Due to the rapid increase of electronic data, the concern for privacy, and the negative impact exploitation of a security gap or vulnerability could have on achieving our primary mission, NIST guidance is being drafted, finalized, and revised on an on-going basis. When NIST guidance is finalized or revised, the url for the draft or final document changes.
There are two tools that I have posted to ShareHIPAA recently that contain web addresses for NIST guidance. I have made the following changes to these tools, and the updated version for both is now available in the files section of ShareHIPAA group.
Change #1
Revision A of NIST SP-800-27 {Engineering Principles for Information Technology Security (A Baseline for Achieving Security)}published in final June 2004. Rev. A url: http://csrc.nist.gov/publications/nistpubs/800-27A/SP800-27-RevA.pdf
The NIST SP 800-66 Guidance entry for HIPAA Security Rule CFR Section 164.308(a)(1) is effected by this change.
Change #2
DRAFT NIST SP 800-63 Recommendation for Electronic Authentication was finalized June 2004 and NIST SP 800-63 Electronic Authentication Guidelines' new url is: http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63v6_3_3.pdf
The NIST SP 800-66 Guidance effects the following CFR Sections of the HIPAA Security Rule:
164.308(a)(4)
164.312(a)(1)
164.312(d)
164.312(e)(1)
If you would like to download the updated tools from the files section of ShareHIPAA group, go to the ShareHIPAA group's home page at http://health.groups.yahoo.com/group/ShareHIPAA/ , sign in with your Yahoo! ID and password, and select "Files" from the left column.
To access/download HIPAA-Security-Privacy-NIST-ISO17799 Super Crosswalk (333 KB) look for the following file:
Assessment Tool - ShareHIPAA.xls
Msg #199 HIPAA/NIST/ISO17799 Crosswalk Rev 07/11/2004
Msg #199 HIPAA/NIST/ISO17799 Crosswalk Rev 07/11/2004
To access/download NIST SP 800-66 in excel (33 KB) look for the following file:
nisthipaaguides.xls
Msg #187 & 188 NIST SP 800-66 in excel Rev 07/11/2004
Msg #187 & 188 NIST SP 800-66 in excel Rev 07/11/2004
If you cannot access the Files section of the ShareHIPAA group, or if you would like for me to send you the excel files directly, please send me a request for them no later than July 15, 2004. I will send the tools as an attachment to you on July 16, 2004.
Regards,
Barbara McGowin, CPC
Executive Recruiting
HIT Recruiting
(843) 824-8537
mcgowins@...
Connecting Healthcare Organizations with People,
Products and Services to Achieve HIPAA Compliance.
Executive Recruiting
HIT Recruiting
(843) 824-8537
mcgowins@...
Connecting Healthcare Organizations with People,
Products and Services to Achieve HIPAA Compliance.