<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Kraft Business Systems</title>
	<atom:link href="http://www.kraftbusiness.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kraftbusiness.com/blog</link>
	<description>One call. One Click. One Source. </description>
	<lastBuildDate>Fri, 10 May 2013 12:00:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<item>
		<title>New Technology: Sharp AQUOS BOARD</title>
		<link>http://www.kraftbusiness.com/blog/2013/05/technology-sharp-aquos-board/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/05/technology-sharp-aquos-board/#comments</comments>
		<pubDate>Fri, 10 May 2013 12:00:01 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Document Management]]></category>
		<category><![CDATA[Health Care Management]]></category>
		<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Office Equipment Management]]></category>
		<category><![CDATA[Sustainability]]></category>
		<category><![CDATA[aquos board]]></category>
		<category><![CDATA[document management]]></category>
		<category><![CDATA[kraft business]]></category>
		<category><![CDATA[Office Equipment]]></category>
		<category><![CDATA[presentations]]></category>
		<category><![CDATA[Sharp]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=1015</guid>
		<description><![CDATA[One of Sharp&#8217;s many new offerings aims to match your organization&#8217;s BIG thinking: the AQUOS BOARD.  Designed with the idea that a BIG SCREEN provides a BIG IMPACT with BIG ADVANTAGES over conventional display solutions, the AQUOS BOARD definitely delivers. Three available &#8230; <a href="http://www.kraftbusiness.com/blog/2013/05/technology-sharp-aquos-board/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>One of Sharp&#8217;s many new offerings aims to match your organization&#8217;s BIG thinking: the AQUOS BOARD.  Designed with the idea that a <strong>BIG SCREEN</strong> provides a <strong>BIG IMPACT</strong> with <strong>BIG ADVANTAGES</strong> over conventional display solutions, the AQUOS BOARD definitely delivers.</p>
<p>Three available size options exit to fit your needs: 80&#8243; class, 70&#8243; class, and 60&#8243; class.</p>
<p>The brilliant high definition LCD panel, with energy-efficient design, provides a beautiful display while also allowing you to annotate, store and sharing your information.  The easy multi-touch operation with a pen or finger defines the functionality of the device.  The exclusive, user-intuitive Sharp Pen Software™ pairs well with high-performance optical imaging and infrared detection systems for quick response.  The Direct Sharp MFP connectivity makes it easy to import or export data between machines.  To further usability, the device comes with built-in templates that include calendars, to-do lists, and more.</p>
<p>For more information on the AQUOS BOARD or other Sharp products, give us a call at (616) 977-2679.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/05/technology-sharp-aquos-board/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Smart Video™ by LifeSize</title>
		<link>http://www.kraftbusiness.com/blog/2013/05/smart-video-lifesize/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/05/smart-video-lifesize/#comments</comments>
		<pubDate>Wed, 08 May 2013 12:00:45 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Sustainability]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Voice & Data Services]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[lifesize]]></category>
		<category><![CDATA[logitech]]></category>
		<category><![CDATA[smart video]]></category>
		<category><![CDATA[video conferencing]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=1023</guid>
		<description><![CDATA[Smart Video is a term coined by LifeSize, a division of Logitech, to describe a video conferencing experience that is feature-rich, simple and doesn&#8217;t require any training.  Smart Video is following the trend of smartphones by having a keen focus &#8230; <a href="http://www.kraftbusiness.com/blog/2013/05/smart-video-lifesize/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Smart Video is a term coined by LifeSize, a division of Logitech, to describe a video conferencing experience that is feature-rich, simple and doesn&#8217;t require any training.  Smart Video is following the trend of smartphones by having a keen focus on providing a radically simplified user experience.</p>
<p>The top five reasons that LifeSize believes they offer truly Smart Video:<br />
<strong>1.  Easy enough for anyone to use without training<br />
2.  Lots of infrastructure applications with none of the hassle<br />
<strong>3.  Heads-up experience<br />
4.  Name-based dialing<br />
5.  Smart scheduling</strong></strong></p>
<p>Seeing is believing, so <a href="http://www.lifesize.com/en/products/video-conferencing-systems/icon">click here </a>to request a demo to see LifeSize Icon Series in action.</p>
<p>Give us a call at (616) 977-2679 to have us answer any questions you may have or to get involved with this exciting technology.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/05/smart-video-lifesize/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information Technology: As Easy As IT</title>
		<link>http://www.kraftbusiness.com/blog/2013/05/information-technology-easy/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/05/information-technology-easy/#comments</comments>
		<pubDate>Mon, 06 May 2013 12:00:34 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Document Management]]></category>
		<category><![CDATA[IT Management]]></category>
		<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Office Equipment Management]]></category>
		<category><![CDATA[Sustainability]]></category>
		<category><![CDATA[easy IT]]></category>
		<category><![CDATA[information technology]]></category>
		<category><![CDATA[level platforms]]></category>
		<category><![CDATA[managed workplace]]></category>
		<category><![CDATA[office management]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=1019</guid>
		<description><![CDATA[With mobility, cloud, converging voice, video and data services and other technology innovations helping drive end-user productivity and business results, Managed Workplace from Level Platforms solves your increasingly complex IT network and device management issues. Managed Workplace is a next-generation &#8230; <a href="http://www.kraftbusiness.com/blog/2013/05/information-technology-easy/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>With mobility, cloud, converging voice, video and data services and other technology innovations helping drive end-user productivity and business results, Managed Workplace from Level Platforms solves your increasingly complex IT network and device management issues.</p>
<p>Managed Workplace is a next-generation remote monitoring and management software platform, which delivers end-to-end visibility into the networks, cloud, applications and devices relied on by your end-users.  See everything that is happening in your IT environment through a unified web-based dashboard, with automatic discovery and monitoring of existing and new devices.  Use alerting to proactively address performance and security concerns.  Automate configuration and network settings to increase productivity, enforce usage policies and improve security.</p>
<p>For more information about Managed Workplace, visit: <a href="http://www.levelplatforms.com">www.levelplatforms.com</a></p>
<p>For more information on how you can use this and similar tools to grow your business, contact Kraft Business Systems at (616) 977-2679.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/05/information-technology-easy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>KBS named 2012 GreatAmerica Premier Dealer</title>
		<link>http://www.kraftbusiness.com/blog/2013/05/kbs-named-2012-greatamerica-premier-dealer/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/05/kbs-named-2012-greatamerica-premier-dealer/#comments</comments>
		<pubDate>Thu, 02 May 2013 12:00:40 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Health Care Management]]></category>
		<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Social Media]]></category>
		<category><![CDATA[financial services]]></category>
		<category><![CDATA[greatamerica]]></category>
		<category><![CDATA[Office Equipment]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=1012</guid>
		<description><![CDATA[Kraft Business Systems has been named a 2012 GreatAmerica Premier Dealer by GreatAmerica Financial Services! GreatAmerica defines this title as having &#8220;the business acumen it takes to be an industry market leader; a long-term outlook, ethical business conduct, customer focus &#8230; <a href="http://www.kraftbusiness.com/blog/2013/05/kbs-named-2012-greatamerica-premier-dealer/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Kraft Business Systems has been named a 2012 GreatAmerica Premier Dealer by GreatAmerica Financial Services!</p>
<p>GreatAmerica defines this title as having &#8220;the business acumen it takes to be an industry market leader; a long-term outlook, ethical business conduct, customer focus and loyalty to worthy business partners.&#8221;</p>
<p>For more information about GreatAmerica Financial Services, visit their website at: <a href="http://www.greatamerica.com">www.greatamerica.com</a>.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/05/kbs-named-2012-greatamerica-premier-dealer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Printer and MFP Security in the News</title>
		<link>http://www.kraftbusiness.com/blog/2013/04/printer-mfp-security-news/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/04/printer-mfp-security-news/#comments</comments>
		<pubDate>Fri, 19 Apr 2013 12:00:51 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Sharp]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=998</guid>
		<description><![CDATA[Printer and MFP Security in the News Help Keep Your Customers Protected! Addressing published claims of HP® printer and MFP vulnerabilities and reviewing how a Sharp MFP&#8217;s extensive feature set provides data and network security! At Sharp we are dedicated &#8230; <a href="http://www.kraftbusiness.com/blog/2013/04/printer-mfp-security-news/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p align="center"><strong>Printer and MFP Security in the News</strong></p>
<p align="center"><strong><em>Help Keep Your Customers Protected!</em></strong></p>
<p align="center"><em>Addressing published claims of HP<sup>®</sup> printer and MFP vulnerabilities and reviewing how a Sharp MFP&#8217;s</em></p>
<p align="center"><em>extensive feature set provides data and network security!</em></p>
<p>At Sharp we are dedicated to ensuring that our customers are provided with the latest MFP security features and functions; and, we make every effort to<strong>provide you with timely information designed to address current and important topics regarding MFP security</strong>.</p>
<p>A recently published articledetailing a potential <strong>security vulnerability found with HP printers</strong> affords us an opportunity to bring to your attention the many ways, including access control, data security, and network security,<strong>Sharp MFPs can help protect customer data and the networks on which the MFPs reside</strong>.</p>
<p>We have a long-standing tradition of providing the finest security features in the industry. To assist you further please refer to the attached bulletin and matrix&#8211;these items describe in additional detail the many security features available on our equipment.</p>
<p>Sincerely,</p>
<p><strong>RICHARD HUELBIG</strong></p>
<p>Product Manager&#8211;Security &amp; Print</p>
<p>Sharp Imaging And Information Company Of America</p>
<p><a href="http://www.kraftbusiness.com/blog/wp-content/uploads/2013/04/Sharp_Security_At_A_Glance_Matrix_Page_4_3.14.13.pdf">http://www.kraftbusiness.com/blog/wp-content/uploads/2013/04/Sharp_Security_At_A_Glance_Matrix_Page_4_3.14.13.pdf</a></p>
<p><a href="http://www.kraftbusiness.com/blog/?attachment_id=1001">http://www.kraftbusiness.com/blog/?attachment_id=1001</a></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/04/printer-mfp-security-news/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>World Backup Day</title>
		<link>http://www.kraftbusiness.com/blog/2013/04/world-backup-day/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/04/world-backup-day/#comments</comments>
		<pubDate>Mon, 01 Apr 2013 16:15:25 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Cloud]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Sustainability]]></category>
		<category><![CDATA[document management]]></category>
		<category><![CDATA[world backup day]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=993</guid>
		<description><![CDATA[Yesterday was not only Easter, it also served as the third annual World Backup Day. &#8220;There are two kinds of computer owners: those that backup their data, and those who will backup after they lose something irreplaceable. It&#8217;s that last group &#8230; <a href="http://www.kraftbusiness.com/blog/2013/04/world-backup-day/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Yesterday was not only Easter, it also served as the third annual World Backup Day.</p>
<p>&#8220;There are two kinds of computer owners: those that backup their data, and those who will backup after they lose something irreplaceable. It&#8217;s that last group for whom World Backup Day exists, and the special occasion has returned for a third year to make sure we all wind up in that first, very responsible camp.&#8221;</p>
<p>Don&#8217;t be a part of the second camp, ask us about our Disaster Recovery services.</p>
<p>Read the full article by Jon Fingas: <a href="http://www.engadget.com/2013/03/31/world-backup-day-2013/">http://www.engadget.com/2013/03/31/world-backup-day-2013/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/04/world-backup-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Associate HIPAA Compliance – Impact on the Business Associate and Covered Entity</title>
		<link>http://www.kraftbusiness.com/blog/2013/03/business-associate-hipaa-compliance-impact-business-associate-covered-entity/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/03/business-associate-hipaa-compliance-impact-business-associate-covered-entity/#comments</comments>
		<pubDate>Fri, 22 Mar 2013 12:00:27 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Health Care Management]]></category>
		<category><![CDATA[Business Associate]]></category>
		<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=981</guid>
		<description><![CDATA[Introduction: Over the past couple of years with HITECH and now the HIPAA Omnibus Rule, there are higher restrictions with business associates and their vendors.  I want to spend some time talking a little bit about that today. Slide: Agenda &#8230; <a href="http://www.kraftbusiness.com/blog/2013/03/business-associate-hipaa-compliance-impact-business-associate-covered-entity/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Introduction:</strong></p>
<p>Over the past couple of years with HITECH and now the HIPAA Omnibus Rule, there are higher restrictions with business associates and their vendors.  I want to spend some time talking a little bit about that today.</p>
<p><strong>Slide: Agenda</strong></p>
<p>First of all let’s lay out a quick agenda.  I want to talk about HIPAA, HITECH, Omnibus, and how it relates to the Business Associate.  Then we’ll give some background about the relationships those healthcare organizations have with healthcare entities and medical practices.  After, we’ll wrap things up by talking about what comes next; what will be the next step for entities, what will be the next step for Business Associates.  Then we’ll have a summary and Q&amp;A section.</p>
<p><strong>Slide: HIPAA, HITECH, and The Business Associate</strong></p>
<p>First of all, let’s talk about this idea of a Business Associate.  In the HIPPA world we have a couple different types of organizations.  Generally, we know the covered entity gets the most HIPAA exposure; but it’s important to understand that a Business Associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.  So, organizations that provide services to position practices, hospitals, insurance companies are considered Business Associates.</p>
<p><strong>Slide: HIPAA, HITECH, and The Business Associate ctd.</strong></p>
<p>The important phrase in that definition is “certain functions or activities”.  First thing is disclosures.   At this point, a disclosure is the release of some patient information to a third party.  There are some Business Associates or vendors of medical providers that have to make disclosures in some cases.   The main term, or general term, is that of services.</p>
<p>I also want to spend some time talking about this idea of reasonable and appropriate safeguards.  Anybody who has worked with Business Associates knows that you have business associate contracts in place. If you’re a covered entity, a provider or insurance company, you have contracts with your vendors; if you’re a vendor you have contracts with your clients.  In those contracts, which are called, Business Associate Agreement or Business Associate Contracts, the names are used synonymously; there is certain language in there that suggests that a Business Associate has to take reasonable and appropriate safeguards.</p>
<p><strong>Slide: Safeguards- Not Just Vague Language</strong></p>
<p>Now I am going to talk about a bit about that language and what that means.  When we talk about this concept of safeguards it specifically mentions in Business Associates contracts about administrative, physical, and technical safeguards.  In my experience working with a lot of companies, those statements are sometimes interpreted as just safeguards.  And what I think Business Associates are learning more and more is that administrative, physical, and technical safeguards are very specific HIPAA requirements and citations.  So, the point I want to drive home here is when you’re engaged with a Business Associate, or if you’re a Business Associate engaged with a client those terms are very specific HIPAA requirements.  When you’re signing a Business Associate Agreement, understand that you’re committing to meeting those requirements.</p>
<p><strong>Slide: Add HITECH/Omnibus to the Mix</strong></p>
<p>A little bit of history on HIPPA.  We know that it came out in 1996 and that from privacy prospective we’ve all had patients sign HIPAA forms, or signed them ourselves as patients.  Well, the HIPAA rules have changed a little bit over the years.  In particular, the first major change that occurred was when the HITECH Act was introduced in 2009.  HITECH was a part of the American Reinvestment Act stimulus package, and it stands for the Health Information Technology for Economic Recovery and Reinvestment Act of 2009.  There were a number of things that were put into that whole stimulus plan.  First was the introduction of what we now call Meaningful Use; in other words, there were incentives available for  providers who had not yet implemented medical records in electronic form to do so.  The second part of that entire measure was around educating the workforce and the providers on electronic medical records and technology within the healthcare industry.  What is really not widely known is that a good portion of that HITECH Act was set aside to redefine and restructure some portion in HIPAA.</p>
<p><strong>Slide: Post-HITECH/Omnibus HIPAA</strong></p>
<p>The second thing that happened over the last four weeks was we were introduced to the HIPAA Consolidated Omnibus.  The consolidated omnibus was a combination of rules that had changed over the years plus the introduction of new requirements that were added, in what I’m calling “HIPAA 2.0”.  We had some minor revisions along the way and now we have our second version of HIPAA.  So let’s now talk about HITECH and omnibus and what changed relative to HIPAA.  First of all, the physicians who are attesting to meaningful use to receive their incentive, there were specific HIPPA requirements built into the whole Meaningful Use standard.  Enforcement changed; there were increases in the maximum level of fines, there were also various entities that were made responsible for enforcing HIPPA violations.  The other thing that changed is HIPAA ignorance is no longer tolerated.  This means that if there is a violation, in the past, it was frequent that an organization would claim they simply didn’t know they had to comply here or have to comply there, and often times they would get a slap on the wrist and be put in a position where they could remedy the situation.  Well that has changed, and at this point if you are ignorant of your responsibilities that puts you in the category of willful neglect.  The other major piece, the core of this presentation, is the fact that Business Associates and Subcontractors now have the same HIPAA responsibilities as the Covered Entities they service.  This one is key because this one says that the Business Associate has to be HIPAA compliant, and so do their vendors.</p>
<p><strong>Slide: The Business Associate Relationship</strong></p>
<p>I am going to lay out the way HIPAA sees the Business Associate relationship.  Covered entities are your providers, your hospitals, your insurance companies, your clearing houses.  Generally, those covered entities have vendors or groups that provide services; these are defined as the Business Associates.  Additionally, those Business Associates may have companies that provide services, and those organizations in the HIPAA world are called subcontractors to the covered entity.  The Business Associate has responsibilities to the covered entity, and the subcontractor has responsibilities to the Business Associate.  There is a fourth type of organization called a conduit; this is an organization like the US Postal Services or UPS.  Ultimately, that conduit has responsibilities to all three of those.  However, the one thing that has changed is that conduits are exempt from HIPAA compliance for a number of reasons.</p>
<p><strong>Slide: Post-HITECH/Omnibus HIPAA</strong></p>
<p>Now we will go into detail about what changed relative to HITECH and Omnibus as it relates to Business Associates.  One, as mentioned before, is that Business Associates and Subcontractors must comply with all HIPAA Security Rules and relative Privacy Rules.  Business Associates and Subcontractors are now liable for any misuse or failure to safeguard protected health information (PHI).  Business Associates and Subcontractors must have a relative Breach Notification Process; Business Associates now have the responsibility to identify, recognize, and report breaches through the chain accordingly.  Business Associates and Subcontractors are required to provide access to a copy of the electronic protected health information (ePHI) to the covered entity when requested.  For example, if you have electronic medical record software and you request an electronic copy of that medical record, the Business Associate is obligated to provide that to you in a type of disclosure.  Lastly, Business Associates and Subcontractors must provide access to PHI in the event of an audit.  This means that if a Business Associate is chosen for a HIPAA audit, they would have to provide access to the records in the same way that a provider would have to give access to the records.</p>
<p><strong>Slide: HIPAA Compliance Responsibility</strong></p>
<p>I am going to further dive into the responsibilities of the organizations.  So, the Covered Entities, the Business Associate, and the Subcontractor all have responsibilities to achieve and maintain HIPAA Compliance.  All Business Associates may not apply or have relevant compliance responsibilities to each area under the administrative simplification.  It may just be security, depending on the rule, and the purpose they serve.  I also note here that the Conduits do in fact not have HIPPA Compliance Responsibilities.</p>
<p><strong>Slide: Business Associate Impact</strong></p>
<p>Let me explain a little bit why the government is putting significant effort in making sure that the BA’s and their vendors are meeting compliance.  These stats were pulled from the Office for Civil Rights Health and Human Services, known as the “wall of shame”; it’s when an organization has a breach of 500 or more individuals who are affected by that breach.  Ultimately, between September 2009 and December 2012, there have been breaches and the number of patients affected by those breaches is 21,516,294.  The numbers that stand out to me are that Business Associates were involved in 21% of those breaches; when you look at the total individuals affected, Business Associates were responsible for 57% of the individuals breached.  What were saying here is that the healthcare organizations whose patients were breached, 57% of those individuals was the fault of one of their vendors.  As you look at the average individuals per breach, when a BA is involved, there is an average of 106,698 individuals involved per breach.  Anybody that has had to deal with a breach knows that it has to be dealt with in terms of cost per individual per breach.</p>
<p><strong>Slide: The Covered Entity’s Perspective</strong></p>
<p>So, let’s look at it from the Covered Entity’s perspective.  So, we may have organizations on this call that are providers or Business Associates.  I am first going to draw out some enforcement activities, specifically, the categories of enforcement that have been laid out.</p>
<p>The worst possible scenario is to commit a breach or have an audit and be in a category of willful neglect where nothing is corrected.  The second willful neglect category is where the violation is corrected.  The third category, which is less severe than the other two, is due to reasonable cause and not willful neglect.  The final category, and the best scenario you could be in if a breach does occur, is by exercising reasonable diligence would not have known.   Understand that, in the event of a breach, or in the event of an audit or investigation, recognize that a fine or penalty is extremely likely, where you fall on this spectrum is directly proportional to the amount of work you’ve done to become compliant and stay compliant.  The purpose of this slide is that with the increasing degree of effort, you decrease your decrease your degree of HIPAA Compliance Risk.</p>
<p><strong>Slide: The Covered Entity’s Relationships with Business Associates  </strong></p>
<p>Now, let’s talk specifically about the Business Associate relationship and how that factors in.   I drew the same parallel with the increasing degree of HIPAA Compliance effort by the Covered Entity, Business Associate, and Subcontractor and its relationship to the decreasing degree of HIPAA Compliance Risk to the Covered Entity.</p>
<p>The worst possible scenario that can exist is that you could be doing business with an organization, a Business Associate, and have no BA contract in place.  Obviously, the next best step is to have a BA contract in place.  The next best step, relative to impact of the Covered Entity, is if the Business Associate or Subcontractor has conducted a risk assessment.  The next best step is that the BA or Subcontractor is taking necessary steps to compliance.  The most optimal step is if the BA or Subcontractor   produces proof of HIPAA Compliance.</p>
<p>Now, there’s a couple of questions any myths that float around, and I’ll go over those later, but it’s important to understand that the further you take this HIPAA effort, the decreasing amount of risk you’re presenting to your client.  One of the questions I often ask is is there a see no evil, hear no evil mentality for HIPAA.  In other words, if I don’t do a risk assessment and I don’t uncover anything that’s vulnerable, am I in a worse position than if I were to discover it and uncover it.  The answer is yes.  If you elect not to perform a risk assessment or to take yourself down the path of business and healthcare and you haven’t done, at the minimum a BA contract or risk assessment, you’re in this situation of willful neglect.  In other words, the government or auditor would rather see you do something and perhaps not achieve 100% compliance, but do something on that path as opposed to doing nothing.  And of course, as you can imagine, the level of fines and enforcement are relative as you cross the spectrum.</p>
<p><strong>Slide: Common Questions</strong></p>
<p>So I said I’d go over some common myths and questions.  First, is the Covered Entity responsible for their Business Associate’s or Subcontractor’s HIPAA Compliance, or vice versa?  And the answer to that is no.</p>
<p>Second, is the Covered Entity responsible for engaging in relationships with HIPAA Compliant Business Associates and Subcontractors?  And the answer to that is absolutely.  The Covered Entity has a responsibility of diligence that they have to execute in making sure that they’re doing business with those who will protect their information.</p>
<p>The last question I’m commonly asked is if the Business Associate or Subcontractor claims HIPAA Compliance, does this imply that the Covered Entity is HIPAA Compliant?  And the answer to that is no.  This is very common, and I’ll give you a great example of where I see this.  When a practice or a provider implements and electronic medical records software and that EMR software developer produces a HIPAA Compliant statement, many organizations believe that because they have that in hand that they have filled their HIPAA Responsibilities.  When, in actuality, that’s not the case.  The practice, provider, health system insurance company has to do their own HIPAA Compliance measures.</p>
<p><strong>Slide: HIPAA Compliance of Business Associates and Subcontractors</strong></p>
<p>As I see it, in the HIPAA world, when you’re working with a Business Associate you have two types of compliance that should be measured.  The first is solution compliance.  For example, I’m going to use the idea of an electronic medical record solution.  The solution means that the EMR is HIPAA compliant and is hosted in a HIPAA compliant Facility.  In other words, the development of that application includes all the measures to control items such as having everyone use their I.D., having audit trails within the EMR, and other factors.</p>
<p>However, on the institutional compliance side I’m looking for that EMR Company and Hosting Company to have gone through an exercise to make sure that they have all the correct policies and procedures in place, to make sure their employees have been trained, to make sure they have a disaster recovery plan in the event that wherever their EMR is hosted was essentially taken care of in the event of a disaster.  So I’m looking at it from two perspectives, and it’s important that as you deal with your Business Associates, you look at it as well.  Another example would be a basic shredding company.  For example, I know that now a days that a lot of shredding companies will actually drive a truck to your office where they shred it on site.  So in other words, they’re showing you a HIPAA compliance solution.  However, my question to them is have your employees been trained? Do you have policies around sanctioning employees if they happen to commit a HIPAA violation?  So there are two areas to make sure are reviewed in this process.</p>
<p><strong>Slide: A Healthcare Scenario</strong></p>
<p>I also mentioned earlier that I would lay out a scenario of a basic single doctor healthcare practice and show you the complexities that exist.  You’re looking at a diagram that shows a physicians practice in the left corner.  That physician practice may use an electronic medical record that is hosted in the cloud.  That cloud has a disaster recovery site and is also connected with the medical record company.   That practice may also use an It Services company that works with their local work stations and servers, a document destruction company to do their shredding, they may also interface with the lab and the insurance company.  So when you start laying out this scenario, and you look at where the PHI is located, what you find is that PHI owned by the doctor is in a lot of different places.  Therefore, when you start looking at who has HIPAA Responsibility, everybody who has physical or technical visibility to that patient information is responsible for HIPAA Compliance.</p>
<p><strong>Slide: What constitutes compliance?</strong></p>
<p>The other important thing is to recognize what constitutes compliance.  For example, I always look at it in a three pronged approach.  When you look at things you have within your business; you have antivirus software, everyone has a login I.D., you do backup and recovery.  You have the technical capabilities to do this which I lumped in this whole category called safeguards.  To the left of that is policy; you have to have policy and procedures surrounding each one of those.  In other words, how often do you backup?  Who does it?  How is it done, how is it recovered?  The third, and most important, is to be able to prove that.  It’s great in practice to say “I do ABC”, but it’s something different in an audit situation when you have to prove that you do it.  I always equate HIPAA to the IRS.  Yes, it’s great to be able to say I spent this much here and this much there, but if the IRS comes out they are going to want proof of it.  It is the same thing with HIPAA when an audit occurs.</p>
<p><strong>Slide: Who enforces HIPAA Compliance?</strong></p>
<p>So, very quickly about who enforces HIPAA.  One, it is enforced through the United States Department of Health and Human Services in the Office for Civil Rights.  In addition to that, along with the HITECH Act, there were also funds that were appropriated to train individuals within each individual state’s Office of the Attorney General or HIPAA enforcement on behalf of the public.  So there are a couple entities that take after enforcing HIPAA.</p>
<p><strong>Slide: Is there an easy way to take the first step?</strong></p>
<p>Introduction:</p>
<p>Over the past couple of years with HITECH and now the HIPAA Omnibus Rule, there are higher restrictions with business associates and their vendors.  I want to spend some time talking a little bit about that today.</p>
<p>Slide: Agenda</p>
<p>First of all let’s lay out a quick agenda.  I want to talk about HIPAA, HITECH, Omnibus, and how it relates to the Business Associate.  Then we’ll give some background about the relationships those healthcare organizations have with healthcare entities and medical practices.  After, we’ll wrap things up by talking about what comes next; what will be the next step for entities, what will be the next step for Business Associates.  Then we’ll have a summary and Q&amp;A section.</p>
<p>Slide: HIPAA, HITECH, and The Business Associate</p>
<p>First of all, let’s talk about this idea of a Business Associate.  In the HIPPA world we have a couple different types of organizations.  Generally, we know the covered entity gets the most HIPAA exposure; but it’s important to understand that a Business Associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.  So, organizations that provide services to position practices, hospitals, insurance companies are considered Business Associates.</p>
<p>Slide: HIPAA, HITECH, and The Business Associate ctd.</p>
<p>The important phrase in that definition is “certain functions or activities”.  First thing is disclosures.   At this point, a disclosure is the release of some patient information to a third party.  There are some Business Associates or vendors of medical providers that have to make disclosures in some cases.   The main term, or general term, is that of services.</p>
<p>I also want to spend some time talking about this idea of reasonable and appropriate safeguards.  Anybody who has worked with Business Associates knows that you have business associate contracts in place. If you’re a covered entity, a provider or insurance company, you have contracts with your vendors; if you’re a vendor you have contracts with your clients.  In those contracts, which are called, Business Associate Agreement or Business Associate Contracts, the names are used synonymously; there is certain language in there that suggests that a Business Associate has to take reasonable and appropriate safeguards.</p>
<p>Slide: Safeguards- Not Just Vague Language</p>
<p>Now I am going to talk about a bit about that language and what that means.  When we talk about this concept of safeguards it specifically mentions in Business Associates contracts about administrative, physical, and technical safeguards.  In my experience working with a lot of companies, those statements are sometimes interpreted as just safeguards.  And what I think Business Associates are learning more and more is that administrative, physical, and technical safeguards are very specific HIPAA requirements and citations.  So, the point I want to drive home here is when you’re engaged with a Business Associate, or if you’re a Business Associate engaged with a client those terms are very specific HIPAA requirements.  When you’re signing a Business Associate Agreement, understand that you’re committing to meeting those requirements.</p>
<p>Slide: Add HITECH/Omnibus to the Mix</p>
<p>A little bit of history on HIPPA.  We know that it came out in 1996 and that from privacy prospective we’ve all had patients sign HIPAA forms, or signed them ourselves as patients.  Well, the HIPAA rules have changed a little bit over the years.  In particular, the first major change that occurred was when the HITECH Act was introduced in 2009.  HITECH was a part of the American Reinvestment Act stimulus package, and it stands for the Health Information Technology for Economic Recovery and Reinvestment Act of 2009.  There were a number of things that were put into that whole stimulus plan.  First was the introduction of what we now call Meaningful Use; in other words, there were incentives available for  providers who had not yet implemented medical records in electronic form to do so.  The second part of that entire measure was around educating the workforce and the providers on electronic medical records and technology within the healthcare industry.  What is really not widely known is that a good portion of that HITECH Act was set aside to redefine and restructure some portion in HIPAA.</p>
<p>Slide: Post-HITECH/Omnibus HIPAA</p>
<p>The second thing that happened over the last four weeks was we were introduced to the HIPAA Consolidated Omnibus.  The consolidated omnibus was a combination of rules that had changed over the years plus the introduction of new requirements that were added, in what I’m calling “HIPAA 2.0”.  We had some minor revisions along the way and now we have our second version of HIPAA.  So let’s now talk about HITECH and omnibus and what changed relative to HIPAA.  First of all, the physicians who are attesting to meaningful use to receive their incentive, there were specific HIPPA requirements built into the whole Meaningful Use standard.  Enforcement changed; there were increases in the maximum level of fines, there were also various entities that were made responsible for enforcing HIPPA violations.  The other thing that changed is HIPAA ignorance is no longer tolerated.  This means that if there is a violation, in the past, it was frequent that an organization would claim they simply didn’t know they had to comply here or have to comply there, and often times they would get a slap on the wrist and be put in a position where they could remedy the situation.  Well that has changed, and at this point if you are ignorant of your responsibilities that puts you in the category of willful neglect.  The other major piece, the core of this presentation, is the fact that Business Associates and Subcontractors now have the same HIPAA responsibilities as the Covered Entities they service.  This one is key because this one says that the Business Associate has to be HIPAA compliant, and so do their vendors.</p>
<p>Slide: The Business Associate Relationship</p>
<p>I am going to lay out the way HIPAA sees the Business Associate relationship.  Covered entities are your providers, your hospitals, your insurance companies, your clearing houses.  Generally, those covered entities have vendors or groups that provide services; these are defined as the Business Associates.  Additionally, those Business Associates may have companies that provide services, and those organizations in the HIPAA world are called subcontractors to the covered entity.  The Business Associate has responsibilities to the covered entity, and the subcontractor has responsibilities to the Business Associate.  There is a fourth type of organization called a conduit; this is an organization like the US Postal Services or UPS.  Ultimately, that conduit has responsibilities to all three of those.  However, the one thing that has changed is that conduits are exempt from HIPAA compliance for a number of reasons.</p>
<p>Slide: Post-HITECH/Omnibus HIPAA</p>
<p>Now we will go into detail about what changed relative to HITECH and Omnibus as it relates to Business Associates.  One, as mentioned before, is that Business Associates and Subcontractors must comply with all HIPAA Security Rules and relative Privacy Rules.  Business Associates and Subcontractors are now liable for any misuse or failure to safeguard protected health information (PHI).  Business Associates and Subcontractors must have a relative Breach Notification Process; Business Associates now have the responsibility to identify, recognize, and report breaches through the chain accordingly.  Business Associates and Subcontractors are required to provide access to a copy of the electronic protected health information (ePHI) to the covered entity when requested.  For example, if you have electronic medical record software and you request an electronic copy of that medical record, the Business Associate is obligated to provide that to you in a type of disclosure.  Lastly, Business Associates and Subcontractors must provide access to PHI in the event of an audit.  This means that if a Business Associate is chosen for a HIPAA audit, they would have to provide access to the records in the same way that a provider would have to give access to the records.</p>
<p>Slide: HIPAA Compliance Responsibility</p>
<p>I am going to further dive into the responsibilities of the organizations.  So, the Covered Entities, the Business Associate, and the Subcontractor all have responsibilities to achieve and maintain HIPAA Compliance.  All Business Associates may not apply or have relevant compliance responsibilities to each area under the administrative simplification.  It may just be security, depending on the rule, and the purpose they serve.  I also note here that the Conduits do in fact not have HIPPA Compliance Responsibilities.</p>
<p>Slide: Business Associate Impact</p>
<p>Let me explain a little bit why the government is putting significant effort in making sure that the BA’s and their vendors are meeting compliance.  These stats were pulled from the Office for Civil Rights Health and Human Services, known as the “wall of shame”; it’s when an organization has a breach of 500 or more individuals who are affected by that breach.  Ultimately, between September 2009 and December 2012, there have been breaches and the number of patients affected by those breaches is 21,516,294.  The numbers that stand out to me are that Business Associates were involved in 21% of those breaches; when you look at the total individuals affected, Business Associates were responsible for 57% of the individuals breached.  What were saying here is that the healthcare organizations whose patients were breached, 57% of those individuals was the fault of one of their vendors.  As you look at the average individuals per breach, when a BA is involved, there is an average of 106,698 individuals involved per breach.  Anybody that has had to deal with a breach knows that it has to be dealt with in terms of cost per individual per breach.</p>
<p>Slide: The Covered Entity’s Perspective</p>
<p>So, let’s look at it from the Covered Entity’s perspective.  So, we may have organizations on this call that are providers or Business Associates.  I am first going to draw out some enforcement activities, specifically, the categories of enforcement that have been laid out.</p>
<p>The worst possible scenario is to commit a breach or have an audit and be in a category of willful neglect where nothing is corrected.  The second willful neglect category is where the violation is corrected.  The third category, which is less severe than the other two, is due to reasonable cause and not willful neglect.  The final category, and the best scenario you could be in if a breach does occur, is by exercising reasonable diligence would not have known.   Understand that, in the event of a breach, or in the event of an audit or investigation, recognize that a fine or penalty is extremely likely, where you fall on this spectrum is directly proportional to the amount of work you’ve done to become compliant and stay compliant.  The purpose of this slide is that with the increasing degree of effort, you decrease your decrease your degree of HIPAA Compliance Risk.</p>
<p>Slide: The Covered Entity’s Relationships with Business Associates</p>
<p>Now, let’s talk specifically about the Business Associate relationship and how that factors in.   I drew the same parallel with the increasing degree of HIPAA Compliance effort by the Covered Entity, Business Associate, and Subcontractor and its relationship to the decreasing degree of HIPAA Compliance Risk to the Covered Entity.</p>
<p>The worst possible scenario that can exist is that you could be doing business with an organization, a Business Associate, and have no BA contract in place.  Obviously, the next best step is to have a BA contract in place.  The next best step, relative to impact of the Covered Entity, is if the Business Associate or Subcontractor has conducted a risk assessment.  The next best step is that the BA or Subcontractor is taking necessary steps to compliance.  The most optimal step is if the BA or Subcontractor   produces proof of HIPAA Compliance.</p>
<p>Now, there’s a couple of questions any myths that float around, and I’ll go over those later, but it’s important to understand that the further you take this HIPAA effort, the decreasing amount of risk you’re presenting to your client.  One of the questions I often ask is is there a see no evil, hear no evil mentality for HIPAA.  In other words, if I don’t do a risk assessment and I don’t uncover anything that’s vulnerable, am I in a worse position than if I were to discover it and uncover it.  The answer is yes.  If you elect not to perform a risk assessment or to take yourself down the path of business and healthcare and you haven’t done, at the minimum a BA contract or risk assessment, you’re in this situation of willful neglect.  In other words, the government or auditor would rather see you do something and perhaps not achieve 100% compliance, but do something on that path as opposed to doing nothing.  And of course, as you can imagine, the level of fines and enforcement are relative as you cross the spectrum.</p>
<p>Slide: Common Questions</p>
<p>So I said I’d go over some common myths and questions.  First, is the Covered Entity responsible for their Business Associate’s or Subcontractor’s HIPAA Compliance, or vice versa?  And the answer to that is no.</p>
<p>Second, is the Covered Entity responsible for engaging in relationships with HIPAA Compliant Business Associates and Subcontractors?  And the answer to that is absolutely.  The Covered Entity has a responsibility of diligence that they have to execute in making sure that they’re doing business with those who will protect their information.</p>
<p>The last question I’m commonly asked is if the Business Associate or Subcontractor claims HIPAA Compliance, does this imply that the Covered Entity is HIPAA Compliant?  And the answer to that is no.  This is very common, and I’ll give you a great example of where I see this.  When a practice or a provider implements and electronic medical records software and that EMR software developer produces a HIPAA Compliant statement, many organizations believe that because they have that in hand that they have filled their HIPAA Responsibilities.  When, in actuality, that’s not the case.  The practice, provider, health system insurance company has to do their own HIPAA Compliance measures.</p>
<p>Slide: HIPAA Compliance of Business Associates and Subcontractors</p>
<p>As I see it, in the HIPAA world, when you’re working with a Business Associate you have two types of compliance that should be measured.  The first is solution compliance.  For example, I’m going to use the idea of an electronic medical record solution.  The solution means that the EMR is HIPAA compliant and is hosted in a HIPAA compliant Facility.  In other words, the development of that application includes all the measures to control items such as having everyone use their I.D., having audit trails within the EMR, and other factors.</p>
<p>However, on the institutional compliance side I’m looking for that EMR Company and Hosting Company to have gone through an exercise to make sure that they have all the correct policies and procedures in place, to make sure their employees have been trained, to make sure they have a disaster recovery plan in the event that wherever their EMR is hosted was essentially taken care of in the event of a disaster.  So I’m looking at it from two perspectives, and it’s important that as you deal with your Business Associates, you look at it as well.  Another example would be a basic shredding company.  For example, I know that now a days that a lot of shredding companies will actually drive a truck to your office where they shred it on site.  So in other words, they’re showing you a HIPAA compliance solution.  However, my question to them is have your employees been trained? Do you have policies around sanctioning employees if they happen to commit a HIPAA violation?  So there are two areas to make sure are reviewed in this process.</p>
<p>Slide: A Healthcare Scenario</p>
<p>I also mentioned earlier that I would lay out a scenario of a basic single doctor healthcare practice and show you the complexities that exist.  You’re looking at a diagram that shows a physicians practice in the left corner.  That physician practice may use an electronic medical record that is hosted in the cloud.  That cloud has a disaster recovery site and is also connected with the medical record company.   That practice may also use an It Services company that works with their local work stations and servers, a document destruction company to do their shredding, they may also interface with the lab and the insurance company.  So when you start laying out this scenario, and you look at where the PHI is located, what you find is that PHI owned by the doctor is in a lot of different places.  Therefore, when you start looking at who has HIPAA Responsibility, everybody who has physical or technical visibility to that patient information is responsible for HIPAA Compliance.</p>
<p>Slide: What constitutes compliance?</p>
<p>The other important thing is to recognize what constitutes compliance.  For example, I always look at it in a three pronged approach.  When you look at things you have within your business; you have antivirus software, everyone has a login I.D., you do backup and recovery.  You have the technical capabilities to do this which I lumped in this whole category called safeguards.  To the left of that is policy; you have to have policy and procedures surrounding each one of those.  In other words, how often do you backup?  Who does it?  How is it done, how is it recovered?  The third, and most important, is to be able to prove that.  It’s great in practice to say “I do ABC”, but it’s something different in an audit situation when you have to prove that you do it.  I always equate HIPAA to the IRS.  Yes, it’s great to be able to say I spent this much here and this much there, but if the IRS comes out they are going to want proof of it.  It is the same thing with HIPAA when an audit occurs.</p>
<p>Slide: Who enforces HIPAA Compliance?</p>
<p>So, very quickly about who enforces HIPAA.  One, it is enforced through the United States Department of Health and Human Services in the Office for Civil Rights.  In addition to that, along with the HITECH Act, there were also funds that were appropriated to train individuals within each individual state’s Office of the Attorney General or HIPAA enforcement on behalf of the public.  So there are a couple entities that take after enforcing HIPAA.</p>
<p>Slide: Is there an easy way to take the first step?</p>
<p>So the question now is if there is an easy way to take the first step?  Well, one, I want to reiterate that you should treat HIPAA compliance with the same degree of diligence and urgency as accounting, taxes, and the IRS.  Start with a simple checklist, particularly if you are a Business Associate, of areas that need to be addressed.  For example, with our organization we have a specific services working with Business Associates to help understand their requirements, help understand where their HIPAA vulnerabilities exist, and then help them through that process; in other words, we perform a risk assessment.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>So the question now is if there is an easy way to take the first step?  Well, one, I want to reiterate that you should treat HIPAA compliance with the same degree of diligence and urgency as accounting, taxes, and the IRS.  Start with a simple checklist, particularly if you are a Business Associate, of areas that need to be addressed.  For example, with our organization we have a specific services working with Business Associates to help understand their requirements, help understand where their HIPAA vulnerabilities exist, and then help them through that process; in other words, we perform a risk assessment.</p>
<p>&nbsp;</p>
<p>To view the presentation, click the link below:</p>
<p><a href="http://www.slideshare.net/HealthCareManagement/business-associate-hipaa-compliance-impact-on-the-business-associate-and-covered-entities">http://www.slideshare.net/HealthCareManagement/business-associate-hipaa-compliance-impact-on-the-business-associate-and-covered-entities</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/03/business-associate-hipaa-compliance-impact-business-associate-covered-entity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lexmark &amp; KBS Happy Hour</title>
		<link>http://www.kraftbusiness.com/blog/2013/03/lexmark-kbs-happy-hour/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/03/lexmark-kbs-happy-hour/#comments</comments>
		<pubDate>Mon, 18 Mar 2013 18:00:10 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[acorn grille]]></category>
		<category><![CDATA[Happy Hour]]></category>
		<category><![CDATA[kraft]]></category>
		<category><![CDATA[lexmark]]></category>
		<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=977</guid>
		<description><![CDATA[Kraft Business Systems and Lexmark are excited to host a Happy Hour on Wednesday, April 3rd from 4:00 &#8211; 7:00 pm at Thousand Oaks.  We are proud to introduce new products, features, and much more.  We also are very excited &#8230; <a href="http://www.kraftbusiness.com/blog/2013/03/lexmark-kbs-happy-hour/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Kraft Business Systems and Lexmark are excited to host a Happy Hour on Wednesday, April 3rd from 4:00 &#8211; 7:00 pm at Thousand Oaks.  We are proud to introduce new products, features, and much more.  We also are very excited for an opportunity to interact with you.</p>
<p>We hope you will join us and we look forward to seeing you there!</p>
<div>
<div>
<div>
<div>The Acorn Grille @ Thousand Oaks</div>
<div>
<div id="u_jsonp_8_6">4100 Thousand Oaks Drive, Grand Rapids, Michigan 49525</div>
</div>
</div>
</div>
</div>
<p>RSVP via<a href="http://www.facebook.com/home.php#!/events/503033013091540/"> Facebook </a>or contact Nicole Rodammer at (616) 977-2679.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/03/lexmark-kbs-happy-hour/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Compliance Webinar Reminder</title>
		<link>http://www.kraftbusiness.com/blog/2013/03/hipaa-compliance-webinar-reminder/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/03/hipaa-compliance-webinar-reminder/#comments</comments>
		<pubDate>Mon, 11 Mar 2013 12:00:09 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Health Care Management]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[webinar]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=974</guid>
		<description><![CDATA[HIPAA Compliance Webinar:  Impact on the Business Associate and Covered Entity March 20 – 12:15-1 p.m. Joe Dylewski, Managing HIPAA Partner at Health Care Management, will be talking about Business Associates and their involvement in the HIPAA Omnibus Rule .  &#8230; <a href="http://www.kraftbusiness.com/blog/2013/03/hipaa-compliance-webinar-reminder/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>HIPAA Compliance Webinar:  Impact on the Business Associate and Covered Entity</strong></p>
<p><strong>March 20 – 12:15-1 p.m.</strong></p>
<p>Joe Dylewski, Managing HIPAA Partner at Health Care Management, will be talking about Business Associates and their involvement in the HIPAA Omnibus Rule .  A &#8220;business associate&#8221; is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.</p>
<p>Register Here: <a href="https://www3.gotomeeting.com/register/736002358" target="_blank">https://www3.gotomeeting.com/<wbr>register/736002358</wbr></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/03/hipaa-compliance-webinar-reminder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why life through Google Glass should be for our eyes only</title>
		<link>http://www.kraftbusiness.com/blog/2013/03/life-google-glass-eyes/</link>
		<comments>http://www.kraftbusiness.com/blog/2013/03/life-google-glass-eyes/#comments</comments>
		<pubDate>Tue, 05 Mar 2013 17:00:47 +0000</pubDate>
		<dc:creator>nicole</dc:creator>
				<category><![CDATA[Kraft Business Systems]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[google glass]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[kraft business]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.kraftbusiness.com/blog/?p=972</guid>
		<description><![CDATA[By Andrew Keen &#8220;When we put on these surveillance devices, we all become spies, or scrooglers, of everything and everyone around us.&#8221; As the technological world continues to grow, Google will soon put us in a position where our privacy &#8230; <a href="http://www.kraftbusiness.com/blog/2013/03/life-google-glass-eyes/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>By Andrew Keen</p>
<p>&#8220;When we put on these surveillance devices, we all become spies, or scrooglers, of everything and everyone around us.&#8221;</p>
<p>As the technological world continues to grow, Google will soon put us in a position where our privacy disappears.  The revolutionary Google Glass will let one of the most powerful companies in the world see what we see and tailor itself to our every want and need&#8230;but at what cost to us?</p>
<p>&nbsp;</p>
<p>Read the full article: <a href="http://www.cnn.com/2013/02/25/tech/innovation/google-glass-privacy-andrew-keen/index.html?iid=article_sidebar">http://www.cnn.com/2013/02/25/tech/innovation/google-glass-privacy-andrew-keen/index.html?iid=article_sidebar</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.kraftbusiness.com/blog/2013/03/life-google-glass-eyes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
