NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Los Angeles County Government Has Been Putting Patient PHI at Risk for 7 Years

The Los Angeles County government has failed to safeguard the Protected Health Information (PHI) of state residents for up to seven years, according to a recent audit. Three departmental audits have been conducted since December 2014 and a catalog of data security failures have been uncovered that potentially put PHI in the hands of thieves. Data including Social Security numbers and health information could be accessed by former workers, and the information could already be in the hands of criminals. It is simply not known. Computer equipment has vanished – having been misplaced or stolen – devices were not encrypted, and equipment was simply not tracked. Serious Administrative Failures Lasting up to 7 Years Serious administrative failures in several L.A County government departmenta were discovered by auditors, the most serious being a failure to terminate access to computer systems when employees changed employment. An audit conducted by the Probation Department revealed that 695 former employees still had access to computer systems containing the protected health data of...

Read More

Ohio University Hospitals Worker Fired for Improper EHR Access

An Ohio University Hospitals Elyria Medical Center worker has been fired for inappropriately accessing the medical records of patients while employed at the hospital. Alicia Reale, a spokesperson for the hospital, announced yesterday that the medical records of approximately 300 patients had potentially been improperly accessed by an employee of the hospital. The data breach resulted in Protected Health Information (PHI) potentially being viewed and copied. An investigation was triggered when the hospital discovered an employee had accessed the EHR system without a legitimate work purpose for doing so. Reale said “The information that may have been accessed for the impacted patients includes names, dates of birth, medical record numbers, dates of service and diagnostic and treatment information, ” according to a report in the Chronicle-Telegram. Another Case of Hospital Employees Snooping on Medical Records No financial information or Social Security numbers were exposed in the incident, and while the extent of access was determined, Reale said “We did not identify any purpose for...

Read More

Florida Hospital Submits Motions to Dismiss Two Data Breach Lawsuits

Last month, the Florida Hospital group reported a data breach had exposed the records – including Social Security numbers – of 94 individuals. A data breach class-action lawsuit for this year’s breach is almost certain to be filed; however, the hospital group’s legal team is already busy with two class action lawsuits. The two potential lawsuits have been filed for two separate data breaches that occurred in 2011 and 2012; the latter was not discovered for two years. Recently the healthcare provider’s lawyers have made the move to have booth class-action motions thrown out, according to a recent report in the Orlando Sentinel. The class-action lawsuits are currently pending in the Florida Orange County Circuit Court. Motions Submitted to Toss the Data Breach Lawsuits   Both cases are viewed by the Florida Hospital Group as being speculative claims for non-existent damages. Patient data was exposed, and in one case also sold on; however, there is perceived to be only a low risk of losses or damage being suffered. In the 2011 breach, Patient information was obtained and...

Read More

Malware as a Service Being Offered to Criminals on Darknet

You can choose a cloud-platform-as-a-service and software-as-a-service; however for the criminally minded, it is possible to purchase malware-as-a-service. Cybercriminals are now adopting the same business model to sell their malicious software as legitimate software vendors. A platform or software-as-a-service is a business model that allows a product to be used, developed and managed by an individual or company; gaining the benefits of the software without having to develop everything from scratch. Malware-as-a-service is available on the darknet and offers criminals the same benefits. In depth computer knowledge is not required; a criminal can select off-the-shelf malware to suit his or her needs. The creations of skilled hackers can be used by any number of relatively unskilled individuals to allow them to gain access to computers and networks and steal the valuable data they store. Industry leaders are now referring to this mass-market malware sale as “the industrialization of cybercrime,” and it is a highly profitable business. It is so successful and profitable that sales...

Read More

HIMSS Releases 2015 Healthcare Cybersecurity Report

297 healthcare leaders and information security professionals have recently given their opinions to HIMSS on the state of healthcare cybersecurity, with the results of the survey recently published in HIMSS’s 2015 Cybersecurity Report. The release of the report coincided with the Chicago Privacy and Security Forum event between June 30 and July 1 of this year. The report highlights a number of concerns about cybersecurity; perhaps the most pressing being the sheer shale of the current attack surface. Hackers are breaking through security defenses left, right and center; but more worrying is the fact that they have been doing that for a number of months, and are already inside many computer systems. Healthcare Professionals are Concerned Their Protections may not be Enough   Numerous major breaches have affected tens of millions of employees, consumers and patients over the course of the past few months. New data breaches are being discovered on an almost daily basis and no industry appears to be safe from attack. Hacking groups are (allegedly) being financed by foreign...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist