PogoWasRight.org

Menu
  • About
  • Privacy
Menu

The FISMA challenge

Posted on August 15, 2009July 3, 2025 by Dissent

Carolyn Duffy Marsan has an informative piece on Government Health IT about the different requirements of different pieces of federal legislation and how they impact sharing federally held health data with the private sector. She writes, in part:

FISMA has 171 information security controls that are mandated for federal agencies. In contrast, the U.S. healthcare industry must meet the Health Insurance Portability and Accountability Act (HIPAA), which has only 101 of the FISMA controls.

“There is a gap of approximately 70 controls between FISMA and HIPAA,” Sankaran said. The challenge in healthcare information exchange is that data will be flowing from a more-secure FISMA- compliant federal system to a less-secure HIPAA-compliant private sector system.

“How do you make sure the information remains secure as it flows through two different domains of security controls?” Sankaran asked.

Among the questions that needs an answer from OMB is whether data that moves from a federal computer system to a private sector system is still considered federal data, and whether the recipient of that data needs to comply with FISMA. “This requires clear guidance from OMB to the agencies’ Designated Approving Authorities (DAAs) about moving data between federal and private sector systems,” Sankaran said.

Read more on Government Health IT.

Related posts:

  • “Out Of Control”: Dozens of Telehealth Startups Sent Sensitive Health Information to Big Tech Companies
Category: Featured NewsLawsU.S.

Post navigation

← Clooney to sue paparazzi over photos
NSWLRC recommends privacy cause of action →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

RSS Recent Posts at DataBreaches.net

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
©2025 PogoWasRight.org. All rights reserved.