25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Deven McGraw Offers Advice on the Upcoming HIPAA Compliance Audits

Deven McGraw – deputy director of health information privacy at the Office for Civil Rights (OCR) – has offered some advice to covered entities ahead of the HIPAA-compliance audits which are scheduled to take place later this year. The second round of HIPAA-compliance audits will be conducted on covered entities first, followed by business associates. OCR contacted covered entities earlier this year to verify contact information. That process is almost complete and a pool of healthcare providers, health plans, and healthcare clearinghouses will soon be finalized. OCR will select approximately 200 organizations from that pool for a desk audit. Covered entities selected for audit will be notified and given 10 days to submit the requested documentation to the OCR. This does not give covered entities much time so it is important that preparations are made early. In an interview with the Information Security Media Group, McGraw suggested that covered entities should start preparing now in case they are selected for a desk audit. Last month, OCR released the updated audit protocol which...

Read More
Illinois Data Breach Notification Law Updated
May20

Illinois Data Breach Notification Law Updated

Illinois data breach notification law has been updated, broadening the definition of personal information and changing the timescale for notifying the Attorney General of data breaches. A breach notification will need to be issued if a person’s full name or last name and initial is exposed in combination with any of the following data elements: Driver’s license number Social Security number Credit or debit card number Biometric data Usernames and email addresses (along with passwords or other data that would allow access to accounts to be gained) Medical information Health insurance information Notifications will not be required if a breach occurs and data are encrypted, or if exposed data are publicly available. The new law specifically mentions health insurance information which includes a subscriber ID number, health insurance policy number, or any other unique identifier used to identify an individual. Any medical data provided to a health insurer in an application, appeals records, or claims history, is also included in the new definition. The exposure of information relating...

Read More

Apology Issued by Sharp Grossmont Hospital for Filming and Sharing Videos of Obstetrics Patients

An apology has been issued by Sharp Grossmont Hospital for violating the privacy of patients by filming them undergoing surgical procedures and subsequently sharing those videos with a third party. Videos were recorded using hidden surveillance cameras as part of a sting operation to catch a thief who was believed to be stealing narcotic drugs from anesthesia carts in the operating theater of the Women’s Health Center. The hospital set up surveillance cameras hidden inside moveable monitors in three operating rooms at the Women’s Health Center at Sharp Grossmont Hospital to obtain evidence of drug thefts from anesthesia carts. Some of the recorded clips show an anesthesiologist taking bottles of the anesthetic propofol from the carts and placing them in his top pocket. Over the course of the surveillance operation – which took place between July 2012 and July 2013 – 12 bottles of propofol were allegedly stolen from the cart by the anesthesiologist. The video footage of the thefts was submitted to the California Medical Board as evidence. The accused anesthesiologist’s...

Read More

4000 Michigan Chiropractic Patients Notified of Potential Data Breach

4,082 patients of Complete Chiropractic & Bodywork Therapies (CCBT) of Ann Arbor, MI., have been notified of a potential breach of protected health information after malware was discovered on one of the company’s servers. The malware was discovered on March 19, 2016., after the server malfunctioned. The malfunctioning of the server triggering CCBT’s security protocols which included isolating the server, blocking Internet access, and changing all workstation and third party passwords. CCBT also installed an additional firewall as an extra precaution. External forensics experts were brought in to investigate the security incident. Their investigation revealed malware had been installed which scanned the network for passwords and login information and transmitted sensitive data to the hacker(s) command and control server. The server stored patient data including treatment and billing information, in addition to encrypted medical record data. Encrypted information included patient names, addresses, dates of birth, health and diagnosis information, and Social Security numbers. The...

Read More

Zocdoc Notifies Patients of Breach Discovered in June 2015

This week, Zocdoc – an online medical booking system – notified the California Attorney General’s office of a breach of personal information that was first identified almost a year ago. Programming errors were discovered in June 2015., that allowed past and present practice staff members to gain access to their Provider Dashboard’s after their usernames had been removed from the system or their access had otherwise been limited. The usernames had been provided to medical and dental practices that had signed up to use the Zocdoc appointment system. Patients affected by the data breach have now been sent notification letters advising them that their name, phone number, email address, appointment history, and in some cases Social Security number, could have been accessed by staff members at each practice that were unauthorized to view the information. Health insurance information and medical histories could also have potentially been accessed if patients had provided that information via Zocdoc when making appointments. According to the breach notice, “Access may have...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist