The practice was formed by nationally-known and widely-respected information technology attorney John R. Christiansen after many years in large, national law and consulting firm practice, to provide service more directly, flexibly and creatively.
I started this blog to try to help move information security theory and practice forward as both an intellectual discipline and professional practice area. Information security as a discipline is very new, as are the technologies involved and the professional disciplines of computer science, network implementation, and information management upon which information security builds. And […]
The following policy is intended to set up a structure for security incident response for healthcare organizations. It takes into account HIPAA as well as state security incident response laws, as well as other federal requirements and the other information security laws of most US states. (It might well be consistent with all of them […]
That’s what I call this. It’s more fully justified and explained in Christiansen, An Integrated Standard of Care for Healthcare Information Security (2005): Integrated Information Security Standard of Care 1. An information security duty of care exists when an entity: a. Uses an information system to create, store, process or transmit information, and b. The […]