NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Major Mobile Health Application Growth Predicted

Mobile technology has potential to revolutionize the provision of healthcare. Mobile technology is already having a major impact on the industry. According to PwC, one of the few limiting factors is how the technology can be implemented to allow healthcare providers to obtain the full benefits of the technology. This does not appear to have hindered growth in the sector. PwC has predicted growth to increase six-fold over the course of the next two years. Growth in the sector will mostly come from the development of new mHealth applications and from monitoring services. A new report published by healthcare market research firm Kalorama Information suggests that the growth of mobile health applications will outstrip all other mobile application areas over the next four years. The Kalorama report highlights the substantial growth already seen in the mHealth market so far in 2015. Manufacturers of devices, software developers, and providers of wireless services are capitalizing on growing demand. By the end of the year, the industry is expected to have generated close to $34 billion....

Read More

Pathways Professional Counseling Reports Theft of Laptop Containing SSNs

A breach of social security numbers, health insurance information, medical data, and personally identifiable information has been announced by Pathways Professional Counseling after a laptop computer was stolen from the vehicle of an employee. The laptop computer was password protected, but was not encrypted. The device contained highly sensitive information that could potentially be used by criminals to commit identity theft and fraud. Other data stored on the laptop included patient names, dates of birth, addresses, email addresses, phone numbers, demographic data, clinical information, financial information, referring physician names, and medical diagnoses of patients. The theft occurred on September 24, 2015, and was discovered the following day. The incident was immediately reported to law enforcement and to Pathways Professional Counseling, and an investigation into the data breach was immediately launched. Pathways Professional Counseling was able to determine that the laptop had not been used to gain access the organization’s network. Network access was blocked by changing...

Read More

Healthcare Industry Data Breaches in 2015

2015 has been a difficult year for healthcare industry cybersecurity professionals. More confidential records have been exposed in 2015 than since the OCR started publishing healthcare data breach reports. Huge healthcare industry data breaches at Anthem Inc., Premera BlueCross, Excellus BlueCross BlueShield, UCLA Health, Medical Informatics Engineering, and CareFirst BlueCross BlueShield have been suffered this year. 2015 Healthcare Industry Data Breaches Have Exposed 120 Million Records With so many large-scale data breaches suffered this year it is perhaps no surprise that healthcare industry data breaches have affected more people than breaches suffered by organizations in other industries. The latest figures from the Identity Theft Resource Center (ITRC) indicate over 120 million people have had their medical and/or personal data exposed so far this year as a result of healthcare industry data breaches. That represents 68.1% of the total number of breach victims created so far in 2015 across all industry sectors. The ITRC first started charting data breaches back in 2005. To...

Read More

Texas Attorney General Takes Action over Improper Disposal of PHI

Legal action has been taken by the Texas attorney general’s office against Alliance Health Management & Consulting Inc., for the improper disposal of Protected Health Information (PHI) of patients. The home healthcare management company is no longer in business, having ceased trading in July 2009; however last year, documents containing the PHI of patients were discovered to have been discarded in a dumpster without first having been rendered indecipherable. HIPAA Rules Covering the Disposal of Protected Health Information The HIPAA Privacy Rule requires covered entities to implement physical safeguards to keep all forms of PHI secured at all times. When PHI is no longer required by a covered entity it must be disposed of securely (45 CFR 164.310(d)(2)(i) and (ii)). PHI must be destroyed, or rendered unreadable and indecipherable. It must not be possible for any element of PHI to be reconstructed. The exact method that must be used to destroy records is not stipulated by HIPAA Rules, although for physical records the OCR recommends pulping, burning, shredding, or pulverizing....

Read More

OCR Settlement Reached with Lahey Hospital

The HHS has announced that Lahey Hospital and Medical Center has agreed to settle a case with the Office for Civil Rights (OCR) over alleged HIPAA violations following a data breach that occurred back in October, 2011. Lahey Hospital and Medical Center has agreed to pay $850,000 to settle the case without admission of liability. The nonprofit teaching hospital has also agreed to adopt the OCRs corrective action plan to address HIPAA-compliance issues discovered by OCR investigators. The settlement covers six ‘potential’ violations of HIPAA Rules, specifically the failure to implement appropriate administrative and physical controls to prevent the accidental disclosure of ePHI. Failure to Safeguard ePHI Results in $850,000 Settlement The incident which led to the OCR investigation involved the theft of an unencrypted laptop computer that had been left in an unlocked treatment room at the hospital. The laptop contained data recorded from one of the medical center’s CT scanners.  The laptop contained electronic Protected Health Information of 599 patients. A financial penalty was...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist