HN user

Kadrith

172 karma

Information Assurance/Compliance/Risk Assessment/Auditing/Mamagement type.

Personal email: Wayne@knownGood.com

Posts0
Comments114
View on HN
No posts found.

http://hipaacow.org/ is another good resource for anyone in this field. In the top nav select Resources, Documents and then the subgroup you want information for. Right now the site has Privacy & Security, EDI and Risk Toolkit.

Disclaimer: I am involved with HIPAA-COW on the Security, Risk and soon the Technical Security working groups; we release a lot of information to help people.

If the code is released with an Open Source license, haven't they already met the claim? Sure the company could be bought out, but the code can't be.

Even if they were bought out the code would still be available and someone else could provide the service and continue development. Releasing the code seems like the best guarantee possible.

From what I recall the parents assets can be used, up to a certain percentage, to determine what the child is eligible for. One way around this is to use a Roth IRA, since it allows you to take money out for college without a penalty and would not be used to determine FAFSA.

It also does not mean that CL has any obligation to provide that data to another for free. If you want the data in multiple locations, post it to those other locations.

I know, but I thought the existence of robots.txt was why Google is allowed to crawl sites. If a site disagrees with the crawling they can add a robots.txt entry and Google will honor it. It at least shows that you are giving the publisher an option.

Isn't this a difference in what DirecTV has implemented in their applications? I read the OP as asking for applications that do not function on an Android tablet or function significantly different on an Android tablet vs. an Android phone.

I had a question along those lines come up recently where I work. Someone had heard a little about the lawsuit and asked if there was a concern that Oracle was suing organizations that used Java. The person I spoke with admitted that they knew almost nothing about the issue, just that Google used Java and got sued; and since we use Java in some cases could it mean that we were open to the possibility of being sued by Oracle.

That is how all of our resumes work; HR just verifies the information and has no role in determining whether someone is appropriate...unless it is for an HR job. Someone in our department must review every resume for the initial pass before HR begins the background checks or schedules interviews. It takes longer to hire someone but we know that nobody is making decisions for our department.

"No HR department can interview people without a degree when there are so many people with degrees. A degree doesn't get you in the door, but is a minimum standard for just about any job."

Nonsense. I have never been to college and I am currently responsible for the IT Security of a mid-sized health network. Not only was I hired without a degree but I've been promoted several times.

I also have no technical certifications, at various points in the past I had some but have let them lapse. Having a piece of paper may make things easier, but in the end it comes down to whether or not you can sell yourself to the organization.

My experience has been very different however I work in a place that does care about the burden placed on people by compliance. I am also heavily involved with compliance, drafting policies and the implementation of those policies. When someone wants a new policy implemented I have a rule that they are the first ones I hold to the new policy.

One example was a change to the password complexity requirements for our organization (health care); since this was approved by senior leadership I changed the passwords for senior leadership first and did not allow any exceptions to the new policy. This ensured that the people who initiated the policy and are in a position to change the policy are the first ones impacted by it. If something was horribly wrong I would only change the policy or provide an exception if anyone who met the same criteria was also to be given the exception. If the exception is by job title or position I would require that they explicitly put that in the policy; that has never been requested though.

When there is a process to communicate issues and a culture that actually cares, compliance isn't as bad. For example we instituted a stricter change management process about a year ago.

We got people together to figure out what we thought a good balance was between the compliance needs, operational needs and the problems we were attempting to solve. As we were using the new process we gathered information from people then reviewed the entire thing at around six months. Based upon the feedback we made changes to the process, loosening somethings and tightening other parts. We have another meeting to review this in a few weeks since there have been some new proposals for how to streamline the process.

As far as management learning the rules, I tend to not have too much issue with that. If they don't follow the rules and are unwilling to comply their access to all systems will be shut off; the IT security group reports to me. :) Once people know you will go so far as to shut off their access for not cooperating it is amazing how quickly they work with you when an issue arises.

For us there is always a process to get exceptions with any policy; but the person performing the action may not be authorized to give themselves an exception arbitrarily.

Presumably the organization has already performed a risk analysis and determined that the existing compliance program is sufficient to address the risks and threats while not being too burdensome. The OP and many others may disagree, but it is not their call to arbitrarily change how things are done.

I'm in charge of IT security and the designated HIPAA Security Officer for a health network. Some of my favorite conversations will typically begin with someone saying that they will follow the rules when they believe the rules make sense.

Meteor meets NoGPL 14 years ago

I read the comment from nkoren differently and agree. With something like ClearCase or a CAD tool there is a defined licensing model. They aren't going to charge based upon each CAD file generated.

With meteor there is no knowing how the pricing will be without asking first; but nkoren's concern is that they won't know a viable business model until after significant work has gone into development. At that point if nkoren doesn't like the pricing they would have to switch to another framework.

I never got the impression that nkoren was against paying for meteor, just against taking a leap of faith on _any_ system which would require significant investment of time before finding out even a general idea of how the pricing works.

Kaiser uses Epic, so they have a system called Intraconnect; now Care Everywhere to share information. This also works between other Epic customers with Care Everywhere installed. For the non-Epic customers there is something called Care Elsewhere.

But there are a LOT of smaller practices without an EMR or that don't want to go through the work of initial integration.

I have a list in GV for people who frequently dial the wrong number. It plays a special VM telling them that they often dial the wrong number but to leave a message if this is correct and I will get back to them, eventually. I would probably use this for a similar setup.

I'm often on the other end of this; assigning "10 minute" tasks to people. What I try to do is have a common place where I will put these with the expectation that it is checked at least once per day; normally OneNote. I don't expect all of the tasks to be done each day, but I also don't want them sent into a black hole. I leave it up to the team to figure out when they can accomplish the tasks based upon when I need the work done or to provide me with feedback on feasibility.

If I have an urgent item that has to be done RIGHT NOW there may be an exception but in four years of being in this job I've only had a few of those. Those types of events are usually patient safety events where a patient's life is literally on the line and some piece of technology is acting up.

My understanding of Epic's approach, to some extent, is that they know approximately how much it will cost to support an organization. When we were going live they had reservations due to our size at the time; if we were not big enough they did not want us as a client since the cost of support would be greater than what we honestly afford.

I really like how they have structured the support concerning Forums, UGM and Good Maintenance; for an enterprise software company it is the best approach I've seen.

Not always true; for any project we do which would impact patient care there is always at least a physician involved, sometimes a nurse as well. The reason our Epic UI looks they way it does is because clinicians want it that way.

We have tried to streamline the interface, but they don't want IT telling them what is important to put on the screen. During our last upgrade we had issues because some physicians put so much on the screen that caused a problem with the program; Epic implemented a fix for us, but the physician took something we showed them and ran with it. Then they started telling others who did the same.

The end result was like the image people like to link to whenever this topic comes up; a screen full of check boxes and sliders. They like this because all of the information they want is on one screen and they can quickly go down the screen making selections. When we tried to streamline this they didn't like that there would be multiple screens to load and then they wouldn't have one way to see everything selected without a summary page which was yet another screen.

I work in IT security and user experience is one of the key things we focus on; a system that is confusing or difficult to use will be used in ways we do not expect. Making the most obvious choice the right choice reduces risk, confusion and helps ensure people do the right thing.

We can't standardize on RDP because it closes the remote display when we need someone to walk our help desk through what they are experiencing, VNC was hit or miss for features and support when we were looking at products so that wasn't used. pcAnywhere also integrates with our asset management system and help desk; both from Symantec.