25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Burglary of Vermont Medical Practice Reported: PHI of 2,000 Patients Exposed

The offices of Vermont-based physician, Max. M. Bayard, MD PC, have been burglarized and a number of electronic devices have been stolen, resulting in the Protected Health Information (PHI) of approximately 2,000 patients being exposed. According to a breach notice posted on the website of the Vermont Attorney General, the burglary occurred on August 5, 2015. By today’s standards, the data breach exposed a relatively small number of patient records; however the breach is particularly serious as patient names, dates of birth, Social Security numbers and Medicare/Medicaid numbers were stored on the computers. The exact information needed by identity thieves to commit fraud. Other data exposed varies from patient to patient, and includes health information such as medical diagnoses, treatment information, and treatment dates. Patients face a high risk of fraud and identity theft. To reduce the risk of harm and loss, all affected patients have been offered a year of free credit monitoring and identity theft repair services. Patients are also covered by a $1 million identity theft...

Read More

Sutter Health Discovers 2013 HIPAA Breach Affecting 2.5K Patients

Sutter Health, a Northern California not-for-profit health system, has recently discovered a HIPAA breach that occurred on April 26, 2013. A former employee of the healthcare provider was discovered to have emailed company billing documents to a personal email account, which was against company regulations and was in violation of the Health Insurance Portability and Accountability Act (HIPAA). Those documents contained the Protected Health Information (PHI) of 2,582 patients, the vast majority of whom had been patients of the Sacramento-based Sutter Medical Foundation. The ex-employee had previously worked for Sutter Physician Services, which provides billing services for the healthcare provider’s medical foundations. Sutter Health received a tip-off about inappropriate use of a company computer by the former employee, who had left the company in November 2014. An investigation was immediately launched to determine whether the complaint had any foundation and to determine whether HIPAA Rules had in fact been violated. Bill Gleeson, a spokesperson for Sutter Health, said that...

Read More

WEDI Issues New Resources to Assist with ICD-10 Transition

The Workgroup for Electronic Data Interchange (WEDI), the country’s leading authority on the use of IT in healthcare to improve health information exchange, has developed two new resources to assist organizations implementing the new ICD-10 codes required by the Health Insurance Portability and Accountability Act (HIPAA). The new resources, ICD-10 State Workers’ Compensation Readiness List and the List of State Medicaid Sites with ICD-10 Information, have been developed with the aim of “Ensuring that all entities are adopting and or are aligning with ICD-10”. The resources will “help further [the health] industry’s movement towards streamlining and automating end-to-end workflow processes.” The new ICD-10 codes must be adopted by HIPAA-covered entities under federal law, but the new codes do not need to be adopted by the workers’ compensation industry. The industry is now becoming more aligned with HIPAA Transaction and Code Set rules, but rather than being covered by a national mandate, the industry is instead subject to state laws. A number of states will be adopting ICD-10...

Read More

Sony Data Breach Lawsuit Settlement Agreed

The huge cyberattack to hit Sony last year resulted in the confidential information of employees being obtained by hackers, potentially placing those individuals at risk of suffering damage or loss. In the wake of the breach, employees were rapidly signed up for a class-action lawsuit against Sony. Approximately 50,000 current and former employees of the entertainment giant added their names to the lawsuit, which sought damages for the potential exposure of data. In many cases, employees of Sony had their confidential data posted online for all to see. The data included detailed information on medical diagnoses of employees and their families, and included information such as cancer, kidney failure and alcoholic liver disease diagnoses, in addition to birth dates, gender, health condition and medical costs incurred. Approximately 30,000 individuals’ clinical information was exposed in the data breach. The 2014 cyberattack may have been the largest data breach to be suffered by the company, but it was not the first. In 2011, Sony suffered a large-scale data breach that exposed the...

Read More

Oakland Family Services Phishing Attack Claims 16K Victims

Oakland Family Services, a community outreach organization based in Pontiac, MI, has alerted 16,000 of its patients that some of their Protected Health Information was compromised in an email phishing attack that took place on July 14, 2015. By responding to an apparently legitimate request for information, an employee inadvertently gave the hacker access to data contained in a single email account. The electronic medical record databases were not accessed during the security breach. A press release issued by Oakland Family Services explained that no financial information was exposed in the security breach, although it is possible that patient names, medical ID numbers, service dates and details of the services provided were all potentially accessed. Some emails contained more detailed information on patients, which included health insurance and health plan ID numbers, contact telephone numbers, home addresses, dates of birth, and medical diagnoses. A total of 173 Social Security numbers were also exposed. The data related to patients who had visited Oakland Family Services for...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist