NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Massachusetts General Hospital Reports PHI Incident

Massachusetts General Hospital (MGH) has announced that some patients of its dental group had their protected health information exposed earlier this year. The security breach occurred at one of the healthcare provider’s business associates, Patterson Dental Supply Inc., (PDSI). MGH first became aware of the security breach on February 8, 2016. Under normal circumstances, patients would have been notified of the breach within 60 days of discovery – the time frame stipulated in the HIPAA Breach Notification Rule. However, the intrusion was reported to law enforcement which requested MGH delay the issuing of breach notification letters so as not to interfere with the investigation. The investigation continued, but on May 26, 2016., MGH was given permission by law enforcement to start notifying patients of the breach. A substitute breach notice was uploaded to the MGH website on June 29, 2016., just over a month later. According to that notice, “we began notification as quickly as possible once we completed our investigation. The investigation revealed that some patient files that...

Read More
Pruitt Health Alerts Patients to Potential Privacy Breaches after Two Break-ins
Jun29

Pruitt Health Alerts Patients to Potential Privacy Breaches after Two Break-ins

PruittHealth, a provider of home health and hospice services in the southeast United States, has started notifying 1,437 patients of a potential breach of protected health information following two break-ins at its offices in South Carolina. In both cases, it would appear that the thieves were not interested in patient health information, although patients’ files could potentially have been viewed. The first break-in occurred on March 2, 2016. Thieves smashed the glass in the front door and entered the PruittHealth Home Health – Low Country office. No electronic devices were stolen by the thieves and only petty cash was believed to have been taken. However, patient files were stored in the office and could potentially have been accessed. On discovery of the break-in on March 3, PruittHealth staff alerted law enforcement and checked to determine whether any patient files had been accessed or stolen. The files did not appear to have been disturbed and no paper files appeared to have been removed by the thieves. Patients have now been notified that if the files were accessed, their...

Read More

Criminal HIPAA Case: Conviction for Respiratory Therapist

A former respiratory therapist has been convicted on criminal HIPAA violations by a federal jury in Ohio. The jury agreed with prosecutors that the protected health information of patients was wrongly obtained and that PHI was used to seek and obtain intravenous prescription drugs. Jamie Knapp was employed as a respiratory therapist at the ProMedica Bay Park Hospital in Oregon, Ohio. Over a period of 10 months Knapp improperly accessed the medical records of 596 patients. Knapp was permitted access to patient records in order to conduct her work duties; however, she was only permitted access to the records of patients she was treating. Knapp abused her access rights and viewed the HIPAA PHI of other patients without authorization, according to the prosecution. Sentencing has been tentatively scheduled for October and Knapp could be jailed for up to a year. It is relatively rare for individuals to be tried for HIPAA violations, even when violations of the Health Insurance Portability and Accountability Act clearly appear to have taken place. Criminal convictions are even rarer. In...

Read More

Three Hospitals’ Medical Devices Hacked Using Ancient XP Exploits

Cybercriminals are using increasingly sophisticated methods to gain access to healthcare networks, although according to a recent report – MEDJACK.2 Hospitals Under Siege – from Trap X Research Labs, old school malware and ancient exploits can still be effective. Three hospitals have been discovered to have been infected with malware via medical devices running on legacy systems. The researchers discovered “a multitude of backdoors and botnet connections,” that had been installed using ancient exploits of the unsupported Windows XP platform. Hackers had succeeded in compromising the machines even though the hospitals had modern, sophisticated cybersecurity defenses in place. The initial attacks used old malware which was not detected by advanced security software. The malware was not deemed to pose a threat as the vulnerabilities that the malware exploited had been addressed in Windows 7 and did not exist in later Windows versions. Sophisticated Cybersecurity Defenses Failed to Identify Windows XP Malware Infections One of the hospitals tested by TrapX researchers had a...

Read More

655,000 Health Records from Unreported Data Breaches For Sale on Darknet

Over the course of the past few weeks there have been huge data dumps from historic cyberattacks on LinkedIn, MySpace, and Tumblr. More recently, over 33 million hacked Twitter accounts were listed for sale online. These accounts are believed to have been hacked using the credentials obtained in the LinkedIn breach. Given the number of healthcare data breaches that have occurred over the past few years, it is to be expected that some of these data will be listed for sale on underground forums as hackers look to turn data into cash. However, three large healthcare databases have just been listed for sale online which do not appear to have come from historic healthcare data breaches. 655,000 Healthcare Records Listed for Sale from Recent Unreported Data Breaches The data appear to have come from three separate breaches. The hacker who listed the data for sale has indicated there will be more to come. The batches of data currently being offered for sale total 655,000 patient records. The data have been listed for sale by the hacker “TheDarkOverlord” who claims the data have been...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist