NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

South Carolina Hospital Reports Loss of Camera Containing Babies’ PHI
Jan25

South Carolina Hospital Reports Loss of Camera Containing Babies’ PHI

Roper St. Francis Mount Pleasant Hospital in South Carolina has discovered that a digital camera used to take photographs of new born babies has been lost and potentially stolen. As is recommended by the National Center for Missing and Exploited Children, photographs of new born babies are taken by hospital staff for security reasons. In the event that a baby goes missing, the digital images can be used for identification purposes. According to hospital spokesperson Andy Lyons, the camera was stored in a secure location in the hospital not accessible by the general public. Following the discovery that the camera was missing, an extensive search of the hospital was conducted, although the missing camera has not yet been located. The camera stored images on a memory card which was in the device when it went missing. The memory card is believed to contain the images of approximately 500 babies born at the hospital between November 2015 and November 2016. The photos also contained physicians’ names, the birthdate of each baby, and the babies’ names. Parents of the babies are being...

Read More

ePHI Improperly Accessed, Copied, and Lost by Employee

The protected health information of 600 individuals who received treatment for mental health disorders and/or substance abuse at a Baltimore treatment center has been compromised. On November 28, 2016, Complete Wellness discovered that highly confidential information had been accessed and copied onto a flash drive without authorization. Even though the treatment center was able to identify the individual responsible, it was not possible to recover the drive as the device was allegedly lost by the employee. While no reports of misuse of the information contained on the device have been received by Complete Wellness, the possibility remains that the drive has been found and patient data accessed. Data stored on the device included patients’ names, phone numbers. home addresses, email addresses, ages and dates of birth, languages spoken, ethnicity, race, marital statuses, the names of primary care physicians, emergency contact information, level of education, employer information, hurricane victim status, living situation, arrest history, military service information, and whether...

Read More
FDA Confirms Muddy Waters’ Claims that St. Jude Medical Devices Can be Hacked
Jan24

FDA Confirms Muddy Waters’ Claims that St. Jude Medical Devices Can be Hacked

The U.S. Food and Drug Administration (FDA) issued a safety communication Tuesday about cybersecurity flaws in certain St. Jude Medical cardiac devices and the Merlin@home transmitter after it was confirmed the devices could potentially be remotely accessed by unauthorized individuals. The FDA confirmed that unauthorized users could “remotely access a patient’s RF-enabled implanted cardiac device by altering the Merlin@home Transmitter,” potentially causing patients to be harmed. The flaws would allow an attacker to deplete the battery on implanted devices, alter pacing, or trigger shocks. The FDA confirmed that there have been no reported instances of the cybersecurity flaws being exploited to cause harm to patients to date and patients have been advised to continue using the devices as instructed by their healthcare providers. A patch to address the flaws has been developed and will be automatically applied this week. However, in order for the Merlin@home device to receive the update it must be left plugged in and connected to the Merlin Network. The...

Read More
Theft of Unencrypted Laptop Exposes Wonderful Health & Wellness Patients’ ePHI
Jan24

Theft of Unencrypted Laptop Exposes Wonderful Health & Wellness Patients’ ePHI

Los Angeles-based Wonderful Health and Wellness has notified patents that their electronic protected health information (ePHI) was exposed in early December, 2016 when an unencrypted laptop computer was stolen from the company’s Wonderful Center for Health Innovation. Staff at the Center discovered the laptop computer was missing on December 12 when they returned to work after the weekend, with the theft having occurred at some point between December 9 and 12. The theft was immediately reported to law enforcement, although the device has not been recovered. The laptop contained a range of protected health information including patients’ names along with their home addresses, telephone numbers, dates of birth, email addresses, clinical account numbers, medical conditions, treatment information, treatment dates, and test results. No Social Security numbers or financial information were stored on the device. While the laptop computer was not encrypted, software had been installed which allows data on the device to be remotely deleted, although only if the laptop is used to connect to...

Read More

Court of Appeals Rules Horizon BCBS Class Action Has Standing Without Evidence of ID Theft

The United States Court of Appeals for the Third Circuit has ruled that a class action lawsuit filed by customers of Horizon Blue Cross Blue Shield whose protected health information was exposed when two laptop computers were stolen from its New Jersey offices does have standing, even without proof of harm. The case had previously been dismissed by U.S. District Judge Claire Cecchi. The incident which led to the lawsuit occurred between November 1 and 3, 2013. Two unencrypted laptop computers containing the personal information of 839,000 plan members were stolen from Horizon BCBS’s headquarters in Newark, NJ. Stored on the laptops were names, addresses, birth dates, Social Security numbers, medical histories, demographic data, lab test results, insurance information, and other care-related data. Four plaintiffs – Courtney Diana, Karen Pekelney, Mark Meisel, and Mitchell Rindner – are named on the lawsuit, which was filed on behalf of themselves and other customers whose personal information was exposed. The complainants maintain that the laptop computers were targeted...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist