25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

California Dept. of Corrections and Rehabilitation Reports Health Care Facility Privacy Breach
Jul07

California Dept. of Corrections and Rehabilitation Reports Health Care Facility Privacy Breach

The California Department of Corrections and Rehabilitation has announced that an employee of the Division of Adult Institutions’ California Health Care Facility emailed a document containing patients’ names and Social Security numbers to an individual unauthorized to view the data. The disclosure of patients’ data occurred on May 2, 2016 and was not believed to have been conducted with malicious intent. The email was simply sent to the wrong person. To reduce the risk of similar incidents occurring in the future, the California Health Care Facility has revised its policies and procedures. The email has also been deleted from the email system, although it is possible that the data were viewed by at least one unauthorized individual. All individuals affected by the privacy incident have been advised to place a fraud alert on their credit files and have been told to read the California Attorney General’s consumer tips for victims of privacy breaches and to take the appropriate steps they feel are necessary to mitigate risk. The incident has not yet appeared on the Department of...

Read More

Congressmen Call for Different HIPAA Rules for Malware and Ransomware Attacks

Ted Lieu, D-Calif. and Will Hurd, R-Texas., have written to OCR Deputy Director for Health Information Privacy Deven McGraw raising issues related to healthcare ransomware infections ahead of the release of new OCR guidance on ransomware attacks. The bipartisan pair of Congressmen have pointed out some important differences between ransomware infections and hacking, which they believe should be reflected in the upcoming guidance. They believe that ransomware should require different rules to other malware infections and hacking incidents, although there is some debate as to whether HIPAA Rules should treat different types of malware differently. The Congressmen point out in the letter that under 45 CFR § 164.402, a breach if ePHI is defined as “the acquisition, access, use, or disclosure of protected health information in a manner not permitted.” This would mean that a ransomware attack qualifies as a data breach. In order to encrypt data, those data must be accessed. Consequently, covered entities would be required to perform a risk assessment under HIPAA Rules. While...

Read More

Colorado Allergy Clinic Reports Ransomware Attack

Allergy, Asthma & Immunology of the Rockies, P.C. (AAIR) has experienced a ransomware infection on computers used to store the electronic protected health information (ePHI) of patients. The computers that were locked with the malicious file-encrypting malware contained the health records of 6,851 patients. The ePHI stored on the computers included patients’ names, medical test results, and Social Security numbers. The ransomware attack was discovered on May 16, 2016 and affected AAIR’s Glenwood Springs medical office. Staff at the office were unable to access files on computers and IT staff were alerted to a potential cyberattack. The IT department immediately shut down the company’s servers to prevent data exfiltration and to contain the infection. A third party cybersecurity firm was called in to conduct a forensic analysis of the allergy clinic’s network. According to a statement issued by AAIR’s attorney, Kari Hershey, “They weren’t able to track exactly what the hackers did, but what they did find was a draft of the ransom letter on the system.” It is unclear exactly...

Read More
Potential Privacy Breach at Planned Parenthood Dubuque Health Center
Jul05

Potential Privacy Breach at Planned Parenthood Dubuque Health Center

On July 1, 2016, Planned Parenthood of the Heartland announced that the protected health information (PHI) of certain patients of its Dubuque health center in Iowa may have been accessed by unauthorized individuals. The health center permanently closed its doors to patients this April year and the premises was listed for sale and was sold. However, hard copies of patient files were left in the Dubuque health center. In April 2016, individuals entered the medical center and could potentially have viewed and/or copied patient files. The potential breach was discovered by Planned Parenthood on May 6, 2016. The files have now been removed from the premises and have been secured. Planned Parenthood said this was an isolated incident and is not representative of the stringent privacy standards usually maintained by the healthcare organization. Patients affected by the potential privacy breach had sought treatment at the Dubuque health center between August 1, 2008 and April 30, 2014. In total, the PHI of 2,506 patients may have been compromised. Patients have now been notified of the...

Read More
CMS Finalizes New Rules for QEs on Sale and Sharing of Medicare Claims Data
Jul05

CMS Finalizes New Rules for QEs on Sale and Sharing of Medicare Claims Data

The Centers for Medicare and Medicaid Services (CMS) has finalized a new set of Rules for qualified entities that will allow the sharing or sale of Medicare claims data to healthcare providers, employers, and other entities. The rule changes will help to ensure that healthcare organizations, employers, and other organizations have access to the data they need to make informed decisions about the provision of care to patients. With access to all Medicare and private sector claims data, it is hoped that the quality of care provided to patients will be improved. The rule changes, which were required under the Medicare Access and CHIP Reauthorization Act (MACRA), will permit organizations classed as qualified entities to confidentially share analyses of Medicare and private sector claims with healthcare providers, employers, and other groups that are able to use the data to improve patient care. The sale of data is also permitted. Qualified entities will be permitted to sell data to healthcare providers such as doctors, nurses, and skilled nursing facilities. While data can be sold or...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist