NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Unity Recovery Group Discovers 12-Month HIPAA Breach

Unity Recovery Group (URG), a provider of drug and alcohol rehabilitation services, has announced that some of its patients have been affected by a data breach that has violated their privacy rights and breached Health Insurance Portability and Accountability Act Rules. The organization is in the process of notifying an as of yet unspecified number of individuals of a privacy breach which lasted almost a year, starting in April, 2014 and lasting until March, 2015. Patients have been advised that some of their Protected Health Information (PHI) “was impermissibly disclosed” to “one or more unaffiliated recovery and/or rehabilitation service providers,” according to the company’s breach notice. HIPAA Breach Exposed Health Information and Social Security Numbers for 12 Months URG is alerting affected individuals that their names, dates of birth, addresses, contact telephone numbers, email addresses, health insurance information, Social Security numbers, and “certain health information” were exposed. Since the breach notice does not provide much information about the exact nature of...

Read More

Ohio Radiologist Disciplined for HIPAA Violation

The Ohio State Board of Medicine has taken action against a radiologist who violated the Health Insurance Portability and Accountability Act (HIPAA) by unlawfully accessing the medical records of a colleague. The radiologist, Dr. Aimee Hawley, accessed the records of a work colleague of Mercy Health St. Rita’s Medical Center in September 2013. Hawley has since left the hospital’s medical staff. It is not known why Hawley accessed the records of her physician colleague, when she should have been aware of the restrictions in place covering access to Protected Health Information under HIPAA. The State Medical Board of Ohio’s education & outreach program manager, Joan Wehrle, said the source of the compliant into the HIPAA violation was being kept confidential. He pointed out that patient privacy is a serious matter and “No one can access a patient’s medical records unless they are a treating or consulting physician or have permission from the patient.” As a result of this transgression, Hawley has agreed to sign a consent agreement submitting to disciplinary action. A consent...

Read More

Judge Approves HIPAA Protective Order for Auto Accident

St. Clair County Associate Judge, Heinz Rudolf, has approved a HIPAA Protective Order to allow the defendants in a wrongful death lawsuit to have access to the two victims’ medical information. A lawsuit was filed against Access Courier, Inc., Contractor Solutions, LLC – Senad Hodzic and Alfredo McGee – by the plaintiff, Debra Dyer-Webster, for an accident which occurred on Oct. 25, 2013 and resulted in fatal injuries being suffered by two minors. Damages of 1.5 million are being sought. In the compliant, it is alleged that the two victims of the fatal automobile accident – Alicea McGee and Anastashia McGee – were killed as a result of Senad Hodzic failing to keep his vehicle under control, not paying sufficient attention, failing to keep a sufficient lookout and failing to “pull a vehicle off the traveled portion of the highway.” At the time of the accident, Hodzic was employed by Access Courier and Contractor Solutions. Alicea and Anastashia McGee were traveling in a 2000 Chevrolet Impala in the northbound lane of Interstate 55 in Macoupin County when the vehicle...

Read More

Ponemon: Data Breach Cost Increases to $154 per Record

The Ponemon Institute has released a new IBM-sponsored report on the financial implications for organizations suffering data breaches. The Cost of Data Breach Study: Global Analysis study involved 350 companies from 12 countries: Australia, Brazil, Canada, France, Germany, India, Italy, Japan, Saudi Arabia, United Arab Emirates, United Kingdom and the United States, although Saudi Arabia and the United Arab Emirates were grouped together under “Arabian Region.” One of the main findings is a 23% increase in the average cost of a data breach since 2013. The Average cost is now $3.8 million per data breach with an average cost per record of $154. Stark Contrast with Verizon Data Breach Cost Estimates Estimating the cost of a data breach is a highly complicated business. Last month Verizon released a study that included a data breach calculation which estimated the cost per record to be 58 cents, although Verizon researchers were quick to admit that their methodology had flaws. Since the cost was estimated to be lower than that of printing and mailing a breach notification letter,...

Read More

Philadelphia Judge Tosses Class Action Data Breach Lawsuit

A proposed class action lawsuit against the HIPAA-covered entities Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan has been tossed by a Philadelphia judge. The alleged negligence of the health plans was not deemed to warrant a class action lawsuit. Avrum Baum, one of the plaintiffs named in the lawsuit, alleged negligence and unfair trade practices when filing the claim on behalf of his special needs daughter. The suit was filed after a flash drive containing the Protected Health Information and Personally Identifiable Information of over 200,000 health plan members was lost in 2010. Employees copied the data onto the drive, but then misplaced it and were unable to locate the plug-in device. A case could have been filed on the grounds of violations of the Health Insurance Portability and Accountability Act (HIPAA), although the plaintiff’s legal team chose to file the suit on the grounds of negligence and a breach of the state of Pennsylvania’s Unfair Trade Practices and Consumer Protection Law (“UTPCPL”). Class Action Lawsuits under Pennsylvania’s Unfair Trade...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist