NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

No Insurance Cover for Cottage Health HIPAA Breach?

Columbia Casualty Co – a unit of Chicago-based CAN Financial Corp. – is seeking a ruling from a judge in an attempt to avoid paying a $4.1 million settlement for the HIPAA breach suffered by the Cottage Health System; a not-for-profit network of hospitals in Southern California. The data breach in question took place between October 8, 2013, and December 2, 2013, not at the Cottage Health System, but a Business Associate (BA). The breach occurred when data was placed on an unencrypted network server, allowing the information to be indexed in Google and be made freely available on the internet. The data breach resulted in approximately 32,500 medical records being exposed along with Personally Identifiable Information (PII) and Social Security numbers. A class action lawsuit was filed against Cottage Health System for the disclosure of information with a $4.1 million settlement being sought. That settlement received preliminary court approval in December 2014, and Columbia Casualty is trying to avoid paying. Breach of Policy Could Mean No Payout Since the Cottage Health...

Read More

UT Southwestern Medical Center Announces Data Disclosure

The UT Southwestern Medical Center has inadvertently breached Health Insurance Portability and Accountability Act and state privacy laws after accidentally transmitting the immunization records of 1,032 individuals to a confidential state registry. The data was posted to the ImmTrac immunization database, used by the Texas Department of State Health Services, school districts and physicians to keep a check on children’s immunizations to ensure they have been performed. The database contains over 120 million immunization records, mostly for children although some adults have data recorded on the system. Access to ImmTrac is strictly controlled and only authorized individuals would have been able to view the information uploaded. Under Texan law, written authorization must be obtained from the patient before any data is shared statewide ImmTrac users. The information started being transmitted on January 9, 2015 after a routine computer upgrade was performed. Russell Rian, a spokesperson for UTSW, said in a statement the transmission was the result of a “computer glitch.” At no point...

Read More

Metro Health System HIPAA Breach: Malware Claims 981 Victims

The MetroHealth System has announced it has suffered a HIPAA breach after malware was discovered on three of its computers. 981 medical records of patients who received cardiac catheterizations were potentially compromised in the attack. The MetroHealth System, a county operated non-profit healthcare provider based in Cleveland, Ohio, discovered on March 17 that malware had infected three Cardiac Cath Lab computers. The malicious software was removed the following day on March, 18. MetroHealth initiated an immediate investigation into the malware infection and potential data breach to determine how the software had been installed, the extent to which data had been compromised, the patients who had been affected and whether any data had actually been viewed or copied. While the malware was initially thought to have been successfully removed, the forensic investigation revealed the highly sophisticated nature of the software. Some days into the investigation, it was discovered that in addition to the malware, a back door had been created allowing the creator of the software full...

Read More

University of Pittsburgh Medical Center Patients Warned of BA HIPAA Breach

A Business Associate (BA) of the University of Pittsburgh Medical Center has notified the healthcare provider, and numerous other clients, of a HIPAA breach caused by a rogue employee. The now former employee is alleged to have stolen the records of 2,259 patients. Medical Management LLC – a medical billing company – was notified by federal law enforcement agencies that a member of staff at the company was believed to have stolen and disclosed confidential data and that the incident was being investigated. The employee in question – who has not been named – was a worker in the company’s call center. That person has been accused of copying “personal information from the billing system” and disclosing the information to a third party. Social Security Numbers and Personally Identifiable Information Stolen Patients affected by the breach are being sent breach notification letters from today to alert them that their personal information has been obtained and disclosed. They have been advised that their names, dates of birth and Social Security numbers had been compromised. Breach...

Read More

NLRB Judge Rules HIPAA Violation not Grounds for Employment Termination

A National Labor Reform Board (NLRB) judge has ruled that the termination of an employee’s contact on the grounds of a clear HIPAA violation was not justified under the circumstances. The International Union of Operating Engineers (Charging Party or Union) alleged that Rocky Mountain Eye Center, P.C. had violated the National Labor Relations Act (NLRA) by terminating the employment of a worker, Britta Brown, on the grounds of a HIPAA violation. The employee had accessed protected records of co-workers to obtain contact information for a union-organizing campaign. In this case, the violation occurred because the organization in question was a medical practice and its patients included employees. The records needed to be legitimately accessed, but the employee used Centricity – Rocky Mountain Eye Center’s healthcare IT system – to obtain the information. When employee contact information is accessed, it is also possible for authorized users to access the Protected Health Information of those individuals. The National Labor Relations Act offers protections to employees, the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist