NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

White Plains and Conemaugh MMC Hospitals Announce HIPAA Breaches

White Plains Hospital, N.Y. and Conemaugh Memorial Medical Center, Pa. have issued breach notices confirming they have been affected by the data breach caused by an employee of Business Associate (BA), Medical Management. Earlier this week we reported Medical Management LLC suffered a data breach after an employee copied protected data from the company’s billing system and disclosed that information to a third party. Medical Management is a billing vendor providing a range of billing and coding services to a number of healthcare providers, many of which are in New York. The data exposed included names, dates of birth and Social Security numbers. The University of Pittsburgh Medical Center (UPMC) was the first healthcare provider to announce that some of its patients had been affected by the data breach. Two more hospitals have now issued breach notices to the media and have sent notifications to affected patients.. White Plains Hospital Notifies 1,100 of Data Breach White Plains Hospital in New York announced it was affected by the data breach caused by the BA and learned that...

Read More

Thomas Boyd Hospital: Potential HIPAA Violations; Theft Allegations; No exposed PHI

Boyd Hospital in Carrollton, Ill. has potentially violated the HIPAA Security Rule after it failed to remove medical records from an old property before it was sold. A resident of Jerseyville, Edward Crone, purchased an old property – an ambulance shed in Main Street – from the county on March 19, after it had been sitting dormant on the market for over a year. The shed was being used by the hospital as an off-site storage facility. The property was used to store office equipment such as desks, chairs and filing cabinets and it was also home to a number of boxes of medical records. A breach report was submitted to the Department of Health and Human Services’ Office for Civil Rights – dated May, 21 – announcing that 8,300 records were in the boxes. Boyd hospital had made the transition to Electronic Health Records some time ago, and the data on the paper files had been scanned into digital documents which were stored on the hospital network. The paper files appear to have been something of an issue, as they could not be disposed of and the hospital was...

Read More

Holston Valley Medical Center Reports HIPAA Breach

Holston Valley Medical Center, a Kingsport, Tenn. hospital run by the Wellmont Health System, has discovered that 1,726 patients’ medical records have been improperly disposed of, according to a report on WYMT Mountain News. On March 1, 2015, the hospital was alerted to the presence of a number of documents containing Protected Health Information (PHI) in a recycling container in Steel Creek Park, Bristol. The documents contained notes on patients taken by a nurse and related to patients who had visited the Holston Valley Medical Center between 1998 and 2007. It is not clear exactly what information was included on the patients, although a statement released by Wellmont’s Chief Compliance Officer, Nancy Merritt, confirmed “The notes were not part of any patients’ legal medical record and were never in a public area before they were placed in the recycling bin.” Merrit went on to say, “Holston Valley and Wellmont did not authorize these notes, their retention or their disposal at Steele Creek.” The taking of notes was in violation of company policy and in an interview with the nurse...

Read More
HHS Launches Redesigned Responsive Website
May18

HHS Launches Redesigned Responsive Website

The Department of Health and Human Services has completed the re-vamp of its website and its visitors are now presented with a clearer, crisper and more user-friendly interface thanks to a design that was developed to work on all devices and screen sizes. The change has been long overdue as any regular visitor to the HHS website could attest; the information was always there, but finding that information was a slow process and searching was especially difficult on a handheld device. Designed with Current and Future Visitors in Mind Before the site was developed, the HHS conducted market research survey, web analytics, workshops and usability testing with the public, and took the initiative from companies such as WIRED and NPR; both of which have recently redesigned, reorganized and re-purposed their own web content. “Out with the old and in with the new” has been taken to heart, with the HHS clearing out 154,000 files that were obsolete, removing all of the unnecessary files to speed up site searches. With less files to search with every query, search sped has been greatly...

Read More

Cybersecurity Firm Accused of PHI Theft and Mafia Style Extortion

According to a recent report on CNN, cybersecurity firm Tiversa has been staging break-ins, stealing PHI, and extorting its clients in an attempt to get them to pay for additional services provided by the firm. An accusation firmly denied by Tiversa. The story of Tiversa is likely to become well known over the coming weeks, as a whistle-blower has come forward with tales of extortion, theft, scare tactics, and fraud closer to what would be expected of the mafia, not a cybersecurity company. The company may not be particularly well known, but some of its board members are. According to the CNN report, “board members include several highly-decorated experts in the security and privacy fields, including the retired four-star U.S. Army General Wesley K. Clark (formerly NATO’s Supreme Allied Commander in Europe) and Larry Ponemon (founder of the Ponemon Institute, a pro-privacy think tank).” Whistle-Blower Reveals Details of Mafia-Style Extortion An ex-employee of the company, Richard Wallace, has testified in a Washington D.C court claiming, as one of the company’s former...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist