NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Worker Asks for ‘Massive Break’ after Stealing Half a Million Dollars

Markitta Washington, a resident of Farmington Hills, MI., is just like many Americans. She has been working two jobs in order to make ends meet. However, unlike most Americans, she also drives an expensive Cadillac which has been made possible by stealing the Social Security numbers and personal information of hospital patients and filing fraudulent tax returns in their names. Washington has added close to $500,000 to her salary with this “third job”. She recently admitted the theft and fraud, and has asked the judge to give her a “massive break” and suspend her jail sentence for 5 years. Washington worked two hospital jobs, taking a position at both Henry Ford Hospital in West Bloomfield and Harper Hospital in Detroit. In addition to taking home a pay check from each she also took home patents’ Social Security numbers and personal information. At her trial, Washington admitted to stealing the data of 14 patients and using that information to file false tax returns in their names. Washington and her husband, who was also part of the scam, also sent in fraudulent tax returns...

Read More
New Oregon Breach Notification Law Comes Into Effect
Jan09

New Oregon Breach Notification Law Comes Into Effect

Organizations doing business in the state of Oregon must now comply with a new data breach law that came into effect on January 1, 2016. If a data breach is suffered that exposes the personal information of more than 250 state residents, a breach notice must be submitted to the Oregon Attorney General. On June 10 last year, Oregon Governor Kate Brown signed the new law (Oregon Revised Statutes 646A.604) updating the Oregon Consumer Identity Theft Protection Act of 2007. The amendment expanded the definition of “personal information” to include biometric data such as a retina or iris images and fingerprints, as well as medical and health insurance information. Other data classed as personal information include Social Security numbers, government ID numbers, Driver’s license numbers and financial information including credit or debit card number in combination with any required security code, access code or password. The exposure of any of those data elements along with a person’s full name or last name and initial requires a breach notice to be issued. Oregon is one of a few states...

Read More

NSF Grant Funds Development of Mobile Cloud Dietary Assessment Tool

Many mHealth apps lack sufficient controls to keep patient data secure. In late 2014, a Trustworthy Health and Wellness (THaW) project funded by the National Science Foundation (NSF) determined that 63% of popular mHealth apps were not encrypting data (out of a test sample of 22), potentially placing data at risk of theft. Furthermore, 81% of mHealth apps were using third party storage or hosting services. The benefits of mHealth apps for patients and healthcare providers are considerable. Unfortunately, healthcare providers wishing to use mHealth apps are prevented from doing so by HIPAA. Unless developers of mHealth apps encrypt stored and transmitted data to a nationally accepted standard, or implement other controls to keep data secure, use of the apps by the healthcare industry will be limited. Secure Mobile Cloud Dietary Assessment Tool Under Development University of Massachusetts Medical School and UMass Lowell have recently embarked on a new National Science Foundation grant funded project to test a new mHealth infrastructure that will allow patient data to be collected...

Read More
Henry Schein Gets 20-Year Consent Order and $250K FTC Fine for False Advertising of Data Encryption
Jan08

Henry Schein Gets 20-Year Consent Order and $250K FTC Fine for False Advertising of Data Encryption

The HIPAA Security Rule defines encryption as the “use of an algorithmic process to transform data into a form in which there is a low probability of assigning meaning without use of a confidential process or key.” 45 CFR 164.304. Covered entities must ensure that the strength of the encryption software is appropriate. Not all encryption software protects data to the same degree. In fact, some methods of encryption are better referred to as data camouflage rather than data encryption. The Department of Health and Human Services’ Office for Civil Rights recommends using robust encryption that conforms to a nationally recognized standard such as the Advanced Encryption Standard (AES), recommended by the National Institute of Standards and Technology (NIST). Henry Schein Practice Solutions, Inc., a vendor of software solutions for dental practices, chose a different encryption standard for its Dentrix G5 software solution. The software allows dentists to enter and store patient data, process claims and payments, and send appointment reminders. Dentists are covered under HIPAA and must...

Read More
IU Health Arnett Security Breach Impacts 29K Patients
Jan07

IU Health Arnett Security Breach Impacts 29K Patients

Indiana University Health’s Arnett Hospital has alerted 29,324 patients about the potential exposure of their Protected Health Information after an unencrypted flash drive disappeared from its emergency department. The flash drive was discovered to be missing on November 20, 2015, and an investigation was immediately launched. Efforts are continuing to try to locate the missing flash drive, which was lost in an area of the hospital not accessible to the public. Consequently, hospital officials do not believe patient data have been acquired or viewed by an external third party. IU Health Arnett Hospital started sending breach notification letters to affected patients last week to inform them that some of their PHI has potentially been compromised. However, no reports of inappropriate use of the data have so far been received by the hospital. The flash drive was not used to store Social Security numbers, financial information, or credit card numbers, although spreadsheets saved on the device included patient names, medical record numbers, dates of birth, and medical diagnoses. Norma...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist