25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

2016 Global State of Cybersecurity Study Released

The threat landscape is ever-changing and the risk of cyberattacks has grown enormously in recent years; however, organizations have responded to the increased threat level by implementing a range of new cybersecurity defenses to keep networks and data secure, according to a recent report on the global state of cybersecurity. Cloud-enabled cybersecurity defenses have been deployed, advanced authentication software installed, and big data analytics are increasingly common. As a result, cybersecurity risks are, in many cases, being effectively managed. One of the main advances has been the use of cybersecurity intelligence, which allows insights to be gained into the biggest security threats. This has allowed IT security professionals to manage risks more effectively, and allocate resources to deal with the biggest threats. We are now also seeing organizations adopt a more collaborative approach to data security, with greater sharing of intel between corporations to deal with a common threat. Global State of Cybersecurity Assessed by PWC The new Pricewaterhouse Coopers (PWC) study...

Read More

Data Breach Laws in California Updated

Data breach laws in California have been updated following the signing of three new bills by California Governor Jerry Brown. The new bills were passed as a single package, and will come into effect on January 1, 2016. The new bills – Assembly Bill 964 (A.B. 964), Senate Bill 570 (S.B. 570) and Senate Bill 34 (S.B. 34) – are intended to clarify data breach laws in California, and provide further explanations on data encryption, the issuing of data breach notices, as well as expanding the definition of “personal information” under California Law. New Data Encryption Definition   There are a number of data encryption standards and methods of encrypting data to prevent accidental or deliberate disclosure. However, not all encryption methods offer the same level of protection. One of the new bills introduced last week helps to clarify what is meant by “encryption” in California. Assembly Bill 964 confirms that encryption means information is “rendered unusable, unreadable or indecipherable to an unauthorized person through a security technology or methodology generally accepted in...

Read More

Encryption Almost Prevents Humana Data Breach in Wisconsin

Data encryption technology used by Humana may not have prevented a data breach, but it has certainly limited the extent of data exposed, the damage caused, and has considerably reduced the cost of remediation. On Friday last week, Humana reported the theft of an encrypted laptop from an employee’s vehicle. Security keys for the laptop were not stolen, and the data stored on the device remain secure; however, along with the laptop, the thief stole documentation containing the names, dates of birth, and “clinic names” of 2,800 Medicare Advantage Plan subscribers. In addition to the above data, 250 subscribers also had their Humana member identification numbers exposed, according to a recent report in the Milwaukee Journal Sentinel. A statement issued by Humana confirms that financial information and Social Security numbers were not compromised in the security incident. The Breach Notification Rule of the Health Insurance Portability & Accountability Act (HIPAA) requires notification letters to be sent to all individuals who have had their Protected Health Information (PHI)...

Read More

Alleged Intimidation and Potential VA HIPAA Violations Investigated

The Department of Veteran Affairs has come under increasing criticism in recent weeks for privacy and potential HIPAA violations. The White House Office of Special Counsel initiated an investigation into the VA for veteran privacy breaches, and now the Department of Health and Human Services has taken the decision to start an investigation, this time for potential VA HIPAA violations caused when the medical records of a whistleblower were allegedly accessed in retaliation for the disclosure of VA privacy violations. This week, whistleblower Brandon Coleman received a notification from the HHS of an investigation into a complaint he made of inappropriate and unauthorized accessing of his confidential medical files by the VA. He was informed that the HHS had started an investigation into his privacy complaint on May 1, 2015. He claimed the privacy violation occurred in an effort to intimidate him for giving evidence against the VA. Two weeks ago, in a Senate hearing, Coleman and other whistleblowers accused the VA of conducting smear campaigns that involved VA staff accessing the...

Read More

CarePlus Discovers Privacy Breach Affecting 1400

A potential privacy breach has been discovered to have affected CarePlus Health Plans. This is one of a number of patient privacy breaches to have been reported in recent weeks that have involved errors made when printing and mailing information to patients. On September 18, 2015, CarePlus prepared a mailing of CarePlus Late Enrollment Penalty Premium Statements to patients. A machine was used to insert two premium statements into each envelope, but instead of inserting one statement, two were placed into each envelope by accident. The error resulted in 1,400 patients being sent statements intended for other patients. The information potentially disclosed did not include highly sensitive information such as Social Security numbers, but patients have their names, addresses and CarePlus ID numbers accidentally disclosed to other health plan subscribers. All affected members will undoubtedly already be aware of the error if they opened their statements, although they have now also been sent a HIPAA breach notification letter explaining the exposure of their information and how the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist