NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Insider Data Breaches Continue to Plague the Healthcare Industry

Protenus has published its February Healthcare Breach Barometer Report. The report includes healthcare data breaches reported to the Department of Health and Human Services’ Office for Civil Rights or disclosed to the media in February 2018. The report, compiled from data collected from databreaches.net, indicates at least 348,889 healthcare records were confirmed as breached in February, although that figure will be considerably higher as the number of people affected by 11 breaches is not yet known. There were 39 security breaches involving protected health information in February – a slight rise from the 37 breaches reported in January, although the number of records exposed was down from January’s total of 473,807 records. Insider breaches continue to pose problems for healthcare providers with 16/39 incidents (41%) involving insiders. Those incidents resulted in the exposure/theft of 51% of all records confirmed as having been exposed or stolen in February. Protenus notes that 94% of insider breaches were the result of errors by healthcare employees, with only one confirmed...

Read More
The Soldiers Project Protects Veterans’ Data with Lua Secure Mobile Communications Solution
Mar21

The Soldiers Project Protects Veterans’ Data with Lua Secure Mobile Communications Solution

The Soldier’s Project provides free, confidential mental health support services to post-9/11 military veterans and active service members and their loved ones. Those support services naturally involve contact with sensitive health and mental health information. All sensitive information collected, maintained, or received by The Soldier’s Project is stored securely and a range of safeguards have been implemented to ensure health and mental health information remains 100% confidential and protected against unauthorized access. In order to provide quality care and support, the Soldier’s Project must transmit sensitive information to healthcare professionals and others involved in an individual’s care. To ensure all sensitive information is protected in transit against unauthorized access, The Soldier’s Project has partnered with the leading secure mobile messaging solution provider Lua. Lua’s HIPAA-compliant secure communications platform was created to allow sensitive data to be quickly, easily, and efficiently shared. The platform allows health information such as medical images to...

Read More
Ransomware Attack on Finger Lakes Health Cripples Computers
Mar21

Ransomware Attack on Finger Lakes Health Cripples Computers

Geneva, NY-based Finger Lakes Health has experienced a ransomware attack that has crippled its computer system. Staff have been forced to work on pen and paper while the health system attempts to remove the malware and restore access to electronic data. The ransomware attack on the health system started at around midnight on Sunday March 18, 2018, with staff becoming aware of the attack when a ransom demand was issued by the attackers. Finger Lakes Health operates Geneva General Hospital and Soldiers & Sailors Memorial Hospital in Pen Yan and several specialty care practices, primary care physician practices, long-term health facilities, and day care centers in upstate New York. It is unclear exactly how many facilities have been impacted by the ransomware attack. Finger Lakes Health has developed emergency procedures for attack scenarios such as this, which were immediately implemented when the attack was discovered. On March 20, the health system issued a statement to local media channels about the attack explaining that while some of its information systems were...

Read More

RoxSan Pharmacy Notifies 1,049 Patients About 2015 Email Breach

Beverly Hills, CA-based RoxSan Pharmacy has notified 1,049 patients that some of their protected health information has been disclosed to a business associate via unencrypted email. The notification letters were mailed to affected individuals last month, although the incident occurred on January 20, 2015. In a recent press release, RoxSan explained that affected individuals are being notified in “as timely a manner as possible”. The delay in issuing notifications was due to “the protected nature of the forensic investigation”. It is unclear when RoxSan Pharmacy became aware of the error. The protected health information was included in a data file that was sent to a single individual – A business associate of the pharmacy – who worked in the legal field. That individual had signed a business associate agreement with the pharmacy and was aware of the responsibilities of HIPAA with respect to patients’ PHI. However, the PHI was exposed as the data file was sent via unencrypted email. The data file only contained a limited amount of protected health information and did not...

Read More

Analysis of February 2018 Healthcare Data Breaches

Our February 2018 healthcare data breach report details the major data breaches reported by healthcare providers, health plans, and business associates in February 2018. Summary of February 2018 Healthcare Data Breaches February may have been a shorter month, but there was an increase in the number of healthcare data breaches reported to the Department of Health and Human Services’ Office for Civil Rights. In February, HIPAA covered entities and business associates reported 25 breaches – a 19% month on month increase in breaches. While there was a higher breach tally this month, the number of healthcare records exposed as a result of healthcare data breaches fell by more than 100,000. In January 428,643 healthcare records were exposed. February 2018 healthcare data breaches saw 308,780 healthcare records exposed. Largest Healthcare Data Breaches of February 2018 The largest healthcare data breaches reported to the Office for Civil Rights in February are listed below. Covered Entity Covered Entity Type Individuals Affected Type of Breach Location of PHI St. Peter’s Surgery...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist