Policy 2
Please don’t give me a two to three sentence replies. It has to look bulky. At least 8 to 10 sentences. Thank you
Reply needed 1
Provide in-text citations and references for 3 or more authoritative sources. Put the reference list at the end of your posting.
The Federal Trade Commission "Red Flags Rule" (2013) requires businesses and organizations to implement a written identity theft prevention program to detect the "red flags" of identity theft in their day-to-day operations, take steps to prevent the crime, and mitigate its damage." (FTC, 2013) This is document has set requirements on how companies will go about implementing the Red Flags Rule no matter the companies' size. It is a proactive method for companies to look for and stop potential identity theft risk. Not all businesses must have and follow the Red Flags Rule only those that have covered accounts. There are two types of covered account one type are "accounts that a financial institution or creditor offers or maintains, primarily for personal, family, or household purposes, that involves or is designed to permit multiple payments or transactions; the other type is any other accounts that poses a reasonably foreseeable risk to customers of identity theft." (SEC, 2013) Any financial institutions (banks or federal credit unions) and creditors has to complete periodic risk assessments to determine if they have any covered accounts and require implementation of the Red Flags Rule.
The Red Flags Rule applies to the Red Clay Renovations Company because the company collects, maintains, and stores personal information about customers, such as credit checks and personal information about a customer’s family members for the purpose of design and construction while conducting business with them. (FTC, 2013) The collection of this information would consider these accounts to be covered accounts. Therefore, the Red Clay Renovations Company has to abide by the Red Flags Rule and ensure we follow the requirement set for how we must implement the rules and protect our customers’ personally identifiable information from possible identity theft.
It is the duty and obligation of the Red Clay Renovations Company to protect its costumers from compromise. In doing so, our company will abide by the Red Flags Rule by thoroughly creating and expediting the implementation our own identity theft prevention program, that would be designed to effectively detect the “red flags” of identity theft. We will also ensure we inform our costumers that we take the necessary steps to prevent compromise, and mitigate its damage via written statements within their contracts. The basis of Red Flags Rule is to have a program that will assist us with identifying suspicious patterns and prevent the costly consequences of identity theft, it provides protect for our costumers as well as our company.. (FTC, 2013)
References
FTC, 2013. Fighting identity theft with the red flags rule: A how-to guide for business. Retrieved from, https://www.ftc.gov/tips-advice/business-center/guidance/fighting-identity-theft-red-flags-rule-how-guide-business
SEC, 2013. Identity Theft Red Flags Rules. Retrieved from, https://www.sec.gov/info/smallbus/secg/identity-theft-red-flag-secg.htm
Reply needed 2
Introduction:
Often times, it becomes necessary for companies to collect personal information from their clients to better serve them in the long run. A similar case is with Red Clay Renovations as it requires specific types of information from its clients so that it can update homes/buildings in such a way that it becomes convenient for the residents. For example, home renovations may become necessary in the case that residents have certain illnesses or disabilities which prevent them from operating in a normal matter (King, 2016, p. 5). Therefore, it is essential for the company to know the medical conditions of individuals that will reside within the location that they are renovating. The purpose of this briefing statement is to analyze the Health Insurance Portability and Accountability Act (HIPAA), determine its relationship to the collection and management of client information by Red Clay Renovations, and classify the private information of clients which is protected by the HIPAA Security Rule (Dorrian, 2016, para. 4). “The Security Rule establishes a national set of security standards for protecting certain health information that is held or transferred in electronic form” (U.S. Department of Health and Human Services, The Security Rule, n.d., para. 2).
Analysis:
Although it is encouraged for companies to collect, process, manage, and store important personal information about their clients, the HIPAA security rule requires this information to be protected so that it does not get in the hands of unauthorized individuals (U.S. Department of Health and Human Services, The Security Rule, n.d., para. 5). The HIPAA security rule “establishes national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity. It requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity, and security of the information” (U.S. Department of Health and Human Services, The Security Rule, n.d., para. 1). Red Clay Renovations is known as a business associate to clients as they require the knowledge of personal client information in an effort to provide the client services (U.S. Department of Health and Human Services, Business Associates, n.d., para. 3). These services are provided through modifications to the house to better suit individuals with health issues. The regulatory requirements as they apply to the company’s collection, processing, management, and storage of personal information include protecting the data from misuse and only using it for purposes which would benefit the client (U.S. Department of Health and Human Services, Business Associates, n.d., para. 1). This is required so that the confidentiality, integrity, and availability of the Electronic Protected Health Information can be maintained. The Security Rule follows the confidentiality, integrity, and availability requirement of protected health information so much so that the health information should not be provided to unauthorized individuals, it should not be modified unless the alteration is made by an authorized individual, and the information must be accessible to authorized individuals at all times (U.S. Department of Health and Human Services, The Security Rule, n.d., para. 21).
Summary:
Electronic Protected Health Information (e-PHI) is the type of personal information which is covered by the HIPAA security rule. Essentially, the HIPAA security rule protects individually identifiable health information that is stored by a covered entity, regardless of the way in which the data is stored (Office for Civil Rights, n.d., p. 3). This information includes but is not limited to “demographic data that relates to the individual’s past, present or future physical or mental health, the provision of health care to the individual, and the past, present, or future payment for the provision of health care to the individual” (Office for Civil Rights, n.d., p. 4). In conclusion, regulatory requirements for Red Clay Renovations in regards to protected health information include maintaining its confidentiality, integrity, and availability and solely using the information for the purposes of renovating the clients’ place of residence.
References
Department of Health and Human Services. (n.d.). 45 CFR Subtitle A (10-1-07 edition). Government Printing Office. Retrieved from https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-sec160-310.pdf
Dorrian, J. (2016). Policies to implement regulatory requirements in CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
King, V. J. (2016, March 30). Red Clay Renovations: A case study for CSIA 413. Document posted in University of Maryland University College CSIA 413 6381 online classroom, archived at: http://campus.umuc.edu
Office for Civil Rights. (n.d.). Summary of the HIPAA privacy rule. Retrieved from http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/understanding/summary/privacysummary.pdf
U.S. Department of Health & Human Services. (n.d.). Business associates. Retrieved from http://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
U.S. Department of Health & Human Services. (n.d.). The security rule. Retrieved from http://www.hhs.gov/hipaa/for-professionals/security/index.html
REPLY 3 Needed
Red Clay Renovations receives, process, stores, and transmits Protected Health Information (PHI) which means we must comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The Security Rule requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information (The Security Rule, n.d.). Each one of the safeguards that was just mentioned has a list of implementation specification that are either required or need to be addressed. If an implementation specification is required then policies and procedures must be implemented and if it is addressable then the organization must assess whether it is a reasonable and appropriate safeguard in the entity’s environment (Security 101 for Covered Entities, 2007).
The administrative safeguard has twelve required implementation specifications and eleven addressable. Administrative safeguards are used to protect Electronic Protected Health Information by limiting the personnel that have access to the information, training personal with access, ensuring there is a response to an incident where information is either leaked or stolen and identifying who has access. To ensure that the administrative safeguard are effective once the policies have been created and implemented they must be tested. Once the test has been conducted the results should be documented and any policy or procedure that failed the test should be revised to ensure compliance.
The Physical security safeguards contain four required implementation specifications and six addressable. The physical safeguards addresses the physical access to the facility, workstation and any device or media that may contain Electronic Protected Health Information. To meet this specification we can employ physical security at each facility and make sure that employee’s that are authorized to access Electronic Protected Health Information has a unique username and password.
Technical safeguards contain four required implementation specifications and four addressable. According to the HIPAA Security Rule, technical safeguards are “the technology and the policy and procedures for its use that protect electronic protected health information and control access to it (Snell, 2014). Technical safeguards address the level of access each person has, transmission security, and the integrity of Electronic Protected Health Information. To address technical safeguards encryption must be used when Electronic Protected Health Information is in transit, stored or being accessed, audit controls must be in place, and there must be a method to authenticate users requesting access to the information.
Once our organization meets all of the required implementation specifications and addresses the others we will be in compliance with the HIPPA Security Rule.
References
Security 101 for covered entities. (2007, March). Retrieved from HHS: http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/administrative/securityrule/security101.pdf
Snell, E. (2014, November ). HIPAA technical safeguards: A basic review. Retrieved from Halthitsecurity: http://healthitsecurity.com/news/hipaa-technical-safeguards-basic-review
The security rule. (n.d.). Retrieved from HHS: http://www.hhs.gov/hipaa/for-professionals/security/
Follow-up replies needed 4
John,
I like the way you broke down the Payment Card Industry Data Security Standard or PCI DSS. PCI DSS can be defined as a set of security standards designed to ensure that all companies that accept credit cards payments process, store and/or transmit credit card information in a safe and secure environment. Anyone reading you response would be able to get a pretty good understanding of what these standards are, who they affect, who is responsible for keeping card information secure and how the companies should go about ensuring these security measures are taken. I believe failures in PCI DSS security, whether it was improper equipment, not enough security, or an issue with the software or firewalls used, was the cause behind most of the major breaches we have since in the last few years such as Target and Home Depot. I completely agree with your statement, “Forensic examiners had found that security controls conveyed by organizations that had passed an evaluation were frequently out of compliance when ruptures happened at a later date”, there are often time where companies will not update equipment or software until something bad happens. The problem with conducting business in this manner has proven time and time again it will cost the companies’ way more in the end but could also have some major effects on the cardholders. The only issue I see with your response is you did not mention or incorporate any information from the Red Clay Renovations Company case study, such as how this company should be using and maintaining PCI DSS. Great post.
Follow-up replies needed 5
Great job on your briefing, you did an excellent job on breaking down PCI-DSS and all of its various steps and standards. Whats funny is I never knew about PCI-DSS or even the PCI-SCC until when started this discussion but I should have assumed that businesses and companies can't just process, manage, and collect information from their clients and as well process some kind of transactions without laws and regulations they have too adhere too. Really once you think about it it is great that the PCI-SCC created the PCI-DSS standards because critical information like credit card and debit numbers as well as account numbers is something that a hacker would love to get there hands on for evil use.
With PCI-DSS clients and other people can feel safe that there card information is being protected during use and a business has too take into consideration that they will have more ways of processing payments than just cash too hand transactions, but people will be more willing too use credit and debit cards knowing that there information is protected best as possible. Companies like Red Clay Renovations that specialize in home renovations probably see a lot of transactions through the use of cards because it makes it faster and easier for a customer to pay for services rendered than having to come into the company building with cash in hand.
In your briefing you talked about the PCI three step process which was access, remediate, and report as it relates to the PCI standards and those are in my opinion a good set of steps because it really helps to keep account for whats happening as far as transactions go, its history, and the number of tranactions.