NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Up to 400,000 Prisoners’ PHI and SSNs Exposed
Jun07

Up to 400,000 Prisoners’ PHI and SSNs Exposed

Up to 400,000 current and former prisoners incarcerated by the California Department of Corrections and Rehabilitation between 1996 and 2014 have potentially had their Social Security numbers, medical data, and personally identifiable information exposed. The data breach was reported last month by California Correctional Healthcare Services (CCHCS) and a substitute breach notice was posted on the CCHCS website on May 13; however, at the time it was unclear exactly how many prisoners had been affected. While this is still uncertain, the Office for Civil Rights breach report indicates as many as 400,000 individuals may have been affected. An exact figure is not known as the investigation conducted by CCHCS has not determined which individuals’ data were stored on the device. The figure of 400,000 is the total number of patients who had received healthcare services from CCHCS between 1996 and 2014. That makes this the third largest healthcare data breach so far reported in 2016, behind only the 483,000-record breach at Radiology Regional Center, and the 2.2 million-record data breach...

Read More
Anthem Data Breach Lawsuit Heading for Trial
Jun06

Anthem Data Breach Lawsuit Heading for Trial

Following the mammoth 2015 data breach at Anthem Inc., around 100 lawsuits were filed by plan members seeking damages for the exposure of their protected health information. In June last year, the lawsuits were consolidated and moved to the Northern District of California and are being presided over by the Honorable Lucy H. Koh. The cyberattack on Anthem was the largest healthcare data breach ever reported, involving approximately 37 million records and affecting close to 78.8 million individuals. The persons responsible for the cyberattack have not been identified, although the security breach is widely believed to have been a state-sponsored attack by Chinese hackers. Class-action lawsuits are often filed by data breach victims following the exposure of personally identifiable information, although the cases are usually dismissed unless there is concrete evidence of actual harm of losses being suffered by the victims. However, the huge data breach case has survived motions to dismiss and looks set to be heading to trial. Last week, Koh indicated the latest motion by the defense...

Read More
Head of House Select Investigative Panel Calls for HIPAA Investigation into Abortion Clinic PHI Disclosures
Jun06

Head of House Select Investigative Panel Calls for HIPAA Investigation into Abortion Clinic PHI Disclosures

Last week, the head of the House Select Investigative Panel tasked with investigating the trade of baby body parts by abortion clinics wrote to the director of the Department of Health and Human Services’ Office for Civil Rights requesting an investigation into violations of the Health Insurance Portability and Accountability Act (HIPAA). It is alleged that Planned Parenthood – Planned Parenthood Mar Monte (PPMM) and Planned Parenthood Shasta Pacific (PPSP) – and Family Planning Specialists Medical Group (FPS) improperly disclosed the protected health information (PHI) and personally identifiable information (PII) of female patients to StemExpress. In her June 1 letter to Jocelyn Samuels, Rep. Marsha Blackburn explains that employees of StemExpress were provided with details of the abortions that were scheduled to take place on each day and were also given access to the medical files of patients who would be likely to provide fetal tissue donations. Blackburn claims that StemExpress employees were allowed inside of clinics and were given permission to interview patients in...

Read More
ONC Releases Videos Explaining Patients’ HIPAA Rights
Jun03

ONC Releases Videos Explaining Patients’ HIPAA Rights

Earlier this year, the HHS’ Office for Civil Right (OCR) released guidance for healthcare organizations on patients’ HIPAA rights in an attempt to clear up confusion over access and ensure that covered entities were aware of their obligations under the HIPAA Privacy Rule. The guidance covered many of the questions commonly asked by healthcare organizations, including the models that can be adopted by healthcare organizations for charging for PHI copies. Now that covered entities are prepared, efforts have shifted to advising patients of their access rights under HIPAA. This week, the Office of the National Coordinator for Health Information Technology (ONC) -in conjunction with the OCR – released a series of educational videos to improve understanding of patients’ HIPAA rights. The ONC wants to improve patient engagement and get patients to take greater interest in their health. Encouraging patients to obtain copies of their ePHI can help in this regard. Having access to medical records allows patients to check for errors, provide their data to other healthcare providers or...

Read More

ProMedica Uncovers Unauthorized Accessing of PHI by 7 Employees

ProMedica has recently discovered that seven of its employees had been improperly accessing the protected health information of patients for almost two years. The employees in question had been granted access to patient files in order to perform their work duties, but had accessed the medical records of patients who they were not required to treat, nor was there any legitimate business reason for patient data being accessed. ProMedica was alerted to the privacy breaches on April 7, 2016., and a thorough internal investigation was launched. That investigation revealed that the records of 3,500 patients had been improperly accessed over a period of two years, from May 1, 2014., to April 26, 2016. Affected patients had received medical services at either ProMedica’s Bixby Hospital in Adrian, MI., or Herrick Hospital in Tecumseh, MI. The type of data viewed by the employees include patients’ names, addresses, dates of birth, contact telephone numbers, insurance information, medical diagnoses, details of medications that had been prescribed, and other clinical data. ProMedica’s...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist