<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Disruptive Knowledge &#124; Jordan Lawrence &#187; Jordan Lawrence</title>
	<atom:link href="http://www.disruptiveknowledge.com/category/jordan-lawrence/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.disruptiveknowledge.com</link>
	<description>A resource for information about hold management, records management and information management policies and news</description>
	<lastBuildDate>Tue, 29 Jun 2010 18:16:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Analyze Your Risks</title>
		<link>http://www.disruptiveknowledge.com/2010/06/analyze-your-risks/</link>
		<comments>http://www.disruptiveknowledge.com/2010/06/analyze-your-risks/#comments</comments>
		<pubDate>Tue, 29 Jun 2010 13:30:54 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[confidential information]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=383</guid>
		<description><![CDATA[The Federal Government has been vigorously enforcing the HIPAA Security Rule.  Recently they released draft guidance regarding the risk analysis requirements in the HIPAA Security Rule. 
The guidelines call for identifying where electronic protected health information is stored, received, maintained or transmitted.  The risk analysis process should be periodically reviewed and updated. 
With GRIPTM Privacy Management Services creating and maintaining a Personal [...]]]></description>
			<content:encoded><![CDATA[<p>The Federal Government has been vigorously enforcing the HIPAA Security Rule.  Recently they released <a href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/securityrule/radraftguidance.pdf" target="_blank">draft guidance regarding the risk analysis requirements </a>in the HIPAA Security Rule. </p>
<p>The guidelines call for identifying where electronic protected health information is stored, received, maintained or transmitted.  The risk analysis process should be periodically reviewed and updated. </p>
<p>With <a href="http://www.jordanlawrence.com/products/privacymanagement/" target="_blank">GRIP<sup>TM</sup> Privacy Management Services </a>creating and maintaining a Personal Data Inventory has never been easier or more accurate.  In just 30 days, an inventory of where all your structured and unstructured data containing all privacy related information can be developed .  GRIP<sup>TM </sup>provides detailed datamaps and reports showing what departments, media, applications, vendors and record types that contain personally identifiable information (PII). </p>
<p><a href="http://www.jordanlawrence.com/products/privacymanagement/" target="_blank">Privacy Management Services</a> leverages automation, benchmarking and best practice standards to automatically identify and highlight areas of immediate concern.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/06/analyze-your-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are You Identifying All The Players In Your Litigation Hold Notices?</title>
		<link>http://www.disruptiveknowledge.com/2010/06/are-you-identifying-all-the-players-in-your-litigation-hold-notices/</link>
		<comments>http://www.disruptiveknowledge.com/2010/06/are-you-identifying-all-the-players-in-your-litigation-hold-notices/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 13:47:34 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[E-discovery]]></category>
		<category><![CDATA[Hold Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[legally-defensible programs]]></category>
		<category><![CDATA[litigation hold]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=337</guid>
		<description><![CDATA[Judge Shira Scheindlin has entered an order amending her recent opinion in Pension Comm. Univ. of Montreal Pension Plan v. Bank of Am. Secs., LLC.  The amended opinion cites negligence for failure to “obtain records from all those employees who had any involvement with the issues raised in the litigations or anticipated litigation, as opposed to [...]]]></description>
			<content:encoded><![CDATA[<p>Judge Shira Scheindlin has entered an order amending her recent opinion in <em><a href="http://www.gibsondunn.com/publications/Documents/PensionCommvBofAmSec05Civ016Jan112010.pdf" target="_blank">Pension Comm. Univ. of Montreal Pension Plan v. Bank of Am. Secs., LLC</a></em>.  The <a href="http://www.ediscoverylaw.com/uploads/file/Pension%20Order(1).pdf" target="_blank">amended opinion </a>cites negligence for failure to “obtain records from all those employees who had any involvement with the issues raised in the litigations or anticipated litigation, as opposed to just the key players.”</p>
<p>When litigation arises, it is critical for an organization to implement and enforce a hold order notice quickly and accurately to avoid sanctions.  <a href="http://www.jordanlawrence.com/products/holdmanagement/" target="_blank">Hold Management Services </a>allows you to filter and search notice recipients by typical attributes like job classification or business area so you can identify <em>all</em> employees who had any involvement.  And you can deliver those hold notices through a secure, closed communication channel for compliance verification every time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/06/are-you-identifying-all-the-players-in-your-litigation-hold-notices/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are You Compliant with the Massachusetts Privacy Law?</title>
		<link>http://www.disruptiveknowledge.com/2010/06/are-you-compliant-with-the-massachusetts-privacy-law/</link>
		<comments>http://www.disruptiveknowledge.com/2010/06/are-you-compliant-with-the-massachusetts-privacy-law/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 13:00:38 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[confidential information]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>
		<category><![CDATA[Massachusetts privacy law]]></category>
		<category><![CDATA[personally identifiable information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[regulatory compliance]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=326</guid>
		<description><![CDATA[The Massachusetts privacy law, that went into effective March 1, 2010, is not a law that only Massachusetts businesses need to be concerned about, but any company that retains personally identifiable information (PII) about a Massachusetts resident needs to be compliant. 
Requirements to comply with this law include creating an inventory of all paper and electronic [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.azbiz.com/articles/2010/05/14/media_technology/tech_talk/doc4bed858c5f538483907683.txt" target="_blank">The Massachusetts privacy law</a>, that went into effective March 1, 2010, is not a law that only Massachusetts businesses need to be concerned about, but any company that retains personally identifiable information (PII) about a Massachusetts resident needs to be compliant. </p>
<p>Requirements to comply with this law include creating an inventory of all paper and electronic records and media that contain PII, perform regular threat assessments to identify risks and vulnerabilities for a breach, and maintain a written security policy.</p>
<p>Most companies struggle with how to <a href="http://www.jordanlawrence.com/products/privacymanagement/" target="_blank">develop a data inventory</a>, which is the foundation of any privacy program, as well as the costs associated with the typical approach of using spreadsheets, the man hours and the disruption to the business.  With <a href="http://www.jordanlawrence.com/products/privacymanagement/" target="_blank">Privacy Management Services</a> you can create a personal data inventory in 30 days and update and maintain that information with minimal costs.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/06/are-you-compliant-with-the-massachusetts-privacy-law/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Prevent Data Breaches by Knowing the People “Breakdowns”</title>
		<link>http://www.disruptiveknowledge.com/2010/06/prevent-data-breaches-by-knowing-the-people-%e2%80%9cbreakdowns%e2%80%9d/</link>
		<comments>http://www.disruptiveknowledge.com/2010/06/prevent-data-breaches-by-knowing-the-people-%e2%80%9cbreakdowns%e2%80%9d/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 13:25:25 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[confidential information]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data privacy breach]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>
		<category><![CDATA[personally identifiable information]]></category>
		<category><![CDATA[PII]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=323</guid>
		<description><![CDATA[The number of data breaches involving personally identifiable information (PII) is on the rise.  The majority of these data breaches are caused due to bad business processes rather than by unauthorized access to networks.
In order to protect your personal and sensitive information from exposure due to bad processes you need to know what you have [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.broking.co.uk/insurance-age/news/1650947/ico-warns-breach-risk" target="_blank">The number of data breaches</a> involving personally identifiable information (PII) is on the rise.  The majority of these data breaches are caused due to bad business processes rather than by unauthorized access to networks.</p>
<p>In order to protect your personal and sensitive information from exposure due to bad processes you need to know what you have and where it resides.  The first step to identify those “bad processes” is creating and maintaining <a href="http://www.jordanlawrence.com/products/privacymanagement/" target="_blank">a personal data inventory</a>.  With <a href="http://www.jordanlawrence.com/products/privacymanagement/" target="_blank">Privacy Management Services </a>an inventory can be completed in 30 days giving you insight into what type of records exist, which records contain PII,  what media it resides in, and how it moves across the enterprise.</p>
<p>Having this information enables you to perform regular threat assessments to identify where your risks and vulnerabilities lie so you can develop actionable policies and procedures to mitigate those “breakdowns”.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/06/prevent-data-breaches-by-knowing-the-people-%e2%80%9cbreakdowns%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The First Step in Reducing the Cost of eDiscovery</title>
		<link>http://www.disruptiveknowledge.com/2010/05/the-first-step-in-reducing-the-cost-of-ediscovery/</link>
		<comments>http://www.disruptiveknowledge.com/2010/05/the-first-step-in-reducing-the-cost-of-ediscovery/#comments</comments>
		<pubDate>Thu, 27 May 2010 12:19:42 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[E-discovery]]></category>
		<category><![CDATA[Email Management]]></category>
		<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[document retention]]></category>
		<category><![CDATA[email retention]]></category>
		<category><![CDATA[financial risks]]></category>
		<category><![CDATA[over retainment of records]]></category>
		<category><![CDATA[reduce email]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=312</guid>
		<description><![CDATA[How many emails do you receive and send in a day?  Now, imagine over a course of a year, or three years, or even five years the number of emails one person in your organization produces or receives. 
According to the Federal Rules of Civil Procedure and state rules, parties are required to produce their electronically stored information during [...]]]></description>
			<content:encoded><![CDATA[<p>How many emails do you receive and send in a day?  Now, imagine over a course of a year, or three years, or even five years the number of emails one person in your organization produces or receives. </p>
<p>According to the Federal Rules of Civil Procedure and state rules, parties are required to produce their electronically stored information during litigation. To avoid the outlandish costs and burden of producing the enormous amounts of electronically stored information companies should take a pre emptive approach to <a href="http://www.law.com/jsp/lawtechnologynews/PubArticleLTN.jsp?id=1202458402969&amp;Mechanisms_That_Help_Reduce_the_Cost_of_EDiscovery" target="_blank">reducing the cost of eDiscovery</a>.</p>
<p>The first step is to reduce the amount of records and emails you have stored.  The best way is to develop and implement document retention policies including an email retention policy.  With Jordan Lawrence’s <a href="http://www.jordanlawrence.com/products/informationgovernance/" target="_blank">Information Governance</a> you can assess your records and information management in 30 days and develop actionable retention schedules using our best practice standards.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/05/the-first-step-in-reducing-the-cost-of-ediscovery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Happens to the Personal Data Your Company Maintains?</title>
		<link>http://www.disruptiveknowledge.com/2010/05/what-happens-to-the-personal-data-your-company-maintains/</link>
		<comments>http://www.disruptiveknowledge.com/2010/05/what-happens-to-the-personal-data-your-company-maintains/#comments</comments>
		<pubDate>Thu, 13 May 2010 03:04:22 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[data storage]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>
		<category><![CDATA[personal identifiable information]]></category>
		<category><![CDATA[Privacy Management]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=275</guid>
		<description><![CDATA[Remaining compliant with privacy laws and regulations begins with knowing what records contain personally identifiable information and where to find those records across the organization.  And hopefully it is not in a dumpster behind your company’s building as is the case this week in Tampa, FL.
When dealing with any personal and confidential information, companies must [...]]]></description>
			<content:encoded><![CDATA[<p>Remaining compliant with privacy laws and regulations begins with knowing what records contain personally identifiable information and where to find those records across the organization.  And hopefully it is not in a dumpster behind your company’s building <a href="http://www.abcactionnews.com/content/taking_action_for_you/investigations/story/INVESTIGATION-Medical-records-discovered-in-local/2nrKK7y6R0SgytmrnQO53g.cspx">as is the case this week in Tampa, FL</a>.</p>
<p>When dealing with any personal and confidential information, companies must have proper processes and policies in place to protect that data from ending up somewhere it should not be.  With Jordan Lawrence’s <a href="http://www.jordanlawrence.com/products/privacymanagement/">Privacy Management Services</a> you can identify those processes, use best practices to develop policies that govern private data and communicate privacy policies and directives straight to employees’ desktops using our secure and compliance-verified tool.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/05/what-happens-to-the-personal-data-your-company-maintains/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Three Realities of Data Privacy</title>
		<link>http://www.disruptiveknowledge.com/2010/05/the_three_realities_of_data_privacy/</link>
		<comments>http://www.disruptiveknowledge.com/2010/05/the_three_realities_of_data_privacy/#comments</comments>
		<pubDate>Mon, 03 May 2010 18:32:42 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>
		<category><![CDATA[Missing Flash Drive]]></category>
		<category><![CDATA[Patients Comprimised]]></category>
		<category><![CDATA[personal identifiable information]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=272</guid>
		<description><![CDATA[A flash drive containing personal information on 24,600 patients is missing from a Louisville, Kentucky hospital.  This unfortunate event illustrates three realities of data privacy:

The majority of data breaches are caused due to process issues and not by unauthorized access to networks.
Investing in proactive steps to prevent a breach is a lot cheaper than paying [...]]]></description>
			<content:encoded><![CDATA[<p>A flash drive containing personal information on 24,600 patients is <a href="http://www.courier-journal.com/apps/pbcs.dll/article?AID=20104290343">missing from a Louisville, Kentucky hospital</a>.  This unfortunate event illustrates three realities of data privacy:</p>
<ul>
<li>The majority of data breaches are caused due to process issues and not by unauthorized access to networks.</li>
<li>Investing in proactive steps to prevent a breach is a lot cheaper than paying for a breach.</li>
<li>The greatest security threats are seldom where you expect to find them.</li>
</ul>
<p>With data breach costs averaging close to $300 per individual affected, this flash drive could cost the hospital millions. Hospital officials are not talking about why this information was on a flash drive, but we know from experience that personally identifiable data can always be found throughout departments and in processes that you would not suspect.</p>
<p><a href="http://www.jordanlawrence.com/products/privacymanagement/">GRIP<sup>TM</sup> Privacy Management </a>enables companies to create and maintain incredibly discrete personal data inventories and to conduct regular threat assessments that uncover the elusive business processes that are the source of most breaches. <a href="http://www.jordanlawrence.com/products/privacymanagement/">GRIP<sup>TM</sup> Privacy Management </a>is fast, cost effective and works for any company. To learn more contact <a href="mailto:kdingley@jordanlawrence.com">Kathie Dingley </a>at 636-821-2232.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/05/the_three_realities_of_data_privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GRIP™ Privacy Management Met with Overwhelming Response</title>
		<link>http://www.disruptiveknowledge.com/2010/04/grip%e2%84%a2-privacy-management-met-with-overwhelming-response/</link>
		<comments>http://www.disruptiveknowledge.com/2010/04/grip%e2%84%a2-privacy-management-met-with-overwhelming-response/#comments</comments>
		<pubDate>Wed, 28 Apr 2010 19:58:26 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>
		<category><![CDATA[Iapp]]></category>
		<category><![CDATA[IAPP Conference 2010]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=264</guid>
		<description><![CDATA[Last week, Jordan Lawrence attended the annual IAPP (International Association of Privacy Professionals) Global Privacy Summit, where their introduction of GRIP™ Privacy Management was met with an overwhelming response.  The days of manually creating personal data inventories using error- prone and cumbersome spreadsheets are a thing of the past thanks to GRIP™ Privacy Management. 
Utilizing GRIP™ Privacy Management, any [...]]]></description>
			<content:encoded><![CDATA[<p style="LINE-HEIGHT: 14.25pt"><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt">Last week, Jordan Lawrence attended the annual </span><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt"><a href="http://www.privacyassociation.org">IAPP</a></span><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt"><a href="http://www.iappnet.org"> </a>(International Association of Privacy Professionals) Global Privacy Summit, where their introduction of<a href="http://www.jordanlawrence.com/products/privacymanagement/"> </a></span><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt"><a href="http://www.jordanlawrence.com/products/privacymanagement/">GRIP™ Privacy Management </a></span><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt">was met with an overwhelming response.  The days of manually creating personal data inventories using error- prone and cumbersome spreadsheets are a thing of the past thanks to GRIP™ Privacy Management. </span></p>
<p style="LINE-HEIGHT: 14.25pt"><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt">Utilizing GRIP™ Privacy Management, any company of any size can quickly and effectively create a personal data inventory in 30 days.  In addition, GRIP™ Privacy Management gives companies the tools needed to conduct regular threat assessments and to manage privacy and security policies.  </span></p>
<p style="LINE-HEIGHT: 14.25pt"><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt">To learn more about GRIP™ Privacy Management and how your company can benefit, contact </span><span style="FONT-FAMILY: 'Georgia','serif'; FONT-SIZE: 10pt"><a href="mailto: kdingley@jordanlawrence.com">Kathie Dingley</a>.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/04/grip%e2%84%a2-privacy-management-met-with-overwhelming-response/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 Ring Binder Source of Data Breach</title>
		<link>http://www.disruptiveknowledge.com/2010/04/3-ring-binder-source-of-data-breach/</link>
		<comments>http://www.disruptiveknowledge.com/2010/04/3-ring-binder-source-of-data-breach/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 15:27:47 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[personal data inventory]]></category>
		<category><![CDATA[personal identifiable information]]></category>
		<category><![CDATA[protecting customer data]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=259</guid>
		<description><![CDATA[Good old fashion paper is often overlooked as a potential source of a data breach. This is a big mistake because personally identifiable information is just as likely to be found in hard copy as it is electronically.  This was the case when a three ring binder containing the names, phone numbers and health information [...]]]></description>
			<content:encoded><![CDATA[<p>Good old fashion paper is often overlooked as a potential source of a data breach. This is a big mistake because personally identifiable information is just as likely to be found in hard copy as it is electronically.  This was the case when a three ring binder containing the names, phone numbers and health information of 1,272 patients <a href="http://www.chron.com/disp/story.mpl/ap/tx/6969571.html">was stolen from a car belonging to a hospital case manager in San Antonio</a>. </p>
<p>Preventing a data breach begins with creating and maintaining an accurate personal data inventory. But most companies’ attempts to create an inventory are doomed from the start because they are too high level and fail to identify the discrete business processes that contain, access or move personally identifiable information.  </p>
<p>When <a href="http://www.jordanlawrence.com">Jordan Lawrence </a>builds a personal data inventory, we leverage benchmarked industry and job function based profiles that ensure the inventory identifies what really matters.  Finding social security numbers in a database in a highly secure server is important but knowing patient information is maintained in a 3 ring binder that leaves the facility is how you prevent a breach. If you’re looking for a fast and accurate way to create and maintain an exceptional personal data inventory, then we should talk.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/04/3-ring-binder-source-of-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Management Goes Beyond Password Protection</title>
		<link>http://www.disruptiveknowledge.com/2010/04/privacy-management-goes-beyond-password-protection/</link>
		<comments>http://www.disruptiveknowledge.com/2010/04/privacy-management-goes-beyond-password-protection/#comments</comments>
		<pubDate>Sat, 17 Apr 2010 02:22:32 +0000</pubDate>
		<dc:creator>Jordan Lawrence</dc:creator>
				<category><![CDATA[Information Management]]></category>
		<category><![CDATA[Jordan Lawrence]]></category>
		<category><![CDATA[Privacy and Records Management]]></category>
		<category><![CDATA[Records Management Policies]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[GRIP™ Privacy Management]]></category>
		<category><![CDATA[John Muir Health]]></category>
		<category><![CDATA[personal identifiable information]]></category>

		<guid isPermaLink="false">http://www.disruptiveknowledge.com/?p=257</guid>
		<description><![CDATA[John Muir Health, a San Francisco based hospital system, recently revealed that 5,450 individuals’ personal identifiable information may have been compromised due to the loss of two laptops at one of their offices.
A data breach can happen in an instant. In order to safeguard sensitive information and reduce the financial and legal risks associated with [...]]]></description>
			<content:encoded><![CDATA[<p>John Muir Health, a San Francisco based hospital system,<a href="http://sanfrancisco.bizjournals.com/sanfrancisco/stories/2010/04/05/daily9.html"> recently revealed</a> that 5,450 individuals’ personal identifiable information may have been compromised due to the loss of two laptops at one of their offices.</p>
<p>A data breach can happen in an instant. In order to safeguard sensitive information and reduce the financial and legal risks associated with a data breach companies must take a proactive approach.  Knowing where that information lives, what media it resides in and the processes of how it is managed enables companies to reduce those risks. With our GRIP<sup>TM </sup>Privacy Management, any company can quickly create a personal data inventory and identify their current information management practices to assess and manage their risks responsibly, defensibly and cost-effectively.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disruptiveknowledge.com/2010/04/privacy-management-goes-beyond-password-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
