Search the web
Sign In
New User? Sign Up
ShareHIPAA · Share HIPAA
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Messages 581 - 610 of 641   Newest  |  < Newer  |  Older >  |  Oldest
Messages: Show Message Summaries   (Group by Topic) Sort by Date v  
#610 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Wed May 27, 2009 12:43 am
Subject: Fw: Survey: Timeframe to rollout possible revised 1500 claim form
dafeinberg
Offline Offline
Send Email Send Email
 
----- Somewhat Edited Original Message -----
From: Nancy Spector
Sent: Thursday, May 21, 2009 2:01 PM
Subject: Survey: Timeframe to rollout possible revised 1500 claim form

The National Uniform Claim Committee (NUCC) is researching the needs for
a possible revised 1500 claim form.  No decision has been made yet about
whether or not we will revise the form, but we need to know if we do
revise it, when would be the best time to roll it out, with the 5010 and
ICD-10 work going on.

We want to make sure that we get the provider perspective on when would
be the best time to roll out a revised form.

The following is a link to a survey asking about the best timeframe to
rollout a revised form.

http://www.surveymonkey.com/s.aspx?sm=E6dM98zYy8EsJp4v_2fqC6hg_3d_3d

Please distribute this link to your constituents and encourage them to
complete the survey.  The deadline for completing the survey is close of
business Wednesday June 10th.

Thanks,

Nancy

Nancy Spector, RN MSC
Director, Electronic Medical Systems
American Medical Association
515 N. State St
Chicago, IL 60654
Phone: 312-464-4059

#609 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Thu May 14, 2009 7:19 pm
Subject: Fw: CMS to Host First National Provider Education Call on HIPAA Version 5010 - June 9, 2009
dafeinberg
Offline Offline
Send Email Send Email
 
----- Original Message -----
Sent: Thursday, May 14, 2009
Subject: CMS to Host First National Provider Education Call on HIPAA Version 5010 - June 9, 2009

CMS to Host First National Provider Education Call on HIPAA Version 5010 - June 9, 2009

 

The Centers for Medicare & Medicaid Services (CMS) will host a national education conference call to address the implementation of HIPAA Version 5010. This call is being conducted for all Medicare fee-for-service providers.  The call will give a general overview of the transition to HIPAA Version 5010 and address some of the exceptions and situations you may encounter as the new version is implemented. A presentation will be given and CMS Subject Matter Experts will be available to answer questions. A PowerPoint presentation will be posted on the CMS 5010 Web page prior to the call. The 5010 Web page is located at http://www.cms.hhs.gov/ElectronicBillingEDITrans/18_5010D0.asp

 

 

Conference call details:

 

Date:  June 9, 2009

           

Conference Title: 

 

CMS audio conference call: HIPAA Version 5010 – What you need to know!

           

Time:   2:30 – 4:00 p.m. ET               

 

In order to receive the call-in information, you must register for the call. It is important to note that if you are planning to sit in with a group, only one person needs to register to receive the call-in data.  This registration is solely to reserve a phone line, NOT to allow participation.  If you cannot attend the call, replay information is available below.

 

Registration will close at 2:30 p.m. ET on June 8, 2009, or when available space has been filled.  No exceptions will be made, so please be sure to register prior to this time.

 

  1. To register for the call participants need to go to: http://www2.eventsvc.com/palmettogba/060909

 

  1. Fill in all required data. 

 

  1. Verify your time zone is displayed correctly the drop down box.

 

  1. Click "Register".

 

  1. You will be taken to the “Thank you for registering” page and will receive a confirmation email shortly thereafter.   Note: Please print and save this page, in the event that your server blocks the confirmation emails.  If you do not receive the confirmation email, please check your spam/junk mail filter as it may have been directed there.

 

###


#608 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Thu May 14, 2009 6:38 am
Subject: Fw: X12 Multiple Transactions Surveys
dafeinberg
Offline Offline
Send Email Send Email
 
The following is a consolidation of four messages from Gail Kocher, co-chair of Accredited Standard Committee (ASC) X12's HIPAA Implementation and Coordination Work Group.
 
                    Dave Feinberg
                    Rensis Corporation  [A Consulting Company]
                    206-617-1717
                    DAFeinberg@...
                    Author of  "Understanding HIPAA Communications"
 
 
----- Consolidated Original Messages ----- 
The ASC X12 Insurance Subcommittee Health Care Task Group HIPAA Implementation and Coordination Work Group (X12N TG2 WG21) is conducting a short survey designed to capture the health care industry’s capability to simultaneously support in long-term production multiple mandated versions of the X12 transactions. Support of multiple versions due to transition periods are out of scope, i.e. supporting a version that will be sunset upon a compliance date in lieu of the other version is not part of this survey.

 

In addition to capability, we are looking to collect some baseline information around the impacts to various stakeholders, specifically implementation costs and timeframes. Costs would include dollars associated with procurement, maintenance, and resources/labor.

 

Survey Links:

 

For software application vendors:

http://www.surveymonkey.com/s.aspx?sm=ilRLrhBMbRk6R8Y3IbRVqg_3d_3d

 

For providers:

http://www.surveymonkey.com/s.aspx?sm=_2bdQ_2bTEOxtjgGT_2fXN_2bh4JYQ_3d_3d

 

For payers:

http://www.surveymonkey.com/s.aspx?sm=qBbJYaI_2buT5BbvhTfa3lMA_3d_3d

 

For clearinghouses or billing services:

http://www.surveymonkey.com/s.aspx?sm=uJ_2bFNr8MlppiH7uvuw3PZg_3d_3d

 

 

Absolutely NO identifying information about responses or respondents will be captured in the survey. Taking the time to respond to the few questions will assist our Work Groups in gathering important information for the development work of X12. All of the questions are visible on one webpage so you may view it first to determine whether you need to consult additional staff within your organization prior to submitting the survey.

 

The survey will close on May 29th.

 

We thank you in advance for your willingness to participate in this survey.

 

###


#607 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Mon May 11, 2009 3:19 pm
Subject: Fw: Reminder and New/Revised Materials for ICD-10-CM/PCS Conference Call
dafeinberg
Offline Offline
Send Email Send Email
 
----- Original Message -----
Sent: Monday, May 11, 2009
Subject: Reminder and New/Revised Materials for ICD-10-CM/PCS Conference Call

Reminder:

Providers may now register for the Centers for Medicare & Medicaid Services’ ICD-10-CM/PCS Implementation and General Equivalence Mappings (Crosswalks) National Provider Conference Call that will be conducted on May 19, 2009 from 1:00 p.m. – 2:30 p.m. Eastern Daylight Time. This conference call will include a discussion of the following topics:

·         An overview of the ICD-10 final rule, which requires the implementation of ICD-10-CM/PCS on October 1, 2013;

·         The differences between ICD-9-CM and ICD-10-CM/PCS codes; 

·         The use of the General Equivalence Mappings that have been created to assist in converting policies, edits, and trend data from ICD-9-CM to ICD-10-CM/PCS; and

·         The resources that are available to assist in planning for the transition from ICD-9-CM to ICD-10-CM/PCS.

 

Note:

A new fact sheet has been developed that provides additional information about the ICD-10 General Equivalence Mappings, and the slide presentation that will be discussed during the conference call has been revised. These discussion materials have been posted in the Downloads Section at http://www.cms.hhs.gov/ICD10/07a_2009_CMS_Sponsored_Calls.asp . If you are unable to access the hyperlink in this message, please copy and paste the URL into your Internet browser. 

###

 


#606 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Wed May 6, 2009 3:40 am
Subject: Fw: CMS Releases Special Edition MLN Matters Article
dafeinberg
Offline Offline
Send Email Send Email
 
----- Original Message -----
Sent: Monday, May 04, 2009
Subject: CMS Releases Special Edition MLN Matters Article

New from the Medicare Learning Network (MLN):  The Centers for Medicare & Medicaid Services (CMS) Releases a New MLN Matters Article of Particular Interest!

 

SE0904 – An Introductory Overview of the HIPAA 5010

http://www.cms.hhs.gov/MLNMattersArticles/downloads/SE0904.pdf

 

The implementation of HIPAA 5010 presents substantial changes in the content of the data that providers submit with their claims, as well as the data available to them in response to their electronic inquiries.  This Special Edition MLN Matters article alerts providers of these HIPAA changes and how they need to plan for their implementation.

 

###

 


#605 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Wed Apr 22, 2009 12:13 am
Subject: NIST Released Draft SP 800-118 Guide to Enterprise Password Management
hitrecruiting
Offline Offline
Send Email Send Email
 

 

 


From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of Patrick O'Reilly
Sent: Tuesday, April 21, 2009 3:00 PM
To: Multiple recipients of list
Subject: NIST Released Draft SP 800-118

 

DRAFT SP 800-118 Guide to Enterprise Password Management

 

NIST announces that Draft Special Publication (SP) 800-118, Guide to Enterprise Password Management, has been released for public comment. SP 800-118 is intended to help organizations understand and mitigate common threats against their character-based passwords. The guide focuses on topics such as defining password policy requirements and selecting centralized and local password management solutions.

 

NIST requests comments on draft SP 800-118 by May 29, 2009. Please submit comments to 800-118comments@... with "Comments SP 800-118" in the subject line.

 

Drafts page URL for 800-118:

http://csrc.nist.gov/publications/PubsDrafts.html#800-118

 

 


#604 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Sat Apr 18, 2009 4:07 pm
Subject: HITECH Act Breach Notification Guidance and Request for Public Comment
hitrecruiting
Offline Offline
Send Email Send Email
 

 

 


From: OCR HIPAA Privacy Rule information distribution [mailto:OCR-PRIVACY-LIST@...] On Behalf Of OS OCR PrivacyList, OCR (HHS/OS)
Sent: Friday, April 17, 2009 5:01 PM
To: OCR-PRIVACY-LIST@...
Subject: HITECH Act Breach Notification Guidance and Request for Public Comment

 

HITECH Act Breach Notification Guidance and Request for Public Comment

 

April 17, 2009

 

The U.S. Department of Health and Human Services (HHS) issued guidance today specifying the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals, as required by the Health Information Technology for Economic and Clinical Health (HITECH) Act passed as part of American Recovery and Reinvestment Act of 2009 (ARRA).  This guidance was developed through a joint effort by the HHS Office for Civil Rights (OCR), Office of the National Coordinator for Health Information Technology (ONC), and Centers for Medicare and Medicaid Services (CMS).

 

This guidance relates to two forthcoming breach notification regulations – one to be issued by HHS for covered entities and their business associates under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Sec. 13402 of HITECH) and one to be issued by the Federal Trade Commission (FTC) for vendors of personal health records and other non-HIPAA covered entities (Sec. 13407 of HITECH).  HITECH requires these regulations to be published within 180 days of enactment.  If the entities subject to the regulations apply the technologies and methodologies specified in the guidance to secure information, they will not be required to provide the notifications required by the regulations in the event the information is breached.  

 

In addition to this guidance, HHS has also concurrently issued a request for information (RFI) soliciting public comment on the breach notification provisions of the HITECH Act to inform future rulemaking and updates to the guidance.  The guidance and RFI is available at www.hhs.gov/ocr/privacy.  Once published in the Federal Register, the guidance and RFI will also be available for public comment at www.regulations.gov.

**********************************************************************

This email is being sent to you from the OCR-Privacy-list listserv, operated by the Office for Civil Rights (OCR) in the US Department of Health and Human Services.

This is an announce-only list, a resource to distribute information about the HIPAA Privacy Rule. For additional information on a wide range of topics about the the Privacy Rule, please visit the OCR Privacy website at www.hhs.gov/ocr/hipaa/. You can also call the OCR Privacy toll-free phone line at (866) 627-7748. Information about OCR's civil rights authorities and responsibilities can be found on the OCR home page at www.hhs.gov/ocr

If you believe that a person or organization covered by the Privacy Rule (a "covered entity") violated your health information privacy rights or otherwise violated the Privacy Rule, you may file a complaint with OCR. For additional information about how to file a complaint, see the Fact Sheet "How to File a Health Information Privacy Complaint," available at http://www.hhs.gov/ocr/privacyhowtofile.htm .

To subscribe to or unsubscribe from the list serv, please go to: http://list.nih.gov/cgi-bin/wa?SUBED1=ocr-privacy-list&A;=1


#603 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Fri Apr 17, 2009 7:09 pm
Subject: Proposed FTC Breach Notification Rule for EHI
hitrecruiting
Offline Offline
Send Email Send Email
 

 

 


From: NESNIPPRIVACY@yahoogroups.com [mailto:NESNIPPRIVACY@yahoogroups.com] On Behalf Of Sheila Wrobel
Sent: Friday, April 17, 2009 9:11 AM
To: NESNIPPRIVACY@yahoogroups.com
Subject: [NESNIPPRIVACY] Proposed FTC Breach Notification Rule for EHI

 




http://www.ftc.gov/opa/2009/04/healthbreach.shtm

http://www.ftc.gov/os/2009/04/R911002healthbreach.pdf


Sheila A. Wrobel, JD, MBA
Compliance Officer/Privacy Officer
University of Nebraska Medical Center
987810 Nebraska Medical Center
Omaha, Nebraska 68198-7810
Ph: (402)559-6767
Fax: (402)559-7845


#602 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Wed Apr 15, 2009 4:27 am
Subject: X12 Version 005010 -- X12N's Responses to NPRM Technical Comments
dafeinberg
Offline Offline
Send Email Send Email
 
In the Final Rule adopting X12 version 005010 Type 3 Technical Reports
for HIPAA {Federal Register, Vol. 74, No. 11, 16 January 2009, page
3298, middle of second column and top of third column}, CMS wrote,

     "After publication of the final rule, all of the technical comments
      reviewed by the X12 workgroup, with the dispositions, will be
      posted on the CMS Web site ... as well as on the X12 portal [sic]
      ... ."

