25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Breach of Patient Data Reported by Barrington Orthopedic Specialists

Barrington Orthopedic Specialists, an Illinois-based healthcare provider, has reported it has suffered a breach of patient data after a laptop computer and an EMG machine were stolen from a vehicle while being transported between its facilities. The equipment theft took place at some point between August 14 and August 18, 2015, and was discovered by Barrington Orthopedic Specialists (BAS) on August 18. Following the discovery of the theft, BAS informed law enforcement officers and an investigation was launched to determine the extent of the breach wand which patients had been affected. That investigation has now been concluded. The data breach is understood to have affected 1,009 individuals and resulted in their names, dates of birth, and EMG test results and reports potentially being exposed to criminals. According to the breach notice issued by BAS, no Social Security numbers, financial data, insurance information or contact details were stored on the equipment. The risk of identity theft and fraud faced by the victims is therefore believed to be particularly low. As such the...

Read More

HealthCare.gov Security Vulnerability Critical, Says OIG

A “critical” HealthCare.gov security vulnerability has been discovered which could potentially be exploited by hackers looking to gain access to highly confidential data, according to the Department of Health and Human Services’ Office of the Inspector General. The government’s team of ethical hackers were let loose on the HealthCare.gov website, and discovered a critical weakness in its otherwise robust security features. The team used standard techniques known as vulnerability scanning, which simulate an attack by malicious outsiders. The scans therefore assessed security vulnerabilities that could realistically be exploited by external hackers. The team of “white hat” hackers discovered the vulnerability, although they were not able to exploit it to gain access to data due to a range of other security defenses installed to safeguard stored data. The HealthCare.gov website is the gateway to taxpayer-subsidized health plans and is used by 36 states, with those health plans subscribed to by millions of Americans. The data potentially accessible through the site is extensive. The...

Read More

New Rules for Electronic HIPAA Transactions Approved by CAQH CORE

Last week, the CAQH® Committee on Operating Rules for Information Exchange (CORE®) approved a new set of national rules for electronic HIPAA transactions, as part of Phase IV of the CAQH® CORE® Operating Rules. The new rules for electronic HIPAA transactions cover four groups of healthcare business transactions – prior authorizations, employee premium payment, enrollment/disenrollment in health plans, and healthcare claims. The aim of the new rules is to facilitate the exchange of healthcare information, as mandated by the Affordable Care Act (ACA). The new rules will augment existing HIPAA administrative standards to ensure uniform transmission of electronic healthcare data. Phase IV of the CAQH® CORE® Operating Rules addresses infrastructure requirements such as connectivity, system availability, and response times. Rules covering the data content of transactions are due to be added to the Operating Rules at a later date. The approval process involves a vote on the new rules by the subgroups and work groups responsible for preparing the draft version of the Operating Rules. If...

Read More

Document Scanner Error Exposes PHI of Silverberg Surgical and Medical Group Patients

Silverberg Surgical and Medical Group is alerting patients to the potential exposure of highly sensitive Protected Health Information after an error made in the configuration of a document scanner resulted in patient information being accessible via the internet. The device had been used to scan documents containing personal information such as patient names, dates of birth, contact telephone numbers, home addresses, fax numbers, and e-mail addresses. Some patients’ Social Security numbers were exposed, as were medical record numbers, health plan ID numbers, beneficiary numbers, medical information, full face photographs and state license numbers: A Smorgasbord of data that could potentially be used by criminals to commit medical, insurance and identity fraud. Silverberg discovered the security breach on August 28, 2015, and immediately launched an investigation. That investigation revealed the device had posted data online since September 10, 2013. The company has now secured the device and data and has enlisted the help of a specialist data security firm to conduct a forensic...

Read More

Bogus Doctors Behind Horizon Blue Cross Blue Shield of New Jersey Data Breach

A Horizon Blue Cross Blue Shield of New Jersey data breach has been reported following the discovery that criminals posed as doctors in order to gain access to the Protected Health Information of patients. The bogus physicians obtained insurance ID numbers and other sensitive PHI, after being given access rights to Horizon BCBSNJ members’ data. The information was stolen in order for the criminals to file false insurance claims in the names of the victims. Fraudulent activity was first uncovered on July 30, 2015 and approximately 1,100 individuals are understood to have been affected by the security breach. In addition to member ID numbers, the bogus doctors were able to gain access to patient names, gender, and dates of birth. A notice on the Horizon BCBSNJ website confirms that Social Security numbers and financial information were not obtained by the criminals. It is understood that the information was stolen with the sole purpose of making false insurance claims. Patient PHI is not believed to have been used for any other purpose. All affected members of Horizon BCBSNJ...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist