<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	>

<channel>
	<title>In the News Archives - Third Rock</title>
	<atom:link href="https://thirdrock.com/blog/category/in-the-news/feed/" rel="self" type="application/rss+xml" />
	<link>https://thirdrock.com/blog/category/in-the-news/</link>
	<description>Building a Cyber Confident World</description>
	<lastBuildDate>Thu, 21 Nov 2019 19:32:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.8</generator>

<image>
	<url>https://i0.wp.com/thirdrock.com/wp-content/uploads/cropped-favicon-check.png?fit=32%2C32&#038;ssl=1</url>
	<title>In the News Archives - Third Rock</title>
	<link>https://thirdrock.com/blog/category/in-the-news/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">65153150</site>	<item>
		<title>Prevention is Cheaper than Correction</title>
		<link>https://thirdrock.com/blog/2019/11/22/prevention-is-cheaper-than-correction/</link>
		
		<dc:creator><![CDATA[Ed Jones, PMP, CHSP]]></dc:creator>
		<pubDate>Fri, 22 Nov 2019 15:00:59 +0000</pubDate>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[HIPAA compliance]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[risk management]]></category>
		<guid isPermaLink="false">https://thirdrock.com/?p=8681</guid>

					<description><![CDATA[<p>The post <a href="https://thirdrock.com/blog/2019/11/22/prevention-is-cheaper-than-correction/">Prevention is Cheaper than Correction</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="et_pb_section et_pb_section_0 et_section_regular" >
				
				
				
				
				
				
				<div class="et_pb_row et_pb_row_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_0  et_pb_css_mix_blend_mode_passthrough et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>The healthcare industry led the nation in regulations for information security. In an effort to protect private health information (PHI), healthcare organizations are required to protect patient data against <em>any reasonably anticipate threats or hazards</em>.  You are required to perform risk assessments, but knowing your risk is not enough. Steps must be taken to fix issues and prevent data loss. Most other industries and states are joining the bandwagon with regulations of their own. The basics are the same: do your due diligence to protect data or face the consequences.</p>
<p>&nbsp;</p>
<h2><em>The Breach</em></h2>
<p>The University of Rochester Medical Center (URMC) recently agreed to a $3,000,000 settlement with the Office of Civil Rights (OCR). URMC reported data loss in 2013 when an unencrypted flash drive was lost. They again reported a breach when a personal laptop with unencrypted ePHI was stolen from a treatment facility. The fine may seem steep when you think that only 43 patients’ data was on the stolen laptop. The bigger issue, however, was the lack of progress in breach prevention from the first to the second incident.</p>
<p><em style="color: #333333; font-family: 'Roboto Slab', Georgia, 'Times New Roman', serif; font-size: 18px;">The Cost</em></p>
<p><span style="font-size: 14px;">Beyond the fine to the OCR, breaches can cost a company much more. According to the IBM Security Cost of a Data Breach Report 2019, healthcare is the industry with the highest average cost at $6.45 million, not including fines. Lost business was the largest contributing factor to this total, accounting for 36% of the total cost. Other factors include detection and reporting, notification of affected parties and post breach clean up.</span></p>
<p> <em style="color: #333333; font-family: 'Roboto Slab', Georgia, 'Times New Roman', serif; font-size: 18px;">Corrective Action</em></p>
<p><span style="font-size: 14px;">The list of requirements mandated by the OCR look very similar to the actions that are expected to prevent the breach in the first place.</span></p>
<ul>
<li>Conduct a Risk Analysis</li>
<li>Implement a Risk Management Plan</li>
<li>Implement customized Policies and Procedures</li>
<li>Train your staff</li>
<li>Create and maintain a body of compliance evidence</li>
</ul>
<h2><em>Prevention is always cheaper</em></h2>
<p><span style="font-size: 14px;">URMC is facing a guaranteed loss of $3,000,000 plus other expenses in breach clean up, notification and potential loss of business. The cost of our cyber risk management from assessment, reporting and remediation starts at $699/year for a small organization. Our automated tool, CyberCompass™, puts you in charge of your cyber risk, cybersecurity and compliance. Addressing all the requirements listed above, we also save you 70% of the typical cost, time and effort. An easy to use dashboard prioritizes your corrective actions, allowing you to work through them at your own pace. With built in regulations for most industries, start your move toward Cyber Confidence® today.</span></p>
<p> <span style="font-size: 14px;">Contact Us for more details or visit thirdrock.cybercompass.co</span></p></div>
			</div>
			</div>
				
				
				
				
			</div>
				
				
			</div>
<p>The post <a href="https://thirdrock.com/blog/2019/11/22/prevention-is-cheaper-than-correction/">Prevention is Cheaper than Correction</a> appeared first on <a href="https://thirdrock.com">Third Rock</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">8681</post-id>	</item>
	</channel>
</rss>