X12N's original of this report -- 239 pages -- is now posted at
http://www.x12.org/x12org/subcommittees/X12N/N0221_X12Responses_to_Tech.pdf

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#601 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Mon Apr 6, 2009 11:56 pm
Subject: Fw: ICD-10 ... New Medicare Learning Network Publication and FAQs Now Available
dafeinberg
Offline Offline
Send Email Send Email
 
----- Original Message -----
Sent: Monday, April 06, 2009 11:54 AM
Subject: New Medicare Learning Network Publication and FAQs Now Available for ICD-10

The General Equivalence Mappings – ICD-9-CM To and From ICD-10-CM and ICD-10-PCS Fact Sheet (March 2009), which provides information and resources regarding the General Equivalence Mappings that were developed as a tool to assist with the conversion of International Classification of Diseases, 9th Edition, Clinical Modification (ICD-9-CM) codes to International Classification of Diseases, 10th Edition (ICD-10) and the conversion of ICD-10 codes back to ICD-9-CM, is now available in downloadable format from the Centers for Medicare & Medicaid Services (CMS) Medicare Learning Network at http://www.cms.hhs.gov/MLNProducts/downloads/ICD-10_GEM_factsheet.pdf . The General Equivalence Mappings information discussed in this fact sheet has also been posted in the CMS Frequently Asked Questions database at https://questions.cms.hhs.gov/cgi-bin/cmshhs.cfg/php/enduser/std_alp.php?p_sid=l2s5Zouj . If you are unable to access any of the hyperlinks in this message, please copy and paste the URL into your Internet browser.

--------------------------------------------------------------------------------------------------------------------

Note:  If you have problems accessing any hyperlink in this message, please copy and paste the URL into your Internet browser. 

 


 


#600 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Sat Mar 21, 2009 5:25 pm
Subject: NIST Announces the Release of Information Security Training Draft Special Publication 800-16 Revision 1
hitrecruiting
Offline Offline
Send Email Send Email
 
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Friday, March 20, 2009 4:55 PM
To: Multiple recipients of list
Subject: NIST Announces the Release of Draft Special Publication 800-16
Revision 1


NIST announces the release of the Initial Public Draft (IPD) of
Special Publication 800-16, Revision 1, Information Security Training
Requirements: A Role- and Performance-Based Model. This publication
is now available for public comment.

The comprehensive training methodology provided in this publication
is intended to be used by federal information security professionals
and instructional design specialists to design (1) role-based
training courses or modules for personnel who have been identified as
having significant responsibilities for information security, and (2)
a basics and literacy course for all users of information systems.

We encourage readers to pay special attention to the Notes to
Reviewers section, as we are looking for feedback on the many changes
we have made to this document.

Comments will be accepted until June 26, 2009. Comments should be
forwarded via email to 800-16comments@....

URL to Draft SP 800-16 Rev. 1:
http://csrc.nist.gov/publications/PubsDrafts.html#800-16-rev1


Quick update - in the email sent to list on March 3, the NIST IR 7536
2008 Computer Security Division Annual Report was released.  We have
updated the PDF file for this document.  We now have a final layout
version available which includes charts, graphics, etc.  The text
inside this report did not change.  For those interested in viewing
the final printed version can find the updated PDF file here:

It is a PDF file and depending on your Internet speed, it may take a
couple extra seconds to load - PDF file is about 3.9 MB.
http://csrc.nist.gov/publications/nistir/ir7536/NISTIR-7536_2008-CSD-Annual-
Report.pdf

#599 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Thu Mar 19, 2009 2:16 pm
Subject: X12 Version 005010 and ICD-10 Regulations Now In Effect
dafeinberg
Offline Offline
Send Email Send Email
 
The official updated HIPAA transactions and code sets regulations
including X12 Version 005010,  ICD-10-CM,  ICD-10-PCS,  and various
NCPDP standards are now in effect as of 3/17/2009.  The online Code of
Federal Regulations (CFR) was updated last night, 3/18/2009, to
incorporate the modifications published in the Federal Register on
1/16/2009.  These most recent complete regulations may be viewed at
http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&tpl=/ecfrbrowse/Title45/45c\
fr162_main_02.tpl
starting at Subpart I -- General Provisions for Transactions.


Copies of X12's Type 3 Technical Reports (TR3s) incorporated by
reference into the updated regulations may be obtained via the
following link:
         http://store.X12.org .

As CMS is no longer subsidizing X12 for these documents, it will cost
you directly to have them downloaded or shipped.  Note, though, that
there is a single price for a package of all nine of the adopted version
005010 TR3s, and significant discounts are available to X12 members.

The first page of an online X12 membership application, including a dues
schedule, is located at
https://www.disa.org/apps/memberservices/x12/X12MembershipSection1.cfm


A summary of the changes between the current X12 version 004010 and
004010A1 Implementation Guides and the newly adopted version 005010 TR3s
is available at
http://www.x12.org/x12org/subcommittees/X12N/N0221_WEDI-X12-V5010_file.pdf.
Additionally, playbacks of webinars about the adopted X12 version 005010
TR3s can be arranged via
         http://www.x12.org/webinars/5010.cfm.
Topics covered in these webinars include:
   + the business justification for solutions included in version 005010
   + examples of how the implementation of version 005010 transactions
      addresses industry-requested requirements
   + specific answers to some of the questions from public comments to
      the Notice of Proposed Rule Making (NPRM)
   + details of changes across all affected transactions, including the
      explanatory, technical and structural modifications
   + details of how version 005010 is improved compared to version
      004010 and 004010A1
   + insight from original subject matter experts.
Again note that X12 members receive a discount on webinar fees.


Researched questions regarding the contents of any of X12's version
005010 TR3s for health care, as well as the current HIPAA-adopted 004010
and 004010A1 Implementation Guides, may be submitted to X12's Insurance
Subcommittee Interpretations Portal at www.x12n.org/portal .  Responses
to prior questions -- approximately 575 to date -- are easily located
via the Portal's search feature, and links to other useful sites are
also provided.  The Portal is open to all, and there is no charge for
using it.


Happy implementing to all.  Contact me should you have any questions or
desire any additional information.  And keep in mind that work on the
next iteration, presently version 005050, of the nine HIPAA-adopted X12
TR3s is already in progress.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#598 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Fri Feb 27, 2009 9:05 pm
Subject: Fw: Enhancements/Updates to NPPES effective March 7, 2009
dafeinberg
Offline Offline
Send Email Send Email
 
----- Original Message -----
Sent: Friday, February 27, 2009
Subject: Enhancements/Updates to NPPES effective March 7, 2009

On March 7, 2009, the National Plan and Provider Enumeration System (NPPES) will undergo system maintenance.  As such, neither NPPES nor the National Provider Identifier (NPI) Registry will be available on March 7, 2009. 

