right.http://www.fisma1.net/If you are working with medical/health records, this will apply to you.The least you need to know:Privacy Rule puts limits on disclosure of protected health information (PHI)Security Rule outlines security requirements for electronic PHIRule of thumb re: disclosure under Privacy Rule: do not disclose PHI to anyone other than the patient unless you get written permis