25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Oregon Health & Science University to Pay OCR $2.7 Million for 2013 Data Breaches
Jul14

Oregon Health & Science University to Pay OCR $2.7 Million for 2013 Data Breaches

Oregon Health & Science University (OHSU) has agreed to settle a case with the Department of Health and Human Services’ Office for Civil Rights stemming from two data breaches experienced in 2013. A penalty of $2.7 million will be paid by OHSU to settle alleged HIPAA violations without admission of liability. The privacy breaches occurred shortly after each other in 2013. Within the space of three months, the protected health information of over 7,000 patients was exposed. The first breach of patient data involved the theft of an unencrypted laptop computer from a vacation apartment in Hawaii that was rented by an OHSU physician. The laptop computer contained the PHI of 4,022 patients. The second incident involved the accidental disclosure of PHI via a cloud storage service. Physicians were using the Internet service to share a spreadsheet containing patient data. However, the cloud service provider was a HIPAA business associate of OHSU and no business associate agreement had been obtained prior to the service being used. Consequently, the data of 3,044 patients was placed at...

Read More

House Passes Mental Health Reform Bill (Without the HIPAA Changes)

A mental health bill that aims to improve mental healthcare in the United States has been passed by the House. The bill – H.R. 2646 – which was first introduced three years ago, was intended to usher in sweeping changes to improve the treatment of mental illness in the United States. While the bill was passed with an overwhelming majority of 422-2 last Wednesday, a number of the more contentious issues needed to be removed from the bill. One of the sticking points that was dropped from the bill were the changes to the Health Insurance Portability and Accountability Act (HIPAA). The bill introduces a number of important changes that will improve mental health care; however, the proposed changes to HIPAA were opposed by a number of Democrats and Republicans. In order for the bill to be passed, the HIPAA changes had to be dropped. In its original form, the bill would have changed HIPAA Rules to permit healthcare providers to share mental health data about patients with their caregivers. Instead, the Department of Health and Human Services is now required to clarify the law...

Read More
Stolen Ultrasound Machines Contained PHI, says Kaiser Permanente
Jul14

Stolen Ultrasound Machines Contained PHI, says Kaiser Permanente

Kaiser Permanente discovered that some of its ultrasound machines and other medical equipment had been stolen by two company employees. Kaiser Permanente was alerted to the theft of equipment on June 10 and immediately launched an investigation. Efforts were then made to recover the missing equipment. Kaiser Permanente has now recovered the stolen equipment and has performed an analysis to determine whether any patient data were stored on the devices. Kaiser Permanente determined that some of the machines contained a limited amount of patients’ protected health information including MRN’s, patients first and last names, and ultrasound images. The equipment had been taken from a number of different Kaiser Permanente facilities and had been temporarily moved to a storage unit. The Kaiser Permanente investigation is ongoing, but it is believed that the ultrasound machines and medical equipment were only taken by the employees to sell on for profit, and not for any data stored on the devices. The theft of equipment has been reported to law enforcement and a criminal investigation has...

Read More

OCR Phase 2 HIPAA Audits: Documentation Requests Issued

The Department of Health and Human Services’ Office for Civil Rights (OCR) has now selected covered entities from its pool of eligible organizations and has chosen 167 for a HIPAA compliance audit. Covered entities selected for a compliance audit have now been notified by email. Those organizations now have just 10 days to respond to the emails and submit the requested documentation to the OCR. The audits – which are desk based – have been split between healthcare providers, health plans, and healthcare clearinghouses. The audits are being conducted on a geographically representative sample that includes healthcare organizations of all sizes. Desk audits of HIPAA business associates will follow in the fall. The desk audits comprise of a documentation check to ensure compliance with the Health Insurance Portability and Accountability Act’s Privacy, Security, and Breach Notification Rules. Earlier this year the OCR published details of the new audit protocol. The protocol contains a long list of different aspects of HIPAA Rules that could potentially be assessed by OCR...

Read More

OCR Ransomware Guidance: Ransomware Attacks Are Reportable Breaches

The Department of Health and Human Services’ Office for Civil Rights has issued new guidance on ransomware. A fact sheet on healthcare ransomware attacks has been published along with a 12-page document providing technical guidance for CIOs and CISOs on best practices to adopt to prevent ransomware infections, mitigation strategies to adopt when ransomware is installed on computers or healthcare networks, and detailed information on the correct ransomware response. The new guidance is essential reading for CISOs, CIOs, and all members of the senior leadership team. Ransomware and HIPAA The OCR has confirmed the proactive measures that covered entities should take to prevent ransomware infections: Perform a comprehensive, organization-wide risk analysis Establish a plan to remediate any identified risks to the confidentiality, integrity, or availability of ePHI Implement policies and procedures to safeguard ePHI against malicious software – including malware and ransomware Provide staff members with training on cybersecurity best practices Train authorized users to detect malicious...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist