THE AMERICAN LAW INSTITUTE Continuing Legal Education

Similar documents
Cyber Insurance: How to Investigate the Right Coverage for Your Company

Cyber Liability & Data Breach Insurance Claims

Cyber Security An Exercise in Predicting the Future

cyber invasions cyber risk insurance AFP Exchange

Vendor Management Challenges and Solutions for HIPAA Compliance. Jim Sandford Vice President, Coalfire

GALLAGHER CYBER LIABILITY PRACTICE. Tailored Solutions for Cyber Liability and Professional Liability

Joe Dylewski President, ATMP Solutions

Cybersecurity. Are you prepared?

RISKY BUSINESS SEMINAR CYBER LIABILITY DISCUSSION

BUSINESS ASSOCIATE AGREEMENT. Recitals

Cybersecurity: Protecting Your Business. March 11, 2015

Data Breach Cost. Risks, costs and mitigation strategies for data breaches

Implementing Electronic Medical Records (EMR): Mitigate Security Risks and Create Peace of Mind

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

Arizona Physicians Group To Pay $100,000 To Settle HIPAA Charges

Are Data Breaches a Real Concern? Protecting Your Sensitive Information. Phillips Auction House NY- 03/24/2015

October 24, Mitigating Legal and Business Risks of Cyber Breaches

Updates within Network Security and Privacy Risk Management

How to Respond When Sensitive Customer and Employee Data is Breached, Stolen or Compromised

4A Healthcare Data Security & Privacy

Cybersecurity for Nonprofits: How to Protect Your Organization's Data While Still Fulfilling Your Mission. June 25, 2015

Data Breach and Cybersecurity: What Happens If You or Your Vendor Is Hacked

Cyber Liability & Data Breach Insurance Claims

An Independent Member of Baker Tilly International

HITRUST CSF Assurance Program You Need a HITRUST CSF Assessment Now What?

Data Breach Response Planning: Laying the Right Foundation

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

Security and Privacy

Mastering Data Privacy, Social Media, & Cyber Law

Compliance, Security and Risk Management Relationship Advice. Andrew Hicks, Director Coalfire

HIPAA Cyber Security: Your Vendor is a Back Door to Your Server

Cyber Liability. Michael Cavanaugh, RPLU Vice President, Director of Production Apogee Insurance Group Ext. 7029

Please Read. Apgar & Associates, LLC apgarandassoc.com P. O. Box Portland, OR Fax

Nine Network Considerations in the New HIPAA Landscape

The HIPAA Security Rule: Cloudy Skies Ahead?

Mastering Data Privacy, Protection, & Forensics Law

Managing Cyber & Privacy Risks

GALLAGHER CYBER LIABILITY PRACTICE. Cyber Risk Exposures and Solutions

Logging In: Auditing Cybersecurity in an Unsecure World

Brief. The BakerHostetler Data Security Incident Response Report 2015

OCR UPDATE Breach Notification Rule & Business Associates (BA)

Law Firm Cyber Security & Compliance Risks

SECURETexas Health Information Privacy & Security Certification Program FAQs

Security Considerations for the Cloud

HIPAA and HITECH Compliance for Cloud Applications

Discussion on Network Security & Privacy Liability Exposures and Insurance

How to use the Alertsec Service to Achieve HIPAA Compliance for Your Organization

The HIPAA Audit Program

Cyber Liability Insurance:

3/4/2015. Scope of Problem. Data Breaches A Daily Phenomenon. Cybersecurity: Minimizing Risk & Responding to Breaches. Anthem.

JAMIE L. SHELLER SHELLER, P.C Walnut Street, Fourth Floor Philadelphia, PA (215)

Data Breach and Senior Living Communities May 29, 2015

The Onslaught of Cyber Security Threats and What that Means to You

Cybersecurity y Managing g the Risks

Jefferson Glassie, FASAE Whiteford, Taylor & Preston

InfoGard Healthcare Services InfoGard Laboratories Inc.

Executive Order 13636: The Healthcare Sector and the Cybersecurity Framework. September 23, 2014

8/3/2015. Integrating Behavioral Health and HIV Into Electronic Health Records Communities of Practice

Checklist for HIPAA/HITECH Compliance Best Practices for Healthcare Information Security

Understanding Professional Liability Insurance

Security & Privacy Strategies for Expanded Communities. Deven McGraw Partner Manatt, Phelps & Phillips LLP

Network Security & Privacy Landscape

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist.

Vendor Management Panel Discussion. Managing 3 rd Party Risk

Healthcare and IT Working Together KY HFMA Spring Institute

Health Care Data Breach Discovery Strategies for Immediate Response

NZI LIABILITY CYBER. Are you protected?

HIPAA: Understanding The Omnibus Rule and Keeping Your Business Compliant

Transcription:

1 THE AMERICAN LAW INSTITUTE Continuing Legal Education Mobile Technology, Health Care, and Data Security: Minimizing the Risks and Leveraging the Benefits June 26, 2014 Telephone Seminar/Audio Webcast Mobile Technology, Health Care, and Data Security: Minimizing the Risks and Leveraging the Benefits - Power Point By Mark Greisiger NetDiligence Gladwyne, Pennsylvania Dominic A. Paluzzi McDonald Hopkins PLC Bloomfield Hills, Michigan Vinny Sakore Verizon HIPAA Security Office & ICSA Labs Mechanicsburg, Pennsylvania Alex Ricardo Beazley Group New York, New York

2 Mobile Technology, Health Care, and Data Security: Minimizing the Risks and Leveraging the Benefits an ALI CLE program What we are NOT doing today Providing Legal Advice Informational Purposes Only You should consult with Privacy Counsel for any decisions surrounding your Incident Response Plan or Data Breach Response Methodology 2

3 Mark Greisiger Mark Greisiger leads NetDiligence a Cyber Risk Management company. For 13+ years NetDiligence has been offering unique cyber risk assessment services to organizations of all sectors. Their service supports the data risk management & compliance needs for many businesses. NetDiligence supports the loss control needs of many US and UK insurers that offer cyber liability coverage. Mr. Greisiger is also to a frequently published contributor for various insurance & risk management publications on similar topics. Dominic A. Paluzzi Dominic regularly advises clients regarding data privacy and cybersecurity measures, drafting of written information security programs and incident response plans, and responding to data security breaches involving sensitive personal information and protected health information. When a data breach occurs, Dominic acts as a breach coach, ensuring a client s compliance and minimizing their exposure. He also works with federal, state and local authorities, as well as third party vendors, throughout the breach notification process. Moreover, Dominic litigates matters involving data security and data privacy, including defending single plaintiff and class action litigation. His work in this area covers a myriad of industries, including, education, healthcare, hospitality, retail, automotive, accounting, finance, information technology, staffing services, manufacturing, professional employer organizations, fleet services, franchising, drug and pharmacy, and insurance. Dominic is a frequent speaker and writer in data privacy law and regularly conducts Incident Response Workshops for clients and their data breach risk management teams. If you suspect that your business has suffered a data breach, call our Hotline: 855-MH-DATA1 (855-643-2821).

4 Alex Ricardo Alex Ricardo joined Beazley in April 2011 and is based in Beazley's New York City office. He is responsible for assuring BBR insureds take full advantage of the professional services made available to them to reduce their risk & liability profile prior to or in the event of a privacy breach incident. Alex graduated from the Stevens Institute of Technology with a Bachelor of Engineering degree. He has been in the privacy sector for fifteen years and is a Certified Information Privacy Professional (CIPP/US). Vinny Sakore Vinny Sakore, former CTO of Opti-Script & MT Audit, has twenty years of Healthcare IT experience. At Verizon he is a senior member of the HIPAA Security Office and leads the Cloud Security program at ICSA Labs. Prior to joining Verizon he was Immersion's Vice President of Business Development and assisted clients manage incident response for data breaches. ICSA Labs is an independent division of Verizon that provides security testing and certification services. At ICSA Labs he provides leadership support for the Healthcare IT testing programs and the Mobile Security program. Vinny is an active member of HIMSS, serving on two of the national privacy and security workgroups and recently completed a three year term as an officer and board of director for the Central Pa HIMSS chapter. He frequently speaks on numerous cyber security topics including breach response, cloud security, mobile security and HIPAA Security. In 2014 he will be speaking at both the HIMSS14 and RIMS14 national events along with a number of regional conferences including Net Diligence s Cyber Risk and Privacy Forums. Vinny is a graduate of Penn State University and is credential in privacy through IAPP.

5 What We Will Cover Today & Who Will Cover It 1. quantifying risk and exposure: litigation exposure, potential costs, and statistics regarding breach frequency (Alex) 2. mobile health technology today and how EPHI is compromised (Vinny) 3. mobile security BYOD and mobile app (Vinny) 4. cloud security vendor management, due diligence, DDOS attacks (Vinny/Mark) 5. HIPAA Omnibus Final Rule's impact on breach standards, risk assessment, business associates and covered entities, as well as recent OCR resolution agreements (Dominic) 6. OCR's security guidance on mobile devices and remote access (Vinny) 7. other Legal Standards: HIPAA, HITECH, And The FTC(Dominic) 8. state standards and new initiatives broadening the definition of personally identifiable information to include medical information (Dominic) 9. unique issues for self- insured entities related to their employees (Alex) 10. what you need to know about health information exchanges (Alex, along with the entire panel) 11. practical compliance and risk management strategies for mobile applications (Vinny, Mark) 12. cyber claims and loss trends impacting the healthcare sector (Mark, Alex) Quantifying Risk And Exposure: Litigation Exposure, Potential Costs, And Statistics Regarding Breach Frequency By Alex Ricardo