NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

McLean Hospital Brain Donators Have PHI Exposed

Another Partners HealthCare hospital has suffered a data breach; this time potentially exposing the Protected Health Information (PHI) of 12,600 individuals who donated their brains to medical research. The latest data breach involved the loss of backup tapes containing patient names, dates of birth, Social Security numbers and medical diagnoses. The incident is not believed to have involved malicious insiders, and the probability of the data being accessed or used inappropriately is understood to be low. The backup tapes were not encrypted, but according to a statement released by McClean Hospital, the psychiatric facility in Belmont, Mass., “It would take specialized software, equipment, and technical expertise in order to access the information on the tapes.” The tapes were stored in Partners Healthcare’s Harvard Brain Tissue Resource Center and were declared missing on May 29, 2015. The data related to individuals who had agreed to donate their brains – or some brain tissue – to the hospital after their death. Many of the victims are now deceased, although some...

Read More

OhioHealth Reports Loss of Flash Drive Containing 1,006 Protected Health Records

A flash drive containing the Protected Health Information of 1,006 patients has been declared missing by OhioHealth Riverside Methodist Hospital. The data stored on the portable storage device related to valve-replacement candidates and research subjects who had taken part in value replacement projects between July, 2010 and December, 2014. The data stored on the portable storage device included patient names, addresses, dates of birth, physician names, medical record numbers, insurance information, types of medical procedures performed and treatment dates. 30 Social Security numbers have also potentially been exposed. It is not clear exactly when the flash drive went missing, although the hospital system was able to determine the device was last used on April 14, 2015 in the heart and vascular department; an area inaccessible to the general public. On May, 29 the drive was declared missing. On Friday last week, OhioHealth issued a press release announcing the possible breach. Notification letters were also sent to the affected individuals to alert them to the possibility that...

Read More

HIPAA Survey Shows Compliance Assessments Can Increase Business

A recent series of customer polls conducted by RapidFire Tools Inc., a leading provider of HIPAA-compliance assessment tools, showed that Managed Service Providers (MSPs) are using compliance assessments to engage prospects and increase business. Furthermore, those assessments are now proving more effective at increasing business and winning new contracts than in previous years. The polls were conducted on MSP customers using RapidFire’s Network Detective HIPAA Compliance Module. The results clearly show that compliance assessments are allowing MSPs to capture new clients and create new projects, as well as being instrumental in obtaining extended service agreements. MSPs were asked about instances where they have been able to use the compliance assessment tools to justify the services being provided to clients. Respondents explained that the compliance assessments enabled them to show that the protections currently in place to safeguard Protected Health Information were far inferior to those being offered. The recent spate of successful hacks on healthcare providers’ servers and...

Read More

New Information Released on Medical Informatics Engineering Data Breach

Back in June we reported on a data breach that affected clients of NoMoreClipboard, although at the time few details were made available. This week, further information was released on the security breach. The latest announcement does not add a great deal of new information. The data fields exposed in the breach have now been confirmed, and an updated list of NoMoreClipboard clients affected has also been announced. Hackers Gained Access to Data for 19 Days – 239 Clients Affected NoMoreClipboard runs MyKSHealth eRecord, which was infiltrated by hackers on May 7, 2015. Access to the records continued for 19 days until May 26, when the breach was discovered and access to the database was shut down. The data understood to have been exposed in the incident includes patient names, addresses, email addresses, dates of birth, Social Security numbers, usernames, hashed passwords, security questions and answers, spouse names, in some cases, spouses’ dates of birth. Health information and health insurance details were also exposed. Some healthcare providers have started issuing announcements...

Read More

NCCoE Cybersecurity Practice Guide for Mobile Devices Released: Comments Requested

The use of smartphones and other portable devices in healthcare is growing and the federal government is concerned. The devices carry a high risk of causing a data breach, and the feds are concerned that physicians and other healthcare workers may accidentally expose patient data, or worse still, give hackers an entry point into hospital EHRs. Medical identity theft costs billions of dollars every year, and patient’s privacy is being violated on an almost daily basis. Hackers are targeting healthcare organizations, thieves are looking for portable devices to steal, and malicious insiders are copying data from EHRs; however, Smartphones have the potential to cause even more data breaches. The reason? The data security and privacy protections used to safeguard data stored on the devices are often inadequate. NCCoE Takes Steps to Protect Mobile Healthcare Devices The National Cybersecurity Center of Excellence (NCCoE) was formed by the National Institutes of Standards in Technology (NIST), the state of Maryland, and Montgomery County, MD in 2012, and during the past three years it has...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist