NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

New Android Smartphone Data Security Warnings Issued

New Android Smartphone data security warnings have been issued, alerting users to new security flaws in the software which could potentially allow hackers to gain control of the devices. The Android security flaw discovered by IBM’s X-Force Application Security Research Team could affect 55% of Android phone owners, while Check Point’s discovery could similarly affect millions. These announcements come after Samsung, Google and LG had stated they will now be providing monthly security updates for Android devices, including a fix for the Stagefright vulnerability. Unfortunately, Android devices often include additional software installed by the device manufacturer, a problem Apple and Blackberry do not share: Both companies have developed their own hardware and software. As a result the latter companies can roll out security updates much more quickly. With the open-source Android platform, security fixes will always be issued more slowly. ‘Certifi-gate’ Security Breach Reported   Android Smartphone data security warnings are now being issued with increasing frequency. The...

Read More

UCLA Health Data Breach Lawsuits Mount

The cyberattack that hit UCLA Health could potentially have been suffered by a large number of hospitals in the United States. Hackers are deliberately targeting healthcare providers, and their employees, to gain access to healthcare data. With the current barrage of ever more sophisticated attacks, it is only a matter of time before some succeed. UCLA Health Invested Heavily in Cybersecurity Protections   Given the high risk of attack, hospital systems must invest in robust cybersecurity protections to ensure, as far as is possible and practical, that patient data is kept secure. UCLA Health had recently committed tens of millions of dollars to improve cybersecurity defenses. In its announcement of the attack, it was pointed out that even with multi-million dollar defenses it was unable to prevent this cyberattack, although “millions of known hacker attempts [are repelled] each year,” and it is under “near-constant attack.” Alleged Failures to Secure Protected Health Information of Patients   In spite of these protections, some patients do not believe UCLA did enough to...

Read More

Hospital Employee Steals Protected Patient Data to Commit Identity Theft

A former employee of the Bethesda Hospital in Boynton Beach, Fla, has been arrested and charged with identity theft; after fraudulently obtaining IDs and credit in the names of 20 individuals, most of whom had been patients of the Boynton Beach hospital in which she worked. Elexes Thaddies, 24, was arrested on Friday, Aug 7, by Boca Raton police officers as part of an investigation into identity theft and credit fraud, with the investigation first starting in September 2014. Other police departments were also investigating the crimes, with Coral Springs and Boynton Beach police both looking into identity theft crimes. The investigations uncovered 20 victims, a number of whom were able to identify Thaddies, saying they had seen her working at the hospital. Law enforcement officers also discovered a new account had been opened in a victim’s name, which listed Thaddies named as an authorized user of that account. She had used that account to make a $1,160 purchase at Nordstrom in Palm Beach Gardens, according to the police report. Thaddies was using the stolen identities to pay her...

Read More

Illegal Dumping of Medical Records Exposes PHI of Ohio Drug Rehab Clinic Patients

Illegal Dumping Medical Files Uncovered Another case of illegal dumping of medical records has been reported, this time involving a Utah drug and rehabilitation clinic, Positive Adjustments. The company went out of business approximately 6 months ago; however medical records were discovered in a dumpster outside the abandoned clinic – at 4548 South Atherton, Taylorsville, by a contractor employed by Dr. Scott Cold, DDS on Friday last week. Dr. Cold confirmed to Fox News that the files contained complete patient records, including patient names, contact information, Social Security numbers and treatment data, in addition to confidential court documents. Medical Records Dumped in Public View When Dr. Cold’s contractor turned up for work on Friday, August 7, the medical records were noticed in the physician’s dumpster, which was open, with the files in clear view of anyone passing close by. The matter was brought to the attention of Dr. Cold who was aware of HIPAA Rules covering Protected Health Information (PHI), and notified law enforcement; however, the records could just as easily...

Read More

Prima Care Discovers Improper Dumping of PHI: 1,651 Patients Affected

This week another case of improper dumping of PHI has been discovered, with an employee of a New England healthcare provider allegedly dumping files that were no longer needed. Employees are the Weakest Link   Healthcare employees are the weakest link in security defenses. Being human, they are prone to make errors from time to time. A mistyped email address can be all it takes to expose thousands of patient health records, as has occurred on numerous occasions already this year. Improper Dumping of PHI Discovered   However this week, a (now former) employee of a healthcare provider has exposed patient records in a rather atypical way. The individual in question was an employee of Prima CARE, P.C, a healthcare provider based in New England. That individual breached HIPAA and hospital rules by maintaining patient records without the knowledge of his or her employer, and apparently dumped the files when they were no longer required. Prima CARE was alerted to the breach when binders containing a wide variety of patient data was discovered in some bushes off Jefferson Street...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist