NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

LCO Health Center Investigates Potential HIPAA Violations

The Lac Courte Oreilles (LCO) Tribal Governing Board of the Ojibwe Indian Reservation has reported a HIPAA breach in which an undisclosed number of individuals have had their PHI exposed. The LOC reported “several pieces of Health Center information from 2010-2011” were compromised in the incident. An investigation was conducted by the LCO along with the tribal police force into a potential breach of the Health Insurance Portability and Accountability Act (HIPAA) after an employee of the LCO Health Center (LCOHC) took PHI from the health center, according to a notice published on the tribe’s website. Late last year, the Director of the LCOHC was made aware of a potential breach of HIPAA Rules after an employee had allegedly taken health center files home. The following investigation quickly established that the employee had taken the files in order to complete some work; however, those files were not returned to LCOHC “in a timely fashion.” The matter was brought to the attention of the Director of the LCOHC by the employee’s partner, who reported the incident after the couple...

Read More

Saint Agnes Health Care Hack Exposes 25,000 HIPAA Records

Saint Agnes Health Care, Inc. of Maryland has reported that hackers have gained access to an email account as a result of a phishing campaign. One email account was compromised in the attack; however, that user had privileges to access Protected Health Information (PHI) and the account contained the records of approximately 25,000 patients of the facility. Out of the 24,967 records exposed, only four contained Social Security numbers but a considerable amount of data was potentially obtained by the person responsible for the attack. The data included patient names, gender, dates of birth, medical record numbers and health insurance information, and a limited amount of clinical data. It is not clear from the notice when the incident occurred, although it was posted on the company website on April 27, 2015, and the incident was reported to the Office for Civil Rights on April 24, 2015. The email account that was compromised was immediately closed as soon as the intrusion was detected and the healthcare provider has been on high alert since. No further threat is believed to remain of...

Read More

Study Suggests HIPAA Data De-identification Improvements Required

Under HIPAA Rules, healthcare providers and other covered entities (CEs) are permitted to use the Protected Health Information (PHI) of patients – and share this information with others – provided that the data has been de-identified. It must not be possible for PHI data to be tied to any individual. CEs are permitted to share the data if it can be demonstrated that the risk of that data being associated with a particular patient is small and have two options for de-identifying healthcare data prior to sharing that information with a Business Associate: They can de-identify data using a model such as k-anonymity, or they can set a rule-based policy – the Safe Harbor model – that changes data values; for example, changing dates of birth to the following or preceding year, or stripping out days and dates to just provide a patient’s age. However, while the latter method is often used, it is far from perfect. According to a recent study published in the Journal of the American Medical Informatics Association (JAMIA), this procedure does not tailor protections to the...

Read More
Improper Disposal Nets Small Pharmacy $125K OCR HIPAA Penalty
Apr27

Improper Disposal Nets Small Pharmacy $125K OCR HIPAA Penalty

The mega data breaches to hit large insurers and healthcare providers have been making the headlines in recent months; however, the Department of Health and Human Services’ Office for Civil Rights (OCR) showed yesterday that even smaller healthcare providers must abide by HIPAA Rules or face the consequences. Yesterday, the OCR issued a statement on the latest settlement to be reached with a healthcare provider for violations of HIPAA Rules. The OCR announced that it has reached a settlement for $125,000 with a Denver-based healthcare provider, Cornell Pharmacy, following the improper disposal of patient health records. Cornell Pharmacy is a single-location healthcare provider that mostly serves hospice care organizations in Denver and provides compound medications. HIPAA-Covered Entities of All Sizes Must Obey HIPAA Rules The Office for Civil Rights has been cracking down on HIPAA violations in recent years and has issued a number of large fines to organizations that fail to abide by HIPAA Privacy and Security Rules. Organizations large and small are being investigated by the OCR...

Read More

26 Percent of Healthcare Organizations Have Suffered a Data Breach

According to a recent Harris Poll survey conducted on behalf of Vormetric, 26% of healthcare organizations have suffered a data breach. With the volume of data breaches now being reported, it is highly probable that this figure will rise significantly over the course of the next 12 months. The survey asked questions of 818 IT decision makers – including 102 from the healthcare sector – relating to data breaches, threats, and actions taken to prevent cyber attacks. Over half of the respondents (54%) said that achieving full HIPAA-compliance status had been the main reason why Protected Health Information has now been safeguarded; indicating that HIPAA is proving to be effective in this regard. 68% of respondents said that HIPAA has been “very or extremely effective at stopping insider threats and data breaches.” While PHI protection has improved there is still a long way to go. The survey indicated that over a quarter (26%) of healthcare providers had suffered at least one data breach. In spite of the efforts made by many healthcare providers to become HIPAA-compliant,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist