NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

UPMC Health Plan Data Breach Affects 722 Subscribers
Jul15

UPMC Health Plan Data Breach Affects 722 Subscribers

UPMC health plan has reported a data breach affected 722 insurance subscribers. This is the second data breach to affect the health plan this year. In May UPMC reported  2,000 patient records had been compromised. The latest data breach appears to have resulted from an internal error. Yesterday, UPMC spokeswoman, Gina Pferdehirt, said patient information was compromised when an email containing PHI was sent to an unauthorized person. The statement released by UPMC says the email was sent by accident, suggesting there was no malicious intent behind the data breach. According to UPMC, “The email meant for a physician’s office in Lawrence County was sent instead to an incorrect address, revealing patient names, insurance membership numbers, birth dates and phone numbers.” According to a response provided to the Pittsburgh Post Gazette, Pferdehirt said, “while we take this seriously, in context the breach is very minor.” The email did not contain financial information, health data or Social Security numbers, although member names, dates of birth, ID numbers and phone...

Read More

Two More Flash Vulnerabilities Discovered: Calls for Software to be Retired

A useful and valuable software platform or a collection of security holes held together with code? Opinion is divided on the usefulness of Adobe Flash, when hackers can apparently exploit vulnerabilities with ease. Some are calling for Adobe Flash to be consigned to the annals of history following after five security flaws have recently been discovered: Flaws that are already being used by hackers to gain access to computers and data. Three zero-day vulnerabilities have already been discovered this year, including one just a few days ago. Now a further two zero-day vulnerabilities have been identified. The latest two are arguably the most serious; one of which allows hackers to use the Adobe Flash security flaw to take full control of a computer. Patches not Yet Developed to Address Latest Adobe Flash Security Vulnerabilities The flaws were uncovered as a result of the recent data breach at Hacking Team, and have been identified as CVE-2015-5122 and CVE-2015-5123. They affect Adobe Flash operating on Windows, OS X and Linus systems. The new bugs are similar to the security...

Read More

Computer Theft Exposes Data of 560 ABCBS Applicants

Arkansas Blue Cross and Blue Shield (ABCBS) – Arkansas’s largest provider of health insurance – has reported the theft of a laptop computer containing the unencrypted data of 560 insurance applicants. An independent insurance agency – Treat Insurance Agency (TIA) – suffered a burglary at its Little Rock, Ark. offices on June 16. The perpetrators stole two computers that contained data of ABCNS applicants. Those individuals had applied for health insurance through TIA between October 1, 2012, and June 16, 2015. The exposed data includes the “personal information” of applicants. The exact information exposed has not been announced; however, victims will be informed by post if they have been affected together with details of the information has potentially been exposed. A helpline has also been set up for concerned members and applicants to find out more information. Arkansas Blue Cross and Blue Shield Computers Not Affected The data breach did not affect the ABCBS computer network or any of its equipment. Data exposure was limited to the information held by the TIA....

Read More
Healthcare Data Breach Report: June 2015
Jul14

Healthcare Data Breach Report: June 2015

This month’s healthcare data breach report looks a lot healthier than May; a particularly bad month for data breaches, with over 1.1 million records exposed in 18 security incidents. June could be considered a relatively good month for the healthcare industry in terms of records exposed, although more security incidents were reported in June than May, and numbers have not changed much year on year. 21 breaches were reported in June compared to 23 last year. In total, 159,231 records were reported as being exposed during the month. In June 2014 the figure stood at 252,873, and in June 2013, only 46,713 records were compromised.   Quarterly Figures Show Little Has Changed Since 2014   Data breach figures for the second quarter of 2015 differ only by one incident from this time last year. Data breaches continue to be experienced at the same rate, in spite of improved protections being put in place by healthcare providers. It would appear it is only possible to maintain pace with malicious insiders and outsiders. Figures for the quarter indicate 750,000 more data breach...

Read More

PHI Falls from Sky at Soccer Parade

The U.S. Women’s World Cup Soccer champions toured NYC celebrating their historic win, and were treated to a shower of confetti, some of which appeared to be made from medical prescription records. One local resident noticed the confetti contained writing and upon closer inspection, realized it was Protected Health Information. The confetti was photographed and uploaded to twitter, with the story being picked up by 12WMAZ. According to the finder, the data included the patient’s name, treating physician and the address of the location where the prescription was provided; information covered by the Health Insurance Portability and Accountability Act. HIPAA requires all holders of PHI to follow strict rules governing the disposal of PHI. All data must be destroyed and rendered unreadable and undecipherable before disposal. Each year confetti is purchased for the Thanksgiving Day parade, with the official contract given to Atlas Packaging Company this year. An order was placed for confetti made from strip-cut, blank news roll. Two tons of confetti was ordered, delivered and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist