25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Industry Tops 2015 Data Breach List

The number of healthcare data breaches reported so far this year has been staggering, so it should come as no surprise to hear that the healthcare sector has suffered more data breaches than any other industry sector during the first six months of the year. According to a new data breach report compiled by data security firm, Gemalto, the healthcare industry’s 187 data breaches add up to 21.1% of all global data breaches reported in first half of the year. The report also suggests 34% of all healthcare records kept on U.S patients were exposed between January 1, and June 30 this year. The report provides data breach figures of 84 million compromised healthcare records, the majority of which came from the colossal cyberattack of Anthem, which resulted in 78.8 million records being exposed: 32% of the total number of global records exposed in data breaches, across all industries. Overall, 888 data breaches were reported during the first 6 months of 2015, resulting in 245.9 million records being exposed around the globe. The figures have remained pretty constant year on year according...

Read More

VA Data Breaches Fell Dramatically in August

The VA Information Security Report usually makes for unpleasant reading, oftentimes detailing numerous mis-mailings, mis-handling accidents, lost PIV cards, and lost and stolen devices; however the data breach figures for August are surprisingly low, with considerably fewer records exposed than in previous months. The number of veterans’ records exposed in July were half that of June, and the reduction has continued in August, with the VA data security report indicating just 431 veteran records were exposed. 127 breach notification letters were sent, and 304 individuals were offered credit protection services to mitigate the risk of harm. August has therefore been the best month for the VA since March 2015. Victims of VA Data Breaches in 2015   Month Veteran Records Exposed January 310 February 891 March 383 April 987 May 1018 June 2076 July 1031 August 431   Average number of records exposed per month: 890 Total number of veterans affected in 2015: 7,127   VA Data Breaches Continue to Fall   The total number of lost PIV cards reported for the month of August...

Read More

HIPAA Compliant Wellness Platform Launched By Fitbit

Yesterday, Fitbit, America’s leading manufacturer of activity and fitness trackers, announced it has developed a HIPAA compliant wellness platform which it aims to use to corner the lucrative healthcare market. The company has flirted with health and fitness trackers for the healthcare sector for some time; however, until now one of the major stumbling blocks has been the Health Insurance Portability and Accountability Act (HIPAA), which places a number of restrictions on the use of electronic devices capable of recording, storing and transmitting Protected Health Information (PHI). No electronic device can be fully HIPAA-compliant, as compliance with HIPAA Rules is dependent on the actions of the users of the devices. Therefore, rather than being billed as a HIPAA compliant wellness platform, Fitbit announced that it ‘supports’ HIPAA compliance, having incorporated the necessary safeguards – as demanded by HIPAA – to keep stored and transmitted data protected from prying eyes. According to James Park, CEO and Co-Founder of Fitbit, “We prioritize protecting our consumers’...

Read More

Close Call but VA Hospital Thwarts Attempted Cyberattack

A VA hospital has contained a cyberattack that could potentially have exposed the records of 100,000 patients and 5,000 hospital staff. The security breach is believed to have been caused by a member of the hospital staff responding to a phishing campaign. Trojan Virus Discovered on Computer Drive Shared by 4,000 Employees   The James A. Haley VA Medical Center (JAHMC) had a particularly close call last week when a virus was discovered to have infected a number of the hospital’s files. Only the fast action of the hospital’s IT staff prevented the exposure of over 100,000 patient and employee records. The virus was discovered on a JAHMC computer drive used by 4,000 hospital employees. The Trojan is believed to have been installed as a result of a member of staff responding to a phishing campaign. Hackers send out emails containing links to malware and virus-infected websites, which if visited, download malicious software onto computers and shared drives. Emails containing virus-infected attachments are also sent to healthcare employees. Should those attachments be opened, viruses...

Read More

LSU Health Laptop Theft Exposes PHI of at Least 5,000 Minors

A laptop computer issued to Dr. Christopher Roth by the LSU Health New Orleans School of Medicine has been reported stolen, and along with it, the electronic Protected Health Information (PHI) of approximately 5,000 patients. The majority of patients affected by the breach were minors. The computer was left in a vehicle that was parked in front of the physician’s home on July 16. The theft was discovered the following morning and was immediately reported to law enforcement officers. Physician Breached Hospital Data Security Policies   LSU Health New Orleans School of Medicine has data security policies in place which forbid staff from leaving electronic devices unattended. All members of staff were also instructed to take extra care of devices containing PHI. Dr. Roth therefore violated the School of Medicine’s data security policies by leaving the laptop computer in his vehicle, and will be disciplined by LSU Health for the infraction once the investigation is completed. That investigation has proved complicated, as patient data were stored on the laptop’s hard drive, not on...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist