25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Lack of Ransomware Protections Could Violate FTC Act

The Department of Health and Human Services’ Office for Civil Rights has recently issued guidance for HIPAA covered entities on ransomware to help covered entities deal with the increased threat of ransomware attacks. Now the Federal Trade Commission (FTC) has warned businesses that they must do more to deal with the ransomware threat. The failure to implement appropriate defenses against ransomware could constitute a violation of the FTC Act. At a recent FTC forum that explored the current ransomware problem and the strategies that can be adopted to mitigate the threat, FTC Chair Edith Ramirez issued a stern warning to businesses, explaining more must be done to prevent ransomware attacks. Ramirez explained that ransomware is now one of the “most troubling cyber threats.” The Department of Justice has reported that there has been a 300% increase in ransomware attacks in the past year, and an average of 4,000 ransomware attacks are now occurring every day. Ramirez also pointed out that an estimated 93% of all phishing emails are now being used to deliver ransomware, and that...

Read More

Sharing of Health Data with Patients: 95% of Hospitals Now Offer ePHI Access

The Department of Health and Human Services has been encouraging patients to take a more active role in their own healthcare and to engage more with their healthcare providers. Not only will this help to improve patient outcomes, it will also help to reduce healthcare costs. Healthcare organizations have also been encouraged to improve patient engagement, in part by ensuring that patients can easily access their ePHI. Under the Shared Nationwide Interoperability Roadmap, healthcare providers should allow patients not only to view their health data, but also to download copies and transmit those data to any healthcare provider of their choosing. This week, the Office of the National Coordinator for Health IT has released statistics showing the progress that has been made and the extent to which electronic capabilities for patient engagement have been implemented by U.S. hospitals. According to the data brief, significant progress has been made. The vast majority of U.S. Non-Federal Acute Care Hospitals are now allowing patients online access to their ePHI. There has also been a...

Read More

Improving Healthcare Cybersecurity: HIMSS Suggests Information Sharing is Key

Healthcare organizations are committing more funding to cybersecurity and are improving their defenses against cyberattacks, although there is still a long way to go before cybersecurity defenses reach the standards in other industry sectors. Many healthcare organizations are still struggling to plug security gaps and effectively manage risk, and while large healthcare organizations are now being more proactive when it comes to cybersecurity, small to medium sized healthcare organizations are having difficulty overcoming some of the many challenges faced by the industry. As the National Institute of Standards and Technology (NIST) recently pointed out, “Many [healthcare] organizations still have a reactive stance towards cybersecurity.” NIST is attempting to address this issue and has recently submitted a request for information on current and future states of cybersecurity in the digital economy. Its aim is to make detailed recommendations on how cybersecurity can be enhanced to improve public safety and patient privacy. NIST is also looking for ways to foster the discovery and...

Read More

2,800 Members Affected by Geisinger Health Plan Mailing Error

Danville, Pennsylvania-based Geisinger Health Plan has alerted 2,814 members from 220 employer health plans that some of their protected health information has been exposed to unauthorized individuals as a result of a processing error that occurred when mailing monthly invoices. Invoice statements were prepared on July 30; however, a number were accidentally mailed to private citizens. The error was discovered on August 4, a few days after the invoices were mailed. The invoices did not contain Social Security numbers, financial information, or other data that is typically used by criminals to commit fraud. The exposed data were limited to plan members’ names, health insurance premium amounts, member ID numbers, dates of birth, and smoking status. The breach was limited to members of the Geisinger Health Plan. Geisinger Gold, GHP Family and GHP Kids members were unaffected. All individuals who were sent the invoices have been contacted and requested to send the invoices back to Geisinger Health Plan to ensure they are securely destroyed, in accordance with Geisinger Health System...

Read More
The Importance of Auditing Business Associates Highlighted by OIG Investigation
Sep14

The Importance of Auditing Business Associates Highlighted by OIG Investigation

The Department of Veteran Affairs’ Office of Inspector General (OIG) has published a report on the investigation of a VA contractor that was alleged to be allowing employees to access, share, and store the protected health information of veterans on personally owned devices. Anchorage-based ProCare Home Medical Inc., a supplier of home oxygen services on behalf of the VA, was reported to OIG for breaching federal information security standards. The tipoff came via the VA OIG Hotline in December 2014. OIG was informed that the company’s employees were permitted to use personal computers and smartphones to access the company’s computer system. They were also alleged to have downloaded the PHI of veterans to their personal devices. OIG conducted an onsite review of ProCare facilities in May 2015. Staff were interviewed and contractor business processes were observed. VA staff were also interviewed to determine the level of oversight of contractors that was taking place. The allegations made against ProCare were substantiated by OIG, and while it was not possible to examine the devices...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist