25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The Age of the Healthcare Data Breach: 40% of Americans Now Victims

According to a new study conducted by iSherriff, almost 45% of Americans have now had their personal information exposed in a healthcare cyberattack; and in some cases, more than once. It is clear that we are now well and truly in the ‘Age of the Data Breach’, and the situation is likely to get worse. This year has already seen the largest ever HIPAA data breach: The 78.8-million record heist at Anthem Inc., and also the second largest healthcare data breach reported: The 11 million record cyberattack at Premera Blue Cross., and recently, a further 4.5 million records were exposed in the UCLA Health cyberattack. More than 100 million new healthcare data breach victims have been created so far this year, representing almost a third of the population of the United States. The total number of records exposed in the last 5 years is now 143 million. We are therefore just over 16 million records short of half the population of the United States. With the volume of breaches now occurring, it is possible that unwanted milestone may even be reached this year. According to iSherriff CEO,...

Read More

Frisco Psychiatrist’s Computer Stolen from Vehicle Trunk: PHI Exposed

Vehicles are clearly not good places to store the Protected Health Information of patients, even temporarily, as another medical professional has recently discovered. San Francisco psychiatrist, Robert E. Soper M. D., was transporting an old desktop computer that he intended to give to his brother; however, he left the car unattended and during that time it was broken into and the desktop computer was stolen along with other goods from the car. Although the data on the desktop computer was not encrypted, it was protected by two passwords, making it unlikely that the thieves would be able to access the data. According to the breach notice issued by Dr. Soper, the passwords “were maintained in a format unique to the software used to prepare them. The software program itself was not on the computer, making the data almost impossible to decipher.” The computer also contained email data which included lab test results and some third party healthcare provider reports on patients, as well as email correspondence between the office and patients. Email data was similarly password protected...

Read More

Employee Data Theft Announced by Merit Health

With big money to be made from the sale of Protected Health Information, and even bigger gains to be made from using the data for identity theft, many employees are tempted to access and copy medical records. In recent months numerous cases of data theft have reported by hospitals, and this week another has come to light, with the announcement by Merit Health Northwest Mississippi that one of its employees has stolen patient PHI. The now former employee’s acts were uncovered by local law enforcement officers, who notified the hospital of the potential data theft. An investigation into the security breach was initiated immediately to determine the extent of the theft. According to a statement released by Merit Health, the data access is believed to have started in February 2013 with the last data believed to have been removed in June 2015. The healthcare provider was notified of the privacy breach on July 1. The unnamed individual is understood to have accessed and removed the records of up to 810 patients over a period of more than two years without being discovered. The data...

Read More

UCLA Health Patient Receives 9 Incorrect Breach Notification Letters

The UCLA Health cybersecurity attack exposed the data of 4.5 million patients, most of whom have been informed if they have been affected by the breach; however it took a considerable amount of time for patients to receive their breach notification letters, and for one victim in particular, the notification process ran anything but smoothly. According to a recent LA Times report, UCLA Health patient, Steve Reasner, was kept in the dark about the risk of identity risk that he faced, and it took many weeks since his data was exposed to learn he had been affected. After hearing about the data breach on the news, Reasner wondered if his information was now in the hands of the hackers. He had previously used UCLA Health services and could conceivably have had his confidential data stolen. He waited for a letter to arrive in the mail, and a few days later he received not one breach notification letter but nine. To add to his confusion, none of the letters were addressed to him. They had his address on the envelope, but the names of different individuals who had – presumably –...

Read More

Akron Children’s Hospital Reports Loss of Voice Recordings

Ohio’s Akron Children’s Hospital has reported the loss of a hard drive used to store backed up copies of voice recordings of conversations between medical staff and dispatchers. The backup drive was physically secured under lock and key at the hospital, but the data was not encrypted. An investigation into the equipment loss was conducted by hospital staff as soon as the driver was discovered to be missing. According to Akron Children’s Hospital’s COO, Grace Wakulchik, “Our internal investigation indicated the hard drive was lost and nothing malicious was involved.” Since the storage facility was in a secure location of the hospital, it is highly unlikely that the device was stolen by a patient or member of the public, the most probably explanation being the devices was simply misplaced. Limited Protected Health Information Exposed   The recordings were made between Sept. 18, 2014, and June 3, 2015 and involved brief conversations between physicians’ offices and hospital emergency departments. During these conversations a limited amount of Protected Health Information (PHI) of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist