NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Allina Health System Alerts 6,000 About Improper PHI Disposal

The Minneapolis Isles clinic run by Allina Health System has notified approximately 6,000 patients of a breach of their Protected Health Information (PHI). The clinic, located at 2800 Hennepin Avenue, discovered instances of improper PHI disposal had occurred after documents containing sensitive information were found in regular trash. HIPAA rules require all documents containing PHI to be rendered unreadable, indecipherable, and incapable of being reconstructed prior to disposal. The HIPAA breach is not understood to have resulted in any patient health information being viewed by unauthorized individuals, although the clinic is unable to guarantee that to be the case. According to a statement released by Allina Spokesman, David Kanihan, the incident is considered only to be a “technical breach of unsecured protected health information.” Because a risk does exist, out of an abundance of caution Allina Health System will be offering all affected patients a year of credit monitoring services without charge. The data potentially exposed include names of patients, their mailing...

Read More

Study Shows Value of Phishing Simulation Exercises

A recent report indicates the probability of members of staff responding to a phishing campaign can be effectively reduced to zero if phishing simulation exercises are completed regularly. The Growing Threat of Healthcare Phishing Attacks The Office for Civil Rights recently issued its first financial penalty to an organization that suffered a data breach after its employees responded to a phishing campaign. The case resulted in University of Washington Medicine agreeing to a $750,000 fine to settle potential HIPAA violations. UWM had already had to cover significant data breach resolution costs after suffering a 90,000-record breach. The fine and data breach costs could potentially have been avoided if staff members had been trained how to identify phishing emails. The healthcare industry is now being targeted by cybercriminals, and phishing is the most commonly used method of gaining access to patient data. Even when multi-million-dollar security defenses are employed to keep networks secure, a single response to a phishing email can be all it takes to compromise the records of...

Read More

HealthSouth Rehabilitation Hospital Announces 1,359-Record Data Breach

Only a few hours after the announcement of the theft of an unencrypted laptop computer from the vehicle of an employee of the New Mexico Department of Health comes news of another. The latest laptop theft affects 1,359 patients of the HealthSouth Rehabilitation Hospital in Round Rock, TX. An employee of the hospital left an unencrypted laptop computer in the trunk of a vehicle from where it was stolen. As with the NM Department of Health laptop theft, the incident occurred in October. Covered entities have up to two months to issue breach notification letters to patients and the Department of Health and Human Services’ Office for Civil Rights. The notification letters were sent on Tuesday 22, December and OCR has now been notified. The theft was discovered by HealthSouth on October 26, 2015, five days after the theft actually took place. Once the theft was discovered, the incident was reported to Austin law enforcement. It is not clear why it took five days for hospital staff and law enforcement officers to be notified. The laptop computer has not subsequently been recovered. The...

Read More
Pittsburgh Woman Arrested for $600K Medical Insurance Fraud
Dec23

Pittsburgh Woman Arrested for $600K Medical Insurance Fraud

A counselor from the Pittsburgh area has been arrested on suspicion of fraudulently billing over $600,000 for counseling services which were never provided to patients. The investigation was launched after a tip off was received by the Pennsylvania Office of Attorney General’s Insurance Fraud Division by Highmark Blue Cross Blue Shield. Highmark claimed that Lisa A. Wally, 33, also known as Lisa A. Smith Wally from McKeesport, PA, had inflated billings for services she provided to her clients, and billed the insurer for services that were never actually provided. Office of Attorney General investigators discovered Wally had billed for 9,746 office visits for 22 patients between 2011 and 2015. However, investigators only found evidence that 1,987 visits had occurred. In total, Wally had received $601,280 in payments for services that were allegedly provided at her offices in Uniontown, Fayette County, but no evidence could be produced to prove that those sessions had ever taken place. Wally was unable to produce any evidence that the sessions occurred as no patient records were kept...

Read More

Mental Health Counseling Records Stolen in Office Burglary

The Fox River Counseling Center on Bay Shore Drive, Oshkosh, WI, was burglarized on October 23, 2015, and an unencrypted laptop computer was stolen. Highly sensitive data were stored on the laptop, including the medical records and personal information of an undisclosed number of patients. Social Security numbers, details of mental health status, and the results of psychological tests could potentially have been accessed and viewed by the thieves. Other data believed to have been stored on the laptop include patient names, addresses, dates of birth, statements of work capacity, medical diagnoses, and medical histories. In total, 509 patients had their data compromised. Affected patients had visited the Bay Shore Drive Fox River Counseling Center between Nov. 7, 2012, and Aug. 19, 2014. The laptop also included data relating to Wisconsin Disability Determination Bureau psychological evaluations that were conducted between May 13, 2013, and Oct. 21, 2015. As soon as the break-in and theft were discovered, the Oshkosh police department was notified but the laptop computer has not been...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist