Reasonable Security

HHS Releases Voluntary Cybersecurity Practices, Supplementing Existing Requirements

At the close of 2018, the Department of Health and Human Services (HHS) published Health Industry Cybersecurity Practices (HICP): Managing Threats and Protecting Patients. While not formally styled as guidance or interpretive material, when the primary regulator of patient and health data protection offers “suggestions,” those subject to HIPAA had better pay attention. Beyond highlighting common threats to the protection of patient data, the HICP encompasses two supplemental technical volumes centering on small organizations and medium and large organizations. Background Healthcare and life sciences organizations (particularly… more

The Likelihood of Company Executives Being Fired Post-Data Breach – It Isn't Pretty

In April 2018, Verizon released the 11th edition of its Data Breach Investigations Report. As usual, the Verizon DBIR contained interesting data points culled from more than 53,000 incidents and 2,216 confirmed data breaches. It won’t come as a surprise to many to learn that outside agents were responsible for the majority (73%) of cyberattacks in 2017. What may be surprising, though – and is undoubtedly disconcerting – is the assertion that internal actors (i.e., employees and contractors) were behind 28% of data breaches, with financial gain and… more