NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cloud-Based EHR Company Settles with FTC over Alleged Privacy Violations
Jun10

Cloud-Based EHR Company Settles with FTC over Alleged Privacy Violations

Cloud-based EHR company Practice Fusion has agreed to settle a case with the Federal Trade Commission (FTC) after allegedly misleading consumers about the privacy of information collected by the company. In 2012, Practice Fusion sent emails to consumers asking them to write reviews of their healthcare providers in order to populate its healthcare provider directory with data ahead of a planned 2013 launch. Patients names and email addresses were taken from the company’s electronic health record service and emails were sent to patients asking them to review their physicians. Patients were told that the reviews would “help improve your service in the future.” The emails appeared to have been sent by the patients’ healthcare providers. By clicking the link in the email, patients were directed to an online form where they were asked questions relating to their most recent healthcare visit. Patients were provided with a text box on the form where they were able to enter information. Many patients used the text box to submit highly personal information – Information that under the HIPAA...

Read More

12,500 Drug and Alcohol Abuse Program Patients Impacted by San Juan County Hack

Last month, San Juan County, NM., announced that a hacker had gained access to its computer systems and potentially viewed the highly confidential data of patients enrolled in its drug and alcohol abuse program. Patients affected by the breach had previously been ordered by the courts to undergo treatment for drug and alcohol abuse after being caught using methamphetamine or driving while under the influence of alcohol. Patients’ names and participation in the drug and alcohol program were potentially revealed to the hacker, along with their addresses, health assessment data, details of prescription medication, and the treatment methods they had been prescribed. San Juan County was alerted to the intrusion within 30 minutes of access being gained, limiting the potential for data to be viewed or copied. Upon discovery of the hack, access to its system and data was terminated. During this short window of opportunity data may have been viewed or copied. San Juan County hired an external cybersecurity firm to conduct a thorough forensic investigation of the security breach. The...

Read More

OCR Warns of Security Vulnerabilities in Third Party Apps

The Office for Civil Rights has recently reminded covered entities and their business associates to be alert to risks that can be introduced by using third party software applications. While covered entities and business associates may be aware that operating system software patches need to be installed promptly, the same is true for all third party software applications. OCR cites recent research that indicates only one in five companies has performed verification on third party software and applications, even though a majority of companies use third party software. Many organizations fail to apply patches promptly and allow known vulnerabilities to remain unpatched. Updates are frequently issued for third party applications such as Adobe Acrobat, Adobe Flash, and Oracle JRE. Many of the zero day vulnerabilities in these software applications are actively exploited by the time patches are released. A failure to update these applications promptly could place healthcare computer networks at risk of attack. All covered entities must therefore ensure that all third party software is...

Read More
Washington DC VA Medical Center Breach Exposes PHI of 1,062 Veterans
Jun09

Washington DC VA Medical Center Breach Exposes PHI of 1,062 Veterans

Washington DC Veterans Affairs Medical Center has reported a security incident that has exposed the protected health information of 1,062 veterans. On March 31, 2016, the privacy office of the Washington DC Veterans Affairs Medical Center was notified that a controlled substance monthly report had been discovered to be missing. The report included veterans’ full names along with their full or partial Social Security numbers. An investigation into the incident was launched and attempts were made to locate the missing document, but it has not been recovered. In response to the incident, the medical center has updated its procedures and has now implemented new controls to prevent future privacy breaches of this nature from occurring. All veterans affected by the privacy breach are being sent breach notification letters and will be offered a year of credit monitoring and identity theft protection services without charge. Details of the steps that veterans can take to protect their privacy have also been included in the breach notification letters. Berkeley Endocrine Clinic Informs...

Read More

Two Healthcare Providers Announce Billing-Related PHI Breaches

Loyola University Medical Center and University of New Mexico Hospital have discovered separate mailing-related privacy breaches and have started notifying patients of the exposure of a limited amount of their protected health information. Loyola University Medical Center Privacy Breach On April 5, 2016., Loyola University Medical Center discovered billing statements had been sent to incorrect addresses in February 2016. The University had undertaken a project to acquire accurate addresses; however, some billing statements ended up being released to addresses that had not been verified. A limited amount of protected health information was inadvertently disclosed to unauthorized individuals including patients’ names, along with their account number, dates of service, procedure codes, general descriptions of the medical services provided, and the balances due to be paid. No Social Security numbers, credit card details, or insurance information were disclosed. In an effort to minimize the probability of similar privacy breaches occurring, Loyola University Medical Center will also be...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist