NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cottage Health System Security Audit Reveals 11K-Record Data Breach

Cottage Health System notified 11,000 of its patients on Tuesday to advise them that some of their Protected Health Information (PHI) was exposed as a result of a server incident that occurred in late October, 2015. For 14 days, patients had their Social Security numbers, details of medical diagnoses and procedures, and their names and addresses exposed as a result of protections being removed from a server. A statement released by Cottage Health indicates no financial information or Driver’s license numbers were exposed in the incident The security breach was discovered on 8th November and resulted in the affected server being taken offline and secured. Upon investigation, Cottage Health determined that patient data first became accessible on October 26, 2015. An external computer forensics firm has been contracted to conduct a full audit into the security breach to determine whether any of the data were accessed during the period they were accessible. At this present moment in time, no information has been released to indicate whether the security breach was caused by an external...

Read More

Centegra Data Breach Exposes PHI of 3,000 Patients

A mailing error caused a recent Centegra data breach that exposed a limited amount of Protected Health Information of 2,929 of the Health System’s patients. Business Associate Responsible for Centegra Data Breach Centegra Health System operates three hospitals and a number of other healthcare facilities in McHenry County, Illinois. Recently it discovered that one of its third party vendors had made an error that accidentally exposed the PHI of some of its patients. The data breach was caused as a result of a simple error made by an employee of MedAssets. The company had been contracted to mail billing statements to patients.  An error was made configuring the equipment used to prepare the mailing, which resulted in patients being sent two billing statements instead of one. One of the statements was correct and included patients’ personal data and charges, the other statement was for a different patient. Each envelope was filled automatically and was mailed. 2,929 letters were sent to patients by MedAssets between November 2 and Nov 6, 2015. Centegra was notified of the data breach...

Read More

HIPAA Violation Fine of $3.5 Million for Triple-S

Puerto Rico Blue Cross Blue Shield licensee Triple S Management Corporation has agreed to pay a HIPAA violation fine of $3.5 million to the Department of Health and Human Services’ Office for Civil Rights. This is the second HIPAA violation fine to be announced in the space of a week, with the latest financial penalty closely following the $850,000 settlement between OCR and Lahey Hospital and Medical Center. The latest fine highlights just how costly non-compliance can be. This does not need to be explained to Triple S Management Corporation. The company was already hit with a HIPAA violation fine of $6.8 million by the Puerto Rico Health Insurance Administration for a failure to comply with the Health Insurance Portability and Accountability Act’s Privacy Rule last year, although the HIPAA violation fine was reduced to $1.5 million on appeal. The PRHIA fine was issued following the mailing of a pamphlet that displayed the Medicare Health Insurance Claim Numbers of subscribers. The HIPAA violation fine corresponded to $500 for each of the 13,336 members of the insurer’s Medicare...

Read More

HIPAA Right to Privacy Being Waived for Pharmacy Discounts

The HIPAA right to privacy can be waived if patients agree to let healthcare providers, insurers, and other covered entities access and share their data. A number of insurers have trialed issuing subscribers with wearable devices that monitor health metrics. In exchange for agreeing to wear the devices that track heart rate, exercise levels, and other vital signs, subscribers are provided with discounts on their premiums. In such cases there is a benefit to both patient and provider. Insurance companies are able to gain a better understanding of the health of subscribers and they can adjust policies and charges accordingly. Subscribers get to monitor their health and wellness more closely and they get a financial reward. Some pharmacies have also started operating similar schemes. Instead of giving discounts on insurance premiums they give discounts on their products and prescriptions, if customers download a Smartphone app and agree to share their data. By offering discounts the pharmacies are able to secure more business. Just like reward cards, the scheme improves brand loyalty....

Read More

Major Mobile Health Application Growth Predicted

Mobile technology has potential to revolutionize the provision of healthcare. Mobile technology is already having a major impact on the industry. According to PwC, one of the few limiting factors is how the technology can be implemented to allow healthcare providers to obtain the full benefits of the technology. This does not appear to have hindered growth in the sector. PwC has predicted growth to increase six-fold over the course of the next two years. Growth in the sector will mostly come from the development of new mHealth applications and from monitoring services. A new report published by healthcare market research firm Kalorama Information suggests that the growth of mobile health applications will outstrip all other mobile application areas over the next four years. The Kalorama report highlights the substantial growth already seen in the mHealth market so far in 2015. Manufacturers of devices, software developers, and providers of wireless services are capitalizing on growing demand. By the end of the year, the industry is expected to have generated close to $34 billion....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist