NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Brown County Supervisors Meet to Discuss Potential HIPAA Privacy Violation

Supervisors from Brown County, Wis., are considering the position of the Chief Medical Examiner (CME), Jeff Jansen, after he has been accused of committing HIPAA privacy violations on multiple occasions, within 6-months of taking up the position. One incident in particular is at the center of the current discussion. The former CME – Al Klimek – is alleged to have participated in an email discussion with a local funeral director about the condition of a body, even though he had retired and had no legitimate access to that information. In the email, he made a reference to a blood sample and its location and also included information about organ donation. This information was allegedly shared using an insecure medium and the data constituted PHI. However, what is of more concern is how Klimek obtained that information. Jansen is seen as “a protégé of the former Medical Examiner”, according to the Green Bay Press Gazette, and he has been accused of divulging PHI and breaching HIPAA Rules, a claim he vehemently denies. His supporters have said the accusations represent a “witch...

Read More

Indiana State Medical Association HIPAA Breach Update

Details have emerged on the Indiana State Medical Association data breach reported in early March. The Indiana State Medical Association issued a media release in which it confirmed that a data breach was suffered in which approximately 39,000 individuals were exposed, after two back-up hard drives were stolen from an employee’s car. A report in the Star Press yesterday adds further detail to the story, suggesting the initial report was inaccurate and the breach was not reported promptly. The employee in question has also been disclosed as being the ISMA Information Technology Administrator. The employee parked his car in a lot for a period of two and a half hours, and during that time a thief broke into the vehicle and stole two computer back up hard drives containing 39,090 medical records. The hard drives are understood to have been left in plain sight inside the vehicle. The employee did not report the theft until more than 24 hours later. The theft report was filed at 7 pm on February 14. The administrator called law enforcement to report the theft and officers were dispatched...

Read More

Cost of Data Breaches to Hit $2.1 Trillion by 2019

Juniper Research has released a new report suggesting the cost of data breaches will hit $2.1 trillion by 2019 as a result of the increase in cybercrime and the sheer scale of data that will be recorded on consumers’ lives. The Future of Cyber Crime & Security   The new report – The Future of Cybercrime & Security: Financial & Corporate Threats & Mitigation – offers an in depth analysis of the current digital security landscape and the threats now being faced, and creates a roadmap for the evolution of connected devices to predict the effect that data breaches will have over the course of the next four years. While security of the Internet of Things is getting a lot of attention at present, Juniper Research calculates the actual risk of data exposure to be minimal, certainly over the next four years. The real threat, and where the majority of data breaches will occur, is the current IT infrastructure according to Juniper. Network servers, laptop computers and other endpoints will continue to be the major locations of breaches. The report suggests that the...

Read More

21st Century Cures Bill Could Weaken HIPAA Protections

Under current HIPAA legislation, Covered Entities (CEs) and their Business Associates (BAs) are not permitted to disclose the Protected Health Information (PHI) of patients without permission, except when PHI is to be used for treatment, payment of CE operations. However, a new bill has now been drafted which changes the permissible uses of PHI to include research. The new bill is intended to remove some of the roadblocks that are preventing U.S healthcare providers from developing new cures. HIPAA is perceived by many researchers to be detrimental to the healthcare industry, slowing down research, innovation and the development of new drugs and medical treatments. The aim of the 21st Century Cures Bill is to alter HIPAA Privacy Rules to allow healthcare providers to use PHI for research – or supply it to their BAs – without express permission being obtained from patients. Should the Cures Bill be passed, the Secretary of the Department of Health and Human Services would be required to update HIPAA Privacy Rules within 12 months. The discussion draft of the bill – released on...

Read More

Illinois AG Files Improper Dumping Lawsuit Against HIPAA Business Associate

Lisa Madigan, the Illinois Attorney General, has filed a lawsuit against a Northbrook HIPAA Business Associate (BA) for failing to destroy medical records prior to disposal. The BA is alleged to have exposed the PHI of at least 1,500 individual patients. The complaint says that the attorney general’s investigators found 1,500 medical records at Shred Spot. The company had received the medical records from Filefax Inc. of 3405 Commercial Ave., Northbrook. According to the suit, as reported by the Chicago Tribune, “an individual by the name of Halina Bysiek took 1,100 pounds of paper out of the container and brought it to another Sky Harbor business, seeking cash for recycled material.” The data was allegedly left in an “unlocked garbage container behind the building in the Sky Harbor business park.” Paul Kaufmann, Owner of Shred It, identified the material as medical records and alerted his Trade Association – The National Association for Information Destruction. Following the advice he received, Kaufmann contacted the state attorney general’s office and an investigation...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist