benefit analysis of hosting your servers with a third party versus maintaining your own servers, take note that benefits lie primarily in security, support, reliability and scalability. Leaving IT up to the experts can save you time and money better spent on growing your business.<br />
<strong></strong></p>
<p><strong>Security - </strong>Quality <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> will invest the capital and time to undergo audits to ensure their physical security, logical network security, employee training and company-wide policies and procedures meet national standards. The older standard used originally for financial reporting, <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/sas-70-hosting">SAS 70</a> (Statement on Auditing Standard), is now replaced by <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/ssae-16-hosting">SSAE 16</a> (Statement on Standards for Attestation Engagements) and <a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-2-a-soc-3-hosting">SOC 2</a>/<a href="http://www.onlinetech.com/secure-hosting/sarbanes-oxley-sox-compliant-hosting/soc-3-hosting">SOC 3</a> reports to indicate data center excellence.</p>
<p>Managed hosting also provides timely software updates to ensure your servers are protected against any newly developed viruses or malware. <a href="http://www.onlinetech.com/managed-services/offsite-backup">Offsite backup</a> is another critical service that could save your business in the event of a disaster by keeping your vital applications and data safe and available.</p>
<p><strong>Expert support - </strong>An entire team of experienced, certified and responsive staff can provide 24&#215;7 server monitoring and physical data center monitoring to stay aware of any potential issues.</p>
<p>While companies may not be prepared to invest in an in-house IT team, <a href="http://www.onlinetech.com/managed-dedicated-servers/benefits-of-managed-dedicated-servers">managed dedicated servers</a> come with a high level of professional support, saving you time and money that can be better spent elsewhere. Cutting down on staff hiring and training can seriously help your bottom line and streamline business operations.</p>
<p><strong>Reliable - </strong>When IT is not your industry focus, it can be a substantial burden as you try to manage your own servers. Worries about uptime can slow your business growth and become a distraction.</p>
<p>A managed dedicated server host can provide a quality data center infrastructure to ensure your servers are up and running. Since data centers are their business, they should already have uninterruptible power and network connections with no single point of failure. Why not take advantage of their investments?</p>
<p><strong>Scalable - </strong>Dealing with outages when your business is outgrowing product or service demands can be a pain. Managed dedicated server hosts often have additional space available to support your expansion needs.</p>
<p>With the support of professional, experienced staff, you can flawlessly deploy new servers with full expert support. Other additional services can make tasks like updating or monitoring your bandwidth, disk space and CPU usage as easy as logging into a portal and sending requests to your host.</p>
<p>Read more about a <a href="http://www.onlinetech.com/resources/case-studies/the-cellthis-company">fully managed dedicated server case study</a> of a mobile marketing company that was experiencing downtime and needed a new managed server provider, and how Online Tech helped them achieve 100% uptime with quality support and service.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/benefits-of-managed-dedicated-servers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Nine Components of a HIPAA Risk Analysis</title>
		<link>http://resource.onlinetech.com/nine-elements-of-a-hipaa-risk-analysis/</link>
		<comments>http://resource.onlinetech.com/nine-elements-of-a-hipaa-risk-analysis/#comments</comments>
		<pubDate>Tue, 11 Oct 2011 13:22:25 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[components of risk analysis]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[hipaa risk analysis]]></category>
		<category><![CDATA[HIPAA risk analysis components]]></category>
		<category><![CDATA[hipaa safeguards]]></category>
		<category><![CDATA[hipaa security rule]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3269</guid>
		<description><![CDATA[The Department of Health and Human Services requires organizations to conduct a risk analysis as the first step toward implementing safeguards specified in the HIPAA Security Rule, and ultimately achieving HIPAA compliance. But what does a risk analysis entail, and what do you absolutely have to include in your report? The HHS Security Standards Guide [...]]]></description>
			<content:encoded><![CDATA[<p>The Department of Health and Human Services requires organizations to conduct a risk analysis as the first step toward implementing safeguards specified in the HIPAA Security Rule, and ultimately achieving HIPAA compliance. But what does a risk analysis entail, and what do you absolutely have to include in your report?</p>
<p>The HHS Security Standards Guide outlines nine mandatory components of a risk analysis that healthcare organizations and healthcare-related organizations that store or transmit EPHI (electronic protected health information) must include in their document:</p>
<ol>
<li><strong>Scope of the Analysis</strong> – Any potential risks and vulnerabilities to the privacy, availability and integrity of EPHI. This includes all electronic media your organization uses to create, receive, maintain or transmit EPHI – portable media, desktops and networks. Network security between multiple locations is also important to include in the scope of the analysis, and may include aspects of your <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> terms with a third-party or Business Associate.</li>
<li><strong>Data Collection</strong> – Where does the EPHI go? Locate where data is being stored, received, maintained or transmitted. Again, if you’re hosting health information at a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a>, you’ll need to contact your hosting provider to document where and how your data is stored.</li>
<li><strong>Identify and Document Potential Threats and Vulnerabilities </strong>– Identify and document any anticipated threats to sensitive data, and any vulnerabilities that may lead to leaking of EPHI. Anticipating potential <a href="http://resource.onlinetech.com/2011-hipaa-violations-and-audits/">HIPAA violations</a> can help your organization quickly and effectively reach a resolution.</li>
<li><strong>Assess Current Security Measures</strong> – What kind of security measures are you taking to protect your data? From a technical perspective, this might include any encryption, two-factor authentication, and other security methods put in place by your HIPAA hosting provider.</li>
<li><strong>Determine the Likelihood of Threat Occurrence – </strong>Take account of the probability of potential risks to EPHI – in combination with #3 Potential Threats and Vulnerabilities, this assessment allows for estimates on the likelihood of EPHI breaches.</li>
<li><strong>Determine the Potential Impact of Threat Occurrence –</strong> By using either qualitative or quantitative methods, assess the maximum impact of a data threat to your organization. How many people could be affected? What extent of private data could be exposed – just medical records, or both health information and billing information combined?</li>
<li><strong>Determine the Level of Risk –</strong> HHS suggests taking the average of the assigned likelihood (#5) and impact levels (#6) to determine the level of risk. Documented risk levels should be accompanied by a list of corrective actions that would be performed to mitigate risk.</li>
<li><strong>Finalize Documentation – </strong>Write everything up in an organized document – HHS doesn’t specify any format, but they do require the analysis in writing.</li>
<li><strong>Periodic Review and Updates to the Risk Assessment – </strong>It’s important the risk analysis process is ongoing – one requirement includes conducting a risk analysis on a regular basis. While the Security Rule doesn’t set a required timeline, HHS recommends organizations conduct another risk analysis whenever your company implements or plans to adopt new technology or business operations. This could include switching your data storage methods from <a href="http://www.onlinetech.com/managed-servers">managed servers</a> to <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a>, or any ownership or key staff turnover.</li>
</ol>
<div>
<div id="attachment_3313" class="wp-caption aligncenter" style="width: 537px"><img class="size-full wp-image-3313 " title="HIPAA Risk Analysis Components" src="http://resource.onlinetech.com/wp-content/uploads/HIPAA-Risk-Analysis-Components.jpg" alt="HIPAA Risk Analysis Components" width="527" height="486" /><p class="wp-caption-text">HIPAA Risk Analysis Components</p></div>
</div>
<p>Looking for HIPAA resources from organizations that have HIPAA policies, procedures and training materials in place? View <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials">HIPAA resource links</a> on our site, or watch an educational webinar on the <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices">legal implications of HIPAA, HITECH, BAAs and the law</a>.</p>
<p>Source:<br />
<a href="http://www.google.com/url?sa=t&amp;source=web&amp;cd=2&amp;ved=0CFYQFjAB&amp;url=http%3A%2F%2Fwww.hhs.gov%2Focr%2Fprivacy%2Fhipaa%2Fadministrative%2Fsecurityrule%2Fradraftguidance.pdf&amp;ei=OXiLToXHJ4KusAK5uZzfBA&amp;usg=AFQjCNGJFnjsPShJBMnGxUvbjMyP4VJa7g">HIPAA Security Standards: Guidance on Risk Analysis from HHS.gov</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/nine-elements-of-a-hipaa-risk-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud Computing Prompts 2012 Data Center Expansion Plans</title>
		<link>http://resource.onlinetech.com/cloud-computing-prompts-2012-data-center-expansion-plans/</link>
		<comments>http://resource.onlinetech.com/cloud-computing-prompts-2012-data-center-expansion-plans/#comments</comments>
		<pubDate>Mon, 10 Oct 2011 13:32:40 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[2012 data centers]]></category>
		<category><![CDATA[building data center]]></category>
		<category><![CDATA[cloud computing data centers]]></category>
		<category><![CDATA[cloud hosting data centers]]></category>
		<category><![CDATA[data center expansion]]></category>
		<category><![CDATA[facebook data center]]></category>
		<category><![CDATA[google data centers]]></category>
		<category><![CDATA[microsoft data centers]]></category>
		<category><![CDATA[new data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3262</guid>
		<description><![CDATA[Who’s planning to build or expand data centers in the next few years? Major growth in Internet service demands and cloud computing is pushing major companies to expand or build new data centers around the world. Follow the breakdown of investments, land size and reasons for data center expansion: Click to View Full Size. Google [...]]]></description>
			<content:encoded><![CDATA[<p>Who’s planning to build or expand <a href="http://www.onlinetech.com/company/michigan-data-centers">data centers</a> in the next few years? Major growth in Internet service demands and <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> is pushing major companies to expand or build new data centers around the world. Follow the breakdown of investments, land size and reasons for data center expansion:</p>
<div class="wp-caption aligncenter" style="width: 597px"><a href="http://resource.onlinetech.com/eNews/Data-Center-Expansion-Map.jpg"><img class=" " title="2012 Data Center Expansion Plans" src="http://resource.onlinetech.com/eNews/Data-Center-Expansion-Map.jpg" alt="2012 Data Center Expansion Plans" width="587" height="403" /></a><p class="wp-caption-text">2012 Data Center Expansion Plans</p></div>
<p><a href="http://resource.onlinetech.com/eNews/Data-Center-Expansion-Map.jpg">Click to View Full Size.</a></p>
<p><strong>Google</strong></p>
<ul>
<li><strong><em>Dublin, Ireland</em></strong>: An energy-efficient, cloud computing data center on 11 acres of land with a $101 million investment. The natural cooling from Dublin’s climate saves energy by eliminating the need for chillers.</li>
<li><strong><em>Asia – Singapore, Hong Kong &amp;Taiwan</em></strong>: A $200 million investment in three data centers to support increased demand of services via smartphones and tablet computers, and expectations to be operational in 1 to 2 years.</li>
<li><strong><em>Pryor, Oklahoma </em></strong>– Just opened a new $600 million, 130,000 square feet data center, and plans to open a second building for office space. Another energy-efficient project, the data center will be powered from a wind farm which will feed into the electrical transmission grid.</li>
</ul>
<p><strong>Microsoft</strong></p>
<ul>
<li><strong><em>Dublin, Ireland</em></strong>: Microsoft expects to expand its 19-acre, $500 million data center in Dublin by more than a third – similar to Google, the data center uses natural cooling without any chillers.</li>
<li><strong><em>West Des Moines, Iowa</em></strong>: $200 million facility originally started in 2008 but put on hold after the recession. The data center project started up again in 2010, and appears to be nearing completion.</li>
<li><strong><em>Boydton , Virginia</em></strong>: An expansion investment of $150 million and a planned second data center facility. With the first phase of its project requiring $499 million, Microsoft is trying to stay competitive in the cloud computing market.</li>
</ul>
<p><strong>Facebook</strong></p>
<ul>
<li><strong><em>North Carolina</em></strong>: Scheduled for completion by September 2013, the second data center for this social network giant will measure 300,000 square feet, same as its first data center that hasn’t even opened yet. Facebook purchased 150 acres of land and invested $450 million in their first data center. The data center will be energy-efficient and deploy evaporative cooling instead of a chiller system.</li>
</ul>
<p><strong>IBM </strong></p>
<ul>
<li><strong><em>Langfang, China</em></strong>: A cloud computing data center for Range Technology Development Co. Ltd. measured at 620,000 square meters and intended to serve business growth industries such as transportation, telecommunications, e-government and healthcare.  IBM’s data center business in China has reportedly tripled in the last four years.</li>
</ul>
<p>What could be a cause of the rapid data center expansion planned for 2012 and beyond? DataCenterKnowledge.com reports that data center expansion and construction has been boosted by private equity firms and telecom company investments that have acquired established providers. A recent Data Center Market Insights survey shows over half of data center professionals planning to expand or build new data centers.</p>
<p>Online Tech also recently purchased a <a href="http://www.onlinetech.com/company/michigan-data-centers/locations/2nd-ann-arbor-michigan-data-center">new Michigan data center</a> located in Ann Arbor. Read our <a href="http://www.onlinetech.com/resources/news-a-events/press-releases/2011/online-tech-opens-new-data-center">press release</a> for more about our unique geographic advantage for <a href="http://www.onlinetech.com/managed-services/it-disaster-recovery">IT disaster recovery</a> and production.</p>
<p>Sources:<br />
<a href="http://www.thewhir.com/web-hosting-news/100411_Facebook_Building_Second_Massive_Data_Center_in_North_Carolina">Facebook Building Second Massive Data Center in North Carolina</a><br />
<a href="http://www.pcworld.com/businesscenter/article/217744/ibm_to_build_asias_largest_cloud_computing_center.html">IBM to Build Asia’s Largest Cloud Computing Center</a><br />
<a href="http://www.datacenterknowledge.com/archives/2011/09/30/google-to-build-major-new-data-center-in-dublin/">Google to Build Major New Data Center in Dublin</a><br />
<a href="http://online.wsj.com/article/BT-CO-20110928-700133.html">Google to Build Three Data Centers in Asia, Investment to Exceed $200M</a><br />
<a href="http://www.datacenterknowledge.com/archives/2011/09/23/microsoft-steps-up-cloud-expansion-plans/">Microsoft Steps Up Cloud Expansion Plans</a><br />
<a href="http://www.datacenterknowledge.com/archives/2011/09/20/microsoft-to-expand-in-des-moines/">Microsoft to Expand Scope of Iowa Project</a><br />
<a href="http://www.datacenterdynamics.com/focus/archive/2011/09/microsoft-gets-approval-for-dublin-data-center-expansion">Microsoft Lays Out Plans for Dublin Data Center Expansion</a><br />
<a href="http://www.datacenterdynamics.com/focus/archive/2011/09/google-brings-oklahoma-data-center-online">Google Brings Oklahoma Data Center Online</a><br />
<a href="http://www.datacenterknowledge.com/archives/2011/09/28/2012-data-center-market-insights-report/">2011/2012 Data Center Market Insights</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/cloud-computing-prompts-2012-data-center-expansion-plans/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Nationwide Awareness Initiatives: Cyber Security and Health IT</title>
		<link>http://resource.onlinetech.com/nationwide-awareness-initiatives-cyber-security-and-health-it/</link>
		<comments>http://resource.onlinetech.com/nationwide-awareness-initiatives-cyber-security-and-health-it/#comments</comments>
		<pubDate>Fri, 07 Oct 2011 15:19:39 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[health IT]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[HIPAA hosting]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3274</guid>
		<description><![CDATA[It appears our government is stepping up their game when it comes to national awareness of IT issues. The White House recognizes October as National Cyber Security Awareness Month (NCSAM) to raise awareness of online safety and security issues. This initiative comes at a time when the government has been targeted for outdated data security [...]]]></description>
			<content:encoded><![CDATA[<p>It appears our government is stepping up their game when it comes to national awareness of IT issues. The White House recognizes October as <strong>National Cyber Security Awareness Month</strong> <strong>(NCSAM)</strong> to raise awareness of online safety and security issues. This initiative comes at a time when the government has been targeted for outdated data security practices by a number of hacker incidents. According to a recent Infoweek <a href="http://www.informationweek.com/news/government/security/231700231">article</a>, the Government Accountability Office released a <a href="http://www.gao.gov/products/GAO-12-137">report</a> citing security incidents rising by more than 650% in the last five years.</p>
<p>A few cyber security tips from Microsoft in celebration of NCSAM:</p>
<ul>
<li>Use automatic updating for all software to keep it up-to-date</li>
<li>Use antivirus and antispyware software</li>
<li>Never turn off your firewall (an important tip for organizations that need to be PCI or HIPAA compliant)</li>
<li>Never email sensitive information (even if encrypted)</li>
<li>Create strong passwords and diverse passwords for different sites and accounts</li>
</ul>
<p>Continuing in the IT awareness theme, <strong>National Health IT Week</strong> was September 12-16, aiming to educate the healthcare industry on the importance of adopting ‘<a href="https://www.cms.gov/ehrincentiveprograms/30_Meaningful_Use.asp">meaningful use</a>’ electronic health record systems to improve patient care. Other health IT initiatives include the EHR (electronic health records) stimulus funding program rewarding organizations that went paperless and recognized <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliance</a> standards.</p>
<p>Benefits of Health IT and HIPAA standards enforced by HITECH:</p>
<ul>
<li>Improves quality of healthcare delivery – faster and more accurate data access</li>
<li>Increases patient safety</li>
<li>Decreases medical and human errors</li>
</ul>
<p>If you need more details about what a secure <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA hosting</a> solution includes or what a <a href="http://www.onlinetech.com/company/michigan-data-centers/compliance/hipaa-compliant-data-centers">HIPAA compliant data center</a> can provide for your organization, <a href="http://www.onlinetech.com/contact">contact</a> us today.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/nationwide-awareness-initiatives-cyber-security-and-health-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The War of Email Cloud Computing: Google vs. Microsoft</title>
		<link>http://resource.onlinetech.com/the-war-of-email-cloud-computing-google-vs-microsoft/</link>
		<comments>http://resource.onlinetech.com/the-war-of-email-cloud-computing-google-vs-microsoft/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 12:45:05 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[cloud computing security]]></category>
		<category><![CDATA[cloud email]]></category>
		<category><![CDATA[cloud hosting]]></category>
		<category><![CDATA[cloud-based email]]></category>
		<category><![CDATA[email cloud computing]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3249</guid>
		<description><![CDATA[Let the war of the email clouds begin. A recent InfoWorld article reports Gartner’s predictions for Google’s share growth of the enterprise email market to shoot from 1 percent to 10 percent within a few years. And when it comes to the cloud-based email market, Gmail owns nearly half of the market. Gartner’s predictions for [...]]]></description>
			<content:encoded><![CDATA[<p>Let the war of the email clouds begin. A recent InfoWorld article reports Gartner’s predictions for Google’s share growth of the enterprise email market to shoot from 1 percent to 10 percent within a few years. And when it comes to the cloud-based email market, Gmail owns nearly half of the market.</p>
<p>Gartner’s predictions for the cloud email market growth within the overall enterprise email market is an eventual increase from its current 3 to 4 percent market share to 20 percent by 2016, and 55 percent by 2020. With its recent data center investments around the globe, it would appear Google is gearing up for projected growth. Google plans to invest 75 million Euros, or $101 million in a new data center in Dublin, Ireland on 11 acres of land. Just days before, Google announced expansion in Asia plans to build three new data centers located in Singapore, Hong Kong and Taiwan.</p>
<p>The expected benefits of using cloud email and applications are significant in cost savings &#8211; the U.S. Department of Energy’s conversion of its IT department to Google Apps estimates it will save $40 million in technology expenses over a period of five years. InfoWorld details current organizations already using email <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> in the government, automotive and hospitality industries, below:</p>
<div id="attachment_3251" class="wp-caption aligncenter" style="width: 548px"><img class="size-full wp-image-3251 " title="Large Organizations Using Gmail" src="http://resource.onlinetech.com/wp-content/uploads/Large-Organizations-Using-Gmail.jpg" alt="Large Organizations Using Gmail" width="538" height="503" /><p class="wp-caption-text">Large Organizations Using Gmail</p></div>
<p>&nbsp;</p>
<p><strong>Google:</strong> Reportedly made more than two dozen updates to the platform within the past year, including:</p>
<ul>
<li>Security feature: ability to reset a user’s sign-on cookies</li>
<li>System manageability: ability to manage policy by user groups</li>
</ul>
<p>But Gartner’s predictions for <strong>Google obstacles </strong>include:</p>
<ul>
<li>Enterprises may reject Google due to needs too complex for the cloud.</li>
<li>Internal routing, application integration and compliance may be difficult to handle in the cloud.</li>
<li>Lack of transparency about proprietary code details concerning access control and privileged access</li>
<li>Lack of transparency about the degree and form of offline backups used in disaster recovery</li>
</ul>
<p><strong>Microsoft: </strong>Plan to upgrade functionality to Exchange in the cloud <em>before</em> adding it to the on-premises version, and they report a great deal of interest from businesses in Office 365, their cloud productivity product.</p>
<p>Microsoft also announced similar plans to expand their data centers in Iowa, Virginia and Dublin, Ireland. But why Dublin for operating cloud data centers? Similar to Michigan, Dublin’s climate is ideal for natural data center cooling, thus cutting costs for power and cooling that normally dominate operation’s budget.</p>
<p>Have concerns about <strong>cloud computing security</strong>? Read up on the <a href="http://www.onlinetech.com/resources/e-tips/item/300-top-5-tips-for-cloud-computing-security">Top 5 Tips for Cloud Computing Security</a> to keep your data safe. Or watch our recent webinar on <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/modern-security-standards-series/new-solutions-for-security-and-compliance-in-the-cloud">New Solutions for Security and Compliance in the Cloud</a> to understand how to meet compliance and security in virtualized and cloud infrastructure.</p>
<p>Sources:<br />
<a href="http://www.gartner.com/it/page.jsp?id=1793914">Gartner Says Google Gmail is Now a Viable Alternative to Microsoft in the Enterprise Email Market</a><br />
<a href="http://m.infoworld.com/d/cloud-computing/gartner-gmail-threatens-microsoft-in-enterprises-173441">Gartner: Gmail threatens Microsoft in enterprises</a><br />
<a href="http://www2.hernandotoday.com/content/2011/jun/08/HANEWSO14-forecast-clouds-social-networks-email-fi/news/">Forecast: Clouds, Social Networks, Email Filters</a></p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/the-war-of-email-cloud-computing-google-vs-microsoft/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2011 Data Center Market Trends</title>
		<link>http://resource.onlinetech.com/2011-data-center-market-trends/</link>
		<comments>http://resource.onlinetech.com/2011-data-center-market-trends/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 12:42:34 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Michigan Data Centers]]></category>
		<category><![CDATA[2011 data center market]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[colocation]]></category>
		<category><![CDATA[data center outsourcing]]></category>
		<category><![CDATA[managed servers]]></category>
		<category><![CDATA[michigan data centers]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3237</guid>
		<description><![CDATA[DataCenterKnowledge.com recently released their 2011/2012 Data Center Market Insights report detailing the key trends driving data center market growth. Their methodology included a poll of over 200 data center professionals, including IT executives and facilities management in more than 13 different industries. A rising trend toward data center outsourcing is gaining momentum as 62 percent [...]]]></description>
			<content:encoded><![CDATA[<p>DataCenterKnowledge.com recently released their 2011/2012 Data Center Market Insights report detailing the key trends driving<a href="http://www.onlinetech.com/company/michigan-data-centers"> data center</a> market growth. Their methodology included a poll of over 200 data center professionals, including IT executives and facilities management in more than 13 different industries.</p>
<div id="attachment_3243" class="wp-caption aligncenter" style="width: 549px"><img class="size-full wp-image-3243 " title="2011 Data Center Market Insights" src="http://resource.onlinetech.com/wp-content/uploads/2011-Data-Center-Market-Insights.jpg" alt="2011 Data Center Market Insights" width="539" height="590" /><p class="wp-caption-text">2011 Data Center Market Insights</p></div>
<p>A rising trend toward data center outsourcing is gaining momentum as 62 percent of respondents reported they are currently outsourcing, testing, or planning to use a data center service provider. What accounts for the trend in using IT vendors? A few significant advantages include avoiding capital expenses, reallocating resources into operating expenses and helping to ease capacity, or provisioning planning issues.</p>
<p>Annual spending on data center products and services shows over half (57 percent) of respondents investing $1 million or more each year, and 24 percent of respondents invest $1-9.9 million a year. This data is complimentary to the findings of 51 percent of respondents either currently expanding or planning data center expansion in 2012.</p>
<p>The expansion also relates to the ability to keep up with service demands, and aligns with the top concerns and challenges of 44 percent of data center operators – data center scalability. Worries about keeping up with growing applications and audiences may be put to ease with the use of <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud computing</a> services to improve speed-to-market and ease of deployment. The second top concern is data center capacity planning, at 42 percent, which, on average, can take 1-3 years to plan and deploy a data center, not to mention an investment of millions of dollars.</p>
<p>Concerns about scalability and capacity may provide insight to the 15 percent increase in cloud computing usage since 2010. Sixty-two percent surveyed are currently using or testing the cloud, while 28 percent have no future plans to deploy the cloud &#8211; down from 41 percent that had no future cloud plans in 2010, showing increasing comfort cloud adoption in 2011.</p>
<p><em>Online Tech’s CEO, Yan Ness, shares a few insights on the study and data center market changes:</em></p>
<blockquote><p>“According to DataCenterKnowledge.com’s recent survey, 51% will be expanding their data center in 2012.</p>
<p>Of those that plan to do so, I’m sure the CFO, when asked for the CapEx, will ask if they should even be doing it themselves at all. Having to expand a data center is an event that can cause a company to question spending CapEx – is it really justified when outsourcing can move it to a predictable, monthly OpEx expense?</p>
<p>The report shows that 62% of data center operators are using or planning to use providers of <a href="http://www.onlinetech.com/colocation">colocation</a>, <a href="http://www.onlinetech.com/managed-servers">managed servers</a> and <a href="http://www.onlinetech.com/cloud-computing-hosting">cloud hosting</a> services. This is a significant increase from previous surveys on the subject. It also reflects how the service provider market is well-positioned to address the top concerns of today’s data center operators.</p>
<p>Decades ago, just about every company had their own power generation and a ‘Chief Power Officer.’ As power became a utility, every company ultimately ‘outsourced’ their power generation to the local utility.</p>
<p>The same trend is predicted for data centers. Companies who are not in the data center business are less inclined to spend CapEx on building out expensive data center infrastructures.”</p></blockquote>
<p>Read more about a <a href="http://www.onlinetech.com/resources/case-studies/michigan-multispecialty-physicians">HIPAA compliant data center case study</a> in which Michigan Multispeciality Physicians (MMP), a group of surgical physicians, outgrew their data center capacity – the pressures of electrical, heating, cooling and physical space issues confronted their Director of Information Technology with the decision to upgrade their existing data center, build a new one, or outsource to a managed data center provider. Find out why outsourcing was the best solution for MMP and how it worked for them.</p>
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/2011-data-center-market-trends/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Webinar Recap</title>
		<link>http://resource.onlinetech.com/hipaa-webinar-recap/</link>
		<comments>http://resource.onlinetech.com/hipaa-webinar-recap/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 15:32:26 +0000</pubDate>
		<dc:creator>Thu Pham</dc:creator>
				<category><![CDATA[Online Tech News]]></category>
		<category><![CDATA[PCI/HIPAA/SAS-70 Compliance]]></category>
		<category><![CDATA[BAA]]></category>
		<category><![CDATA[HIPAA compliant hosting]]></category>
		<category><![CDATA[hipaa guides]]></category>
		<category><![CDATA[HIPAA hosting]]></category>
		<category><![CDATA[HIPAA law]]></category>
		<category><![CDATA[hipaa policies and procedures]]></category>
		<category><![CDATA[hipaa resources]]></category>
		<category><![CDATA[hipaa training]]></category>
		<category><![CDATA[HIPAA webinar]]></category>
		<category><![CDATA[HITECH]]></category>

		<guid isPermaLink="false">http://resource.onlinetech.com/?p=3189</guid>
		<description><![CDATA[Did you happen to miss our HIPAA, HITECH, BAAs and the Law: Concerns and Best Practices Webinar last Tuesday? No worries, we have the slideshow, video and transcript up on our site, as well as our guest speaker Tatiana Melnik’s contact information if you have any unanswered HIPAA questions. Tatiana also provided numerous external links to [...]]]></description>
			<content:encoded><![CDATA[<p>Did you happen to miss our <em><strong>HIPAA, HITECH, BAAs and the Law: Concerns and Best Practices Webinar</strong></em> last Tuesday? No worries, we have the slideshow, video and transcript up on our site, as well as our guest speaker Tatiana Melnik’s contact information if you have any unanswered HIPAA questions. Tatiana also provided numerous external links to sample <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting/hipaa-resources-policies-procedures-and-training-materials" target="_blank">HIPAA policies, procedures and training</a> from major universities and medical centers for organizations seeking HIPAA compliance resources.</p>
<p><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices">HIPAA, HITECH, BAAs and the Law: Concerns and Best Practices</a></p>
<div id="attachment_3190" class="wp-caption aligncenter" style="width: 477px"><a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices"><img class="size-full wp-image-3190 " title="HIPAA Video Screenshot" src="http://resource.onlinetech.com/wp-content/uploads/HIPAA-Video-Screenshot.png" alt="Legal Implications of HIPAA, HITECH, and BAAs: Pre-recorded Webinar" width="467" height="288" /></a><p class="wp-caption-text">Legal Implications of HIPAA, HITECH, and BAAs: Pre-recorded Webinar</p></div>
<p>This webinar discusses the legal implications of HIPAA, HITECH, and BAAs and their impact on IT Infrastructure and those who support it. Moderated by April Sage, Marketing Director of Online Tech, with special guest speaker Tatiana Melnik of Dickinson Wright law firm.</p>
<p><strong>Some of the major takeaway points:</strong></p>
<ol>
<li>Know the requirements, as well as the extent that your company needs to be <a href="http://www.onlinetech.com/secure-hosting/hipaa-compliant-hosting">HIPAA compliant</a>.</li>
<li>Have a contract in place that sets certain parameters beforehand, including number of days to report a breach.</li>
<li>According to HIPAA, you must have a risk analysis, implement policies and procedures, and you have to train your employees.</li>
<li>While there is insurance available for HIPAA-related issues, there is no insurance that will cover you for a willful violation (knowingly breaking HIPAA law or committing criminal acts) against respective government fines or punishment.</li>
</ol>
<p><strong>Things you should never do:</strong></p>
<ol>
<li>Commit a breach – and it’s important to be prepared and have a plan ready in case a breach does occur.</li>
<li>Never write false policies or procedures that your company doesn’t actually follow. This includes plagiarized policy templates that do not reflect your actual workplace practices.</li>
<li>Don’t ignore the calls of the Department of Health and Human Services. You can suffer from major fines – one company was given a $3 million fine just for avoiding their calls, while their actual HIPAA violation fine was $1.3 million.</li>
</ol>
<p>Webinar attendees were also given the opportunity to ask questions. Here’s some of the Q&amp;A (<a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices" target="_blank">view the full transcript</a>):</p>
<p><strong>Q: What’s a reasonable amount to expect to pay for a risk assessment or HIPAA audit?</strong></p>
<p>A: Anywhere from $500 to $5,000 or $10,000, if you want the in-house training, all of the policies and procedures drafted for you, and if you need any additional services.</p>
<p><strong>Q: Who should be responsible in a Healthcare organization for monitoring HIPAA? Should it be those primarily involved in Compliance? HR? Legal? IT? Everybody?</strong></p>
<p>A: Actually, there is a requirement under HIPAA that each organization have a privacy officer. That is the person that is supposed to be in charge of monitoring these types of things. For example, if you are an organization that deals with HIPAA and you see patients, you are supposed to offer them a notice of privacy practices. It&#8217;s best for organizations to appoint one individual to monitor these types of developments because if you have multiple people, it gets very confusing.</p>
<p><strong>Q: What’s the best way to handle PHI (protected health information) in email?</strong></p>
<p>A: Don’t do it. Email is not a secure form of communication. Unless you’re sending encrypted email, you should not do it whatsoever.</p>
<blockquote><p>This is just a sample of the discussion &#8211; view the slides, read the entire transcript and play the <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices">HIPAA webinar</a> video on our site.</p></blockquote>
<hr style="background: none repeat scroll 0% 0% #000000; height: 2px;" />
<p><img style="float: left; margin: 0 15px 0 5px;" src="http://www.onlinetech.com/images/stories/people/tatiana-melnik-100.jpg" alt="Tatiana_Melnik" width="100" height="150" /></p>
<p><strong>Tatiana Melnik, Attorney, Dickinson Wright PLLC</strong></p>
<p>Tatiana Melnik is an attorney with the Dickinson Wright law firm where her practice focuses on information technology, healthcare information technology, intellectual property and privacy issues. Ms. Melnik sits on the Michigan Bar Information Technology Law Council, the Automation Alley Information Technology Committee, and is a Managing Editor of the Nanotechnology Law &amp; Business Journal. Ms. Melnik holds a JD from the University of Michigan Law School, and a BS in Information Systems and BBA in International Business, both from the University of North Florida. Ms. Melnik regularly writes and speaks on issues surrounding healthcare information technology. Ms. Melnik will be speaking at the 2011 HIMSS Fall Technology Conference in Indianapolis on Social Media and Healthcare. Contact information is <a href="http://www.onlinetech.com/resources/news-a-events/events/webinars/hipaa-a-hitech-a-baas-and-the-law-concerns-and-best-practices">available at our site</a>.</p>
<hr style="background: none repeat scroll 0% 0% #000000; height: 2px; margin-top: 20px;" />
]]></content:encoded>
			<wfw:commentRss>http://resource.onlinetech.com/hipaa-webinar-recap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
