25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

PHI of 1,615 Medicaid Patients Potentially Exposed by NC DHHS
Oct17

PHI of 1,615 Medicaid Patients Potentially Exposed by NC DHHS

The North Carolina Department of Health and Human Services (NCDHHS) has started sending breach notification letters to 1,615 patients alerting them to a breach of their Protected Health Information (PHI), following an internal breach of security protocol. NCDHHS Spokeswoman, Kendra Gerlach, issued a statement yesterday announcing the data breach, which occurred on August 19, 2015. Under the regulations laid down by the Health Insurance Portability and Accountability Act’s Breach Notification Rule, covered entities are allowed up to 60 days to alert the Office for Civil Rights, media, and patients of PHI. This is a maximum time limit. The Breach Notification Rule also says that notices must be issued to patients without unreasonable delay. The notice was issued very close to the 60-day deadline, although the delay was explained by Gerlach as being necessary as NCDHHS “must investigate thoroughly and ensure there is full understanding before determining next steps [to take].” The security breach was caused when an employee sent an email to the Granville County Health...

Read More

SecurityMetrics Reports on HIPAA Security Rule Compliance

What steps are U.S healthcare organizations taking to ensure HIPAA Security Rule compliance? How well are HIPAA rules understood? Are healthcare providers actually now compliant with HIPAA Rules? These questions will naturally be answered when the Office for Civil Rights compliance audit program recommences early in 2016. In the meantime, SecurityMetrics – a Utah-based merchant data security and compliance company – decided to get some answers now and conducted a survey of health IT professionals to gain a better understanding of the general state of HIPAA compliance among healthcare organizations. Attitudes on HIPAA-Compliance Probed Security Metrics compiled a survey to probe attitudes on common patient health data protection issues, network security measures used to safeguard data, and other security issues such as Wi-Fi encryption. The aim was to gain a better understanding of the efforts U.S healthcare organizations are making to comply with the HIPAA Security Rule. Over 300 healthcare professionals took part in the survey and were asked over 40 questions relating to...

Read More

Unencrypted Laptop Theft Exposes PHI of 9,300 University of Oklahoma Patients

Lightening does strike twice, at least in Oklahoma it would seem, where yet another unencrypted laptop has been stolen from the car of a University of Oklahoma (UO) physician, this time exposing the Protected Health Information (PHI) of 9,300 patients, adding to the 7,693 victims created by the last UO unencrypted laptop theft, reported in July. If the Department of Health and Human Services’ Office for Civil Rights has not yet investigated the previous breach – suffered by the University of Oklahoma’s College of Medicine’s Department of Obstetrics and Gynecology – this additional laptop theft may well move the investigation up the priority list. This time around, the security breach hints of HIPAA violations. University of Oklahoma HIPAA Breach?   In the latest case, UO was unaware that the Department of Urology physician in question was storing patient data on the laptop, which was in violation of internal data security policies. The breach notice was issued almost three months after the theft occurred, suggesting a violation of the HIPAA Breach Notification Rule. UO...

Read More

Cost of Health System Cyberattacks to Rise to $305 Billion

The cost of health system cyberattacks is set to increase substantially, according to a recent study conducted by global management consulting firm, Accenture. The new study predicts the cost of health system cyberattacks will rise to $305 billion over the next 5 years, and will affect approximately 25 million patients. The company also estimates that 1 in every 13 U.S healthcare system patients are likely to have their identities stolen and used to commit fraud over the same time period. The research team calculated that 1.6 million patients have already had their medical data stolen from healthcare providers in 2014. With the number of breach victims already created in 2015, next year’s figures are likely to be considerably higher. Cost of Health System Cyberattacks Will Continue to Increase For the study, Accenture used data compiled by the Ponemon Institute along with breach reports submitted to the Department of Health and Human Services’ Office for Civil Rights. That data was used to determine the number of individuals who were likely to suffer identity theft, and then...

Read More

How to Spot a Phishing Email

October is National Cyber Security Awareness Month, a time of the year when events are organized and new initiatives are launched to increase cybersecurity awareness and highlight the risk of cyberattacks, computer fraud, phishing campaigns, and other data security and privacy issues. When President Obama declared October National Cyber Security Awareness Month, his aim was to increase the resiliency of the nation in the event of a cyber incident, and great strides have been made already to make his dream a reality. The Cybersecurity Threat is Greater Than Ever Before Unfortunately for healthcare providers, cybercriminals are now upping their game. They are developing ever more sophisticated methods of attack in an effort to gain access to healthcare data. The United States now faces the highest risk of cyberattack and all healthcare providers must now invest heavily in defenses to protect their computer equipment and systems from the onslaught of attacks. One of the most common methods used by cybercriminals to gain access to healthcare networks is phishing emails. The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist