25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Indiana Attorney General’s Office Investigates Dumping of Medical Records

Earlier this week, an officer from the Indianapolis Metropolitan Police Department (IMPD) discovered a number of medical records in a public recycling dumpster in Broad Ripple Park, Indianapolis. A number of confidential documents were found in file folders in the dumpster which had been mixed up with newspapers and other paper and cardboard. IMPD recovered the files and folders from the recycling dumpster, although there is no way of telling whether any documents had been removed by members of the public. It is also unclear whether files had been dumped on a single occasion, or whether material had been disposed of over an extended period of time. The Indiana Attorney General’s Office is now involved and efforts have been made to contact recycling and waste disposal companies who potentially may have come into contact with dumped medical records. If any further files and folders are recovered the attorney general’s office will arrange for the files to be collected and secured. According to the police report, the files contain highly sensitive data including patient names,...

Read More

16K ENT and Allergy Center Patients Affected by Bizmatics Breach

ENT and Allergy Care, P.A. has announced that its patients have been affected by the data breach at Bizmatics. In early 2015, the server used to host the Bizmatics PrognoCIS tool was hacked. Access to the server was gained and data stored on the server were potentially accessed. In December, 2015., the intrusion was detected and access to the server was rapidly shut down. Bizmatics started investigating the cyberattack and enlisted the services of an external computer forensics company. Law enforcement was also notified on the security breach. Bizmatics notified ENT and Allergy Care of the security breach by mail in January 2016; however, at the time it was not possible to tell whether ENT and Allergy Care patients had been affected. The Bizmatics investigation continued, and in April 2016 ENT and Allergy Care was notified that “at least some” data stored in the PrognoCIS tool had been accessed and possibly copied. Bizmatics was unable to determine exactly which patients’ data were accessed. The data stored in the PrognoCIS tool included patients’ names, addresses, and information...

Read More

OIG Discovers Security Flaws in Washington State Insurance Exchange Website

A review of Washington State’s health insurance exchange conducted by the Department of Health and Human Services’ Office of Inspector General (OIG) has revealed a number of website and database security issues that have placed personally identifiable information (PII) at risk of exposure. OIG conducted its review to determine whether the Washington health insurance marketplace had implemented appropriate controls to ensure PII was protected in line with Federal requirements, including those detailed in the Centers for Medicare & Medicaid Services’ (CMS) Minimum Acceptable Risk Standards for Exchanges. The CMS requires all exchanges to develop security plans, perform risk assessments, conduct scans for security vulnerabilities, develop patch management policies and procedures, conduct penetration testing, and remediate any security vulnerabilities that are identified. OIG assessed the Washington marketplace’s policies and procedures, and evaluated the security controls that had been implemented to protect the website and database. The marketplace’s internal controls were...

Read More
BA Printing Error Exposed PHI of Walmart Pharmacy Patients
Jun17

BA Printing Error Exposed PHI of Walmart Pharmacy Patients

An error by a vendor of Walmart has resulted in a limited amount of protected health information being disclosed to other pharmacy customers. An error was made when one of Walmart’s vendors printed letters accompanying patient refund checks. That error resulted in patients’ protected health information being printed on letters intended for other individuals. Only a limited amount of information was disclosed, although this was sufficient to warrant the issuing of breach notification letters.  The incident has now been reported to the Department of Health and Human Services’ Office for Civil Rights. The breach report indicates 27,393 patients were impacted by the privacy breach. The breach has not been posted on Walmart’s website at the time of writing, although an explanation of the breach was provided to databreaches.net. Walmart explained that the error occurred on or around May 13, 2016. The letters were mailed to patients on May 15, 2016., and Walmart was made aware of the error 5 days later. Affected patients had their name, pharmacy prescription number or optical order...

Read More

Aspen Hospital Sued for HIPAA Breach by Former Employee

A healthcare IT worker formerly employed by Aspen Hospital is suing the hospital and five of its employees for an alleged HIPAA breach after it was disclosed he had contracted HIV. The former employee, only identified as John Doe in the suit, was also a patient at the hospital. His attorneys, Mari Newman, Darold Killmer and Eudoxie Dickey, filed the suit on his behalf and are seeking compensatory and punitive damages, legal fees, and an apology from the hospital for the violation of his privacy. Doe also wants the hospital to change its policies to prohibit the disclosure of sensitive medical information to members of the hospital staff. John Doe had worked in the IT department of Aspen Hospital for 11 years prior to losing his job. Doe was an excellent employee and was well respected in the department according to the suit. He was regularly told he had exceeded expected standards and had often been rated as ‘outstanding’ in his performance evaluations. After filing complaints against the hospital for the disclosure of his HIV status and subsequent retaliatory acts by hospital...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist