NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Cybercrime Report: Children’s Healthcare Data Prized by Thieves

Cybercriminals are targeting healthcare providers and insurers in an attempt to obtain the Protected Healthcare Information (PHI) and Social Security numbers they hold, but above all else, it is the Social Security number of children they are after. According to a study conducted by the University of Texas Center for Identity, children are 35 times more likely to suffer identity fraud after a data breach than adults. A 2011 study conducted by Carnegie Mellon University’s Cylab suggests the risk is much higher, and children are 51 times more likely to suffer from fraud. The UT survey researchers have estimated that one in ten U.S. children have had their identities stolen to some degree. Who do Criminals Use Healthcare Information and Social Security Numbers? Social Security numbers – along with personal identifiers –can be used by criminals to commit fraud in a variety of ways and the value of these numbers has led criminals to come up with highly sophisticated and diverse ways of breaking through organizations’ defenses. Thieves use healthcare data and Social Security numbers to...

Read More
Surprising Results from 2014/2015 HIPAA Breach Analysis
May04

Surprising Results from 2014/2015 HIPAA Breach Analysis

A comparison of data breaches reported to the Department of Health and Human Services’ Office for Civil Rights between January and April of 2014 and 2015 shows some surprising results. Year on Year Comparison of Data Breaches The total number of victims of breaches of PHI during the first four months of 2014 and 2015 differ by only 6,834 records if the two mega data breaches (Anthem / Premera) are taken out of the equation and are considered as anomalies. Add those breaches and the figures tell a very different story, adding a further 89,800,000 individual health plan member records to that total. 118 data breaches were reported during the first third of 2014, with 91 reported during the same period in 2015, a fall of almost 23%. Causes of Data Breaches Recent reports indicate hacking to be the main cause of data breaches, and it has certainly resulted in the most records being exposed. Between January and April, 2014, there were 15 reported data breaches attributed to hacking, while in 2015 30 cases of hacking have been reported: A 100% increase. Theft of devices fell by 42% year...

Read More

Oregon CO-OP Suffers Laptop Theft and Breach Notification Snafu

The Oregon CO-OP, a not-for-profit start-up health insurer, has reported the theft of a laptop containing unencrypted data. The laptop did not contain any health information, although names and addresses of current and former members were stored on the device along with Social Security numbers, health plan details, ID numbers, dates of birth, and the names of dependents. The “security incident” was immediately reported to law enforcement officers and the theft is now being investigated. The incident occurred on April 3, although the laptop computer has not yet been recovered. While the device did not have data encryption software installed, it was protected with a password. This, in itself, is not sufficient protection for data of this nature, as passwords can easily be cracked but it does decrease the likelihood of the data being accessed or used to commit fraud. The CO-OP has no reason to believe that this was the case, or that any members’ information was accessed by the perpetrators of the crime. Breach Notification Snafu Delays Letters All affected individuals are being sent...

Read More
Phishing Attack Causes Partners HealthCare System HIPAA Breach
May01

Phishing Attack Causes Partners HealthCare System HIPAA Breach

Partners Healthcare has announced that it has suffered a HIPAA breach after hackers used a phishing attack to gain access to some of its email accounts. While the company’s EHR system was not compromised, the email accounts did contain some PHI and approximately 3,300 patients are believed to have been affected. Partners Healthcare believes that PHI may not have actually been obtained by criminals as there was no evidence discovered that this was the case, although it is possible that Social Security numbers and some clinical information – including diagnoses, treatments and medical appointments – were accessible through the email account, as were patient names, dates of birth, contact telephone numbers, addresses, medical record numbers and health insurance details. According to the breach notification posted on the company’s website, the attack was discovered on November 25, 2014. A group of user’s accounts were compromised after they received and responded to phishing emails in the belief that they were legitimate. Hackers were subsequently able to gain access to the email...

Read More

Calculating the Cost of a HIPAA Data Breach

Calculating the cost of a HIPAA data breach is not a straightforward process, at least not until a number of years after a data breach has occurred. Actions must be taken following a breach, and the cost of notification and damage mitigation can spiral. Financial penalties are also being issued with increasing frequency to healthcare organizations fail to implement the appropriate privacy and security measures to protect patient healthcare data. HIPAA and Breaches of Protected Health Information The Health Insurance Portability and Accountability Act places a requirement on covered entities to employ the appropriate administrative, physical and technical safeguards to prevent the unauthorized disclosure of Protected Health Information (PHI). Patients must also be allowed access to their healthcare information on request, privacy must be respected and policies developed to de-identify data before it is used for research and marketing purposes. Business Associates – any vendor required to come into contact with PHI – must also be vetted to make sure they comply with HIPAA Rules. When...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist