NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Stolen Premier Healthcare Laptop Returned: No PHI Accessed Says Pondurance
Mar16

Stolen Premier Healthcare Laptop Returned: No PHI Accessed Says Pondurance

When a healthcare laptop is stolen it is exceptionally rare for the device to be recovered. However, Premier Healthcare LLC., has reported that the laptop computer stolen from its billing department on December 31, 2015 has now been recovered. Initially, it was unclear how many patients had been affected by the breach, although an analysis revealed that the laptop computer contained the records of 205,748 individuals. The laptop computer was protected with a password but the data stored on the device were not encrypted. PDF files, spreadsheets, and screenshots containing the protected health information of patients were all potentially accessible. The laptop computer was last seen in the billing department and was believed to have been stolen on December 31; however, more than two months after the device went missing it arrived in the mail. Premier Healthcare reported the device was received in the mail on or before March 7, 2016. It would appear that the individual who took the laptop had second thoughts and returned the device anonymously. However, a data breach may still have...

Read More

Laborers Funds Administrative Office of Northern California Reports HIPAA Breach

The Laborers Funds Administrative Office of Northern California has announced it has experienced a HIPAA security incident that has resulted in the protected health information of participants being disclosed to other individuals. The Laborers Funds Administrative Office of Northern California, which manages Northern California Laborers Trust Funds, conducted a mailing on February 17, 2016 to alert participants that they were not responsible for tax or penalty under the Patient Protection and Affordable Care Act as they had the required minimum level of coverage from the fund. However, a computer error occurred when mailing IRS 1095-B forms to participants which resulted in some individuals receiving correspondence containing data relating to other fund participants and their dependents. The data detailed on the 1095-B forms included Social Security numbers and health plan coverage information along with the full names of other participants and their dependents. In accordance with HIPAA and state regulations, all affected individuals have been sent breach notification letters to...

Read More

Lost Flash Drive Exposes Data of Karmanos Cancer Center Patients

An unencrypted flash drive containing the protected health information of 2,808 patients of the Barbara Ann Karmanos Cancer Center has been declared lost. The flash drive had been mailed to Barbara Ann Karmanos Cancer Center but when the package arrived, the flash drive was discovered to be missing. The portable storage device was placed in an envelope and was mailed, which was the last time the device was seen. The hospital has reported that efforts are being made to try to locate the flash drive although the device appears to have been lost in the mail. The flash drive was used to store data as part of a system upgrade. An investigation into the potential privacy breach was launched when the device was discovered to be missing to determine which patients had been affected, and the nature of the data stored on the device. The portable storage device was found to only contain a limited amount of administrative data which included the names of patients, their treating physicians, the name of the hospital where treatment was provided, and unique patient identifiers. No financial...

Read More

80% of Organizations Concerned About Large Data Breaches

Most organizations now understand that it is no longer a case of whether a breach will occur, but a matter of when their defenses will be breached, yet many organizations appear to be ill-equipped to deal with a data breach when one does occur, according to a recent ID Experts survey. The survey, conducted on behalf of insurance analyst firm Advisen, asked 203 risk assessment experts about data breach preparedness and the measures in place to deal with data breaches when they did occur. The aim of the survey was to find out more about how organizations are managing data breach risk, and how insurance coverage gaps are being addressed. Recent large-scale data breaches have got many CISOs worried that their organization will be attacked. 80% of respondents said they are worried about their organization suffering a large data breach. 17% of respondents said they had already suffered at least one data breach in the past 12 months. The very real threat of a data breach has prompted 64% of organizations to purchase data breach insurance, yet those policies may offer little benefit....

Read More

Economics of Cyberattacks Explored

A Ponemon Institute survey commissioned by Palo Alto Networks has explored the motivations behind cyber-attacks and offers some insight into how organizations can develop defenses to thwart attackers. The survey was conducted in the United States, United Kingdom, and Germany and asked 304 threat experts their opinions on the reasons why criminals chose to attack organizations, how targets are selected, and how much attackers actually make from their criminal acts. In the majority of cases, the main motivation for conducting an attack is money. Respondents indicated that in 67% of cases, attacks are conducted for financial gain. The average earnings for conducting those attacks were determined to be $28,744 per year. In order to earn that amount, hackers spent an average of 705 hours attacking organizations. The figures show that hacking far less profitable than working as a private or public sector security professional, with earnings of four times that figure possible. The report, Flipping the Economics of Attacks, indicates that the majority of hackers look for easy targets. 72%...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist