<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>data breach Archives - InnoHEALTH magazine</title>
	<atom:link href="https://innohealthmagazine.com/tag/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://ztt.nrm.mybluehostin.me/innohealthmagazinetag/data-breach/</link>
	<description>India&#039;s first magazine on healthcare innovations</description>
	<lastBuildDate>Mon, 03 Feb 2020 04:56:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://innohealthmagazine.com/wp-content/uploads/2017/11/innohealthmagazine-favicon.png</url>
	<title>data breach Archives - InnoHEALTH magazine</title>
	<link>https://ztt.nrm.mybluehostin.me/innohealthmagazinetag/data-breach/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">139068796</site>	<item>
		<title>Exclusive Interview with India&#039;s National Cybersecurity Coordinator</title>
		<link>https://innohealthmagazine.com/2019/cybersecurity/national-cybersecurity-coordinator/</link>
					<comments>https://innohealthmagazine.com/2019/cybersecurity/national-cybersecurity-coordinator/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Mon, 14 Oct 2019 05:23:08 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Exclusive Interview]]></category>
		<category><![CDATA[5G]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[connected devices]]></category>
		<category><![CDATA[connected healthcare]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[cyber security implications]]></category>
		<category><![CDATA[cyber security strategy]]></category>
		<category><![CDATA[cyber securty wisdom]]></category>
		<category><![CDATA[cybercrimes]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[device security]]></category>
		<category><![CDATA[DISHA]]></category>
		<category><![CDATA[exclusive interview]]></category>
		<category><![CDATA[Health Sector]]></category>
		<category><![CDATA[health system]]></category>
		<category><![CDATA[healthcare data]]></category>
		<category><![CDATA[healthcare data encryption]]></category>
		<category><![CDATA[IETE]]></category>
		<category><![CDATA[industrial connected devices]]></category>
		<category><![CDATA[InnoHEALTH Magazine]]></category>
		<category><![CDATA[intensive care unit]]></category>
		<category><![CDATA[Internet of Things]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[IoT security]]></category>
		<category><![CDATA[levels of security]]></category>
		<category><![CDATA[login credentials]]></category>
		<category><![CDATA[malicious actor]]></category>
		<category><![CDATA[Medical device regulation act]]></category>
		<category><![CDATA[Medical devices]]></category>
		<category><![CDATA[Ministry of Health]]></category>
		<category><![CDATA[mobile phones]]></category>
		<category><![CDATA[NABH]]></category>
		<category><![CDATA[National Accreditation Board for Hospitals]]></category>
		<category><![CDATA[national cyber security coordinator]]></category>
		<category><![CDATA[NBH]]></category>
		<category><![CDATA[PMO India]]></category>
		<category><![CDATA[Prime Minister of India]]></category>
		<category><![CDATA[Ransomware]]></category>
		<category><![CDATA[ransomware attack]]></category>
		<category><![CDATA[remote server]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security rating device]]></category>
		<category><![CDATA[security testing certification]]></category>
		<category><![CDATA[software based tempering]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[telecom]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=6530</guid>

					<description><![CDATA[<p>Exclusive Interview: Lt General (Dr) Rajesh Pant, India’s National Cybersecurity Coordinator at Prime Minister office with InnoHEALTH Magazine</p>
<p>The post <a href="https://innohealthmagazine.com/2019/cybersecurity/national-cybersecurity-coordinator/">Exclusive Interview with India&#039;s National Cybersecurity Coordinator</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa435c6d987"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row top-level"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<h4><strong>Vision for cybersecurity: An exclusive interview with India&#8217;s National <a href="https://innohealthmagazine.comtheme/cybersecurity-business-evangelist/">Cybersecurity</a> Coordinator at Prime Minister&#8217;s Office</strong></h4>
<p>-Interviewed by Sachin Gaur, executive editor, InnoHEALTH Magazine</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c6eb69"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;"><em><strong>Lt General (Dr.) Rajesh Pant</strong></em> is an internationally recognized Cyber Security expert, presently tenanting the prestigious appointment of National Cyber Security Coordinator at the Prime Minister’s Office, India. General Pant brings to the table an interesting mix of military operations, academic excellence, corporate governance, and cybersecurity wisdom. Prior to this, he was the Head of the Army’s Cyber Training establishment for three years. He served in the Army Signals Corps for 41 years wherein he was awarded three times by the President of India for distinguished service of the highest order. He also served as the Chairman of Precision Electronics Ltd as a Governing Council Member of IETE (India). <a href="https://www.linkedin.com/in/sachgaur/"><em><strong>Sachin Gaur</strong></em></a> interviewed him on his viewpoint on India’s vision for cybersecurity.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c6f12e"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Q. On behalf of InnoHEALTH Magazine, we congratulate you on your new assignment. For our readers, we would like you to share your short-term and long-term vision for Cybersecurity from national</strong><strong> security perspective</strong>.<br />
Short-term vision is to issue National Cyber Security Strategy 2020-25 early next year. Task force is working overtime on this by consulting all stakeholders. Long-term vision is to create an all-encompassing cyber vertical at the national level, to handle incident response, cybercrimes, legal issues and capacity building.</p>
<hr width="100%" />
<strong>Q. We know that there are some fundamental technological shifts waiting to happen like 5G, and along-with it massive (Internet of Things) IoT deployments and especially use cases of connected healthcare. Can you share your views on the cybersecurity implications of the connected devices?</strong><br />
<a href="https://innohealthmagazine.comtheme/iot-can-truly-transform-rural-healthcare-india/">IoT security</a> is a priority topic world over and this is because the limited security capabilities of these devices are also an afterthought. We need to work on a framework, to bring baselinesecurity through the manufacturers and developers of these devices. These devices are omnipresent in our lives, we find them in our home environment to industrial environments including hospitals. We have seen attacks in the past, where such devices are compromised to launch massive denial of service attacks to manipulate the workings of critical infrastructure.<br />
Also, the issue of IoT security is multidimensional, from <a href="https://innohealthmagazine.comissues/patients-sensitive-health-data/">data security</a>, privacy to device security. As we discuss this, there are multiple acts and bills pending in the Parliament on these topics. While the bills and acts will provide a framework, we need to also create awareness on both sides, supplier and consumer on the possible risks and mitigation strategies.</p>
<hr width="100%" />
<strong>Q. What steps can be taken to improve the security in such <a href="https://innohealthmagazine.comtrends/medical-iot-future-of-connected-health/">connected devices</a>?</strong><br />
When I say baseline security framework, it can be achieved in multiple ways.<br />
As of today, most devices that we use including mobile phones, do not have a security testing certification. So, we can agree with the industry and look at important test cases and if they can do self-certification on such test cases.<br />
<em>For </em>example: the device should not have weak default login credentials, it is sending data to a remote server and can be operated remotely. So, we can come up like a 5-star rating framework like that of the energy consumption but for the security of IoT devices basis what kind of tests they clear.<br />
Industry bodies can agree on various levels of security and what it takes to achieve that level. Such a framework, when implemented, can provide confidence to consumers and users on the kind of device they are using vis-a-visthe use case they have at hand. So, they might use a higher security rating device in a use case where the stakes are high.<br />
The other approach is to get the security testing done with notified agencies. Department of Telecom for example has announced mandatory security testing of network elements for telecom given telecom is a part of the critical infrastructure and security issuescannot be taken lightly.<br />
Also, some of the emerging concepts in connected devices are missing in the various governing acts of the industrial connected devices. So, we also need to update our legal frameworks to cover software-based tempering of such devices and make the manufacturers and service providers accountable and proactive towards the security of the systems they provide.</p>
<hr width="100%" />
<strong>Q. What are the threats that you foresee for the health sector? </strong><br />
There are three areas we see where health sector can be impacted:<br />
First is the data breaches and <a href="https://innohealthmagazine.comissues/ransomware-epidemic/">ransomware attacks</a> on healthcare data. As we know, among all the data, healthcare is the most sensitive and sought after by malicious actors. Outside of India, we have seen umpteen cases where ransomware has crippled the health system and it is only after paying the ransom the hospitals can start operation again. Timely backups and encryption of healthcare data during storage is a preventive measure that clinical establishments can take to mitigate the breach and ransomware attacks.<br />
Second is the manipulation of connected devices. The topic of IoT and connected devices security, as discussed in the above sections, directly apply to the medical devices. Healthcare is a domain where attacks on such devices can be life threatening, especially when there are implantable devices. As we have the new Medical Device Regulation Act in India since 2018, we should also consider cyber security aspect in the devices which have a communication interface. For example, a pacemaker which has a communication interface can be manipulated remotely and the patient’s life is at risk.<br />
Third is the manipulation of health system including the building management. We are probably not very far from the days when sophisticated attacks, as we see in the movies, on high security establishments by manipulating the building controls. The building management systems are very weak when it comes to security. Every hospital is a building and imagine what a false fire alarm would mean to patients in Intensive Care Unit. Or even loss of air conditioning or sudden spikes in electrical power.<br />
There is a proposed act <a href="https://innohealthmagazine.cominnovatiocuris/disha-act/">DISHA</a>, Digital Information Security Healthcare Act, which might address some of the legal aspects of security in the healthcare setting. A lot needs to be done in this area, and we are on our way.</p>
<hr width="100%" />
<strong>Q. Our readership consists of health experts all over the world. Any message for them?</strong><br />
We are at the cusp of a new age where we look to take advantage of <a href="https://innohealthmagazine.comexpert-opinion/ai-iot-healthcare-need-future/">Artificial Intelligence</a> to Internet of Things. For such a knowledge economy to take off, health sector is at the center of it and health experts need to pay attention on what they are buying and how such systems are managed and operated. Through intervention of Ministry of Health &amp; Family Welfare and responsible bodies such as National Accreditation Board of Hospitals &amp; Healthcare Providers (NABH) of Quality Council of India, we plan to recommend a cyber audit and increased awareness of information security.<br />
We would not want our hospitals and clinical establishments to be a prey for malicious actors. Rather we would want our experts to leverage technology to take the country to the next level in providing care to a wider population at a lower cost and of the highest quality.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/cybersecurity/national-cybersecurity-coordinator/">Exclusive Interview with India&#039;s National Cybersecurity Coordinator</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/cybersecurity/national-cybersecurity-coordinator/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">6530</post-id>	</item>
		<item>
		<title>Cybersecurity Trends, Challenges, and Threats in Healthcare</title>
		<link>https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/</link>
					<comments>https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Tue, 28 May 2019 06:57:20 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurity framework]]></category>
		<category><![CDATA[cybersecurity policy]]></category>
		<category><![CDATA[cybersecurity threats]]></category>
		<category><![CDATA[cyberspace]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[Digital Health]]></category>
		<category><![CDATA[digital health data]]></category>
		<category><![CDATA[digital information]]></category>
		<category><![CDATA[DISHA]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare websites]]></category>
		<category><![CDATA[Internet of Medical Things]]></category>
		<category><![CDATA[IoMT]]></category>
		<category><![CDATA[Mental Health]]></category>
		<category><![CDATA[National Health service]]></category>
		<category><![CDATA[physicaal health]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[WannaCry]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=5928</guid>

					<description><![CDATA[<p>The healthcare industry is particularly vulnerable to cyber threats not least because of the minimal amount of investment they put in cybersecurity measures.</p>
<p>The post <a href="https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/">Cybersecurity Trends, Challenges, and Threats in Healthcare</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa435c719da"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">Likewise, the global trends, the growth of the Internet in India is incredibly fast-paced, with an estimated addition of 10 million active users each month. Along with the increase in the number of users, the adoption rate of going digital by various stakeholders in our society is also growing exponentially. Unfortunately, this also increases our vulnerability to potential hacks or security breaches that come from individual hackers to organized groups to even attacks from nation states. Cybersecurity, thus, entails protection of our cyberspace, and all the critical infrastructures like banking and finance, defense, healthcare, manufacturing, nuclear reactors, and commercial facilities from being the target to any sort of attack, damage, misuse or act of espionage.</p>
