<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Law Blog 2.0 &#187; CMS</title>
	<atom:link href="http://law2point0.com/wordpress/topics/agencies/cms-agencies/feed/" rel="self" type="application/rss+xml" />
	<link>http://law2point0.com/wordpress</link>
	<description>This blog covers privacy, security, health information technology and e-discovery related topics. The primary goal of this blog is to raise public awareness of legal issues pertaining to the use of law and technology.</description>
	<lastBuildDate>Sat, 12 Jun 2010 02:39:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Is Truly De-identified Data an Impossibility?</title>
		<link>http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/</link>
		<comments>http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/#comments</comments>
		<pubDate>Fri, 11 Sep 2009 02:06:55 +0000</pubDate>
		<dc:creator>Robert Hudock</dc:creator>
				<category><![CDATA[CMS]]></category>
		<category><![CDATA[Computer Security Law -- Federal]]></category>
		<category><![CDATA[Deidentified Health Information]]></category>
		<category><![CDATA[HIPAA Privacy]]></category>
		<category><![CDATA[Health and Humans Services (HHS)]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Individually identifiable health information]]></category>
		<category><![CDATA[Law and Technology]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Safe Harbor Method]]></category>
		<category><![CDATA[unsecured protected health information]]></category>
		<category><![CDATA[adversary]]></category>
		<category><![CDATA[auxiliary information]]></category>
		<category><![CDATA[census data]]></category>
		<category><![CDATA[cyber harrasment]]></category>
		<category><![CDATA[cyber stalking]]></category>
		<category><![CDATA[data fingerprint]]></category>
		<category><![CDATA[de-identified]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[identify]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[re0identified]]></category>

		<guid isPermaLink="false">http://law2point0.com/wordpress/?p=1100</guid>
		<description><![CDATA[Social networking sites, efficient search tools (bing, dogpile, google, yahoo), blogs, cookies, mailing lists, message boards, active x controls/ embedded java script on websites and other databases make it easy to identify that new business prospect or easily cross-reference materials from multiple sources to yield unique insights into a matter of interest.  However, these online repositories of data are making it much more difficult to maintain the anonymity of those whose confidential information has been de-identified.  De-identified data has many useful purposes; the data can be used in its aggregate for tracking disease, flu outbreaks, tax purposes, etc.  There is a darker use of these many data sources, where those in our society that are ethically challenged use these data sources for socially unproductive purposes.  [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_1101" class="wp-caption alignleft" style="width: 310px"><a href="http://law2point0.com/wordpress/wp-content/uploads/2009/09/bigstockphoto_Targeting_Individual_-_Magnify_5243958.jpg"  ><img class="size-medium wp-image-1101"  src="http://law2point0.com/wordpress/wp-content/uploads/2009/09/bigstockphoto_Targeting_Individual_-_Magnify_5243958-300x285.jpg" alt="De-identification of Data" width="300" height="285" /></a><p class="wp-caption-text">De-identification of Data</p></div>
<p>Social networking sites, efficient search tools (bing, dogpile, google, yahoo), blogs, cookies, mailing lists, message boards, active x controls/ embedded java script on websites and other databases make it easy to identify that new business prospect or easily cross-reference materials from multiple sources to yield unique insights into a matter of interest.  However, these online repositories of data are making it much more difficult to maintain the anonymity of those whose confidential information has been de-identified.  De-identified data has many useful purposes; the data can be used in its aggregate for tracking disease, flu outbreaks, tax purposes, etc<span style="text-decoration: line-through;">.</span>.  There is a darker use of these many data sources, where those in our society that are ethically challenged use these data sources for socially unproductive purposes.  For example cyber-stalking and cyber-harassment are now serious problems for both companies and individuals – if you ever tried to stop such individuals you will note the absence of a well developed corpus of law in these areas.</p>
<p>De-identified Information is information that does not allow an individual to be identified because specified identifiers have been removed.  Scientists have demonstrated they can often “reidentify” or “de-anonymize” individuals hidden in anonymized data. <em>See </em>Ohm, Paul, <span style="text-decoration: underline;">Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization</span> (August 13, 2009). University of Colorado Law Legal Studies Research Paper No. 09-12. Available at SSRN: <a target="_blank" href="http://ssrn.com/abstract=1450006"  >http://ssrn.com/abstract=1450006</a>; <em>see also </em>Cassa, Christopher A; Wieland, Shannon C; and Mandl, Kenneth D. <em> </em><span style="text-decoration: underline;">Re-identification of home addresses from spatial locations anonymized by Gaussian skew</span>, International Journal of Health Geographics (August 2008) (available at <a target="_blank" href="http://www.ij-healthgeographics.com/content/pdf/1476-072X-7-45.pdf"  >http://www.ij-healthgeographics.com/content/pdf/1476-072X-7-45.pdf</a>)( finding that multiple de-identified versions of the same data set, each anonymized using a method known as nondeterministic Gaussian skew, can be used to ascertain original geographic locations).</p>
<p>The fundamental flaw with anonymizing data methodologies relates to an adversary being able to find a unique data fingerprint (e.g. date of birth, zip code, and gender), and link that data to auxiliary information or outside information.  A potential adversary can use resources such as the web (Google), public records, blogs, social networks, Facebook, etc; the issue is particularly troublesome when multiple organizations independently release anonymized data about the same or similar populations.  The ultimate balance comes in trying to de-identify data sufficient to withstand inspection by a potential adversary, while also remaining useful for public health, or other similar needs.</p>
<p>De-identification of health information on the one hand is essential, but also can be used to embarrass, extort, or otherwise annoy someone whose information has been disclosed.  With respect to Protected Health Information (PHI), the HIPAA Privacy Rule permits covered entities to release data that have been de-identified without obtaining an authorization and without further restrictions upon use or disclosure because de-identified data is not PHI and, therefore, not subject to the Privacy Rule.  Generally a covered entity can de-identify PHI in one of two ways.  The first way, the &#8220;<strong>safe-harbor</strong>&#8221; method, is to remove all 18 identifiers enumerated at section <strong>164.514(b)(2)</strong> of the regulations.  Data that are stripped of these 18 identifiers are regarded as de-identified, unless the covered entity has actual knowledge that it would be possible to use the remaining information alone or in combination with other information to identify the subject.  However copious amounts of auxiliary information that is publically available on the Internet may render HIPAA safe-harbor protection impossible.  On the other hand the “actual knowledge” requirement may allow for data that could be readily re-identified by a hacker (super user) (i.e. associating a person with the medical or other confidential data), while the covered entity “reasonably” believes the data are de-identified.</p>
<p>The 18 identifiers are:</p>
<p>a)                  Names;</p>
<p>b)                  Geographic subdivisions smaller than a state;</p>
<p>c)                   All elements of dates (except year) related to an individual (including dates of admission, discharge, birth, death and, for individuals over 89 years old, the year of birth must not be used);</p>
<p>d)                  Telephone numbers;</p>
<p>e)                  FAX numbers;</p>
<p>f)                   Electronic mail addresses;</p>
<p>g)                  Social Security numbers;</p>
<p>h)                  Medical record numbers;</p>
<p>i)                    Health plan beneficiary numbers;</p>
<p>j)                    Account numbers;</p>
<p>k)                  Certificate/license numbers;</p>
<p>l)                    Vehicle identifiers and serial numbers including license plates;</p>
<p>m)                Device identifiers and serial numbers;</p>
<p>n)                  Web URLs;</p>
<p>o)                  Internet protocol addresses (IP);</p>
<p>p)                  Biometric identifiers (including finger and voice prints);</p>
<p>q)                  Full face photos and comparable images; and</p>
<p>r)                   Any unique identifying number, characteristic</p>
<p>The second method to de-identify data is to have a qualified statistician determine, using generally accepted statistical and scientific principles and methods, that the risk is <strong>very small </strong>that the information could be used, alone or in combination with other reasonably available information, be used to identify the subject of the information.  The qualified statistician must document the methods and results of the analysis that justify such a determination. (<strong>See 67 Fed, Reg. 53233 (August 14, 2002</strong>.))</p>
<p>As is typically the case &#8212; if some method is built into the system to allow for re-identification, then the covered entity may not (1) use or disclose the code or other means of record identification for any purposes other than as a re-identification code for the de-identified data, and (2) disclose its method of re-identifying the information.  In essence the method and key (the code) almost become an encryption method, but like with encryption when the key is compromised the data are compromised.</p>
<p>One study using 1990 census data showed that 87% (216 million of 248 million) of the United States population reported characteristics that made them uniquely identifiable using only three pieces of data:  5-digit ZIP, gender, date of birth.  Fifty-three percent of the U.S. population could be uniquely identified using only gender, location (city, town, or municipality), and date of birth.  At the county level approximately 18% of the U.S. population could be uniquely identified.  L. Sweeney. <span style="text-decoration: underline;">Uniqueness of Simple Demographics in the U.S. Population</span>, LIDAP-WP4. Carnegie Mellon University, Laboratory for International Data Privacy, Pittsburgh, PA: 2000 (available at http://privacy.cs.cmu.edu/dataprivacy/papers/LIDAP-WP4abstract.html)</p>
<p>Interesting the older the population the easier (the more likely) an individual can be uniquely identified.  Accordingly greater care must be taken with the medical data of elderly populations.  Philippe Golle, <span style="text-decoration: underline;">Revisiting the Uniqueness of Simple Demographics in the US Population</span> (Palo Alto Research Center October 30, 2006)(available at <a target="_blank" href="http://www.truststc.org/wise/articles2009/articleM3.pdf"  >http://www.truststc.org/wise/articles2009/articleM3.pdf</a>).  Additional research has found that when multiple de-identified data sets are made from overlapping data sets re-identification of data becomes progressively easier.  Accordingly even where extremely large geographical areas are used to aggregate data for population studies this information may still be de-identified.</p>
<p>Unlike de-identified data, a limited data set is even easier to re-identify (albeit there are significant legal restrictions on the use of this information).  A limited data set is one that excludes the direct identifiers in <strong>164.514(e)(2)</strong>. Unlike a de-identified data set, a limited data set is PHI because it may include dates, city, state, and ZIP codes, and other unique identifying codes or characteristics not listed as direct identifiers.  A limited data set may be used or disclosed, without Authorization, for research, public health, or health care operations purposes, in accordance with section <strong>164.512(e)</strong>, only if the covered entity and limited data set recipient enter into a data use agreement. However, if the use or disclosure could be made under another provision of the Privacy Rule, such as for public health purposes in accordance with section <strong>164.512(b)</strong>, such agreement is not required.</p>
<p>&#8220;Value-added&#8221; de-identification that replaces personal health information with tags that retain temporal sequences and the georgraphic context simply may not work in a networked world.  Covered entities, business associates and others who aggregate and de-identify data sets may need to start limiting the downstream rights of licensees’ of de-identified data, and conduct some type of quality assurance proccess of their de-identification techniques.  What works today to de-identify data may not work in a year however your data will likely still be available somewhere on the Internet.  However, simply removing all personal health information may negate the value of the data.</p>
<p>Other Resources:</p>
<p>Federal Committee on Statistical Methodology, Office of Management and Budge, <span style="text-decoration: underline;">Statistical Policy Working Paper 22 (Revised 2005)- Report on Statistical Disclosure Limitation Methodology</span> (available at <a target="_blank" href="http://www.fcsm.gov/working-papers/SPWP22_rev.pdf"  >http://www.fcsm.gov/working-papers/SPWP22_rev.pdf</a>).</p>
<p>The <a href="http://mailview.custombriefings.com/mailview.aspx?m=2009101901ahla&amp;r=4205154-a9db&amp;l=018-f82&amp;t=c"  style="color: #0e4d96; text-decoration: underline;"  target="_blank"><span style="text-decoration: underline;">New York Times</span></a> reported in article entitled <span style="text-decoration: underline;">When 2+2 Equals a Privacy Question</span> &#8220;Some healthcare concerns say they have been able to offer study data to researchers stripped of specific personal details like your name, phone number, and email address,&#8221; but &#8220;in some cases researchers may be able to re-identify you by correlating anonymous information with the digital trail that you&#8217;ve left on blogs, chat rooms and Twitter.&#8221; (see <a href="http://www.nytimes.com/2009/10/18/business/18stream.html" rel="nofollow"    target="_blank">http://www.nytimes.com/2009/10/18/business/18stream.html</a>)<!-- pingbacker_start --><br />
<h4>Related Blogs</h4>
<ul class='pc_pingback'>
<li><a target="_blank" href="http://www.infrastructurist.com/2010/03/18/green-ing-the-worlds-data-a-qa-with-ibms-vp-of-energy-and-environment/"  >Green-ing the World&#8217;s Data: A Q&amp;A With IBM&#8217;s VP of Energy and Environment &raquo; INFRASTRUCTURIST</a></li>
<li><a target="_blank" href="http://www.balloon-juice.com/2010/03/17/c-span-gold/"  >Balloon Juice  &raquo; Blog Archive   &raquo; C-Span Gold</a></li>
<li><a target="_blank" href="http://oklo.org/2010/03/17/inside-information/"  >systemic &raquo; Inside Information</a></li>
<li><a target="_blank" href="http://blogza.in.th/2010/03/18/c-span-launches-free-searchable-online-video-library/"  >C-SPAN Launches Free Searchable Online Video Library | Blogza.in.th</a></li>
<li><a target="_blank" href="http://www.yankodesign.com/2010/03/17/dare-they-sell-you-stale-veggies-now/"  >Fresh Code – Barcode For Freshness Indication by Sisi Yuan, Yiwu Qiu, Lei Zhao, Qiulei Huang, Lijun Zhang &amp; Weihang Shu &raquo; Yanko Design</a></li>
</ul>
<p><!-- pingbacker_end --></p>
<div id="spreadx">&nbsp;<a target="_blank" href="http://digg.com/submit?phase=2&url=http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/digg.gif" alt="Digg" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://www.facebook.com/share.php?u=http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/facebook.gif" alt="Facebook" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://www.stumbleupon.com/submit?url=http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/&title=Is+Truly+De-identified+Data+an+Impossibility%3F"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/stumble.gif" alt="StumbleUpon" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://technorati.com/faves?add=http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/technorati.gif" alt="Technorati" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://del.icio.us/post?url=http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/&title=Is+Truly+De-identified+Data+an+Impossibility%3F"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/delicious.gif" alt="Deli.cio.us" border="0" /></a>&nbsp;</div><p><a href="http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/" rel="bookmark">Is Truly De-identified Data an Impossibility?</a> originally appeared on <a href="http://law2point0.com/wordpress">Law Blog 2.0</a> on September 11, 2009.</p>
]]></content:encoded>
			<wfw:commentRss>http://law2point0.com/wordpress/2009/09/11/is-truly-de-identified-data-an-impossibility/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HHS Tranfers Enforcement of the HIPAA Security Rule to OCR (Office of Civil Rights)</title>
		<link>http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/</link>
		<comments>http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 05:56:56 +0000</pubDate>
		<dc:creator>Robert Hudock</dc:creator>
				<category><![CDATA[CMS]]></category>
		<category><![CDATA[Enforcement]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Health and Humans Services (HHS)]]></category>
		<category><![CDATA[Office of Civil Rights]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[OCR]]></category>
		<category><![CDATA[Poor Enforcement]]></category>

		<guid isPermaLink="false">http://law2point0.com/wordpress/?p=986</guid>
		<description><![CDATA[It appears HHS has taken this critique to heart.  HHS recently released notice of an important shift in the internal responsibility/delegation of authority for the monitoring and enforcement of the HIPAA Security Rule (and all additional health IT-related security responsibilities, under ARRA).  Previously responsibility for administering (interpretation, education, guidance, FAQs, etc), monitoring and enforcing the HIPAA Security Rule was a CMS responsibility (specifically, the CMS Office of E-Standards and Services or CMS/OESS).  The administration, monitoring and enforcement of the HIPAA Privacy Rule fell under the Office for Civil Rights [...]]]></description>
			<content:encoded><![CDATA[<p><div id="attachment_921" class="wp-caption alignleft" style="width: 160px"><a href="http://law2point0.com/wordpress/wp-content/uploads/2009/07/bigstockphoto_Analyzing_The_Laptop_4595739.jpg"  ><img class="size-thumbnail wp-image-921"  src="http://law2point0.com/wordpress/wp-content/uploads/2009/07/bigstockphoto_Analyzing_The_Laptop_4595739-150x150.jpg" alt="HIPAA Enforcement" width="150" height="150" /></a><p class="wp-caption-text">HIPAA Enforcement</p></div><br />
On October27, 2008 OCR issued a final report assessing CMS’s enforcement of the HIPAA Security Rule, entitled Nationwide Review of the Centers for Medicate Medicaid Services Health Insurance Portability and Accountability Act of 1996 Oversight (avaliable at </span><span style="text-decoration: underline;"><a href="http://law2point0.com/wordpress/wp-content/uploads/2009/08/CriticalOCR.pdf"    target="_blank">CriticalOCR</a>)</span> concluded that –</p>
<blockquote><p>CMS had taken limited actions to ensure that covered entities adequately implement the HIPAA Security Rule. These actions had not provided effective oversight or encouraged enforcement of the HIPAA Security Rule by covered entities. Although authorized to do so by Federal, regulations as of February 16,2006, CMS had not conducted any HIPAA Security Rule compliance reviews of covered entities. To fulfill its oversight responsibilities, CMS relied on complaints to identify any noncompliant covered entities that it might investigate. As a result, CMS had no effective mechanism to ensure that covered entities were complying with the HIPAA Security Rule or that ePHI was being adequately protected.</p></blockquote>
<p>It appears HHS has taken this critique to heart.  HHS recently released notice of an important shift in the internal responsibility/delegation of authority for the monitoring and enforcement of the HIPAA Security Rule (and all additional health IT-related security responsibilities, under ARRA).  Previously responsibility for administering (interpretation, education, guidance, FAQs, etc), monitoring and enforcing the HIPAA Security Rule was a CMS responsibility (specifically, the CMS Office of E-Standards and Services or CMS/OESS).  The administration, monitoring and enforcement of the HIPAA Privacy Rule fell under the Office for Civil Rights (OCR).</p>
<p>As of July 27, 2009 CMS no longer will handle enforcement of the HIPAA Security Rule.  HHS has made the decision to transfer the responsibility to OCR, which will now have the administrative and enforcement authority for both the HIPAA Privacy and HIPAA Security Rules, in addition to all the new ARRA provision on privacy and security (covering security of EHRs).  The Notice will be officially published August 4, 2009 in the Federal Register. (http://www.federalregister.gov/OFRUpload/OFRData/2009-18561_PI.pdf)</p>
<p>Over the past few years since the enactment of both HIPAA Rules, OCR and CMS have worked together on the administration and enforcement of the two rules.  According to their accounting of complaints and cases brought forward, the majority included both Privacy and a Security component.  In addition, the ARRA will result in increased security and enforcement of personal health information on EHRs, it seems HHS thought it would be the right time to make this transition and have a single office within the agency handle both related areas.</p>
<p>It is expected that people will be able to continue filing complaints through the same online system and that during a transition period, CMS will continue to work and now assist OCR in administering the Security enforcement responsibilities, as well as the administration of the Rule.  Increased enforcement is extremely likely.</p>
<div id="spreadx">&nbsp;<a target="_blank" href="http://digg.com/submit?phase=2&url=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/digg.gif" alt="Digg" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://www.facebook.com/share.php?u=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/facebook.gif" alt="Facebook" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://www.stumbleupon.com/submit?url=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/&title=HHS+Tranfers+Enforcement+of+the+HIPAA+Security+Rule+to+OCR+%28Office+of+Civil+Rights%29"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/stumble.gif" alt="StumbleUpon" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://technorati.com/faves?add=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/technorati.gif" alt="Technorati" border="0" /></a>&nbsp;&nbsp;<a target="_blank" href="http://del.icio.us/post?url=http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/&title=HHS+Tranfers+Enforcement+of+the+HIPAA+Security+Rule+to+OCR+%28Office+of+Civil+Rights%29"  target="_new"><img src="http://law2point0.com/wordpress/wp-content/plugins/spreadx/images/delicious.gif" alt="Deli.cio.us" border="0" /></a>&nbsp;</div><p><a href="http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/" rel="bookmark">HHS Tranfers Enforcement of the HIPAA Security Rule to OCR (Office of Civil Rights)</a> originally appeared on <a href="http://law2point0.com/wordpress">Law Blog 2.0</a> on August 5, 2009.</p>
]]></content:encoded>
			<wfw:commentRss>http://law2point0.com/wordpress/2009/08/05/hhs-tranfer-of-enforcement-of-the-hipaa-security-rule-to-ocr-officr-of-civil-rights_/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