 

The following enhancements will be incorporated into NPPES:

 

·        The NPPES application help page text will be revised to ensure consistency  with the instructions found on the revised National Provider Identifier (NPI) Application/Update Form (CMS-10114 (11/08)).

 

·        NPPES web users will be required to change their passwords after the Enumerator has reset them.  When the Enumerator resets a user’s password, the user will be redirected to the password reset page in order to change the reset password to a password of his/her choice.  NPPES will also enforce a minimum password length of 8 characters. 

 

The following enhancements will be incorporated into the NPI Registry:

 

·        The ‘doing business as’ (DBA) search feature will be restored.

 

·        The NPI Registry will be updated daily. 

 

·        The NPI Registry will display all results in all capital letters..  This change will not affect the way information is displayed in a health care provider’s NPPES record.

 

Electronic File Interchange (EFI)

In addition, the EFI User Manual and Technical Companion Guide have been revised. The upcoming changes will not impact the EFI XML Schema. 

 

Additional Information

 

Health care providers can apply for an NPI online at https://nppes.cms.hhs.gov .  Health care providers needing assistance with applying for an NPI or updating their data in NPPES records may contact the NPI Enumerator at 1-800-465-3203 or email the request to the NPI Enumerator at CustomerService@....

 

 

-------------------------------------------------------------------------------------------------------------------------------------------------------

Note:  If you have problems accessing any hyperlink in this message, please copy and paste the URL into your Internet browser. 

Please DO NOT respond to this email. This email is a service of CMS and routed through an electronic mail server to communicate Medicare policy and operational changes and/or updates. Responses to this email are not routed to CMS personnel. Inquiries may be sent by going to (http://www.cms.hhs.gov/ContactCMS). Thank you.


#597 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Sat Feb 28, 2009 8:23 pm
Subject: NIST Releases 2 Draft Documents and Mark-up Copy of SP 800-53 Rev. 3
hitrecruiting
Offline Offline
Send Email Send Email
 
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Friday, February 27, 2009 5:33 PM
To: Multiple recipients of list
Subject: NIST Releases 2 Draft Documents and Mark-up Copy of SP 800-53 Rev.
3


NIST Computer Security Division released 2 draft publications
(Special Publication & NIST Interagency Report) today and 1 Mark-up
Copy of Draft SP --

1. Mark-up copy of Draft Special Publication (SP) 800-53 Revision 3
2. Draft Special Publication 800-81 Revision 1
3. Draft NIST Interagency Report (IR) 7517

1. Draft SP 800-53 Rev. 3: Recommended Security Controls for Federal
Information Systems and Organizations
The following document provides a line-by-line (mark-up copy)
comparison between SP 800-53, Revision 2 and Draft SP 800-53,
Revision 3. It should also be noted that the section of the
publication addressing scoping considerations for scalability, was
inadvertently omitted from the public draft and will be reinstated in
the final publication.

URL: http://csrc.nist.gov/publications/PubsDrafts.html#800-53_Rev3

******

2. Draft SP 800-81 Rev. 1: Secure Domain Name System (DNS) Deployment Guide
NIST has drafted a new version of the document "Secure Domain Name
System (DNS) Deployment Guide (SP 800-81)". This document, after a
review and comment cycle will be published as NIST SP 800-81r1. There
will be two rounds of public comments and this is our posting for the
first one. Federal agencies and private organizations as well as
individuals are invited to review the draft Guidelines and submit
comments to NIST by sending them to SecureDNS@... before March
31, 2009. Comments will be reviewed and posted on the CSRC website.
All comments will be analyzed, consolidated, and used in revising the
draft Guidelines before final publication.

Reviewers of the draft revised Guidelines should note the following
differences and additions:
    (1) Updated Recommendations for all cryptographic operations
relating to digital signing of DNS records, verification of the
signatures, Zone Transfer, Dynamic Updates, key Management and
Authenticated Denial of Existence.
    (2) The additional IETF RFC documents that have formed the basis
for the updated recommendations include: DNNSEC Operational Practices
(RFC 4641), Automated Updates for DNS Security (DNSSEC) Trust Anchors
(RFC 5011), DNS Security (DNSSEC) Hashed Authenticated Denial of
Existence (RFC 5155) and HMAC SHA TSIG Algorithm Identifiers (RFC 4635).
    (3) The FIPS standards and NIST guidelines incorporated into the
updated recommendations include: The Keyed-Hash Message
Authentication Code (HMAC) (FIPS 198-1), Digital Signature Standard
(FIPS 186-3) and Recommendations for Key Management (SP 800-57P1 & SP
800-57P3).
    (4) Illustration of Secure configuration examples using DNS
Software offering NSD, in addition to BIND.

URL: http://csrc.nist.gov/publications/PubsDrafts.html#800-81-rev1

******

3: DRAFT The Common Misuse Scoring System (CMSS): Metrics for
Software Feature Misuse Vulnerabilities
Draft NIST Interagency Report (IR) 7517, The Common Misuse Scoring
System (CMSS), is now available for public comment. This report
proposes a specification for CMSS, a set of standardized measures for
the severity of software feature misuse vulnerabilities. NISTIR 7517
also provides examples of how CMSS measures and scores would be
determined. Once CMSS is finalized, CMSS data can assist
organizations in making security decisions based on standardized,
quantitative vulnerability data.

NIST requests comments on Draft NISTIR 7517 by April 3, 2009. Please
submit comments to IR7517comments@... with "Comments IR 7517" in
the subject line.

URL: http://csrc.nist.gov/publications/PubsDrafts.html#nistir-7517

#596 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Tue Feb 17, 2009 8:38 pm
Subject: NIST Releases 2 Draft Special Publications
hitrecruiting
Offline Offline
Send Email Send Email
 
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Tuesday, February 17, 2009 1:15 PM
To: Multiple recipients of list
Subject: NIST Releases 2 Draft Special Publications


You may already have seen these 2 new drafts from Feb. 5-6 on CSRC website.
If not, please review the announcement below --

Document #1:  Draft Special Publication 800-85A-1 "PIV Card
Application and Middleware Interface Test Guidelines (SP800-73-2
compliance)"

NIST has a revised version of NIST Special Publication SP 800-85A
"PIV Card Application and Middleware Interface Test Guidelines
(SP800-73 compliance)". The revised document is titled Draft SP
800-85A-1 "PIV Card Application and Middleware Interface Test
Guidelines (SP800-73-2 compliance)" and is posted on the Computer
Security Resource Center Web site (www.csrc.nist.gov). The revisions
include the additional tests necessary to test some of the optional
features added to the PIV Data Model and Card Interface as well as
the PIV Middleware through specifications SP 800-73-2 Parts 1, 2 and
3. A short summary of the changes is available here. This document,
after a review and comment period, will be published as NIST SP
800-85A-1. Federal agencies and private organizations including test
laboratories as well as individuals are invited to review the draft
Guidelines and submit comments to NIST by sending them to
PIVtesting@... with "Comments on Public Draft SP 800-85A-1" in
the subject line. Comments should be submitted using the comment
template (Excel spreadsheet). The comment period closes at 5:00 EST
(US and Canada) on February 28, 2009. All comments will be analyzed,
consolidated, and used in revising the draft Guidelines before final
publication..

URL to this Draft document:
http://csrc.nist.gov/publications/PubsDrafts.html

--------------

Document #2: Draft Special Publication 800-53 Rev. 3 Recommended
Security Controls for Federal Information Systems and Organizations

NIST announces the release of the Initial Public Draft (IPD) of
Special Publication 800-53, Revision 3, Recommended Security Controls
for Federal Information Systems and Organizations. This is the first
major update of Special Publication 800-53 since its initial
publication in December 2005. We have received excellent feedback
from our customers during the past three years and have taken this
opportunity to provide significant improvements to the security
control catalog. In addition, the changing threat environment and
growing sophistication of cyber attacks necessitated specific changes
to the allocation of security controls and control enhancements in
the low-impact, moderate-impact, and high-impact baselines. We also
continue to work closely with the Department of Defense and the
Office of the Director of National Intelligence under the auspices of
the Committee on National Security Systems on the harmonization of
security control specifications across the federal government. And
lastly, we have added new security controls to address
organization-wide security programs and introduced the concept of a
security program plan to capture security program management
requirements for organizations. The privacy-related material,
originally scheduled to be included in Special Publication 800-53,
Revision 3, will undergo a separate public review process in the near
future and be incorporated into this publication, when completed.
Comments will be accepted until March 27, 2009. Comments should be
forwarded via email to sec-cert@....

URL to Draft SP 800-53 Rev. 3
http://csrc.nist.gov/publications/PubsDrafts.html

#595 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Wed Feb 11, 2009 1:43 pm
Subject: HHS OCR posts new Web site for health information privacy
hitrecruiting
Offline Offline
Send Email Send Email
 

 

 


From: OCR HIPAA Privacy Rule information distribution [mailto:OCR-PRIVACY-LIST@...] On Behalf Of OS OCR PrivacyList, OCR (HHS/OS)
Sent: Tuesday, February 10, 2009 5:08 PM
To: OCR-PRIVACY-LIST@...
Subject: HHS OCR posts new Web site for health information privacy

 

HHS OCR posts new website for health information privacy

 

The Department of Health and Human Services, Office for Civil Rights has posted its new Web site.  The health information privacy (HIP) pages have been extensively revised to improve organization and ease of use for consumers, covered entities and others seeking reliable advice on the HIPAA Privacy Rule and the Patient Safety Rule.

The Web site contains significant new content including

  • For Consumers pages (with new information on):
  • Medical Records
  • Employers and Health Information in the Workplace
  • Personal Representatives
  • Family Members and Friends
  • Court Orders and Subpoenas
  • Notice of Privacy Practices
  • Privacy Rule home page—rulemaking timeline 
  • Enforcement Rule home page—rulemaking timeline 
  • Emergency Preparedness home page 
  • Genetic Information Nondiscrimination Act page  
  • Special Topics home page 
  • Before you File a HIP Complaint 
  • Patient Safety Rule home page 
  • Patient Safety Statute home page 
  • Patient Safety Enforcement Activities and Results home page

You can reach the new health information privacy web pages at http://www.hhs.gov/ocr/privacy/index.html

**********************************************************************

This email is being sent to you from the OCR-Privacy-list listserv, operated by the Office for Civil Rights (OCR) in the US Department of Health and Human Services.

This is an announce-only list, a resource to distribute information about the HIPAA Privacy Rule. For additional information on a wide range of topics about the the Privacy Rule, please visit the OCR Privacy website at www.hhs.gov/ocr/hipaa/. You can also call the OCR Privacy toll-free phone line at (866) 627-7748. Information about OCR's civil rights authorities and responsibilities can be found on the OCR home page at www.hhs.gov/ocr

If you believe that a person or organization covered by the Privacy Rule (a "covered entity") violated your health information privacy rights or otherwise violated the Privacy Rule, you may file a complaint with OCR. For additional information about how to file a complaint, see the Fact Sheet "How to File a Health Information Privacy Complaint," available at http://www.hhs.gov/ocr/privacyhowtofile.htm .

To subscribe to or unsubscribe from the list serv, please go to: http://list.nih.gov/cgi-bin/wa?SUBED1=ocr-privacy-list&A;=1


#594 From: "iTech" <expediumx12n@...>
Date: Tue Feb 10, 2009 11:55 am
Subject: expEDIum Claim Browser as a Free Download
expediumx12n
Offline Offline
Send Email Send Email
 

Hello,

iTech Workshop (iTech), a Data Integration for Healthcare company announces the availability of expEDIum Claim Browser (eCB) tool that supports electronic EDI 837P claim file browsing as a free download. This utility is aimed at the healthcare market participants that use HIPAA EDI. This tool is available at http://www.itechws.com/downloads.shtml

Loken Singh

Inside Sales - Support Executive

loken@...

www.itechws.com


#593 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Wed Feb 4, 2009 4:35 pm
Subject: X12 Version 005010 and ICD-10 Final Rules Reviewed by GAO
dafeinberg
Offline Offline
Send Email Send Email
 
As part of the sixty day Congressional Review Period for major final
rules, the Government Accountability Office (GAO) recently published its
reviews of the procedural steps taken by the Department of Health and
Human Services (HHS) in preparing the final rules for updated HIPAA
transactions and code sets.  These reviews are for the final rules
published in the Federal Register on 1/16/2009.  Copies of the GAO's
reviews may be obtained at following links:
      Transactions:  X12 and NCPDP
             http://www.gao.gov/decisions/majrule/d09331r.pdf
      Code Sets:  ICD-10-CM and ICD-10-PCS
             http://www.gao.gov/decisions/majrule/d09335r.pdf

For both final rules, the GAO has determined "that HHS complied with the
applicable [procedural steps] requirements."

The GAO procedural reviews are the last required step necessary for the
updated HIPAA transactions and code sets regulations to become
effective.  If no further -- negating -- actions are taken by Congress
or the Executive Branch, these regulations will take effect on
3/17/2009 -- as published in the Federal Register.

In other words, these new regulations will now automatically go into
effect unless somebody explicitly does something to stop them in the
next six weeks.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#592 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Sat Jan 24, 2009 12:11 am
Subject: Fw: White House Stops Pending Bush Regulations for Review
dafeinberg
Offline Offline
Send Email Send Email
 
Here's a link to the actual memorandum discussed in the article I
referenced on Wednesday.

http://ombwatch.org/regs/midnightregfreezememo.pdf

Feinberg Note:  As I quickly read the memorandum, it appears there is a
small possibility the HIPAA TCS regulations effective date could be
impacted.

----- Original Message -----
From: "David A. Feinberg, C.D.P." <dafeinberg@...>
Sent: Wednesday, January 21, 2009 8:52 AM
Subject: White House Stops Pending Bush Regulations for Review

http://news.yahoo.com/s/nm/20090121/pl_nm/us_obama_regulations

Feinberg Note:  As I understand the processes, the new HIPAA TCS
regulations published last week are not "pending".

#591 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Wed Jan 21, 2009 4:51 pm
Subject: White House Stops Pending Bush Regulations for Review
dafeinberg
Offline Offline
Send Email Send Email
 
http://news.yahoo.com/s/nm/20090121/pl_nm/us_obama_regulations

Feinberg Note:  As I understand the processes, the new HIPAA TCS
regulations published last week are not "pending".

#590 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Thu Jan 15, 2009 4:22 pm
Subject: X12 Version 005010 and ICD-10 Final Rules Scheduled for Publication
dafeinberg
Offline Offline
Send Email Send Email
 
Based on today's report from the Office of the Federal Register (OFR),
Official Final Rules -- including formal Federal Regulations -- adopting
updated HIPAA transactions and code sets are scheduled for publication
tomorrow, 1/16/2009, in the Federal Register.

Based on today's OFR report, the Transactions Final Rule has a small
repeating glitch in it.  Assuming I read the 'glitched' materials
correctly, version 005010 TR3s will become mandated on the effective
date of the Final Rule ... approximately 3/16/2009, and the current
version 004010+A1 IGs will become un-mandated on 12/31/2011.  The
OFR reported Final Rule for ICD-10-CM and ICD-10-PCS shows a compliance
date of 10/01/2013.  We'll know for certain regarding these dates when
the Final Rules are formally published in the Federal Register.  I'll
send another message once links are available.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#589 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Fri Jan 16, 2009 3:33 pm
Subject: Re: Adopting HIPAA Claims Attachments Transactions Standards
dafeinberg
Offline Offline
Send Email Send Email
 
From the Final Rule adopting ICD-10-CM and ICD-10-PCS published in the
Federal Register on 1/16/2009: page 3355, column 3.
     "We have stated publicly, and reiterate once again, that we will not
     consider implementing a new HIPAA standard for claims attachment
     transactions until after the compliance date for ICD-10."
This is somewhat at odds with the statements elsewhere in the same rule
and the Final Rule for updated transactions, also published on
1/16/2009, that state,
     "We appreciate and will consider the commenters' concerns for not
     wanting to have to implement the electronic health care claims
     attachment standards at the same time as Versions 5010, D.0 and 3.0,
     and ICD-10."

The intriguing part of the above occurs with a historical reference to
the original HIPAA statute.  Section 1174(a) called for adopting of
claims attachments standards not later than 30 months after enactment of
the law.  August, 1996, plus 30 months, equals February, 1999 -- ten
years ago as I write this ... almost to the month.

                     Dave Feinberg
                     Rensis Corporation
                     206-617-1717
                     DAFeinberg@...

#588 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Fri Jan 16, 2009 3:21 pm
Subject: X12 Version 005010 and ICD-10 Final Rules Published in Federal Register
dafeinberg
Offline Offline
Send Email Send Email
 
Official Final Rules -- including formal Federal Regulations -- adopting
updated HIPAA transactions and code sets were published today,
1/16/2009, in the Federal Register.  They may be obtained at the
following links:
      Transactions:  X12 and NCPDP
             http://edocket.access.gpo.gov/2009/pdf/E9-740.pdf
      Code Sets:  ICD-10-CM and ICD-10-PCS
             http://edocket.access.gpo.gov/2009/pdf/E9-743.pdf

The initial compliance date for the updated X12 transactions (005010) is
3/17/2009 [potentially a mistake], and the sunset date for current X12
transactions (004010 and 004010A1) is 12/31/2011.
The compliance date for use of ICD-10-CM and ICD-10-PCS and sunset date
for ceasing use of ICD-9-CM volumes 1,2 and 3 is 10/01/2013.

An interesting newly added provision of the transactions rule is 45 CFR
162.925(a)(6):
     "During the period from March 17, 2009, through December 31, 2011, a
     health plan may not delay or reject a standard transaction, or
     attempt to adversely affect the other entity or the transaction, on
     the basis that it does not comply with another adopted standard for
     the same period."


Copies of X12's Type 3 Technical Reports (TR3s) incorporated by
reference into the transactions Final Rule may be obtained via the
following link:
         http://store.X12.org .

As CMS is no longer subsidizing X12 for these documents, it will cost
you directly to have them downloaded or shipped.  Note, though, that
there is a single price for a package of all nine of the adopted version
005010 TR3s, and significant discounts are available to X12 members.

The first page of an online X12 membership application, including a dues
schedule, is located at
https://www.disa.org/apps/memberservices/x12/X12MembershipSection1.cfm


A summary of the changes between the current X12 version 004010 and
004010A1 Implementation Guides and the newly adopted version 005010 TR3s
is available at
http://www.x12.org/x12org/subcommittees/X12N/N0221_WEDI-X12-V5010_file.pdf.
Webinars about the adopted X12 version 005010 TR3s can be arranged via
         http://www.x12.org/webinars/5010.cfm.
Topics covered in these webinars include:
   + the business justification for solutions included in version 005010
   + examples of how the implementation of version 005010 transactions
      addresses industry-requested requirements
   + specific answers to some of the questions from public comments to
      the Notice of Proposed Rule Making (NPRM)
   + details of changes across all affected transactions, including the
      explanatory, technical and structural modifications
   + details of how version 005010 is improved compared to version
      004010 and 004010A1
   + insight from original subject matter experts.
These webinars will be given live during February, and will be available
for on-demand playback thereafter.  Again note that X12 members receive
a discount on webinar fees.


The final step in this HIPAA transactions and code sets adoption process
is clearing the Congressional Review period on or about 3/16/2009.
After that, if Congress takes no action -- the expected outcome -- the
regulations go into effect.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#587 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Wed Jan 14, 2009 3:51 am
Subject: NIST Released 2 Draft Publications
hitrecruiting
Offline Offline
Send Email Send Email
 
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Tuesday, January 13, 2009 3:05 PM
To: Multiple recipients of list
Subject: NIST Released 2 Draft Publications


NIST Announces the release of 2 Draft documents: (1) DRAFT Special
Publication 800-122, Guide to Protecting the Confidentiality of
Personally Identifiable Information (PII) and (2) DRAFT NIST IR 7497
Draft Security Architecture Design Process for Health Information
Exchanges (HIEs)

(1)  NIST announces that draft Special Publication (SP) 800-122,
Guide to Protecting the Confidentiality of Personally Identifiable
Information (PII), is now available for public comment. SP 800-122 is
intended to assist Federal organizations in identifying PII and
determining what level of protection each instance of PII requires,
based on the potential impact of a breach of the PII's
confidentiality. The publication also suggests safeguards that may
offer appropriate protection for PII and makes recommendations
regarding PII data breach handling.

NIST requests comments on draft SP 800-122 by March 13, 2009. Please
submit comments to 800-122comments@... with "Comments SP
800-122" in the subject line.

URL to Draft SP 800-122 on Drafts page:
http://csrc.nist.gov/publications/PubsDrafts.html#800-122

(2)  NIST Interagency Report (IR) 7497, Draft Security Architecture
Design Process for Health Information Exchanges (HIEs), is intended
to provide a systematic approach to designing a technical security
architecture for the exchange of health information that leverages
common government and commercial practices and that applies them
specifically to the HIE domain. This publication assists
organizations in ensuring that data protection is adequately
addressed throughout the system development life cycle, and that
these data protection mechanisms are applied when the organization
develops technologies that enable the exchange of health information.

Please submit your comments to draft-nistir7497-comments@....
The comment period for draft NIST IR 7497 closes on Friday March 13, 2009.

URL to Draft NIST IR 7497:
http://csrc.nist.gov/publications/PubsDrafts.html#nistir-7497

#586 From: "Barbara McGowin" <barbaramcgowin@...>
Date: Wed Jan 14, 2009 2:53 am
Subject: New HIPAA Frequently Asked Questions for Family Medical History
hitrecruiting
Offline Offline
Send Email Send Email
 

 

 


From: OCR HIPAA Privacy Rule information distribution [mailto:OCR-PRIVACY-LIST@...] On Behalf Of OS OCR PrivacyList, OCR (HHS/OS)
Sent: Tuesday, January 13, 2009 5:07 PM
To: OCR-PRIVACY-LIST@...
Subject: New HIPAA Frequently Asked Questions for Family Medical History

 

Announcement

January 13, 2009

 

New HIPAA Frequently Asked Questions for Family Medical History

 

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has published new HIPAA Privacy Rule frequently asked questions (FAQs) related to family medical history.  These FAQs support the roll out of the Surgeon General’s family health history portal, “My Family Health Portrait,” a new version of the web-based tool that enables individuals to electronically record, save and email family medical information in formats that are compatible with electronic health records (EHRs).  Individuals using this portal to assemble, download and transmit family history information may have questions about privacy and how family history can be used or shared by health care providers.  The new FAQs provide answers to these questions.

 

These new HIPAA FAQs are available on the OCR Privacy Rule Web Site at http://www.hhs.gov/ocr/hipaa.  For more information on the Surgeon General’s Family History Tool, see the press release http://www.hhs.gov/news/press/2009pres/01/20090113a.html or visit https://familyhistory.hhs.gov/.

 

**********************************************************************

This email is being sent to you from the OCR-Privacy-list listserv, operated by the Office for Civil Rights (OCR) in the US Department of Health and Human Services.

This is an announce-only list, a resource to distribute information about the HIPAA Privacy Rule. For additional information on a wide range of topics about the the Privacy Rule, please visit the OCR Privacy website at www.hhs.gov/ocr/hipaa/. You can also call the OCR Privacy toll-free phone line at (866) 627-7748. Information about OCR's civil rights authorities and responsibilities can be found on the OCR home page at www.hhs.gov/ocr

If you believe that a person or organization covered by the Privacy Rule (a "covered entity") violated your health information privacy rights or otherwise violated the Privacy Rule, you may file a complaint with OCR. For additional information about how to file a complaint, see the Fact Sheet "How to File a Health Information Privacy Complaint," available at http://www.hhs.gov/ocr/privacyhowtofile.htm .

To subscribe to or unsubscribe from the list serv, please go to: http://list.nih.gov/cgi-bin/wa?SUBED1=ocr-privacy-list&A;=1


#585 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Sat Jan 10, 2009 6:29 pm
Subject: X12 Version 005010 and ICD-10 Final Rules Cleared for Publication by OMB
dafeinberg
Offline Offline
Send Email Send Email
 
From http://www.reginfo.gov/public/do/eoReviewSearch published on
1/10/2009.


AGENCY: HHS-CMS                    RIN: 0938-AM50
TITLE: Updates to Electronic Transactions (Version 5010) (CMS-0009-F)
STAGE: Final Rule
ECONOMICALLY SIGNIFICANT: Yes
RECEIVED DATE: 12/12/2008
LEGAL DEADLINE: None
COMPLETED: 01/09/2009
COMPLETED ACTION: Consistent with Change
http://www.reginfo.gov/public/do/eAgendaViewRule?ruleID=290717


AGENCY: HHS-CMS                   RIN: 0938-AN25
TITLE: Revisions to HIPAA Code Sets (CMS-0013-F)
STAGE: Final Rule
ECONOMICALLY SIGNIFICANT: Yes
RECEIVED DATE: 12/12/2008
LEGAL DEADLINE: None
COMPLETED: 01/09/2009
COMPLETED ACTION: Consistent with Change
http://www.reginfo.gov/public/do/eAgendaViewRule?ruleID=290720


Expect Final Rules publication in the Federal Register within a week or
so; although, the Government Printing Office will place the Final Rules
on public display prior.  Effective and compliance dates will be known
once the Final Rules are viewable.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#584 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Fri Jan 9, 2009 3:57 pm
Subject: X12 Version 005010 TR3s Pricing Changes
dafeinberg
Offline Offline
Send Email Send Email
 
Accredited Standards Committee X12 has posted new prices for their Type
3 Technical Reports (TR3s) ... including those proposed for adoption
under HIPAA.  The new prices include discounts for X12 members.

The new prices can be found starting at http://store.x12.org/

The X12 membership application starts at
https://www.disa.org/apps/memberservices/x12/X12MembershipSection1.cfm

Note that the Final Rule for adopting nine version 005010 TR3s as
replacement HIPAA implementation specifications is presently, 1/09/2009,
in review at the Office of Management and Budget.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

#583 From: "barbaramcgowin" <barbaramcgowin@...>
Date: Mon Jan 5, 2009 5:55 pm
Subject: NIST Releases 4 Publications
hitrecruiting
Offline Offline
Send Email Send Email
 
 
 
From: "Barbara McGowin" <barbaramcgowin@...>  [ Save Address ]
To: <Sharehipaa@yahoogroups.com>,<HIPAA-CISSP@yahoogroups.com>
Subject: RE: NIST Releases 4 Publications
Date: Sun, 14 Dec 2008 11:06:41 -0500

All of these you may find useful. But take a look at #3: Special
Publication 800-115 Technical Guide to Information Security Testing and Assessment. This may be very useful in compliance with
the HIPAA Security Rule.
Regards,
Barbara McGowin
-----Original Message-----
From: compsecpubs@... [mailto:compsecpubs@...] On Behalf Of
Patrick O'Reilly
Sent: Wednesday, October 01, 2008 1:56 PM
To: Multiple recipients of list
Subject: NIST Releases 4 Publications
NIST Releases 4 Publications:
1 Draft (Special Publication 800-82)
and
3 final Special Publications (800-73-2, 800-115, and 800-121)
#1: DRAFT Special Publication 800-82, Guide to Industrial Control Systems (ICS) Security -- The final public draft of SP 800-82 is available for public comment. It provides guidance on how to secure Industrial Control Systems (ICS), including Supervisory Control and Data Acquisition (SCADA) systems, Distributed Control Systems (DCS), and other control system configurations such as Programmable Logic Controllers (PLC), while addressing their unique performance, reliability, and safety requirements. SP 800-82 provides an overview of ICS and typical system topologies, identifies typical threats and vulnerabilities to these systems, and provides recommended security countermeasures to mitigate the associated risks. This publication is an update to the second public draft, which was released in 2007. NIST requests comments on NIST SP 800-82 by November 30, 2008. Please submit comments to 800-82comments@... with "Comments SP 800-82" in the subject line. To view this document please visit the Drafts page on CSRC.
URL to draft:
http://csrc.nist.gov/publications/PubsDrafts.html#800-82
#2: NIST is pleased to announce the release of NIST Special Publication 800-73-2, Interfaces for Personal Identity Verification. Special Publication 800-73-2 (SP 800-73-2) specifies the PIV data model, command interface, client application programming interface and references to transitional interface specifications. The four parts that comprise SP 800-73-2 supersede the single document SP 800-73-1, published in April 2006. Comments received for first and second public draft of SP 800-73-2 have been addressed as are the errata items in SP 800-73-1. The high-level technical changes in SP 800-73-2 are summarized here. The Special Publication 800-73-2 document can be found by going to the Special Publications page.
URL to SP 800-73-2
http://csrc.nist.gov/publications/PubsSPs.html#800-73_Rev2
#3: Special Publication 800-115, Technical Guide to Information Security Testing and Assessment, has been published as final. It seeks to assist organizations in planning and conducting technical information security testing and assessments, analyzing findings, and developing mitigation strategies. The publication provides practical recommendations for designing, implementing, and maintaining technical information security assessment processes and procedures. SP 800-115 provides an overview of key elements of security testing, with an emphasis on technical testing techniques, the benefits and limitations of each technique, and recommendations for their use. SP 800-115 replaces SP 800-42, Guideline on Network Security Testing, which was released in 2003.
URL to SP 800-115
http://csrc.nist.gov/publications/PubsSPs.html#SP800-115
#4: Special Publication 800-121, Guide to Bluetooth Security, has been finalized. It describes the security capabilities of technologies based on Bluetooth, which is an open standard for short-range radio frequency communication. The document gives recommendations to organizations employing Bluetooth technologies on securing them effectively. SP 800-121 supersedes the original SP 800-48, Wireless Network Security: 802.11, Bluetooth and Handheld Devices, which was released in 2002 and was replaced in July 2008 by SP 800-48 Revision 1, Guide to Securing Legacy IEEE 802.11 Wireless
Networks.
URL to SP 800-121
http://csrc.nist.gov/publications/PubsSPs.html#800-121
 

#582 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Fri Nov 21, 2008 4:07 pm
Subject: An Interesting Date Regarding Adoption of Updated HIPAA Transactions
dafeinberg
Offline Offline
Send Email Send Email
 
Today, Friday 11/21/2008, is sixty days prior to 1/20/2009:  the start
of the new Obama "Administration".  Prior to most Federal Final Rules
taking effect, Congress gives itself a sixty day Review Period to
determine whether or not they wish to disapprove any Final Rule.  {5 USC
Chapter 8} This sixty day period typically commences with the
publication of a Final Rule in the Federal Register; although, there are
some 'wrinkles' that extend the Review Period end date at the
adjournment of Congressional sessions -- such as will be occurring
shortly.

As of today, the publication of an Updated HIPAA Transactions Final Rule
hasn't happened.  Thus, barring something weird, any new Updated HIPAA
Transactions Final Rule would become effective -- i.e., modified and new
transactions adopted -- during the Obama Administration; no earlier than
mid-March 2009, even if a Final Rule is published this year.  Ditto for
any Final Rule for the ICD-10-CM and ICD-10-PCS code sets.

Note that March, 2009, effective dates do support compliance dates
contained in the Notices of Proposed Rule Making published on 8/22/2008.

Happy Thanksgiving, all.

                     Dave Feinberg
                     Rensis Corporation  [A Consulting Company]
                     206-617-1717
                     DAFeinberg@...
                     Author of  "Understanding HIPAA Communications"

P.S.    A little bit of background on the 'why' of this message can be
found at http://www.ombwatch.org/regs/PDFs/BoltenMemo050908.pdf .

                     DAF

#581 From: "David A. Feinberg, C.D.P." <DAFeinberg@...>
Date: Tue Nov 4, 2008 1:04 am
Subject: No Changes to X12 version 005010 TR3's Likely Forthcoming
dafeinberg
Offline Offline
Send Email Send Email
 
It appears that Accredited Standards Committee X12 is applying a very strict "catastrophic impediment to ... implementation" hurdle to forwarded Notice of Proposed Rule Making (NPRM) technical comments requesting changes to their version 005010 Type 3 Technical Reports (TR3's) proposed for HIPAA adoption on 8/22/2008.  [See www.regulations.gov comment ID # CMS-2008-0101-0012.1 at
 
Should requested changes to the version 005010 TR3's not be incorporated, two other mechanisms are available for requesting these and additional changes to subsequent TR3 versions.
If you plan to use the DSMO web site, do not delay any submissions.  There is an approximately 3-6 month flow time for change request approvals prior to most TR3 writing work being initiated, and several X12 workgroups are already preparing the next presently planned versions of TR3's: 005050.
 
For attendance at X12 Trimester Meetings, it would be beneficial to send advance copies of any changes you'd like discussed to the co-chairs of the applicable workgroups for placement on workgroup session agendas.  Co-chair e-mail addresses are located at
    www.x12.org -->
      Committees/Groups -->
         Subcommittees -->
            X12N-Insurance -->
               TG2-Health Care,
and agendas are typically established about a month prior to each Trimester Meeting.
 
 
Bottom line, for now at least, assume any NPRM comment-requested version 005010 TR3 changes will not be incorporated, and start the request process for these changes in version 005050 as soon as feasible to ensure they are efficaciously carried forward. 
 
Feel free to write back to me if you have any questions about the DSMO and X12 processes involved and/or their timings. 
 
                    Dave Feinberg
                    Rensis Corporation  [A Consulting Company]
                    206-617-1717
                    DAFeinberg@...
                    Author of  "Understanding HIPAA Communications"
 

Messages 581 - 610 of 641   Newest  |  < Newer  |  Older >  |  Oldest
Advanced
Add to My Yahoo!      XML What's This?

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help