Logo

    pipeda

    Explore "pipeda" with insightful episodes like "Decoding Quebec’s Law 25: What Companies Need To Know With Sharon Bauer", "PIPEDA’s Mandatory Privacy Breach Notification | Episode #084", "GDPR: Government Regulation and the Photo Industry" and "2018-007- Memcached DDoS, Secure Framework Documentation, and chromebook hacking" from podcasts like ""She Said Privacy/He Said Security", "Practice Management Nuggets", "Hanging Pixels Podcast" and "Brakeing Down Security Podcast"" and more!

    Episodes (4)

    Decoding Quebec’s Law 25: What Companies Need To Know With Sharon Bauer

    Decoding Quebec’s Law 25: What Companies Need To Know With Sharon Bauer

    Sharon Bauer is a Lawyer and the Founder of Bamboo Data Consulting, a team of privacy consultants specializing in privacy, security, data strategy, and cutting-edge technology ethics work. As a consultant, she provides privacy solutions for various entities including retail, fintech, health, and education. Sharon is an expert in designing creative privacy programs solving hidden challenges for startups and international corporations. In addition to acting as a virtual chief privacy officer, IT World Canada named Sharon one of the Top 20 Women in Cybersecurity in 2022.

    In this episode…

    Quebec Law 25 is Quebec's privacy legislation, which applies to businesses or businesses collecting Quebec data. As a relatively new law, many companies need to know its governance framework. What are the critical concepts of Law 25, and how does it apply to company compliance?

    Privacy lawyer and consultant Sharon Bauer explains that companies should understand Law 25’s key components: governance, privacy officer, transfer impact assessment, transparency, and employment. However, this privacy legislation does not apply to B2B businesses. Regarding privacy officers, Quebecian CEOs must either appoint a PO or hold themselves accountable for compliance with Law 25. Additionally, companies must adhere to the transfer impact assessment or privacy impact assessment when data is transferred outside of Quebec, when acquiring personal information, or when overhauling electronic service delivery systems involving destroying personal information. Sharon warns that companies that fail to comply with Quebec’s Law 25 are subject to a $25 million fine.

    In this episode of the She Said Privacy/He Said Security Podcast, Jodi and Justin Daniels welcome Sharon Bauer, Founder of Bamboo Data Consulting, to examine Quebec’s Law 25. Sharon reflects on her career background, discusses the intersection of Law 25 and the GDPR, and Canada’s basis for Personal Information Protection and Electronics Data Act (PIPEDA).

    PIPEDA’s Mandatory Privacy Breach Notification | Episode #084

    PIPEDA’s Mandatory Privacy Breach Notification | Episode #084

     

    Organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private sector privacy law, are required to report to the Office of the Privacy Commissioner (OPC) any breaches of security safeguards involving personal information that pose a real risk of significant harm to individuals. They also need to notify affected individuals about those breaches, and keep records of all data breaches within the organization.

    On today's podcast, PIPEDA’s Mandatory Privacy Breach Notification, we will look at how PIPEDA applies to healthcare organizations and the vendors that support them.

    The Privacy Commissioner shares lessons learned after one year of mandatory breach reporting requirements under PIPEDA.

    Does PIPEDA Apply To You?

    PIPEDA applies to private sector businesses across Canada with the exception of Quebec, Alberta, and BC. In these provinces, provincial legislation wish is substantially similar to PIPEDA applies. In all cases, businesses which handle personal information which crosses provincial or national borders fall under PIPEDA regardless of which province that they are based in.

    In Alberta, we have privacy legislation called the Health Information Act (HIA) that takes precedence over PIPEDA and Alberta's Personal Information Protection Act, (PIPA). If a business, like a physician's office, has a privacy breach which includes health information, then the custodian of the physician office must report the privacy breach following the HIA regulations. If it's employee information or other non-health information is included in the breach then that triggers privacy breach notification under PIPA. Sometimes, a breach can include both types of information and the physician office must notify under both legislation.

    In BC the Personal Information Protection Act (PIPA) is BC's private sector privacy laws has also been deemed substantially similar to the federal private sector privacy law. BC does not have health information specific privacy legislation, so PIPA applies to private organizations in BC, including physician practices, and governs how the personal information about patients, employees and volunteers may be collected, used and disclosed.

    If you are a business in Canada, for example, an electronic medical records (EMR) business and you have a data center in Canada where all of your clients provide their information and store it in your data center, the EMR vendor likely falls under the PIPEDA regulations.

    The vendor may be responsive to other legislation as well. If you are an EMR vendor, you do not directly comply with the HIA in Alberta because that applies only to custodians. However, as an information manager of a custodian under the HIA, you have some obligations under the HIA in the event of a privacy breach. But that does not mean that you don't also have obligations under PIPEDA.

    Listen to the podcast to learn more!

    Show Notes

    You can advance the audio to the time entries

    03:00  PIPEDA

    03:18  Does PIPEDA apply to you?

    04:11  Alberta

    04:53  British Columbia

    05:26  EMR vendor and businesses that support healthcare practices

    06:52  What is personal information

    07:44  Why is privacy important?

    In 2017, 65% of large organizations with more than 100 employees indicated that they were privacy aware, but only 43% of small businesses indicated that they were privacy aware.

    09:11  What Is A Privacy Breach

    12:44  PIPEDA Mandatory Privacy Breach Reporting Process

    12:55  Keep Records

    13:27  ROSH

    14:04  Report to the OPC

    14:10  Notification

    Information Manager Agreement – should indicate if a vendor should directly notify a patient about the privacy breach or if the custodian will do the notification. The Information Manager Agreement should also identify which party (parties) is responsible for the cost of notification.

    See the Practice Management Success Tip – Top 3 Agreements https://InformationManagers.ca/Top-3

    15:46  What is ROSH?

    17:47  What information, circumstances of the breach.

    19:33   CASL Canada’s Anti-Spam Legislation

    20:34  Good Privacy Is Good For Business

    When we know better, we can do better…

    I’ve helped hundreds of healthcare practices prevent privacy breach pain like this. If you would like to discuss how I can help your practice, just send me an email. I am here to help you protect your practice.

    How to Manage a Privacy Breach with Confidence

    The 4 Step Response Plan will help you with prevent privacy breach pain and give you the tips, templates, training, and tools that you can use right away to prepare your privacy breach response plan:

    In the world of privacy breaches ‘If’ has become ‘When’. Will you be ready?

    Link to 4 Step Response Plan

    Click here for more information on the on-line 4 Step Response Plan course available now!

    https://informationmanagers.ca/4-step


    New! Podcast Key Word Search Tool

    Did you hear something on today’s podcast that you would like to go back and listen to again?

    Searchie Lady

    Or, maybe you heard something on one of our previous podcasts that you want to listen to again, but you can’t remember which one and you would like to find it quickly and easily.

    Well, that’s easy to do now!

    If you heard something on this podcast that you want to re-visit, go to PracticeManagementNuggets.Live/search and enter the keyword in the magic box.

    You will automatically be brought to the podcast at the exact spot where we talked about it.


    Rate and Review the Podcast

    I am honoured that you choose to spend your time with me today. Thank you for the opportunity to share my obsession about privacy, confidentiality and security with you!

    Reviews for the podcast on whatever platform that you use is greatly appreciated!

    When you provide your honest feedback it helps other people just like you find content that may help them, too.  If you received value from this episode, please take a moment and leave your honest rating and review.

    Jean L. Eaton, Your Practical Privacy Coach

    and Your Practice Management Mentor

    with Information Managers Ltd.

    GDPR: Government Regulation and the Photo Industry

    GDPR: Government Regulation and the Photo Industry

    Join host TW Woodward and guest Harri Olkinuora from Norway-based software company Netlife Suite as they discuss GDPR-the General Data Protection Regulation and how government legislation threatens the future of the photo industry.  With CCPA (California Consumer Privacy Act) coming into effect in January 2020, consumer privacy and protection have become a critical component of how companies in the United States store and share private data.  Host TW Woodward asks the tough questions surrounding government regulation and Harri provides direct experience and real-world examples from the photo industry in Europe.

    2018-007- Memcached DDoS, Secure Framework Documentation, and chromebook hacking

    2018-007- Memcached DDoS, Secure Framework Documentation, and chromebook hacking

    Topics:

    • Secure Framework documents
    • Modifying chromebooks so you can use Debian/Ubuntu
    • Memcached is the new DDoS hotness
    • Announcement of the next BrakeSec Training Class (see Show Notes below for more info)

    Link to secure framework document: https://drive.google.com/open?id=1xLfY4uI88K2AiA1mosWJ7jFyP100Jv5d

    Tickets are already on sale for "Hack in the Box" in Amsterdam from 9-13 April 2018, and using the checkout code 'brakeingsecurity' discount code gets you a 10% discount". Register at https://conference.hitb.org/hitbsecconf2018ams/register/

      

    #Spotifyhttps://brakesec.com/spotifyBDS

    #RSShttps://brakesec.com/BrakesecRSS

    #Youtube Channel:  http://www.youtube.com/c/BDSPodcast

    #iTunes Store Link: https://brakesec.com/BDSiTunes

    #Google Play Store: https://brakesec.com/BDS-GooglePlay

    Our main site:  https://brakesec.com/bdswebsite

     

    Join our #Slack Channel! Email us at bds.podcast@gmail.com

    or DM us on Twitter @brakesec

    #iHeartRadio App:  https://brakesec.com/iHeartBrakesec

    #SoundCloudhttps://brakesec.com/SoundcloudBrakesec

    Comments, Questions, Feedback: bds.podcast@gmail.com

    Support Brakeing Down Security Podcast by using our #Paypalhttps://brakesec.com/PaypalBDS OR our #Patreon

    https://brakesec.com/BDSPatreon

    #Twitter@brakesec @boettcherpwned @bryanbrake @infosystir

    #Player.FM : https://brakesec.com/BDS-PlayerFM

    #Stitcher Network: https://brakesec.com/BrakeSecStitcher

    #TuneIn Radio App: https://brakesec.com/TuneInBrakesec

     

    --Show Notes--

    Announcements:

    Matt Miller’s class on Assembly and Reverse engineering

    Starts 2 April - 6 sessions

    2nd Class - 6 sessions, beginning 21 May

    Beginner course on Assembly

    Advanced course, dealing with more advanced topics

    $150 for each class, or a $250 deal if you sign up for both classes

    paypal.me/BDSPodcast/150USD - Specify in the NOTES if you want the “Beginner” or “Advanced” course

    paypal.me/BDSPodcast/250USD - If you want both courses

    We need a minimum of 10 students per class

     

    Projects:

    Chromebook with Debian

    Bit of a pain, if I could be honest..

    Needed USB hub with eth0, and a USB soundcard

    USB3 low profile thumbdrives would be better

    https://www.amazon.com/gp/product/B01K5EBCES/ref=oh_aui_detailpage_o01_s00?ie=UTF8&psc=1

    https://www.securecontrolsframework.com/ ←--well well worth the signup

    https://drive.google.com/open?id=1xLfY4uI88K2AiA1mosWJ7jFyP100Jv5d - ‘secure.xlsx’

    http://www.dummies.com/programming/certification/security-control-frameworks/

    Numerous security frameworks already exist:

    Cisco

    NiST

    CoBIT

    ITIL (can be utilized)

    SWIFT  https://www.accesspay.com/wp-content/uploads/2017/09/SWIFT_Customer_Security_Controls_Framework.pdf

    “My weird path to #infosec” on twitter

    https://en.wikipedia.org/wiki/Hydrocolloid_dressing

    Logo

    © 2024 Podcastworld. All rights reserved

    Stay up to date

    For any inquiries, please email us at hello@podcastworld.io