All of these you may find useful. But take a look at #3: Special
Publication 800-115 Technical Guide to Information Security Testing and Assessment. This may be very useful in compliance with
the HIPAA Security Rule.
Regards,
Barbara McGowin
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Wednesday, October 01, 2008 1:56 PM
To: Multiple recipients of list
Subject: NIST Releases 4 Publications
NIST Releases 4 Publications:
1 Draft (Special Publication 800-82)
and
3 final Special Publications (800-73-2, 800-115, and 800-121)
#1: DRAFT Special Publication 800-82, Guide to Industrial Control Systems (ICS) Security -- The final public draft of SP 800-82 is available for public comment. It provides guidance on how to secure Industrial Control Systems (ICS), including Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), and other control system configurations such as Programmable Logic Controllers (PLC), while addressing their unique performance, reliability, and safety requirements. SP 800-82 provides an overview of ICS and typical system topologies, identifies typical threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate the associated risks. This publication is an update to the second public draft, which was released in 2007. NIST requests comments on NIST SP 800-82 by November 30, 2008. Please submit comments to 800-82comments@... with "Comments SP 800-82" in the subject line. To view this document please visit the Drafts page on CSRC.
URL to draft:
http://csrc.nist.gov/publications/PubsDrafts.html#800-82
#2: NIST is pleased to announce the release of NIST Special Publication 800-73-2, Interfaces for Personal Identity Verification. Special Publication 800-73-2 (SP 800-73-2) specifies the PIV data model, command interface, client application programming interface and references to transitional interface specifications. The four parts that comprise SP 800-73-2 supersede the single document SP 800-73-1, published in April 2006. Comments received for first and second public draft of SP 800-73-2 have been addressed as are the errata items in SP 800-73-1. The high-level technical changes in SP 800-73-2 are summarized here. The Special Publication 800-73-2 document can be found by going to the Special Publications page.
URL to SP 800-73-2
http://csrc.nist.gov/publications/PubsSPs.html#800-73_Rev2
#3: Special Publication 800-115, Technical Guide to Information Security Testing and Assessment, has been published as final. It seeks to assist organizations in planning and conducting technical information security testing and assessments, analyzing findings, and developing mitigation strategies. The publication provides practical recommendations for designing, implementing, and maintaining technical information security assessment processes and procedures. SP 800-115 provides an overview of key elements of security testing, with an emphasis on technical testing techniques, the benefits and limitations of each technique, and recommendations for their use. SP 800-115 replaces SP 800-42, Guideline on Network Security Testing, which was released in 2003.
URL to SP 800-115
http://csrc.nist.gov/publications/PubsSPs.html#SP800-115
#4: Special Publication 800-121, Guide to Bluetooth Security, has been finalized. It describes the security capabilities of technologies based on Bluetooth, which is an open standard for short-range radio frequency communication. The document gives recommendations to organizations employing Bluetooth technologies on securing them effectively. SP 800-121 supersedes the original SP 800-48, Wireless Network Security: 802.11, Bluetooth and Handheld Devices, which was released in 2002 and was replaced in July 2008 by SP 800-48 Revision 1, Guide to Securing Legacy IEEE 802.11 Wireless
Networks.
URL to SP 800-121
http://csrc.nist.gov/publications/PubsSPs.html#800-121
Today, Friday 11/21/2008, is sixty days prior to 1/20/2009: the start
of the new Obama "Administration". Prior to most Federal Final Rules
taking effect, Congress gives itself a sixty day Review Period to
determine whether or not they wish to disapprove any Final Rule. {5 USC
Chapter 8} This sixty day period typically commences with the
publication of a Final Rule in the Federal Register; although, there are
some 'wrinkles' that extend the Review Period end date at the
adjournment of Congressional sessions -- such as will be occurring
shortly.
As of today, the publication of an Updated HIPAA Transactions Final Rule
hasn't happened. Thus, barring something weird, any new Updated HIPAA
Transactions Final Rule would become effective -- i.e., modified and new
transactions adopted -- during the Obama Administration; no earlier than
mid-March 2009, even if a Final Rule is published this year. Ditto for
any Final Rule for the ICD-10-CM and ICD-10-PCS code sets.
Note that March, 2009, effective dates do support compliance dates
contained in the Notices of Proposed Rule Making published on 8/22/2008.
Happy Thanksgiving, all.
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
P.S. A little bit of background on the 'why' of this message can be
found at http://www.ombwatch.org/regs/PDFs/BoltenMemo050908.pdf .
DAF
It appears that Accredited Standards Committee X12 is applying a very strict "catastrophic impediment to ... implementation" hurdle to forwarded Notice of Proposed Rule Making (NPRM) technical comments requesting changes to their version 005010 Type 3 Technical Reports (TR3's) proposed for HIPAA adoption on 8/22/2008. [See www.regulations.gov comment ID # CMS-2008-0101-0012.1 at
Should requested changes to the version 005010 TR3's not be incorporated, two other mechanisms are available for requesting these and additional changes to subsequent TR3 versions.
Submit a change request to X12 via the Designated Standards Maintenance Organizations (DSMO) change request web site at http://www.hipaa-dsmo.org/Main.asp
If you plan to use the DSMO web site, do not delay any submissions. There is an approximately 3-6 month flow time for change request approvals prior to most TR3 writing work being initiated, and several X12 workgroups are already preparing the next presently planned versions of TR3's: 005050.
For attendance at X12 Trimester Meetings, it would be beneficial to send advance copies of any changes you'd like discussed to the co-chairs of the applicable workgroups for placement on workgroup session agendas. Co-chair e-mail addresses are located at
and agendas are typically established about a month prior to each Trimester Meeting.
Bottom line, for now at least, assume any NPRM comment-requested version 005010 TR3 changes will not be incorporated, and start the request process for these changes in version 005050 as soon as feasible to ensure they are efficaciously carried forward.
Feel free to write back to me if you have any questions about the DSMO and X12 processes involved and/or their timings.
-------------- Original message from "Patrick O'Reilly" <poreilly@...>: --------------
> > NIST announces the release of Special Publication 800-124, Guidelines > on Cell Phone and PDA Security. It provides an overview of cell phone > and personal digital assistant (PDA) devices in use today and offers > insights into making informed information technology security > decisions on their treatment. SP 800-124 gives details about the > threats and technology risks associated with the use of these devices > and the available safeguards to mitigate them. Organizations can use > the information presented in SP 800-124 to enhance security and > reduce incidents involving cell phone and PDA devices. > > URL to SP 800-124: > http://csrc.nist.gov/publications/PubsSPs.html#800-124
Be sure to take a look at #3: SP 800-66 Revision 1, An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule
-----Original Message----- From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of Patrick O'Reilly Sent: Friday, October 24, 2008 4:55 PM To: Multiple recipients of list Subject: NIST Releases 3 Special Publications - 1 Draft and 2 Final
NIST Computer Security Diviison is proud to announce the release of 3
publications - 1 Draft Special Publication (SP) and 2 Special
Publications (SP) (final).See overview of 3 publications below:
#1: Draft SP 800-57, Part 3
NIST announces the release of a draft of Part 3 of Special
Publication 800-57, Recommendation for Key Management:
Application-Specific Key Management Guidance. This Recommendation
provides guidance when using the cryptographic features of current
systems. It is intended to help system administrators and system
installers adequately secure applications based on product
availability and organizational needs, and to support organizational
decisions about future procurements. The guide also provides
information for end users regarding application options left under
their control in the normal use of the application. Recommendations
are given for a select set of applications, namely: PKI, IPsec, TLS,
S/MIME, Kerberos, OTAR, DNSSEC and Encrypted File Systems. Other
topics will be added at a later time, and commenters are invited to
suggest such topics. Please submit comments to ebarker@... with
"Comments on Draft 800-57, Part 3" in the subject line. The comment
Register for Free Webinar with Forrester and Eurekify
Nov 5, 10:30am EST
Forrester Senior Analyst Andras Cser and Eurekify Founder Dr. Ron
Rymon will each present his vision of a Business-Driven Role Management
& Identity GRC. Eurekify will then present Enterprise Role & Compliance
Manager V4.0 – a SOA Server designed to provide Role-based Management
services for Identity Management, Identity GRC, and a variety of other
Enterprise IT systems.
The project announced in the message below is planned to determine what data should be contained in X12 837 claims transactions versus the data to be contained in the combined X12 275 and HL7 CDA claims attachments transactions. [If this latter combination is mysterious to you, feel free to contact me for a short explanation.]
While the outcome of this project won't likely be felt for many years, the determination work is kicking-off soon. Participation in this project is open to all -- X12 or HL7 membership not required -- and this is your opportunity to join-in at almost the very beginning.
Please also forward this message to your colleagues as you see fit. This is the ground-floor opportunity to collaborate, and X12 and HL7 are attempting to notify the widest possible audience of potential contributors.
RE: Official Solicitation to Join HL7 and X12 Data Determination Coordination Project (DDCP)
Dear Health Care Claims and Claims Attachment Stakeholder:
The Standards Development Organizations (SDO), Health Level Seven (HL7) and Accredited Standards Committee (ASC X12) Insurance Subcommittee (X12N), are collaborating on a project to determine where supportive data should reside. Currently some supportive data is included in the 837 electronic claims because there was no “attachment” standard available for use. The SDO's are inviting the industry to participate in this project.
Since 1997, the SDOs have been collaborating in developing a standard electronic attachment transaction. In addition, HL7 has developed standardized content for various attachment types.
