NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Announces $3.9 Million Settlement with Feinstein Institute for Medical Research

The Department of Health and Human Services’ Office for Civil Rights has announced it has settled potential HIPAA violations with Feinstein Institute for Medical Research for $3.9 million. This is the second largest settlement amount agreed with OCR, behind the $4.8 million settlement with New York and Presbyterian Hospital and Columbia University in 2014. However, this is the largest amount paid by a single covered entity, beating last year’s 3.5 million settlement with Triple S Management Corporation. The news comes a day after OCR announced another large settlement – The $1.55 million paid by North Memorial Health Care. Feinstein Institute for Medical Research is a not-for-profit biomedical research institute based in New York. Feinstein is sponsored by Northwell Health, Inc., the new name for North Shore Long Island Jewish Health System, a large 21-hospital and 450-practice health system based in Manhasset, NY. The settlement stems from an investigation into a breach of 13,000 research participants’ data in 2012. As was the case with North Memorial Health Care, the breach...

Read More
6,893 Patient Records Exposed Due to Centers Plan for Healthy Living Laptop Theft
Mar17

6,893 Patient Records Exposed Due to Centers Plan for Healthy Living Laptop Theft

Centers Plan for Healthy Living, a Staten Island NY-based managed care organization, has announced that a laptop computer containing the protected health information of Medicare/Medicaid recipients has been stolen from its corporate offices. The laptop theft was discovered on January 4, 2016., with the device believed to have been taken on or around January 1. Following the discovery of the theft, Centers Plan conducted an investigation and determined that the laptop may have contained a file containing data relating to 6,893 Medicare and Medicaid recipients. No Social Security numbers, financial information, credit card numbers, health data, or other highly sensitive information were contained in the file, although some individuals have had their Medicare and/or Medicaid numbers exposed. Other data believed to have been contained in the file include full names, dates of birth, and home addresses. The theft was immediately reported to law enforcement although the laptop computer has not been recovered. Centers Plan does not believe the laptop was stolen for the data stored on the...

Read More
EHR of Geauga Medical Center Improperly Accessed by Employee
Mar17

EHR of Geauga Medical Center Improperly Accessed by Employee

A former employee of University Hospitals Geauga Medical Center in Chardon, OH., has been discovered to have improperly accessed the protected health information of 677 patients. An internal review of access logs was conducted after UH discovered a pattern of “unusual access” of its electronic health record system. The investigation, completed on January 13, 2016., revealed that an employee had accessed patient health records without any legitimate reason for doing so. The information accessed included patient names, medical record numbers, dates of birth, details of prescribed medications, and other data recorded during patient visits to Geauga Medical Center. The employee first started inappropriately accessing patient health records on August 15, 2015, with periodic access continuing until January 3, 2016. No reason was given as to why the individual had accessed the data, although UH does not believe the records were accessed with a view to committing identity theft. UH has not received any reports of inappropriate use of the data or of patients coming to harm as a result of...

Read More
$1.55 Million HIPAA Settlement for Lack of BAA and Risk Analysis Failures
Mar17

$1.55 Million HIPAA Settlement for Lack of BAA and Risk Analysis Failures

The Department of Health and Human Services’ Office for Civil Rights has announced it has reached a settlement with North Memorial Health Care of Minnesota over alleged HIPAA violations from a 2011 data breach. North Memorial has agreed to pay $1,550,000 to OCR to settle the HIPAA violation charges. Following a PHI breach reported on September 27, 2011, OCR conducted an investigation and discovered HIPAA violations that contributed to the cause of a breach of 9,497 patient health records. The investigation revealed that North Memorial had overlooked “Two major cornerstones of the HIPAA Rules,” according to OCR Director Jocelyn Samuels. The data breach involved the theft of a laptop computer from a business associate of North Memorial. The laptop was stolen from the employee’s vehicle, and while the device was password-protected, the ePHI stored on the device had not been encrypted. The business associate, Accretive Health, Inc., had been contracted to perform a number of payment and healthcare operations on behalf of North Memorial. Those operations required Accretive Health to be...

Read More
OCR Clarifies How HIPAA Rules Apply to Workplace Wellness Programs
Mar16

OCR Clarifies How HIPAA Rules Apply to Workplace Wellness Programs

Office for Civil Rights Director Jocelyn Samuels has written a blog post to clear up confusion about how HIPAA Rules apply to workplace wellness programs provided through employer-sponsored group health plans. Workplace wellness programs have become increasingly popular in recent months and more employers are now offering workplace wellness programs to employees to improve their health. Providing workplace wellness programs to employees requires employers to gather health data through health risk assessments and various other means, and those data must be protected under Health Insurance Portability and Accountability Act Rules. HIPAA also places severe restrictions on how health data can be used. HIPAA does not apply to all workplace wellness programs, only those that are offered through an employer-sponsored group health plan. Samuels explained in the post that employers are not permitted to disclose any health data for employment-related actions, nor are data allowed to be used for marketing purposes or any other reason not permitted by HIPAA Rules. The HIPAA Security Rule...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist