The Experts below are selected from a list of 75 Experts worldwide ranked by ideXlab platform

Burke T Ward - One of the best experts on this subject based on the ideXlab platform.

  • cyberliability is the chief Privacy Officer the solution
    European Conference on Information Systems, 2001
    Co-Authors: Janice C Sipior, Burke T Ward
    Abstract:

    The primary responsibility of the Chief Privacy Officer (CPO) is to protect online consumer Privacy by developing an organization’s Privacy policy and ensuring compliance with Privacy laws and regulations. However, the explosive growth of internet use for business has brought about an escalation of concerns including reduced consumer confidence in internet-related business activities, risk of financial loss, and legal liability from sources categorized as external and internal to the organization. Does the new CPO position provide adequate consideration of the increasing risks? This paper discusses the far-reaching types of misconduct and risks organizations face. The paper concludes by recommending an expanded role for the CPO. In addition to overseeing internet Privacy issues, the new role of Chief Privacy and Integrity Officer (CPIO) would encompass internet integrity. This entails formulating or reformulating an expressed internet use policy, undertaking on-going training and other means to maintain awareness of issues, monitoring internal sources, implementing defenses against external sources, and securing adequate liability insurance. The effectiveness of this new role, in overseeing these responsibilities, would be determined by assessing current operations, implementing proactive measures to reduce potential misuse, and continuously keeping abreast of technological advances, legislative and regulatory initiatives, and new areas of vulnerability.

J Butker - One of the best experts on this subject based on the ideXlab platform.

  • we d 230a 01 panel hipaa compliance and the medical physicist
    Medical Physics, 2006
    Co-Authors: T Faris, T Hoffman, M Moran, J Butker
    Abstract:

    The Health Insurance Portability and Accountability Act of 1996 (HIPAA) made sweeping changes in the ways in which information regarding individuals' health care must be stored and transmitted electronically. Most AAPM members will have some familiarity with the resulting changes to policy and procedures implemented by health care providers and hospitals. The roll‐out of Rules developed by the Department of Health and Human Services (HHS) in response to the Act is now approaching completion. With the dust beginning to settle it is a good time to review what is and is not required under the HIPAA umbrella. The intent of the Act is laudable. It contains provisions to safeguard an individual's access to their own health care information and some degree of control over its use (“Privacy”), provisions mandating standardization of electronic information exchange for health information in order to streamline transmittal of information between health care entities (“Electronic Data Interchange”), and provisions requiring that covered entities take certain measures to safeguard individuals' information against unintended exposure (“Security”). Unfortunately, as is often the case with sweeping Federal regulation, there is a great deal of misinformation and confusion in the marketplace about the Rules and their implications. This arises partly because, while most of the requirements are clear, the detailed mechanisms for compliance must be developed and implemented locally. This is a situation quite analogous to radioactive materials licensing, with which we are all familiar. Often one is unsure of one's degree of compliance until one is actually inspected, a very uncomfortable place to be when there are both fines and bad publicity at stake. Uncertainty creates ample opportunity for unscrupulous consultants to prey on the anxiety of health care administrators by recommending excessive or misdirected “compliance” measures, thus compounding an already difficult transition. We have all seen this dynamic in action. Another unfortunate outcome of the poorly‐informed implementation of layers of unbending bureaucracy in the name of compliance is that sometimes restrictions are imposed locally on information flow which are ultimately against the best interest of the patient. For instance, an absolute local prohibition on releasing patient‐specific treatment planninginformation may be directly in conflict with a Medical Physicist's need to send problematic data to a vendor to obtain timely resolution of a software anomaly. The bulk of our attention in this session will be directed to clarifying the impact of the Rules on the practicing Medical Physicist. The question is not easily answered as the impact on a given Medical Physicist depends very much on the situation in which the Medical Physicist operates. We have in common that many of us act as de factoInformation System managers in our departments and as such have a certain degree of practical responsibility for monitoring access to patient‐specific information. The degree to which we are formally responsible for compliance may vary greatly, though, depending on the specifics of our contractual relationship to the hospital or other entity for which we are performing services. It is in the Medical Physicist's interest to be clear regarding both the responsibilities and the restrictions on practice that might be included in any agreements regarding HIPAA compliance that they might be asked to sign as a condition of employment. A good working knowledge of the basics of the Act and the Rules is a useful starting point. We are fortunate indeed to have four expert Panelists representing four different perspectives on these questions. They are respectively (in order of their presentations) a member of the American College of Radiology's legal office, the Chief Privacy Officer for a major vendor of Radiation Oncologyinformation management systems, the Local Security Coordinator for a mid‐sized Regional Hospital, and a Senior Analyst with the Department of Health and Human Service's Office of Civil Rights (responsible for enforcement of the Rules). The goals of this Panel are to: 1. Briefly review the scope, structure and timeline of the Act and subsequently developed Rules, and introduce some of the specific jargon of HIPAA. 2. Clarify to whom the Rules apply and the chain of responsibility for compliance. 3. Discuss the specific impact on Medical Physicists of HIPAA and the local implementation of compliance programs. 4. Dispel some common myths about the requirements imposed by HIPAA and, conversely, highlight compliance issues that may be less widely appreciated. 5. Suggest some proactive strategies that Medical Physicists can employ to prevent conflicts with local compliance policy.

Michael Waidner - One of the best experts on this subject based on the ideXlab platform.

  • platform for enterprise Privacy practices Privacy enabled management of customer data
    Lecture Notes in Computer Science, 2003
    Co-Authors: Günter Karjoth, Matthias Schunter, Michael Waidner
    Abstract:

    Enterprises collect a large amount of personal data about their customers. Even though enterprises promise Privacy to their customers using Privacy statements or P3P, there is no methodology to enforce these promises throughout and across multiple enterprises. This article describes the Platform for Enterprise Privacy Practices (E-P3P), which defines technology for Privacy-enabled management and exchange of customer data. Its comprehensive Privacy-specific access control language expresses restrictions on the access to personal data, possibly shared between multiple enterprises. E-P3P separates the enterprise-specific deployment policy from the Privacy policy that covers the complete life cycle of collected data. E-P3P introduces a viable separation of duty between the three administrators of a Privacy system: The Privacy Officer designs and deploys Privacy policies, the security Officer designs access control policies, and the customers can give consent while selecting opt-in and opt-out choices.

Günter Karjoth - One of the best experts on this subject based on the ideXlab platform.

  • platform for enterprise Privacy practices Privacy enabled management of customer data
    Lecture Notes in Computer Science, 2003
    Co-Authors: Günter Karjoth, Matthias Schunter, Michael Waidner
    Abstract:

    Enterprises collect a large amount of personal data about their customers. Even though enterprises promise Privacy to their customers using Privacy statements or P3P, there is no methodology to enforce these promises throughout and across multiple enterprises. This article describes the Platform for Enterprise Privacy Practices (E-P3P), which defines technology for Privacy-enabled management and exchange of customer data. Its comprehensive Privacy-specific access control language expresses restrictions on the access to personal data, possibly shared between multiple enterprises. E-P3P separates the enterprise-specific deployment policy from the Privacy policy that covers the complete life cycle of collected data. E-P3P introduces a viable separation of duty between the three administrators of a Privacy system: The Privacy Officer designs and deploys Privacy policies, the security Officer designs access control policies, and the customers can give consent while selecting opt-in and opt-out choices.

  • e p3p Privacy policies and Privacy authorization
    Workshop on Privacy in the Electronic Society, 2002
    Co-Authors: Paul Ashley, Günter Karjoth, Satoshi Hada, Matthias Schunter
    Abstract:

    Enterprises collect large amounts of personal data from their customers. To ease Privacy concerns, enterprises publish Privacy statements that outline how data is used and shared. The Platform for Enterprise Privacy Practices (E-P3P) defines a fine-grained Privacy policy model. A Chief Privacy Officer can use E-P3P to formalize the desired enterprise-internal handling of collected data. A particular data user is then allowed to use certain collected data for a given purpose if and only if the E-P3P authorization engine allows this request based on the applicable E-P3P policy. By enforcing such formalized Privacy practices, E-P3P enables enterprises to keep their promises and prevent accidental Privacy violations.

Janice C Sipior - One of the best experts on this subject based on the ideXlab platform.

  • cyberliability is the chief Privacy Officer the solution
    European Conference on Information Systems, 2001
    Co-Authors: Janice C Sipior, Burke T Ward
    Abstract:

    The primary responsibility of the Chief Privacy Officer (CPO) is to protect online consumer Privacy by developing an organization’s Privacy policy and ensuring compliance with Privacy laws and regulations. However, the explosive growth of internet use for business has brought about an escalation of concerns including reduced consumer confidence in internet-related business activities, risk of financial loss, and legal liability from sources categorized as external and internal to the organization. Does the new CPO position provide adequate consideration of the increasing risks? This paper discusses the far-reaching types of misconduct and risks organizations face. The paper concludes by recommending an expanded role for the CPO. In addition to overseeing internet Privacy issues, the new role of Chief Privacy and Integrity Officer (CPIO) would encompass internet integrity. This entails formulating or reformulating an expressed internet use policy, undertaking on-going training and other means to maintain awareness of issues, monitoring internal sources, implementing defenses against external sources, and securing adequate liability insurance. The effectiveness of this new role, in overseeing these responsibilities, would be determined by assessing current operations, implementing proactive measures to reduce potential misuse, and continuously keeping abreast of technological advances, legislative and regulatory initiatives, and new areas of vulnerability.