HL7 and X12N feel that this project is extremely important to the industry and cannot be accomplished without the input of industry experts such as you.
Once finalized, changes will be submitted for the “next round” of HIPAA, and all entities will have to comply with them. Please take time to consider the importance of this task and join us in this endeavor.
Contact June Rosploch at june.rosploch@... by Friday, November 14, 2008 with your representatives contact information as outlined in the accompanied attachment. Upon receipt of the contact person’s information we will establish communication with them to schedule the initial task group teleconference call. We also ask that you forward this invitation to any person or organization that you feel would be able to contribute to the development of the standardized additional information for this DDCP initiative.
See attachment (DDCP_Attachment_1.doc) for details of the anticipated work effort and volunteer enlistment process.
Remember, anybody may submit comments regarding these NPRM's until 5:00 p.m. Eastern time on Tuesday, 10/21/2008. The electronic submittal sites allow both inline text and/or attachments, using a variety of formats, to be recorded.
Dave Feinberg Rensis Corporation [A Consulting Company] 206-617-1717 DAFeinberg@... Author of "Understanding HIPAA Communications"
----- Original Message -----
From: CMS CMSProviderResource
Sent: Wednesday, September 24, 2008 5:05 PM
Subject: ICD-10-CM/PCS National Provider Conference Calls With Question
& Answer Session
The Centers for Medicare & Medicaid Services (CMS) will host a series of
national provider calls (see below) that will provide an overview of
ICD-10 and how it differs from ICD-9-CM. The presentations will include
the major impacts providers should consider when planning to update any
systems with ICD-10 codes. Issues such as differences in code length,
alpha-numeric characters, and increased details captured by the codes
will be explained. For the provider, payer, vendor, and publishing
community, this overview will help them think about future reporting,
system updates, and training, considering that ICD-10 may be implemented
in the future.
The presenters will include members of the Cooperating Parties for
ICD-9-CM, a formal coalition that has been working together on ICD-10
issues. The role of each will be explained, along with a similar role
they will play should ICD-10 be implemented. The Cooperating Parties
include CMS, Centers for Disease Control and Prevention (CDC), American
Health Information Management Association (AHIMA), and American Hospital
Association (AHA).
A PowerPoint slide presentation has been posted on the ICD-10 Web Page
at http://www.cms.hhs.gov/ICD10 for you to download prior to the
conference call so that you can follow along with the presentation.
[F.Y.I. The direct url for the 69 slide set is
http://www.cms.hhs.gov/ContractorLearningResources/Downloads/ICD-10_Overview_Pre\
sentation.pdf
--DAF]
Conference Call Details:
Separate conference calls have been scheduled for each provider type.
The same information will be presented at each conference call.
Participants may select one of the times listed below to attend a
conference call. Select the appropriate link below, according to your
provider type, to register for a conference call.
Provider Type and Date and Time of Conference Call:
Hospital Staff
October 14, 2008
12:30 p.m. - 2:30 p.m. EDT
To register go to
http://www.cms.hhs.gov/ICD10/downloads/ICD10_hospital.pdf.
Other Part A and Part B Providers
November 12, 2008
12:30 p.m. - 2:30 p.m. EST
Registration information for this conference call will be forthcoming.
Physicians
November 17, 2008
12:30 p.m. - 2:30 p.m. EST
Registration information for this conference call will be forthcoming.
For those who are unable to attend, a transcript will be posted on the
ICD-10 Web Page at http://www.cms.hhs.gov/ICD10 shortly after the
conference call.
###
Office for Civil Rights posted the following documents on Tuesday,
September 16, 2008 on http://www.hhs.gov/ocr/hipaa/privacy.html
Patient Guide: When Health Care Providers May Communicate About You
with Your Family, Friends, or Others Involved in Your Care
Provider Guide: Communicating with a Patient's Family, Friends, or
Others Involved in a Patient's Care
Regards,
Share HIPAA
A colleague of mine and co-chair of X12's (healthcare insurance) Provider Caucus [ http://www.x12.org/x12org/industry/index.cfm ] has prepared a reasonably comprehensive list of links to various materials that could be useful for folks preparing HIPAA TCS NPRM comments. With her permission, following is that list.
NCVHS Letter of Recommendation to HHS for ICD-10 (includes links to Rand study and testimony from industry in 2003) http://www.ncvhs.hhs.gov/031105lt.htm
Greetings all. I recently completed my first passes through the two
HIPAA TCS NPRM's published on 8/22/2008, and have generated a few
interesting observations. In order to avoid clogging everybody's inbox,
I've not included them with this message, but will pass my document
along to anybody who asks by responding to this e-mail via
DAFeinberg@... .
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
Two points to keep in mind over the next ten days or so... .
~ Technical comments on the HIPAA Transactions NPRM proposed
version 005010 TR3 contents are generally planned to be
forwarded by CMS/OESS to X12 to obtain resolution
recommendations.
~ X12 will be holding its next Trimester Meeting the week of
21 September in Pittsburgh.
[See http://www.x12.org/x12org/meetings/x12trimt/index.cfm .]
As a consequence of this confluence, I suspect any comments on the
TR3's referenced in the recently published NPRM which can be submitted
at least a week prior to X12's Trimester Meeting would be welcome, would
likely receive highly focused attention, and could potentially provide
an early indication of any significant issues being discovered.
Note that submitting Transactions NPRM TR3 comments early does not in
any way preclude submission of further comments -- technical and
policy -- through the end of the NPRM public comment period on
10/21/2008.
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
NOTICE
The following version 005050 Type 3 Technical Report (TR3) [formerly
known as Implementation Guide (IG)] Informational Forum is scheduled
to be held at X12's September, 2008, Trimester Meeting in Pittsburgh,
Pennsylvania.
Tuesday, 9/23/2008, 9:00 a.m.
X274 275 Personal Health Record Data Transfer Between
Health Plans
This Informational Forum provides a venue for authors of the listed TR3
to orally respond to comments received during the draft TR3 public
comment period. Comments on this TR3 may be viewed at
http://www.wpc-edi.com/conferences/tg2/implementationguides, and the
authors' responses to these comments will be posted there as well by
Monday, 9/08/2008. A copy of the draft TR3 is available via
http://www.wpc-edi.com/products/publications/x274 .
This Informational Forum is the final X12 opportunity to comment on a
draft TR3 -- but comments are generally limited to only those regarding
modifications generated as a consequence of the received public
comments.
Participation at this Informational Forums is open to anybody with
payment of one applicable X12 Trimester Meeting fee [$0.00 for employees
of X12 members, a sliding scale for others].
http://www.x12.org/x12org/meetings/x12trimt/index.cfm lists logistics
for anybody desiring to attend.
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
P.S. Yes, this TR3 is indeed version 005050, not 005010. It's the
first of around two dozen X12N is creating over the next year or three
in response to evolving industry needs. Write if you'd like a short
summary of the main areas of planned changes.
DAF
Official formal Notices of Proposed Rule Making (NPRM's) -- i.e., draft
federal regulations -- to update HIPAA transactions and code sets were
published today, 8/22/2008, in the Federal Register. They may be
obtained at the following links:
Transactions: X12 and NCPDP
http://edocket.access.gpo.gov/2008/pdf/E8-19296.pdf
Code Sets: ICD-10-CM and ICD-10-PCS
http://edocket.access.gpo.gov/2008/pdf/E8-19298.pdf
Anybody may submit comments regarding these NPRM's from today through
Tuesday, 10/21/2008. References in any comments should be solely to the
versions of the NPRM's contained in the Federal Register. All
pre-publication versions -- particularly from the CMS web site -- should
be discarded; portions have small but significant errors that have been
corrected.
Copies of X12's Type 3 Technical Reports (TR3's) incorporated by
reference into the Version 005010 NPRM may be obtained via the following
shortcut link:
http://store.X12.org .
As CMS is no longer subsidizing X12 for these documents, it will cost
you directly to have them downloaded or shipped. Note, though, that
there is a single price for a package of all nine of the proposed
version 005010 TR3's. [If you're downloading, the present $750 package
price breakeven point is more than four TR3's.]
Playbacks of pre-recorded webinars providing insight from X12's subject
matter experts on how the proposed version 005010 TR3's address
industry-requested requirements can be obtained via
http://www.x12.org/webinars.
Topics covered in these webinars include:
+ global changes across all affected transactions, including
details of explanatory, technical and structural
modifications,
+ the business justification for recommended solutions included
in version 005010, and
+ methods to address each of the nine proposed updated X12
transactions.
And, finally, the authors of the version 005010 TR3's will be working on
NPRM comments and responses to NPRM comments during X12's upcoming
Trimester Meeting, 21-25 September, in Pittsburgh, PA. This meeting is
open to all, and logistics for attending may be obtained at
http://www.x12.org/x12org/meetings/x12trimt/index.cfm .
Be advised, though, that the block of rooms at the X12 group rate in the
Omni William Penn hotel is already filled.
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
"On August 15, 2008, HHS released two proposed rules to adopt updated HIPAA standards; these rules are currently on display at the Federal Register and will be published on August 22, 2008. In one proposal, HHS adopts X12 Version 5010 and NCPDP Version D.0 for the HIPAA transactions. In this rule, HHS also proposes to adopt a new standard for Medicaid subrogation, for pharmacy claims, known as NCPDP Version 3.0. In a separate proposed rule, HHS proposes to adopt the ICD-10 code set to replace the ICD-9 code sets in HIPAA transactions. Version 5010 accommodates the ICD-10 code sets, and has an earlier compliance date than ICD-10 in order to ensure adequate testing time for the industry. These two rules apply to HIPAA covered entities, including health plans, health care clearinghouses, and certain health care providers. To view [pre-publication versions of] both proposed rules, see the links ... below."
Read and reap the benefits! Your comments
are invited.
From:
compsecpubs@... [mailto:compsecpubs@...] On Behalf Of Patrick O'Reilly Sent: Tuesday, August 19, 2008
2:12 PM To: Multiple recipients of list Subject: NIST Releases Special
Publication 800-37 Revision 1
NIST announces the completion of an interagency project to develop a
common process to authorize federal information systems for operation. The
initial public draft of NIST Special Publication 800-37, Revision 1, Guide for Security Authorization of Federal
Information Systems: A Security Lifecycle Approach, is now available
for a six-week public comment period. The publication contains the proposed new
security authorization process for the federal government (currently commonly
referred to as certification and accreditation, or C&A). The new process is
consistent with the requirements of the Federal Information Security Management
Act (FISMA) and the Office of Management and Budget (OMB) Circular A-130,
Appendix III, promotes the concept of near real-time risk management based on
continuous monitoring of federal information systems, and more closely couples
information security requirements to the Federal Enterprise Architecture (FEA)
and System Development Life Cycle (SDLC).
-------------- Forwarded Message: -------------- From: "Patrick O'Reilly" <poreilly@...> To: Multiple recipients of list <compsecpubs@...> Subject: NIST Released 2 Publications - 1 Draft Special Publication and 1 final Special Publication Date: Thu, 14 Aug 2008 13:02:42 +0000
NIST is pleased to announce the release of Special Publication 800-60 Revision 1, Volume I: Guide for Mapping Types of Information and Information Systems to Security Categories and Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories. This publication provides the basic guidelines for mapping types of information and information systems to security categories. The appendices contained in Volume II include security categorization recommendations and rationale for mission-based and management and support information types.
URL to SP 800-60 Rev. 1: http://csrc.nist.gov/publications/PubsSPs.html#800-60_Rev1
Draft NIST Interagency Report (IR) 7511, Security Content Automation Protocol (SCAP) Validation Program Test Requirements, Version 1.1 is now available for public comment. This report describes the requirements that must be met by products to achieve SCAP Validation. Validation is awarded based on a defined set of SCAP capabilities and/or individual SCAP components by independent laboratories that have been accredited for SCAP testing by the NIST National Voluntary Laboratory Accreditation Program. Draft NISTIR 7511 has been written primarily for accredited laboratories and for vendors interested in receiving SCAP validation for their products. To learn more about this draft, please visit the Drafts page at this URL: http://csrc.nist.gov/publications/PubsDrafts.html#800-106
Forwarded from
http://www.cms.hhs.gov/NationalProvIdentStand/Downloads/Revised_NPPES_Enhancemen\
ts.pdf
"On August 10, 2008, the National Plan and Provider Enumeration System
(NPPES) will undergo system maintenance. Neither NPPES nor the NPI
Registry will be available on August 10, 2008. CMS will be implementing
some enhancements/updates to the system. Some of these
enhancements/updates may impact health care provider's NPPES records.
"Beginning on August 11, the following changes will be implemented:
NPPES
+ The 'Application Help' page text will be updated to further
clarify the following:
~ Sole proprietors; Organization subparts; 'Other Provider
Identification Numbers' choices related to the Medicare identifiers
~ Restrict telephone number fields to only allow all numeric
entries. This also affects providers who currently have NPIs with
incorrect telephone number formats located in their NPPES records. These
providers will be required to make the appropriate changes to the
telephone numbers in their NPPES records the next time they submit any
updates/changes to their records. However, these providers are
encouraged to correct their telephone number formats without delay.
"NPI Registry
+ Allow the user to search by an organization's 'doing business as'
(DBA) name
+ NPI Registry will display deactivated NPIs (searches on NPI that
have been deactivated will result in a message that the NPI is
deactivated.)
"Electronic File Interchange (EFI)
+ Revised EFI User Manual (e.g., all-numeric telephone numbers)
+ Revised EFI Technical Companion Guide (e.g., all-numeric telephone
numbers)
+ The upcoming changes will not impact the EFI XML Schema.
"Additional Information
"Health care providers needing assistance with applying for an NPI
or updating their data in NPPES may contact the NPI Enumerator at
1-800-465-3203 or email the request for assistance to the NPI Enumerator
at CustomerService@....
"CMS advises health care providers to read the information available
at www.cms.hhs.gov/NationalProvIdentStand/ on the CMS NPI website.
Included on this site are NPI Frequently Asked Questions and Answers
that can assist with NPI issues. In addition, the NPI Application/Update
form is also a good source of information. Health care providers should
refer to the instructions (they are part of the form) for clarification
on information to be submitted in order to obtain NPIs or update their
records. They can also refer to the 'Application Help' tab located at
https://nppes.cms.hhs.gov on the NPPES website for additional assistance
when online."
###
Subject: Downloadable 005010 Implementation Guides, Available at http://store.X12.org
Falls, Church, Va, July 29, 2008, – In response to the federal government’s anticipated 2008 Notice of Proposed Rule Making (NPRM), expected to name 005010 replacements to the existing 004010A1 HIPAA mandate, X12 today launched a new website for the sale of these 005010 counterparts: http://store.x12.org
“X12 is pleased to work with its Secretariat, the Data Interchange Standards Association (www.DISA.org) and publisher Washington Publishing Company (www.WPC-EDI.com) in developing the website,” said Dan Kazzaz, Chair of ASC X12. “The implementation guides represent over 4 years of refinement based on the collective input from hundreds of industry stake holders. Careful analysis of what worked well with the initial 004010A1 implementation along with answers to the tough questions posed by those charged with that implementation has produced significant improvement over the originally mandated material.”
As a supplement to the guides, X12 is presenting a live webinar series that details the business justification for recommended solutions included in version 005010. Visit www.X12.org/webinars for details and to register.
The twelve transactions embodied in nine documents are now available for immediate PDF download, PDF shipped on a CD, or shipped as a bound document:
• 270/271: Health Care Eligibility Benefit Inquiry and Response • 276/277: Health Care Claim Status Request and Response • 278/278: Services Review Request for Review/Response • 820: Payroll Deducted and Other Premium Payment • 834: Benefit Enrollment and Maintenance • 835: Health Care Claim Payment/Advice • 837P: Health Care Claim: Professional • 837I: Health Care Claim: Institutional • 837D: Health Care Claim: Dental
The Implementation Guides, known as Technical Reports Type 3 (TR3s), may be purchased individually or as a suite for a modest price at www.X12.org. Once a Final Rule is published, pricing is subject to change and may include a discount for X12 members.
Join X12: Participate in this robust standards developing organization with over 25 years of collective business process and technical expertise in the development and adoption of electronic data exchange standards. Proactively shape the most widely used X12 EDI standards in a consensus-based environment that meets both vertical and horizontal market needs.
About DISA: The Data Interchange Standards Association (DISA) is home for the development of cross-industry e-business interchange standards that help individuals and organizations improve business processes, reduce costs, increase productivity and take advantage of new opportunities. Driving an array of e-business initiatives, DISA provides administrative and technical support to the Accredited Standards Committee. For additional information about DISA, visit www.disa.org, or call 703-970-4480.
For additional information: E-mail: pr@... Phone: (703) 970-2052
America's Health Insurance Plans: Real-time Claims Adjudication Virtual Seminar
America's Health Insurance Plans will be hosting a Virtual Seminar on Real-time Claims Adjudication (RTA) on Wednesday, August 6, 2008 from 2 p.m. - 3:30 p.m. Eastern. The RTA Virtual Seminar promises to be educational, informative and entertainingand will be of value no matter where your company is in the process of adopting real-time claims adjudication. We will also include plenty of time after the presentations to answer your questions on RTA.
Join us for AHIP's first Virtual Seminar on RTA. Real-time Claims Adjudication (RTA) Virtual Seminar Wednesday, August 6, 2008 2:00 - 3:30 pm ET Virtual Seminar Website Register Online
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Monday, July 21, 2008 3:04 PM
To: Multiple recipients of list
Subject: NIST Special Publication 800-55 Revision 1 is now available on CSRC
website
NIST is pleased to announce the release of NIST Special Publication
800-55, Revision 1, Performance Measurement Guide for Information
Security. This publication provides assistance in the developing,
selecting, and implementing security performance measures to be used
at the information system and program levels. These measures
indicate the effectiveness of security controls applied to
information systems and supporting information security programs.
URL to document:
http://csrc.nist.gov/publications/PubsSPs.html#800-55_Rev1
For those of you preparing for the federal government's much-anticipated
Notice of Proposed Rulemaking (NPRM) to modify mandated HIPAA
transactions, X12 is offering webinars on version 005010 Type 3
Technical Reports (TR3's) that are presumed referenced.
There will be six distinct webinars covering nine version 005010 TR3's.
They are intended to provide insight from the original subject matter
experts regarding how the implementation of X12 version 005010
transactions addresses industry-requested requirements.
Topics to be covered include:
+ global changes across all affected transactions, including
details of explanatory, technical and structural
modifications,
+ the business justification for recommended solutions included
in version 005010, and
+ methods to address each of the nine specific modified
transactions.
Individuals may register for any number of the six webinars on a
mix-and-match basis. Individuals may also register for the live
presentations, and/or listen-only recordings ... again on a
mix-and-match basis.
Further summary information may be found at
http://www.x12.org/webinars/
and its embedded registration form link at
http://www.x12.org/webinars/ASC%20X12%20005010%20Webinar%20Registration%202008.p\
df
... where detailed mix-and-match pricing is listed.
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
The following entry was posted to the Office of Management and Budget
(OMB) Regulatory Review web site as of 7/11/2008.
AGENCY: HHS-CMS RIN: 0938-AN25
TITLE: Revisions to HIPAA Code Sets (CMS-0013-P)
STAGE: Proposed Rule ECONOMICALLY SIGNIFICANT: Yes
RECEIVED DATE: 07/11/2008 LEGAL DEADLINE: None
ABSTRACT: This proposed rule would revise some of the adopted
transaction and code set standards detailed in regulations published by
HHS on August 17, 2000 and February 20, 2003.
Note that this NPRM is the result of a Regulatory Flexibility Act (RFA)
Section 610 review. RFA §610 "requires federal agencies to review
regulations that have a significant economic impact on a substantial
number of small entities within 10 years of their adoption as final
rules. These periodic rule reviews are a mechanism for agencies to
assess the impact of existing rules on small entities and to determine
whether the rules should be continued without change, or should be
amended or rescinded, consistent with the objectives of applicable
statutes." { http://www.sba.gov/advo/r3/r3_section610.pdf }
The significance of this posting is that, if OMB approves the materials
under review using it's typical process and without any need for
significant modifications, a Notice of Proposed Rule Making (NPRM) would
be published in the Federal Register in approximately three months.
Dave Feinberg
Rensis Corporation [A Consulting Company]
206-617-1717
DAFeinberg@...
Author of "Understanding HIPAA Communications"
HHS, XXXXXXXXX
Health & Services Agree on Corrective Action Plan to Protect Health
Information
The U.S.
Department of Health & Human Services (HHS) has entered into a Resolution Agreement
with XXXXX-based XXXXXXXX Health Services to settle potential violations of the
Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and
Security Rules. In the agreement, XXXXXXXXXX agrees to pay $100,000 and
implement a detailed Corrective Action Plan to ensure that it will
appropriately safeguard identifiable electronic patient information against
theft or loss.
The
Privacy and Security Rules are enforced by HHS’ Office for Civil Rights
(OCR) and the Centers for Medicare & Medicaid Services (CMS). The Privacy
and Security Rules require health plans, health care clearinghouses and most
health care providers (covered entities) to safeguard the privacy of certain
individually identifiable health information and meet additional security
standards for patient information maintained in electronic form. The Resolution
Agreement relates to XXXXXXXXXX’s loss of electronic backup media and
laptop computers containing individually identifiable health information in 2005
and 2006.
Winston
Wilkinson, the director of the OCR, stated, “We are committed to
effective enforcement of health information privacy and security protections
for consumers. Other covered entities that are not in compliance with the
Privacy and Security Rules may face similar action.”
While OCR
and CMS have successfully resolved over 6,700 Privacy and Security Rule cases
by requiring the entities to make systemic changes to their health information
privacy and security practices, this is the first time HHS has required a
Resolution Agreement from a covered entity. XXXXXXXXXX’s cooperation with
OCR and CMS allowed HHS to resolve this case without the need to impose a civil
money penalty.
Director
Wilkinson noted, “We commend XXXXXXXXXX for their cooperation during the
course of the investigation and for their voluntary implementation of
comprehensive and system-wide improvements to protect individually identifiable
health information.”
The
incidents giving rise to the agreement involved two entities within the XXXXXXXXXX
health system, XXXXXXXXXX Home and Community Services and XXXXXXXXXX Hospice
and Home Care. On several occasions between September 2005 and March 2006,
backup tapes, optical disks, and laptops, all containing unencrypted electronic
protected health information, were removed from the XXXXXXXXXX premises and
were left unattended. The media and laptops were subsequently lost or stolen,
compromising the protected health information of over 386,000 patients. HHS
received over 30 complaints about the stolen tapes and disks, submitted after XXXXXXXXXX,
pursuant to state notification laws, informed patients of the theft. XXXXXXXXXX
also reported the stolen media to HHS. OCR and CMS together focused their
investigations on XXXXXXXXXX’s failure to implement policies and
procedures to safeguard this information.
Under the
Resolution Agreement, XXXXXXXXXX agrees to pay a $100,000 resolution amount to
HHS and implement a robust Corrective Action Plan that requires: revising its
policies and procedures regarding physical and technical safeguards (e.g.,
encryption) governing off-site transport and storage of electronic media
containing patient information, subject to HHS approval; training workforce
members on the safeguards; conducting audits and site visits of facilities; and
submitting compliance reports to HHS for a period of three years.
“The
protection of patient information is a top priority for XXXXXXXXXX Health &
Services,” stated XXXXXXXXXX’s Chief Information Security Officer.“Since
these incidents occurred, we have reinforced our security protocols and
implemented new data protection measures. Under the terms of the agreement, we
will continue to implement appropriate policies, procedures and
training.”
Kerry
Weems, the acting administrator of CMS, commented, “This resolution
confirms that effective compliance means more than just having written policies
and procedures. To protect the privacy and security of patient information,
covered entities need to continuously monitor the details of their execution,
and ensure that these efforts include effective privacy and security staffing,
employee training and physical and technical features.”
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Wednesday, July 09, 2008 5:31 PM
To: Multiple recipients of list
Subject: NIST Release 3 Draft Special Publications
NIST announces the public comment release of the following 3 documents:
1. Special Publication (SP) 800-121, Guide to Bluetooth Security,
2. SP 800-107, Recommendation for Applications Using Approved Hash
Algorithms, and
3. SP 800-41 Revision 1, Guidelines on Firewalls and Firewall Policy.
1. Draft SP 800-121, Guide to Bluetooth Security, describes the
security capabilities of Bluetooth technologies and gives
recommendations to organizations employing Bluetooth technologies on
securing them effectively. Much of SP 800-121 was originally included
in draft NIST SP 800-48 Revision 1, Wireless Network Security for
IEEE 802.11a/b/g and Bluetooth, but based on public comments, the
Bluetooth material has been removed from SP 800-48 and placed in its
own publication. NIST requests comments on draft SP 800-121 by August
22, 2008. Please submit comments to 800-121comments@... with
"Comments SP 800-121" in the subject line.
URL: http://csrc.nist.gov/publications/PubsDrafts.html#800-121
2. The release of the 2nd draft Special Publication 800-107,
Recommendation for Applications Using Approved Hash Algorithms. This
document provides security guidelines for achieving the required or
desired security strengths when using cryptographic applications that
employ the approved cryptographic hash functions specified in Federal
Information Processing Standard (FIPS) 180-3, such as digital
signature applications, Keyed-hash Message Authentication Codes
(HMACs) and Hash-based Key Derivation Functions (HKDFs). Please
submit comments to quynh.dang@... with "Comments on Draft
800-107" in the subject line. The comment period closes on October 9, 2008.
URL: http://csrc.nist.gov/publications/PubsDrafts.html#800-107
3. Draft SP 800-41 Revision 1, Guidelines on Firewalls and Firewall
Policy, provides recommendations on developing firewall policies and
on selecting, configuring, testing, deploying, and managing
firewalls. The publication covers a number of firewall technologies,
including packet filtering, stateful inspection, application-proxy
gateways, host-based, and personal firewalls. SP 800-41 Revision 1
updates the original publication, which was released in 2002. NIST
requests comments on draft SP 800-41 Revision 1 by August 15, 2008.
Please submit comments to 800-41comments@... with "Comments SP
800-41" in the subject line.
URL: http://csrc.nist.gov/publications/PubsDrafts.html#800-41-Rev1
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Monday, July 07, 2008 5:10 PM
To: Multiple recipients of list
Subject: NIST Releases 2 Publications - July 7, 2008
NIST announces the release of two publications: Special Publication
(SP) 800-113, Guide to SSL VPNs, and draft SP 800-124, Guidelines on
Cell Phone and PDA Security.
1. SP 800-113, Guide to SSL VPNs, seeks to assist organizations in
understanding Secure Sockets Layer (SSL) virtual private network
(VPN) technologies. The publication also makes recommendations for
designing, implementing, configuring, securing, monitoring, and
maintaining SSL VPN solutions. SP 800-113 provides a phased approach
to SSL VPN planning and implementation that can help in achieving
successful SSL VPN deployments. It also includes a comparison with
other similar technologies such as IPsec VPNs and other VPN solutions.
URL to SP 800-113:
http://csrc.nist.gov/publications/PubsSPs.html#800-113
2. Draft SP 800-124, Guidelines on Cell Phone and PDA Security, is
available for public comment. It provides an overview of cell phone
and personal digital assistant (PDA) devices in use today and offers
insights for making informed information technology security
decisions regarding their treatment. SP 800-124 gives details about
the threats, technology risks, and safeguards for these devices. NIST
requests comments on draft SP 800-124 by August 8, 2008. Please
submit comments to 800-124comments@... with "Comments SP
800-124" in the subject line.
URL to Draft SP 800-124:
http://csrc.nist.gov/publications/PubsDrafts.html#800-124
Some of you have sent emails to inform me that your calendar was being
filled with ShareHIPAA yahoo group calendar events. I have deleted all
calendar entries for the ShareHIPAA yahoo group and have disabled the
calendar function for the group. If you continue to receive ShareHIPAA
calendar events, please let me know by sending an email to
sharehipaa1@... and I will investigate what further actions I can
take to prevent further abuse of this group.
Thank you,
Share HIPAA