25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Majority of Companies Lack Confidence in Data Breach Response Plans

Even though an increasing number of organizations now have data breach response plans in place, there is a general lack of confidence that a full recovery will be possible if a data breach is experienced. According to a survey conducted by the Ponemon Institute on behalf of Experian, 86% of organizations now have a data breach response plan in place. When the survey was last conducted in 2013, only 61% of companies had such a plan. While a plan has been developed, 38% of companies have not set a timescale for reviewing and updating their breach response plan. 29% of respondents said they have never updated their plan since it was put in place. Out of the respondents that said there was a data breach response plan in place, only 42% believed the plan was effective or very effective. Only 27% of respondents said they were confident that their organization could minimize the financial impact of a data breach. International data breaches were also a cause for concern. 31% of respondents were not confident they would be able to deal with such an incident. For many companies the breach...

Read More
Boxes of Abandoned Veterans Services’ Files Discovered
Oct11

Boxes of Abandoned Veterans Services’ Files Discovered

The Virginia Department of Veterans Services (DVS) has launched an investigation following the discovery of 20-30 boxes of files in an abandoned storage unit. The files contain a range of documents including unfiled claims and veterans’ medical records. The storage unit had previously been leased by a former DVS employee who was employed by the agency from January 2012 until August 25, 2015 when she was fired. The employee worked at the veterans’ benefits office at the McGuire Veterans Affairs Medical Center office in Richmond. She had rented the storage unit while employed by DVS; however rental payments for the unit ceased. The unit was then repossessed and the contents were sold at auction. The new owner of the contents of the unit alerted the Dinwiddle County Sherriff’s Office after checking the contents of the boxes and DVS was notified on September 29. DVS officials visited the storage facility and have now removed and secured the files. According to the agency’s director of benefits, Thomas Herthel, the boxes contain “everything from claims to medical records to...

Read More

Georgia Eye Center Discovers Insider Breach: 10,891 Patients Impacted

A former employee of the Thomasville Eye Center in Thomasville, GA has been discovered to have accessed the protected health information of patients without authorization. PHI was stolen from the eye center and used to open credit accounts in the names of the patients. The eye center was alerted to the identity theft on August 8, 2016 and immediately launched an investigation to determine whether this was an isolated incident or if other patients had potentially been affected. The eye center discovered that the records of 10,891 patients had been accessed by the employee. The information contained in those records included names, addresses, birthdates, medical billing information, and Social Security numbers. After confirming that PHI had been improperly accessed, the employee was terminated and law enforcement was notified. The eye center is continuing to work with law enforcement and is assisting in the criminal investigation of the employee’s activities. All affected patients have now been notified of the breach by mail and credit monitoring and identity theft protection...

Read More

Guidance on HIPAA and Cloud Computing Issued by HHS

The Department of Health and Human Services has released updated guidance on HIPAA and cloud computing to help covered entities take advantage of the cloud without risking a HIPAA violation. The main focus of the guidance is the use of cloud service providers (CSPs). Cloud service providers that are legally separate entities from a HIPAA-covered entity are classed as business associates under HIPAA regulations if the CSP is required to create, receive, maintain, or transmit electronic protected health information (ePHI). A CSP is also classed as a business associate when a business associate of a covered entity subcontracts services to the CSP that involve creating, receiving, maintaining, or transmitting ePHI. It is important to note that even when a HIPAA-covered entity, business associate, or subcontractor of a business associate provides ePHI to a CSP in encrypted form, the CSP is still classed as a business associate under HIPAA Rules, even if a key to decrypt the data is not provided. A CSP would not be classed as a business associate and would therefore not be required to...

Read More

Majority of Organizations Worried About Insider Threats

October is National CyberSecurity Awareness Month: An annual campaign designed to raise awareness of cybersecurity threats and improve the resilience of the nation in the event of a cyber incident. Each October, the National Cyber Security Division (NCSD) of the Department of Homeland Security and the National Cyber Security Alliance (NCSA) launch a number of initiatives to educate the public – and public- and private-sector partners – on cybersecurity issues and encourage the adoption of security best practices. Given the volume of cyber-attacks that have occurred over the past 12 months, this year’s event is more important than ever. Attention is being focused on external threats, but it is important not to ignore the threat from within. Insider threats continue to plague organizations, yet defenses against insider attacks are often found lacking. 74% of Cyber Security Pros Feel Vulnerable to Insider Threats Last month saw the release of the 2016 Bitglass Insider Threat Report which provides some insight into the risk of insider data breaches. The report also shows...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist