• TUellner (2/12/2016)


    Tony++ (2/12/2016)


    You said April 12, 2016 as a date to be out of compliance, but didn't give any details on what makes that date important.

    Can you share more info & a link to a site from a government or regulatory body, something a CIO would take as a trusted source?

    Here's something from the US government's Health and Human Services website:

    http://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/enforcement/examples/acmhs/acmhsbulletin.pdf

    See the second paragraph.

    "Moreover, the security incident was the direct result of ACMHS failing to identify and address basic risks, such as not regularly updating their IT resources with available patches and running outdated, unsupported software."

    -Tom

    This is kind of misleading as it implies that A) all old software is insecure and B) software that is secure one day instantly becomes insecure when it goes out of official support.