<p style="text-align: justify !important;">The healthcare industry is particularly vulnerable to cyber threats not least because of the minimal amount of investment they put in cybersecurity measures. Hospitals, insurance companies, pharmacies, developers/ owners of healthcare websites, manufacturers of medical devices, or handsets, or third-party vendors to which sensitive patient data gets shared; all represent a leaky pipeline through which hackers can enter a system and cause extensive damage. The types of attacks can include access to patient’s medical history, prescriptions, financial and personal details or using the Internet of Medical Things to disrupt implanted medical devices or devices like drug infusion pumps. Healthy cybersecurity practices have, therefore, never been more important than today when a ransomware attack like WannaCry has the potential to literally shut down a country’s (UK) National Health Service.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c729d7"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Where India stands today?</strong></p>
<p style="text-align: justify !important;">According to the International Telecommunication Union (ITU), a UN telecommunications agency, India ranked 23rd amongst 165 nations on the Global Cybersecurity Index (GCI) in 2017. GCI ranks nations for their commitment towards cybersecurity using various measures &#8211; legal, technical, organizational, capacity building, and cooperation. With the rapid rise in cyber threats, India’s growing investment in protecting its data is absolutely a positive development. Nevertheless, a quick look at the current status on cybersecurity and data protection laws in India highlights the gap we must fill in as we move towards complete digitizing of various infrastructures in the 21st century.</p>
<p style="text-align: justify !important;">For instance, it was last in 2000 when the legal provisions related to cybersecurity were formulated in the Information Technology Act (ITA) when the nature of threats revolved only around viral or malware attacks. The ITA was later amended in 2008 and now deals with cyber crimes such as hacking, tampering, data or identity theft, cheating, phishing, etc. Sections 43 and 63–74 provide provisions for civil and criminal prosecution in case of different cyber offenses. The ITA requires entities holding private data of users to maintain specified security standards and provides provisions to users for airing grievances in case of the data breach.</p>
<p style="text-align: justify !important;">India established its first cybersecurity policy &#8211; the National Cyber Security Policy (NCSP), in 2013, after much mayhem caused by Edward Snowden’s allegations of NSA snooping on India. The policy designated CERT-In (Indian Computer Emergency Response Team), a national nodal agency to respond to and analyze incidents of cybersecurity breaches. CERT-In provides alerts of cybersecurity incidents, conducts emergency measures for handling such incidents, coordinates necessary response activities and issues guidelines, etc., regarding cybersecurity measures. In the case of a data breach, an organization holding confidential user data must report to CERT-In promptly.</p>
</div>



<div class="divider-wrap" data-alignment="default"><div style="height: 25px;" class="divider"></div></div>
<div class="wpb_text_column wpb_content_element " >
	<p>Also Read:<br />
<a href="https://innohealthmagazine.comexpert-opinion/cyber4healthcare/">Cyber4Healthcare: An Issue of Today &amp; Tomorrow</a><br />
<a href="https://innohealthmagazine.cominnovatiocuris/disha-act/">DISHA – Need of the hour</a></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c73259"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Healthcare specific provisions</strong></p>
<p style="text-align: justify !important;">While the above-mentioned regulations provide a general legal cybersecurity framework for all the organizations, no separate provisions are in place viz a viz the healthcare sector. India decided to fill in this gap last year when the Ministry of Health and Family Affair, the Government of India proposed the Digital Information Security in Healthcare Act (DISHA) and placed it in public domain on 21 March 2018 for comments by various stakeholders. DISHA aims to ensure reliability, data privacy, confidentiality, and security of digital health data. The act, applicable to entire India except for Jammu and Kashmir, establishes eHealth Authorities and Health Information Exchanges at the state and national levels while also outlining the guidelines on standardizing/ regulating the processes related to the collection, storing, transmission and use of digital health data (DHD) in India.</p>
<p>Accordingly, DHD means any electronic record of health-related information</p>
<ul>
<li>concerning the physical or mental health of a person</li>
<li>on any health service provided to an individual</li>
<li>on a donation of any body part of any bodily substance</li>
<li>derived from testing or examination of a body part or bodily substance</li>
<li>collected during providing health services</li>
<li>relating to details of the clinical establishment accessed by a person</li>
</ul>
<p style="text-align: justify !important;">DISHA also specifies the rights of the owner of digital health data, outlines the purposes for which DHD can be collected and explicitly mentions all clinical establishments holding DHD to be duty-bound in maintaining privacy and confidentiality of the patient’s data. Importantly, DISHA touches upon what constitutes a breach of digital health data, compensation in the event of one happening and what punishments an individual or a company might face if convicted of a cybercrime.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="100%" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c73a62"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p><strong>Marching ahead</strong></p>
<p style="text-align: justify !important;">The breach of data far more often in the healthcare sector compared to other sectors highlights the value of information stored in digital health records. It is, therefore, important that cybersecurity takes precedence for all the healthcare providers. Proactive measures include identifying likely targets, securing and updating systems in a timely manner, constant monitoring for malware or security breaches and reinforcing good user behavior among the employees. Similarly, the response to data breach incidents needs to be swift to minimize the extent of damage when a cybercrime occurs. Like the adage, ‘prevention is better than cure’, the healthcare providers also have a necessary task ahead of themselves to up their security measures in accordance with the current legal framework, before a patient’s data or the trust gets compromised.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c73e33"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<h2>About the author</h2>
<p><em><strong>Dr. Urvashi (Raheja) Bhattacharyya</strong> is a Senior Research Analyst at StudyMode. She indulges in machine-learning methods during office hours and enjoys writing about healthcare and education in her free time.</em></p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/">Cybersecurity Trends, Challenges, and Threats in Healthcare</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2019/cybersecurity/cybersecurity-trends-challenges-threats-healthcare/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5928</post-id>	</item>
		<item>
		<title>How Crucial is DISHA Act for Healthcare Industry?</title>
		<link>https://innohealthmagazine.com/2018/others/policy/disha-act-for-healthcare-industry/</link>
					<comments>https://innohealthmagazine.com/2018/others/policy/disha-act-for-healthcare-industry/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Mon, 17 Dec 2018 08:56:22 +0000</pubDate>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[Clinical Establishment Act Standards]]></category>
		<category><![CDATA[CRUD]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[data safe]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[decrypt]]></category>
		<category><![CDATA[digital gealth]]></category>
		<category><![CDATA[digital health record]]></category>
		<category><![CDATA[Digital Information Security]]></category>
		<category><![CDATA[disasters]]></category>
		<category><![CDATA[DISHA]]></category>
		<category><![CDATA[Disha act]]></category>
		<category><![CDATA[Electronic Health Record]]></category>
		<category><![CDATA[emergencies]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[epidemics]]></category>
		<category><![CDATA[financing]]></category>
		<category><![CDATA[health information]]></category>
		<category><![CDATA[healthcare data]]></category>
		<category><![CDATA[healthcare IT company]]></category>
		<category><![CDATA[IBM report]]></category>
		<category><![CDATA[Insurance]]></category>
		<category><![CDATA[Ministry of health and family welfare]]></category>
		<category><![CDATA[national programmes]]></category>
		<category><![CDATA[notifiable diseases]]></category>
		<category><![CDATA[pathlabs]]></category>
		<category><![CDATA[public stakeholder]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Stakeholder]]></category>
		<category><![CDATA[Statistics]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Threat]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=5079</guid>

					<description><![CDATA[<p>The question we need to ask ourselves is that Why DISHA is the need of the hour? Why we need to safeguard the electronic health record in hospitals?</p>
<p>The post <a href="https://innohealthmagazine.com/2018/others/policy/disha-act-for-healthcare-industry/">How Crucial is DISHA Act for Healthcare Industry?</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa435c767f8"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">&#8220;A journey of a thousand miles begins with a single step.&#8221; <strong><a href="https://innohealthmagazine.cominnovatiocuris/disha-act/">The Digital Information Security in Healthcare Act (&#8216;DISHA&#8217;)</a></strong> is that firm first step taken by the Indian Government in the long journey to secure the healthcare data of patients in India. The question we need to ask ourselves is that Why DISHA is the need of the hour? Why do we need to safeguard the electronic health record in hospitals?</p>
<p style="text-align: justify !important;">The draft of the act was made public in November 2017 by Ministry of Health and Family Welfare. The word ‘Disha’ means direction, the GoI has taken the first step in the direction of safeguarding the digital health record. For this <a href="http://www.innovatiocuris.com">InnovatioCuris</a> has also taken the first step towards having a concrete discussion about ‘Challenges in the implementation and opportunities for making health sector DISHA and data protection ready’. There were panelists from various renowned government, private hospitals, and healthcare IT firms.</p>
</div>



<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="default" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c78500"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The first session was about the ‘Challenges in the implementation of DISHA’. The panelists were happy that InnovatioCuris has taken an initiative to critically discuss the challenges a hospital will face once the act becomes the law. All the panelists agreed that the act lacks various aspects. Few concerns that bother the clinicians are, that who will give the consent if the patient is unconscious.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c78aa7"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The ambulances have the capability that it sends the health records from the ambulance to hospital before the patient reaches the hospital for doctors to study the emergency cases. In this scenario, what should be done if a patient denies the consent for sharing the data at a later stage? Should the clinical establishments discard the already shared health record or should they handover the same to the owner (in this case, patient) or what should be done. There are no set protocols defined in the act for such cases.</p>
<p style="text-align: justify !important;">A question was put forward, does the patient has the authority to edit their health record, or can they view, who have seen their health record. A healthy discussion took place where we got to know that citizens of Estonia have chip cards, where one can see their health record and can also see the logs of who has accessed their health record. This made us realize, that India as a nation state can use Aadhar card as a mechanism, where we can log in into a portal and get to see health records.</p>
<p style="text-align: justify !important;">The third challenge that came forward was interoperability of health records. As the record lies with the custodian, not the patient, editing and viewing of it can be done by the clinical establishments. The health record can be shared by the clinical establishments to another, but there is no standard on how to transfer it. Data integrity is a point of concern, which is not mentioned in the act.</p>
<p style="text-align: justify !important;">One of the challenges that came into light was according to ‘Clinical Establishment Act Standards for Hospital<strong><a href="http://clinicalestablishments.gov.in/WriteReadData/147.pdf" target="_blank" rel="noopener noreferrer">[2]</a></strong>’ the hospital has to keep health information and statistics in respect of national programmes, notifiable diseases, and emergencies/disasters/epidemics and furnish the same to the district authorities in the prescribed formats and frequency. The question is what if the patient does not give consent. The proposed act should have a provision where the clinical establishments are liable to take the health data.</p>
<p style="text-align: justify !important;">As we have unstructured healthcare facilities in India, the act should also empower the clinical establishments by various means to keep the data safe. As of now the DISHA is a proposed act, not a law and has lots of loopholes. It also lacks in many aspects discussed earlier. This is just a start and the government should take necessary steps to improve it.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c78ed0"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The second panel discussed on ‘Opportunities for making health sector DISHA and data protection ready’. The panelist consisted of CIO of path labs, owners of healthcare IT firms, who shared relevant thoughts and comments. The panel started the discussion on why do we need the act and what are the benefits of the act. Panelist were grateful to the government to bring the act. They told that the clinical establishments will take steps to increase the safety of the health record.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c79d30"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">The gaps in the technology for generation, storage and transmission will be lowered down. Sectors such as banking, financing and insurance have structured their data, but this lacks in healthcare. Detailed scope of security features are missing from the act, this would help the companies to design the software from the ground up by using security as an important consideration.</p>
<p style="text-align: justify !important;">The imminent threat is in the software which are already in place and have not been patched or the system has not been upgraded. The good news is that many have an audit trail in built in their system, which track any CRUD(creation, read, update, delete) of the records. The discussion contributed a fruitful thought: Data at rest is not encrypted. The question that arises is what is preventing the healthcare IT companies to encrypt the data at rest.</p>
<p style="text-align: justify !important;">One of the challenge in the DISHA is that, the owner of the data must be informed of any breach of the privacy or confidentiality of their digital health record within three days. But according to IBM report it takes on an average of 197 days to detect a breach<strong>[1]</strong>. How can the Healthcare IT companies safeguard the health record and let the owner know about the breach. The solution is to encrypt the tables in the database, but that might hamper the performance.</p>
<p style="text-align: justify !important;">It is a huge opportunity for the stakeholder to bring standards in the act. DISHA might have only completed its first round of comments from the public and stakeholders, it can be expected that the revisions made based on the feedback will churn out a more refined version of the act. In any case, it is evident from the draft that the government has really pushed to provide additional security, privacy and confidentiality for individuals, with respect to their digital health record.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
		<div id="fws_69aa435c7a1d3"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark left">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				<div class="img-with-aniamtion-wrap center" data-max-width="100%" data-max-width-mobile="default" data-shadow="none" data-animation="fade-in" >
      <div class="inner">
        <div class="hover-wrap"> 
          <div class="hover-wrap-inner">
            <a href="http://bit.ly/2IY3u54" target="_blank" class="center">
              <img decoding="async" class="img-with-animation skip-lazy" data-delay="0" height="60" width="728" data-animation="fade-in" src="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png" alt="cyber4healthcare-online-course-bottom-ad (2)" srcset="https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2.png 728w, https://innohealthmagazine.com/wp-content/uploads/2019/04/cyber4healthcare-online-course-bottom-ad-2-300x25.png 300w" sizes="(max-width: 728px) 100vw, 728px" />
            </a>
          </div>
        </div>
        
      </div>
      </div>
			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2018/others/policy/disha-act-for-healthcare-industry/">How Crucial is DISHA Act for Healthcare Industry?</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2018/others/policy/disha-act-for-healthcare-industry/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">5079</post-id>	</item>
		<item>
		<title>GDPR &#8211; General Data Protection Regulation</title>
		<link>https://innohealthmagazine.com/2018/others/policy/gdpr-general-data-protection-regulation/</link>
					<comments>https://innohealthmagazine.com/2018/others/policy/gdpr-general-data-protection-regulation/#respond</comments>
		
		<dc:creator><![CDATA[InnoHEALTH Magazine]]></dc:creator>
		<pubDate>Tue, 01 May 2018 07:31:06 +0000</pubDate>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[28 EU countries]]></category>
		<category><![CDATA[alteration of data]]></category>
		<category><![CDATA[annual revenue]]></category>
		<category><![CDATA[damage to reputation]]></category>
		<category><![CDATA[data and privacy]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data controllers]]></category>
		<category><![CDATA[Data Protection Authority]]></category>
		<category><![CDATA[data protection law]]></category>
		<category><![CDATA[data protection rights]]></category>
		<category><![CDATA[Dhruv Singh]]></category>
		<category><![CDATA[Digital Information Security in Healthcare Act]]></category>
		<category><![CDATA[EU Data Protection Directive]]></category>
		<category><![CDATA[EU residents]]></category>
		<category><![CDATA[European Parliament]]></category>
		<category><![CDATA[european union]]></category>
		<category><![CDATA[financial loss]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[General Data Protection Regulation]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Indian Government]]></category>
		<category><![CDATA[innohealth]]></category>
		<category><![CDATA[InnoHEALTH Magazine]]></category>
		<category><![CDATA[innovatiocuris]]></category>
		<category><![CDATA[international business]]></category>
		<category><![CDATA[loss of confidentiality of personal data]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[personally identifiable information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[right to know]]></category>
		<category><![CDATA[UK Data Protection Act]]></category>
		<guid isPermaLink="false">https://ztt.nrm.mybluehostin.me/innohealthmagazine?p=3861</guid>

					<description><![CDATA[<p>The GDPR aims primarily to give control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.</p>
<p>The post <a href="https://innohealthmagazine.com/2018/others/policy/gdpr-general-data-protection-regulation/">GDPR &#8211; General Data Protection Regulation</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></description>
										<content:encoded><![CDATA[
		<div id="fws_69aa435c7e0e0"  data-column-margin="default" data-midnight="dark"  class="wpb_row vc_row-fluid vc_row"  style="padding-top: 0px; padding-bottom: 0px; "><div class="row-bg-wrap" data-bg-animation="none" data-bg-animation-delay="" data-bg-overlay="false"><div class="inner-wrap row-bg-layer" ><div class="row-bg viewport-desktop"  style=""></div></div></div><div class="row_col_wrap_12 col span_12 dark ">
	<div  class="vc_col-sm-12 wpb_column column_container vc_column_container col no-extra-padding"  data-padding-pos="all" data-has-bg-color="false" data-bg-color="" data-bg-opacity="1" data-animation="" data-delay="0" >
		<div class="vc_column-inner" >
			<div class="wpb_wrapper">
				
<div class="wpb_text_column wpb_content_element " >
	<p style="text-align: justify !important;">General Data Protection Regulation (GDPR) is proposed by the European Parliament and Council to secure data and privacy of the citizens of European Union. It addresses the export of personal data outside the EU. The GDPR aims primarily to give control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.</p>
<p style="text-align: justify !important;">The General Data Protection Regulation (GDPR) standardizes data protection law across all 28 EU countries and imposes strict new rules on controlling and processing personally identifiable information (PII). It also extends the protection of personal data and data protection rights by giving control back to EU residents. GDPR replaces the 1995 EU Data Protection Directive, and goes into force on May 25, 2018. It also supersedes the 1998 UK Data Protection Act.</p>
<p style="text-align: justify !important;">This regulation GDPR applies to all organizations holding and processing EU resident’s personal data, regardless of geographic location. Many organisations outside the EU are unaware that the EU GDPR regulation applies to them as well. If an organization offers goods or services to, or monitors the behavior of EU residents, it must meet GDPR compliance requirements.</p>
<p style="text-align: justify !important;">The aim of giving citizens more control over their information, GDPR ensures citizens can ask to access their data at &#8220;reasonable intervals&#8221;, with controllers having a month to comply with these requests. Both controllers and processors must make clear how they collect citizens’ information, what purposes they use it for, and the ways in which they process the data. The legislation also says that firms must use plain language to convey these things clearly and coherently to citizens: it&#8217;s time to wave goodbye to those confusing, dense terms and conditions.</p>
<p style="text-align: justify !important;">Citizens have the right to access any information a company holds on them, and the right to know why that data is being processed, how long it&#8217;s stored for, and who gets to see it. Where possible, data controllers should provide secure, direct access for citizens to review what information a controller stores about them.</p>
<p style="text-align: justify !important;">If a business suffers a data breach in the form of a loss, alteration of data, or unlawful access to personal information, such a breach needs to be reported to a Data Protection Authority within 72 hours of your organization becoming aware of it. If the breach results in discrimination, fraud or identity theft, financial loss, damage to reputation, loss of confidentiality of personal data, then the breach will need to be reported to the citizen as well.</p>
<p style="text-align: justify !important;">Breaches can result in a fine of € 10M or 2% of a company’s annual revenue, whichever is greater. More serious breaches could result in a fine € 20M or 4% of a company’s annual revenue, whichever is greater. Apart from this, the Data Protection Authority can impose a complete ban on data processing operations by an organization.</p>
<p style="text-align: justify !important;">One can also check similar article on Digital Information Security in Healthcare Act proposed by Indian government <a href="https://innohealthmagazine.comdisha-act/">here</a>.</p>
</div>




			</div> 
		</div>
	</div> 
</div></div>
<p>The post <a href="https://innohealthmagazine.com/2018/others/policy/gdpr-general-data-protection-regulation/">GDPR &#8211; General Data Protection Regulation</a> appeared first on <a href="https://innohealthmagazine.com">InnoHEALTH magazine</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://innohealthmagazine.com/2018/others/policy/gdpr-general-data-protection-regulation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">3861</post-id>	</item>
	</channel>
</rss>
