NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Urology Associates Reports 6500-Record Data Breach

Offsite storage of paper medical records may be convenient if facility space is limited; but the decision to store records offsite may prove to be a costly, as Kailspell-based healthcare provider, Urology Associates recently discovered. The company had taken advantage of a local storage facility and rented a unit to store boxes of old medical records. Unfortunately, the facility was recently burgled. Storage Units are a Risky Place to Keep Sensitive Medical Records   Storage units are frequently burgled. The units are secured with locks; but in many cases, all that is required to access the contents is a set of heavy duty bolt cutters. Thieves have realized there are easy pickings to be had from storage units, and law enforcement has had to deal with a spate of storage unit break-ins recently. The problem is not limited to Kalispell; it is a countrywide problem. Records Potentially Accessed, but not Stolen   Medical records are extremely valuable. Complete sets of data can fetch in the region of $60 on the black market. Clean records, such as those of children, can be...

Read More
Hospital Drug Pump Hacking Risk Discovered
Aug06

Hospital Drug Pump Hacking Risk Discovered

In addition to having to deal with the threat to electronic health records from hackers, hospitals must also be wary of attacks on their medical devices; as evidenced by a new Food and Drug Administration (FDA) warning over a drug pump hacking risk that exists with Hospira’s Symbiq drug pump. Symbiq Drug Pump Hacking Risk Warning Issued by FDA   Only a few days ago, two hackers discovered it was possible to hack into the onboard computers of Fiat Chrysler automobiles and take control of the vehicle; now patient’s plugged into the Symbiq drug pump could potentially be at the mercy of malicious hackers. Such is the severity of the Symbiq drug pump hacking risk, on Friday last week the FDA issued a warning to all hospitals using the device, instructing them to retire the devices and make the transition to other, more secure drug infusion pumps. In the meantime the FDA recommended that healthcare providers should “disconnect the pumps from their networks and update their drug libraries manually.” Since the vulnerability can be exploited via unused ports on the devices, the FDA...

Read More

New Basic Guide to HIPAA Compliance Released By HHS

The Department of Health and Human Services’ Office for Civil Rights has recently issued a basic guide to HIPAA compliance; a summary of HIPAA Rules for covered entities. A Basic Guide to HIPAA Compliance The Health Insurance Portability and Accountability Act (HIPAA) places a number of requirements on healthcare providers, health plans, healthcare clearinghouses, and Business Associates of HIPAA-covered entities, to safeguard data, protect the privacy of patients, and notify them of incidents that expose their Protected Health Information (PHI). HIPAA legislation is complicated, and many covered entities, especially smaller healthcare providers, struggle to understand the HIPAA Privacy, Security, and Breach Notification Rules, and turn those rules into policies into procedures. The Department of Health and Human Services’ Office for Civil Rights is the enforcer of HIPAA Rules, and while the agency investigates data breaches, it is also charged with improving understanding of data privacy and security legislation. One way it achieves this objective is by issuing guidance to help...

Read More

HIPAA Breach: 1,111 Veteran Records Improperly Dumped

The Department of Veterans Affairs has announced the potential exposure of 1,111 veteran health records after files containing Personally Identifiable Information (PII) and Protected Health Information (PHI) were accidentally tossed in a dumpster. The files were thrown out with regular waste by an employee of the VA Hot Springs Hospital in South Dakota on Friday, May 15, during a move to a different location. The files were mistaken for regular rubbish, and would have remained in the publically accessible dumpster were it not for a vigilant employee who noticed the dumped files two days later. The improper dumping was reported to the Veterans Affairs police, who went dumpster diving to retrieve the files. According to a press release issued by the Fort Meade-based VA Black Hills Health Care System, an investigation was launched after the incident came to light. Public Affairs Officer, Teresa Forbes, was interviewed by the Rapid City Journal on Friday last week, and said “It was just an unfortunate mistake during an office move.” The box of files appeared not to have been tampered...

Read More

Husband-Wife Tax Fraudsters Get 231 Months Jail Time

A former employee of Tift Regional Hospital has recently been sentenced to serve 84 months in jail for fraudulently submitting 1,100 bogus tax returns, including making 531 tax claims using the data of 16 year olds. Her husband has been sentenced to serve 147 Months in the Bureau of Prisons. Both are required to pay restitution of $1,107,802.00 to the IRS. United States Attorney for the Middle District of Georgia, Michael J. Moore, recently announced Honorable W. Louis Sands’ verdict on Mrs. Patrice Taylor, 34 and her co-conspirator husband, Antonio Taylor, 44, both of Ashburn, Georgia. The total loss suffered by the IRS was $1,199,897.00 Sentencing took place on July 27, 2015 with Mrs. Taylor convicted of aggravated identity theft and conspiracy to commit wire fraud. Taylor had previously pled guilty to the offences and took a plea deal. She admitted to committing the offenses between January 2011 and February 2013. According to evidence presented at trial, Mrs. Taylor used Social Security numbers obtained during her employment at Tift Regional Hospital to file the tax returns....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist