25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Are You Prepared for A Business Associate Data Breach?

HIPAA-covered entities may be prepared to execute their breach response procedures for a security breach that exposes patients’ Protected Health Information (PHI), but what about business associate data breaches? Have policies and procedures been developed to ensure a rapid breach response can be executed if a business associate suffers a data breach? The Department of Health and Human Services’ Office for Civil Rights has recently warned HIPAA-covered entities that they must take steps to ensure they can deal with a business associate data breach should one occur. OCR: HIPAA-Covered Entities Find Business Associate Data Breach Management Difficult The recent OCR cyber-awareness bulletin confirmed the need for action to be taken by HIPAA-covered entities to prepare for data breaches experienced by their vendors. The bulletin indicates a large percentage of covered entities are concerned that business associate data breaches may not be reported to them. OCR also suggests that when a business associate data breach does occur, covered entities are often unsure whether their vendors’...

Read More
Bay Area Children’s Association Notifies Patients of PHI Theft
May09

Bay Area Children’s Association Notifies Patients of PHI Theft

On April 1, 2016, Bay Area Children’s Association (BACA) was notified that the electronic health records of its patients may have been stolen by hackers. The notice was received from BACA’s electronic health record (EHR) provider which had discovered access to its systems had been gained by unauthorized individuals and malware had been installed. The EHR provider, which was not named in the breach notice, believes the malware was first installed on its systems in January 2015. Consequently, patients’ health data and personal information could conceivably have been in the hands of criminals for over 15 months. After being notified of the potential theft of protected health information, BACA contacted it’s EHR provider to find out more about the extent of the breach and the data that could have been accessed. BACA was informed on April 22, 2016 that there was no way of telling which patients had been affected, and whether data had actually been obtained by the attackers. Consequently, all patients whose data were stored in the EHR have had to be notified of security breach. The data...

Read More
Ohio MHAS Exposes PHI of 59K Patients by Mailing Surveys on Postcards
May09

Ohio MHAS Exposes PHI of 59K Patients by Mailing Surveys on Postcards

This week, patients of the Ohio Department of Mental Health and Addiction Services (OMHAS) were notified of a privacy incident that occurred on February 3, 2016. Patients were sent a satisfaction survey by mail; however, the survey request was sent on postcards rather than in sealed envelopes. Consequently, the fact that each patient had received services related to mental health and addition was inadvertently exposed along with patients’ names and addresses. This was not the first time that these mailings were sent to patients. Each year, OMHAS sends customer satisfaction surveys to patients to obtain feedback about the services they received. The aim of the mailings is to obtain data from patients that can be used to improve the services OMHAS provides and as part of the reporting requirements required for the federal Mental Health Block Grant. On February 25, 2016, OMHAS became aware that the mailing breached Health Insurance Portability and Accountability Act Rules. An investigation into the privacy breach revealed that similar mailings had been sent in the past. In total,...

Read More

Saint Agnes Medical Center Victim of BEC Attack

Saint Agnes Medical Center of Fresno, CA., is in the process of notifying 2,812 employees of a cyberattack that occurred on May 2, 2016. On Monday this week, an employee of Saint Agnes responded to a phishing email and sent copies of employees’ W-2 data to an attacker. The disclosed data included the names of employees along with their home addresses, salary details, withholding information, and Social Security numbers. The email request appeared to have come from the Chief Executive Office of Saint Agnes. The phishing attack was rapidly identified, although not before data were disclosed to the attacker. All employees affected by the data breach have been provided with a year of credit monitoring and identity restoration services through Experian without charge. Affected employees have also been advised to contact the IRS to find out if a fraudulent tax refund has been claimed in their name. The email scam is referred to as a Business Email Compromise (BEC) attack. This year has seen a number of BEC attacks on healthcare providers. The phishing scam is convincing as the emails...

Read More

Data Breach Class-Action Lawsuit Denied by Penn. Superior Court

A proposed class-action lawsuit filed against two health plans for the exposure of members’ protected health information has been rejected by the Pennsylvania Supreme Court. Avrum Baum filed a lawsuit against Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan in 2010 following the loss of a flash drive containing the data of approximately 286,000 patients. One of the patients affected by the data breach was Baum’s special needs daughter. Baum claimed in the suit that the loss of the device violated the privacy rights of patients. He also claimed the health plans had been negligent by failing to protect the data of patients, and the health plans had inaccurately told patients that their protected health information (PHI) was secured. Baum claimed that deceptive practices were used, which violated Uniform Trade Practices and Consumer Protection Law (UTPCPL). In July 2013, the class-action lawsuit was denied by a trial judge as Baum could not show that his daughter’s PHI was stored on the device and that the case did not have standing because Baum had not purchased his...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist