NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

BeHealthy Mailing Error Sees PHI Printed On Outside of Envelopes

Florida-based BeHealthy Health Plan has inadvertently exposed the health insurance claim numbers of 835 subscribers after a mailing error resulted in the data being printed on the outside of envelopes. The mailing of benefit information packets took place on September 23, 2015, with the first complaints alerting the health plan to error being received 5 days later. The privacy breach affects members of the BeHealthy Medicare Advantage Plan who live in Manatee and Sarasota counties. The exposure of a single data element such as the insurance claim number would not typically be a major cause for concern; however, in this case the health insurance claim numbers included the Social Security numbers of plan members. Since the letters also contained the names and addresses of subscribers to the health plan, it is conceivable that this information could be used inappropriatel; should any of the letters have been intercepted. Any exposure of Social Security numbers is a serious matter, and BeHealthy has responded accordingly. All affected individuals have been offered a year of identity...

Read More

Over Half of IT Security Pro’s Do Not Believe They Will be Targeted by Hackers

Major cyberattacks have been suffered by a number of HIPAA-covered entities this year. The frequency of cyberattacks on healthcare providers and insurers has increased. However, over half of IT security professionals do not believe their organization will become a victim of a cyberattack, according to a new report issued by the Ponemon Institute. Should this belief turn out to be true it is great news, as 61% of IT pros do not believe their organization is well prepared to deal with a cyberattack if one does occur. If they are wrong, it is very bad news indeed. Cybersecurity Survey Produces Worrying Results   The results of the Ponemon survey are worrying. Evidence suggests cyberattacks on healthcare providers have increased, and the volume of records exposed in those attacks has spiraled this year. Unfortunately, despite the increase in attack frequency and severity, HIPAA-covered entities do not appear to be doing much to counter the threat according to the report. IT security professionals were asked what measures they were planning to deploy over the coming 12 months, and...

Read More

How Private Are Medical Records?

How Private are Medical Records? The introduction of the Health Insurance Portability and Accountability Act’s Privacy and Security Rules has helped to ensure that patient data is properly protected. The introduction of the Enforcement Rule has made a difference. Prior to the introduction of this rule, few covered entities made sufficient efforts to be compliant with HIPAA. With the threat of financial penalties and sanctions, covered entities have improved policies, procedures, and data security measures to keep data private. However, a look at the Department of Health and Human Services’ Office for Civil Rights (OCR) breach portal shows that healthcare providers, health plans, and BAs of covered entities are still struggling to prevent patient records from falling into the hands of criminals. Over 113 Million Medical Records Exposed in 2015 Alone A recent study suggests that the risk of data exposure has not changed much in the past decade; although the breach reports issued to the OCR show that data breaches are exposing more patient health records. In 2014, 12.5 million patient...

Read More

Nevada Lab Technician Indicted on Healthcare Data Theft Charges

A Las Vegas Lab technician has been indicted on charges of unlawfully obtaining patient healthcare data and using the information to apply for credit cards. Sherice Joan Williams, 41, of North Las Vegas has plead not guilty to the charges. The charges were recently announced by U.S Attorney, Daniel G. Bogden. Williams was charged with one count of unlawfully obtaining the Personally Identifiable Information (PII) of a patient and one count of aggravated identity theft. If Williams is found guilty, she will potentially have to spend up to 12 years in jail. The unlawful accessing and theft of protected health data carries a maximum prison sentence of 10 years. Aggravated identity theft carries a mandatory prison term of 2 years, which must be served consecutively to any other sentence issued. Williams could also potentially be fined up to $250,000 in addition to serving a jail sentence. The offences were alleged to have been committed between December 1, 2014 and January 27, 2015 while Williams was employed as a laboratory technician. She is alleged to have abused her access rights...

Read More

Woodhull Medical and Mental Health Center Data Breach Report

Woodhull Medical and Mental Health Center Data Breach Announced The New York City Health and Hospitals Corporation (HHC) has sent breach notification letters to 1,581 patients of its Brooklyn Woodhull Medical and Mental Health Center after a laptop computer was discovered to have been stolen. The laptop computer was password protected, but data stored on its hard drive had not been encrypted. As a result, the Protected Health Information of some of its patients could potentially have been compromised. Data potentially exposed in the incident include patient names, medical record numbers, narrative physicians’ summaries and medical test results. No insurance information, Social Security numbers, or other data typically used to commit identity theft were stored on the laptop. The theft of healthcare laptop computers is a regular occurrence. The Department of Health and Human Services’ Office for Civil Rights breach portal contains many examples of HIPAA-covered entities that have failed to secure the portable devices. Over the past three months, over 20 cases of portable device theft...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist