<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Tag ORDA - Webmaster Lab</title>
	<atom:link href="http://www.tagorda.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tagorda.com</link>
	<description>Site building, Servers, Hosting</description>
	<lastBuildDate>Fri, 21 Oct 2011 22:13:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>Comment on Having Problems with Zen Cart/First Data by karen</title>
		<link>http://www.tagorda.com/150/#comment-277</link>
		<dc:creator>karen</dc:creator>
		<pubDate>Fri, 21 Oct 2011 22:13:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.tagorda.com/150/#comment-277</guid>
		<description>I What happend with this?  I am running into the same problems with zen/host gator</description>
		<content:encoded><![CDATA[<p>I What happend with this?  I am running into the same problems with zen/host gator</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on So, I am looking into HIPAA complaint hosting by Karl (PCI DSS QSA / Senior Auditor)</title>
		<link>http://www.tagorda.com/124/#comment-60</link>
		<dc:creator>Karl (PCI DSS QSA / Senior Auditor)</dc:creator>
		<pubDate>Mon, 04 Jul 2011 15:13:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.tagorda.com/124/#comment-60</guid>
		<description>Being HIPAA compliant does not mean that an entity would be PCI DSS compliant and vise versa. These are two different standards with a similar goal in mind:  protection of sensitive information (ePHI vs credit/debit cards). PCI is applicable for any process that stores, processes, or transmit cardholder data while the reverse is true for ePHI data.  

It would help you to better define what you are looking for and the roles/responsibilities for protecting the data are.  What are your business processes surrounding the protection of the data?  Are you looking to offload hosting and/or management of systems to ABC hosting provider or will they function in more of an application service provider role (very different)?

~Karl</description>
		<content:encoded><![CDATA[<p>Being HIPAA compliant does not mean that an entity would be PCI DSS compliant and vise versa. These are two different standards with a similar goal in mind:  protection of sensitive information (ePHI vs credit/debit cards). PCI is applicable for any process that stores, processes, or transmit cardholder data while the reverse is true for ePHI data.  </p>
<p>It would help you to better define what you are looking for and the roles/responsibilities for protecting the data are.  What are your business processes surrounding the protection of the data?  Are you looking to offload hosting and/or management of systems to ABC hosting provider or will they function in more of an application service provider role (very different)?</p>
<p>~Karl</p>
]]></content:encoded>
	</item>
</channel>
</rss>

