40,000 small businesses at risk of fraud – Networks – SC Magazine Australia – Secure Business Intelligence

Some 40,000 small and medium-sized businesses across Australia and New Zealand are considered the highest risk victims of fraud, according to Visa.

via 40,000 small businesses at risk of fraud – Networks – SC Magazine Australia – Secure Business Intelligence.

PHR Model Privacy Notice #HHS

The PHR Model Privacy Notice is designed to be a standardized template that a web-based PHR company can use to succinctly inform consumers about its privacy and security policies.

via HealthIT.hhs.gov: PHR Model Privacy Notice.

FTC Proposes Changes To Law Protecting Kids’ Privacy Online

The Federal Trade Commission announced yesterday that it is seeking public comment on proposed changes to the Children’s Online Privacy Act, which would strengthen the law’s ability to protect children under the age of 13

via FTC Proposes Changes To Law Protecting Kids’ Privacy Online – The Consumerist.

Agency to deliver shared governance, risk compliance service

CenITex, the Victorian Government’s shared services IT agency, will adopt a new IT governance, risk and compliance (ITGRC) package to improve its information security function.

via Agency to deliver shared governance, risk compliance service.

AWS FISMA Moderate AA

Amazon Web Services LLC AWS, an Amazon.com company NASDAQ: AMZN, today announced it has received Federal Information Security Management Act FISMA Moderate Authorization and Accreditation from the U.S. General Services Administration.

via Amazon Media Room:News Release.

PCI point-to-point encryption guidelines raise new questions

The PCI Security Standards Council today is expected to issue guidelines on use of point-to-point encryption in protecting sensitive payment card data, but the narrow approach — which is focused on hardware — is raising questions.

via PCI point-to-point encryption guidelines raise new questions.

VMware’s CP&C releases free Compliance Checker tool

The Compliance Checker runs an assessment on ESX/ESXi hosts managed by vCenter

The assessment is based on a predefined subset of 29 of the vSphere 4.1 Security Hardening Guide rules and is run against the first 5 ESX/ESXi hosts found on the target vCenter

via VMware: VMware Security & Compliance: VMware’s CP&C releases another free Compliance Checker!.

Rodriguez to Lead HHS Office for Civil Rights

Health and Human Services Secretary Kathleen Sebelius has appointed Leon Rodriguez as the director of the Office for Civil Rights. Among other duties, OCR enforces the HIPAA privacy, security and breach notification rules.

via Rodriguez to Lead HHS Office for Civil Rights.

Learn how to construct a bar graph and violate HIPAA at the same time

The spreadsheet ended up on a website called Student of Fortune, which allows students to hire people to help them with their homework. It was first posted to the site on Sept. 9, 2010, as an attachment to a question about how to construct a bar graph

via Breach of info for 20K patients at Stanford underscores gaps in business associate security – FierceHealthIT.

Online ID thief sentenced to 14 years – SC Magazine US

A man who pleaded guilty on April 4 to one count of wire fraud and one count of aggravated identity theft was sentenced last week in U.S. District Court in Alexandria, Va. to 14 years in prison.

via Online ID thief sentenced to 14 years – SC Magazine US.