NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HealthFirst Notifies 5,300 Patients of 2-Year Data Breach

New York based health insurer, HealthFirst, will start sending breach notification letters to 5,300 health plan members today, informing them of a breach of their Personal Health Information that potentially started on April 11, 2012 and lasted until March 26, 2014. The breach is serious. Data was stolen with the express purpose of committing fraud and plan members are being advised to take no chances. They have been urged to sign up for the credit monitoring and protection services being offered by CareFirst. The health insurer has already been a victim of fraud as a result of the data breach, although at this stage it is unclear whether any plan members have also suffered from fraud. In 2013, HealthFirst discovered it had become a victim of fraud. The insurer notified the Department of Justice (DOJ) and following an investigation, the individual responsible was identified, arrested and charged with fraud. As the investigation continued, the DOJ determined that the individual in question had possibly obtained information on plan members from HealthFirst. The DOJ alerted the...

Read More

Georgia Division of Aging Services Data Breach Affects 3,000

Approximately 3,000 members of the Community Care Services Program of Georgia’s Department of Human Services Division of Aging Services (GDHSDAS) have been sent breach notification letters to advise them that a limited amount of their Protected Health Information (PHI) has been accidentally exposed. The Community Care Services Program helps seniors stay in their communities, rather than being placed in a nursing home. The breach victims are therefore particularly vulnerable; although since Social Security numbers, contact information, dates of birth, and other highly sensitive data were not exposed, the risk of individuals coming to harm as a result of the breach is believed to be low. Affected individuals have been told the breach was caused when an email containing patient names and “certain health diagnoses” was emailed to a contracted Business Associate. According to Robyn A. Crittenden, Georgia’s Human Services Commissioner, “While we are confident that this data breach was limited in nature and [was] resolved almost immediately, we are obligated to ensure that our clients and...

Read More

Four Unpatched Internet Explorer Vulnerabilities Announced

Four “new” Internet Explorer vulnerabilities have been announced this week. The announcement did not come from Microsoft; security researchers revealed the flaw because Microsoft has been too slow to address the issue. A patch has still not been released to address the security flaws even though Microsoft was made aware of the problems more than seven months ago. The announcement came via Hewlett-Packard’s Zero Day Initiative (ZDI) program, which pays security professionals to identify software flaws that could potentially be used by hackers to gain access to computers or infect them with malware. The ZDI team announces security flaws that have not been addressed by software developers in a reasonable time frame: 120 days from the date of discovery of a vulnerability. Since this time frame has been exceeded, ZDI researchers have now released limited details of the issues to the public. The ZDI team only issues partial information on the location and nature of the security flaws and does not disclose information that would tip off hackers and allow them to take advantage of...

Read More
American Hospital Association Opposes HIPAA HPID Use
Jul24

American Hospital Association Opposes HIPAA HPID Use

Earlier this week, the Vice President and Deputy Director of the American Hospital Association (AHA) sent a letter to the Centers for Medicare & Medicaid Services (CMMS) expressing concern over the implementation of Health Plan Identification numbers (HPIDs) and Other Entity Identifiers (OEIDs). HPID Use and HIPAA When HIPAA was introduced, it required national identification numbers to be used by healthcare providers, health plans and individuals. A national ID number was introduced in 2004, although the IDs were only for providers, not individuals. In September 2012, the HPID proposed rule was published, although it took until November 2014 before the rule was finalized. HPIDs and OEIDs will now be required to be used for HIPAA transactions from Nov 7, 2016. It is not a requirement for health plans to be identified in HIPAA transactions, but if they are, from Nov 7, next year a HPID must be used. AHA States Opposition to HPID Use in HIPAA Transactions   The letter, sent from Ashley Thompson to Andy Slavitt, the acting administrator for CMMS, stated the AHAs opposition to...

Read More

New HIPAA Compliance Tool Released for Small Dental Practices

Achieving compliance with HIPAA Privacy and Security Rules can be a challenge for all organizations, regardless of size; however, smaller healthcare providers tend to have more problems. Budgets tend to be more restrictive, and a lack of suitable staff means slow progress is made. This was clear from the results of the pilot round of HHS HIPAA compliance audits. Regulatory bodies such as the Department of Health and Human Services’ Office for Civil Rights (OCR), State Comptrollers, and Attorneys General, investigate data breaches for HIPAA violations, and periodic audits are conducted to assess compliance. The next round of OCR HIPAA compliance audits will assess how well organizations have implemented the requirements laid down in the Privacy Rule, Security Rule and Breach Notification Rule. Healthcare organizations, health plans, healthcare clearinghouses – and Business Associates of the above – will have their compliance efforts put to the test. The audits will be conducted on large healthcare providers, multiple hospital systems, the nation’s largest health...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist