Welcome Guest. | Log In | Register | Membership Benefits

ID Experts Announces New Breach Product

RADAR 2.0 meets federal and state risk assessment and reporting requirements for privacy, security, and data breach incidents

Feb 14, 2012 | 08:07 PM | 


PORTLAND, Ore. - February 15, 2012 - Healthcare has become one of the most-breached industries, placing hospitals, clinics and health plans under scrutiny of the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and State Attorneys General (AG). To help healthcare organizations navigate the maze of inconsistent federal and 46 states' different patient privacy laws, ID Experts announced RADAR 2.0 today-a patent pending, web-based software tool-to help standardize, centralize and simplify the assessment, documentation and reporting process of privacy or security incidents involving personally identifiable information (PII) and protected health information (PHI).

A key component of ID Experts data breach preparedness and response services, endorsed by the American Hospital Association (AHA), RADAR 2.0 helps healthcare covered entities achieve compliance with federal and states' privacy and breach notification regulations and provides guidance for notification obligations. With its information repository, users can organize and easily retrieve incident details and all corresponding documentation in the event of an OCR audit or investigation. Information and a video are available at http://www2.idexpertscorp.com/RADAR

"Our patients' health and well-being are of utmost importance to us. So is the security and privacy of their medical information," said Dr. Cris V. Ewell, chief information security officer at Seattle Children's Hospital. In 2012, U.S. News & World Report placed Seattle Children's Hospital among the nation's top children's hospitals list for the 19th consecutive year. "RADAR gives us a consistent, efficient, and affordable incident management solution that scales and can grow with our business needs."

RADAR: Risk Assessment Documentation and Reporting Simplified Features and benefits of RADAR 2.0:

. Meets federal and state risk assessment and reporting requirements for privacy, security and data breach incidents; provides incident response plan including a HHS report when notification is expected . Intuitive risk assessment and documentation process with embedded knowledge of federal and states breach notification rules, making reporting consistent and streamlined . Common repository for all privacy and security incidents and incident-related attachments such as notes, reports, remediation plans and checklists that can be easily retrieved for OCR, state, and internal investigations . Proprietary risk assessment with flexibility to handle each incident uniquely based on incident context, internal policies, and privacy office and counsel input . Secure and scalable with role-based access controls to meet the needs of stand-alone and large integrated healthcare systems and health plans; ability for multiple users to collaborate

"We created a highly intuitive tool to help healthcare organizations manage complex regulatory requirements," said Mahmood Sher-Jan, vice president, product management, at ID Experts. "The majority of states have enacted their own breach notification laws, making it challenging for a privacy or compliance officer to keep up with this inconsistent matrix of laws. RADAR unifies all of the federal and states' breach notification guidelines to enable and simplify compliance."

About ID Experts ID Experts is the leader in comprehensive data breach solutions that deliver the most positive outcomes. The company has managed hundreds of data breach incidents, protecting millions of affected individuals, for leading healthcare organizations, corporations, financial institutions, universities and government agencies. In healthcare, the company contributes to relevant legislation and rules including HITECH and is a corporate member of HIMSS. ID Experts data breach preparedness and response services have been endorsed by the American Hospital Association.ID Experts is active with organizations that advocate for privacy for Americans including ANSI/Identity Theft Prevention, Identity Management Standards Panel and the International Association of Privacy Professionals. For more information, visit http://www2.idexpertscorp.com/; join in the All Things HITECH discussion via LinkedIn at bit.ly/AllThingsHITECH; and follow ID Experts on Twitter @IDExperts.

About the AHA The American Hospital Association is a not-for-profit association of health care provider organizations and individuals committed to the health improvement of their communities. The AHA is the national advocate for its members, which includes nearly 5,000 hospitals and health care systems, networks, and other providers of care, and 42,000 individuals. Founded in 1898, the AHA provides education for health care leaders and is a source of information on health care issues and trends. For more information, visit www.aha.org. About AHA Solutions AHA Solutions, Inc. is a resource to hospitals pursuing operational excellence. As an American Hospital Association (AHA) member service, AHA Solutions collaborates with hospital leaders and market consultants to conduct the proprietary AHA Signature Due Diligence ProcessT and identify solutions to hospital challenges in the areas of care continuum, cultural transformation, clinical integration and financial sustainability. AHA Solutions provides related marketplace analytics and education to support product decision-making, and convenes hospital executives for knowledge sharing centered on timely information and research. AHA Solutions is proud to reinvest its profits in the AHA mission: creating healthier communities. For more information, contact AHA Solutions at 800.242.4677 or visit www.aha-solutions.org.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Compliance Reports

report How To Boost Security Via FFIEC Compliance
With just a smartphone, users can conduct nearly all their banking business at any time of the day or night. However, all this flexibility and convenience opens up new avenues for fraud and cybercrime. Guidelines laid out by the FFIEC several years ago predate many of the capabilities-and vulnerabilities-that are in place today. In this report, we examine the latest guidelines and provide advice on how you can extend the work done to comply with FFIEC guidelines to strengthen your organization's overall security posture and keep customers and their data safe.

report Keeping Compliance In Check
Configuration mistakes, access control gaffes, poor documentation--it doesn?t take much for a compliance audit to go all wrong. In this special retrospective of recent news coverage, Dark Reading takes a look at the costs, common missteps and best practices for compliance, as well as the day the Internet nearly went dark due to the threat of new regulations.

report FISMA Lifts All Compliance Boats
FISMA may not be on your radar now, but it likely will be at some point. Geared specifically toward the federal government and its affiliate agencies and third parties, FISMA is a very specific set of requirements aimed at establishing and maintaining at least a baseline level of computer and network security. FISMA requires unique categorization and classification of information assets, not to mention a boatload of documentation to prove compliance. But once your organization achieves FISMA compliance, it will likely be compliant with just about every security mandate out there.

Other reports from the Compliance Tech Center:

Related Content

Log Management in 2012 and Beyond
2012 brings interesting changes to the log management world. Now, more than ever, it is critical to understand the impact to your log infrastructure and the solutions that will better prepare you to manage your security posture.

SANS Log Management Survey Report
Organizations are increasingly dependent on log management to support core business functions, including cost management, service level and line-of-business application monitoring, as well as traditional IT- and security-focused activities.

Cut the Time and Effort of Troubleshooting and Reporting
Organizations generate millions of logs a day and struggle with centralized collection, storage and analysis of those logs. ArcSight Logger is a universal log management solution that unifies searching, reporting, alerting and analysis across any type of IT data. It consolidates silos of logs into a single indexed repository for fast detection and mitigation of operational issues.

Get Turnkey and Automated PCI Compliance
PCI compliance monitoring is seamless with the self-contained ArcSight PCI Logger solution for log collection, storage and analysis. No database administration expertise is required and a web-based interface simplifies deployment and ongoing management.

Swiss Bank Meets Compliance Requirements and Protects Customer Data
Due to long-term data retention requirements, Swiss bank EFG needed a cost-effective way to collect, secure and store audit-quality log data in an easily accessible log repository. ArcSight Logger helps EFG meet key requirements of Switzerland?s banking laws fast and cost-effectively.




Featured Webcasts
Featured Whitepapers
Featured Reports