25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

California Anesthetist Alerts Patients to Improper Disposal of PHI

An anesthetist based in Los Baros, California has notified a number of his patients that some of their protected health information was accidentally disposed of in regular trash containers. Billing tickets used by the practice of Pratap Kurra, M.D., were discovered in trash containers on August 9, 2016. The matter was brought to the attention of Dr. Kurra who established the documents had been disposed of the previous day. Dr. Kurra says the discarded documents were collected from the trash containers and PHI was only exposed for a maximum of 24 hours. Dr. Kurra does not believe any billing tickets were removed from the trash container by unauthorized individuals and all discarded documents are understood to have been retrieved. An investigation was conducted to determine which patients were affected and how the billing tickets came to be discarded. Dr. Kurra ascertained that this was a one-off incident and occurred by accident during his move. The billing tickets did not contain Social Security numbers, dates of birth, insurance details, or financial information, so the risk of...

Read More

University Gastroenterology Reports Cyberattack

University Gastroenterology in Rhode Island has announced that one of its electronic file storage systems has been compromised. An unauthorized individual gained access to the system and succeeded in encrypting a number of files. It is unclear whether that individual issued a ransom demand to unlock the files, or whether ransomware was actually involved. The file system contained a limited amount electronic protected health information relating to patients acquired from Consultants in Gastroenterology, a practice which was acquired by University Gastroenterology in 2014. Upon discovery of the security breach, action was promptly taken to prevent any other systems from being accessed and an investigation was launched to determine the contents of the encrypted files. That investigation revealed that the encrypted files contained the names of patients, along with their home addresses, medical billing information, dates of birth, and Social Security numbers. Electronic health records were stored in a different system and were not exposed. It is not clear when the files were encrypted,...

Read More

U.S. HealthWorks Announces Theft of Encrypted Laptop and Decryption Key

Healthcare providers can use data encryption to ensure that the theft of portable devices does not result in the exposure of patients’ protected health information. However, encryption is not infallible, as U.S. HealthWorks has discovered. A laptop computer containing the PHI of 1,400 patients was recently stolen from a U.S. HealthWorks employee. While this would not usually result in the issuing of breach notifications to patients, in this case the employee had written down the password to access the device and decrypt data. The password was kept with the laptop and it was also stolen. Upon discovery of the theft of the device along with the password, U.S. HealthWorks conducted a full investigation to determine which patients may have had their PHI exposed. The investigation did not uncover evidence to suggest that any data have been used inappropriately, and the possibility remains that the data stored on the device were not accessed. However, if the thief were to use the password to gain access to the device, it would be possible to access emails which contained sensitive...

Read More

Californian Healthcare Provider Informs Patients of Ransomware Attack

Yuba Sutter Medical Clinic in Yuba City, California has reported a recent ransomware attack that resulted in certain parts of its network being taken out of action. Prompt action was taken to restore all encrypted files. Systems were only out of action for a short while. However, due to the inability to access patient data, patients did experience delays in receiving treatment. The attack occurred on or around August 3, 2016, and resulted in the encryption of internal clinical data and patient health information. All data were backed up and could be restored without any data loss or data corruption, although appointments needed to be rescheduled for some patients. The decision was taken to delay notifying patients while an investigation was conducted and appropriate authorities were notified of the incident. Federal law enforcement authorities are continuing to investigate the incident and a policy review and internal investigation into the incident is ongoing. Under HIPAA Rules, ransomware attacks on healthcare organizations are reportable unless the covered entity can demonstrate...

Read More

King of Prussia Dental Associates Announces Potential PHI Breach

King of Prussia Dental Associates (KOPDA) has announced that a third party may have gained access to a server containing the protected health information of its patients. The incident also impacts patients of its affiliate, Pediatric Dentistry of Collegeville. KOPDA started experiencing problems with its computer network on or around June 1, 2016. The IT specialist employed by KOPDA started investigating the problems and became concerned that the issues may have been caused deliberately by a third party. In order to determine whether access to the network had been gained, KOPDA retained the services of a leading computer firm to conduct a thorough forensic analysis of its network. On June 23, the forensics firm determined that a third party may have gained access to the server and the KOPDA network. On June 29, the firm also determined that the breach may have affected patients of Pediatric Dentistry of Collegeville. Patients affected by the incident were mailed breach notification letters on September 9, 2016 and have been offered credit monitoring and identity theft protection...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist