<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	xmlns:georss="http://www.georss.org/georss"
	xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#"
	
	>
<channel>
	<title>
	Comments for Third Rock	</title>
	<atom:link href="https://thirdrock.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>https://thirdrock.com/</link>
	<description>Building a Cyber Confident World</description>
	<lastBuildDate>Thu, 27 Jun 2019 01:57:08 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.8</generator>
	<item>
		<title>
		Comment on HIPAA &#8211; Standard Operations for Business by Frank Ruelas		</title>
		<link>https://thirdrock.com/blog/2017/06/08/hipaa-standard-operations-for-business/#comment-5076</link>

		<dc:creator><![CDATA[Frank Ruelas]]></dc:creator>
		<pubDate>Fri, 09 Jun 2017 22:16:22 +0000</pubDate>
		<guid isPermaLink="false">http://thirdrock.com/?p=3885#comment-5076</guid>

					<description><![CDATA[Thank you!  

So often I hear people complaining about HIPAA in that it needs to be upgraded, modified, etc...and then when I am privy to what BAAs are doing to comply with HIPAA I see most of this comes from folks that don&#039;t comply with HIPAA and are looking for some type of &quot;sounds good&quot; reason to move to a HIPAA 2.0.

In my view, with respect Business Associates (BAs) and HIPAA...which first people out there need to stop telling BAs that they need to comply with all of HIPAA...the Security Rules represent what is often present in most well run IT shops.

It&#039;s that simple and basic.  Now are there people that may find or use the idea that HIPAA is overly complex and burdensome for some other means?  Of course...I hear it on webs and read it on blogs every day.]]></description>
			<content:encoded><![CDATA[<p>Thank you!  </p>
<p>So often I hear people complaining about HIPAA in that it needs to be upgraded, modified, etc&#8230;and then when I am privy to what BAAs are doing to comply with HIPAA I see most of this comes from folks that don&#8217;t comply with HIPAA and are looking for some type of &#8220;sounds good&#8221; reason to move to a HIPAA 2.0.</p>
<p>In my view, with respect Business Associates (BAs) and HIPAA&#8230;which first people out there need to stop telling BAs that they need to comply with all of HIPAA&#8230;the Security Rules represent what is often present in most well run IT shops.</p>
<p>It&#8217;s that simple and basic.  Now are there people that may find or use the idea that HIPAA is overly complex and burdensome for some other means?  Of course&#8230;I hear it on webs and read it on blogs every day.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Comment on Knock, Knock &#8211; We&#8217;re here to perform an onsite HIPAA audit. by Robert Felps		</title>
		<link>https://thirdrock.com/blog/2017/01/05/knock-knock-were-here-to-perform-an-onsite-hipaa-audit/#comment-5048</link>

		<dc:creator><![CDATA[Robert Felps]]></dc:creator>
		<pubDate>Thu, 12 Jan 2017 15:27:16 +0000</pubDate>
		<guid isPermaLink="false">http://thirdrock.com/?p=2773#comment-5048</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://thirdrock.com/blog/2017/01/05/knock-knock-were-here-to-perform-an-onsite-hipaa-audit/#comment-5047&quot;&gt;Julia&lt;/a&gt;.

We initially heard about this from one of our partner HIPAA consultants, whom heard it in a HIPAA CE session.  We then heard the same info from another HIPAA consultant involved with HHS OCR audits.  Recently we heard it from a HIPAA law firm.  No confirmation from the OCR though, so it&#039;s worth the &quot;ink&quot; with which it&#039;s written. :-)  But, with audit submissions now required to be electronic the electronic auditing will soon follow, then it&#039;s just how they will automate the auditing.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://thirdrock.com/blog/2017/01/05/knock-knock-were-here-to-perform-an-onsite-hipaa-audit/#comment-5047">Julia</a>.</p>
<p>We initially heard about this from one of our partner HIPAA consultants, whom heard it in a HIPAA CE session.  We then heard the same info from another HIPAA consultant involved with HHS OCR audits.  Recently we heard it from a HIPAA law firm.  No confirmation from the OCR though, so it&#8217;s worth the &#8220;ink&#8221; with which it&#8217;s written. 🙂  But, with audit submissions now required to be electronic the electronic auditing will soon follow, then it&#8217;s just how they will automate the auditing.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Comment on Knock, Knock &#8211; We&#8217;re here to perform an onsite HIPAA audit. by Julia		</title>
		<link>https://thirdrock.com/blog/2017/01/05/knock-knock-were-here-to-perform-an-onsite-hipaa-audit/#comment-5047</link>

		<dc:creator><![CDATA[Julia]]></dc:creator>
		<pubDate>Thu, 12 Jan 2017 01:08:52 +0000</pubDate>
		<guid isPermaLink="false">http://thirdrock.com/?p=2773#comment-5047</guid>

					<description><![CDATA[Gosh!  Where does the information about 2019 come from?]]></description>
			<content:encoded><![CDATA[<p>Gosh!  Where does the information about 2019 come from?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Comment on Cyber Breach – No One is Immune by Christy		</title>
		<link>https://thirdrock.com/blog/2015/09/01/cyber-breach-no-one-is-immune/#comment-5044</link>

		<dc:creator><![CDATA[Christy]]></dc:creator>
		<pubDate>Tue, 01 Sep 2015 18:40:21 +0000</pubDate>
		<guid isPermaLink="false">http://thirdrock.com/?p=994#comment-5044</guid>

					<description><![CDATA[It seems to me that most health organizations are so behind that it is  a treasure trove for hackers. I work as a temp nurse for several different clinics. I was absolutely shocked to see a front desk nurse put a personal USB into the computer she was working on to copy over music. I just hope that they had some kind of protection, but I doubt it. It does not even seem they were making much of an effort.

Anyway great article.]]></description>
			<content:encoded><![CDATA[<p>It seems to me that most health organizations are so behind that it is  a treasure trove for hackers. I work as a temp nurse for several different clinics. I was absolutely shocked to see a front desk nurse put a personal USB into the computer she was working on to copy over music. I just hope that they had some kind of protection, but I doubt it. It does not even seem they were making much of an effort.</p>
<p>Anyway great article.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Comment on The Breach is Only The Beginning by Doug Pertier		</title>
		<link>https://thirdrock.com/blog/2015/07/22/the-breach-is-only-the-beginning/#comment-5043</link>

		<dc:creator><![CDATA[Doug Pertier]]></dc:creator>
		<pubDate>Wed, 22 Jul 2015 21:40:29 +0000</pubDate>
		<guid isPermaLink="false">http://thirdrock.com/?p=914#comment-5043</guid>

					<description><![CDATA[I have to say that while we most certainly tried to prevent breaches where I work, these statistics are really scary. It seems that while we have a firewall and anti-virus, there is more to be done to find out who gets past them. Which by what I am reading, is a lot.]]></description>
			<content:encoded><![CDATA[<p>I have to say that while we most certainly tried to prevent breaches where I work, these statistics are really scary. It seems that while we have a firewall and anti-virus, there is more to be done to find out who gets past them. Which by what I am reading, is a lot.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		Comment on HIPAA/HITECH Security Risk Analysis Myths and Facts by Doug M.		</title>
		<link>https://thirdrock.com/blog/2015/07/13/hipaahitech-security-risk-analysis-myths-and-facts/#comment-5042</link>

		<dc:creator><![CDATA[Doug M.]]></dc:creator>
		<pubDate>Wed, 15 Jul 2015 18:14:38 +0000</pubDate>
		<guid isPermaLink="false">http://thirdrock.com/?p=452#comment-5042</guid>

					<description><![CDATA[Great post and very true. We were shocked what we found when we went through a Risk Assessment last year.]]></description>
			<content:encoded><![CDATA[<p>Great post and very true. We were shocked what we found when we went through a Risk Assessment last year.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
