25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cybersecurity Training Failing to Tackle Insider Threat

A recent Ponemon Institute/Experian study – Managing Insider Risk Through Training & Culture – has shown that companies are failing to provide adequate cybersecurity training to prevent negligent behavior by employees and to reduce the risk of an insider data breach. For the latest study, over 600 individuals from a wide range of organizations were questioned about their cybersecurity training programs. Respondents included C-suite executives, managers, and IT professionals from companies that had a data protection and privacy training (DPPT) program in place. The study revealed that 55% of companies have experienced a data breach in the past that was caused by employee negligence or human error. When asked about the risk of a data breach as a result of negligence or employee error the majority of companies were aware of the risk. 66% of respondents said they believed employees are the weakest link in the security chain, yet more than half of respondents said their cybersecurity training programs were not effective. When asked about training programs and employees...

Read More

Medical Colleagues of Texas Hacking Incident Impacts 68K Patients

Medical Colleagues of Texas, a physicians’ group in Katy, TX., has discovered an unauthorized individual gained access to its system containing the records of more than 68,000 patients. The exact nature of the incident has not been disclosed and an investigation into the security breach is ongoing. The physicians’ group was unaware how access was gained to its systems at the time of posting the breach notice; however, the investigation into the breach has determined that personnel files and patient medical records have potentially been accessed. Data stored on the compromised system include patients’ names, addresses, Social Security numbers, and health insurance information. The intrusion was first detected on March 8, 2016 when an office employee noticed unusual activity on the computer network of the obstetrics group. The activity was determined to be caused by an unauthorized individual who had gained remote access to the network. A computer forensics firm was called in to investigate the security breach. An attorney for the Medical Colleagues of Texas, Lindsay Nickle, issued a...

Read More

95K More Patients Discovered to Have Been Impacted by Bizmatics Data Breach

The Office for Civil Rights has received two further breach reports from healthcare providers impacted by the Bizmatics data breach. Almost 95,000 patients of the two healthcare facilities have potentially had their data accessed by hackers. Southeast Eye Institute P.A, doing business as Eye Associates of Pinellas, has notified 87,314 patients of the breach, while Lafayette Pain Care, PC., has potentially had the data of 7,500 individuals scanned by hackers. Eye Associates of Pinellas was notified by Bizmatics on March 30, 2016., that some of its patients’ data were accessed by unauthorized third parties. The data potentially viewed include patients’ names, telephone numbers, home addresses, dates of birth, health insurance information, and Social Security numbers.  Patients affected by the breach had visited Eye Associates of Pinellas prior to November 15, 2015. According to the breach notice posted by Eye Associates of Pinellas, Bizmatics had segregated data to improve security, but the company was unable to determine if the separated data fields had been matched by the...

Read More

Apple to Recruit HIPAA Expert as Privacy Counsel

Apple is seeking a Privacy Counsel with extensive experience in healthcare privacy and a thorough understanding of HIPAA regulations. The new position confirms that Apple is planning on developing its products to be more valuable to healthcare professionals and patients, and that the company is intent on making more of a mark in the healthcare sector. The new recruit will be required to work on cutting edge projects, providing essential input on privacy and security, working on privacy by design reviews, supporting compliance and auditing frameworks, drafting policies and procedures to ensure compliance with privacy laws, and assisting with privacy complaints and breaches. The individual will also play a major part in designing privacy solutions for Apple products. The new position could indicate Apple is intent on developing HIPAA-compliant apps or may be working on a HIPAA-compliant backend for its frameworks to enable patient data to be stored and transmitted securely, in accordance with HIPAA Rules. Apple has already developed products and frameworks for monitoring patient...

Read More
ACLU Claims Myriad Genetics Violated HIPAA Rules by Withholding Genetic Data
May24

ACLU Claims Myriad Genetics Violated HIPAA Rules by Withholding Genetic Data

Late last week, a complaint was filed with the Department of Health and Human Services’ Office for Civil Rights by the American Civil Liberties Union after Myriad Genetics refused to provide four patients with copies of their full genetic records – an alleged breach of the HIPAA Privacy Rule. The patients in question had undergone genetic tests to assess hereditary risk for bladder, breast, and ovarian cancer. Myriad provided the patients with details of the genetic factors which were deemed to be significant and useful for healthcare providers. However, the data provided to the patients did not include information about all of the genetic variants Myriad’s testing had uncovered. The patients requested copies of all of their genetic data that was held by Myriad Genetics, including the genetic variants that Myriad deemed not to pose a risk to the patients. Myriad refused to provide copies saying the patients were not entitled to copies of the withheld data. It was claimed that the withheld data was not part of the designated record set which Myriad is required to provide to patients...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist