NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Issues Advice on HIPAA and Workplace Wellness Programs

Protected Health Information (PHI) is safeguarded under the Health Insurance Portability and Accountability Act Rules, which place a number of requirements on covered entities (CEs) to implement a number of controls to ensure that healthcare data is not disclosed to unauthorized individuals. Should that occur, or if the data is stolen, covered entities also have a requirement to notify the Office for Civil Rights (OCR) and any persons affected by the breach, with the rules and regulations for doing so laid down in the Breach Notification Rule. These rules cover most healthcare providers, health plans, and healthcare clearinghouses; however, OCR has recently issued guidance on Workplace Wellness Programs, as there appears to be some confusion about coverage under HIPAA Rules. Are Workplace Wellness Programs Covered by HIPAA? The confusion over HIPAA and Workplace Wellness Programs is understandable because whether these schemes are covered under HIPAA depends on how the wellness programs have been set up, and if they are provided through an employer as part of a group health plan....

Read More
Raytheon Acquires Websense in $1.9 Billion Deal
Apr20

Raytheon Acquires Websense in $1.9 Billion Deal

Raytheon, a major U.S defense contractor, has announced it is to acquire Websense Inc from Vista Equity Partners in a deal reported to be worth $1.9 billion. The deal is expected to add an additional 20,000 commercial customers to Raytheon’s portfolio and is expected to close at the end of Q2, 2015. Over the past couple of years there has been a significant increase in cyberattacks on organizations of all sizes from SMBs to multi-national corporations. The increase in frequency of attacks and the level of sophistication of the attackers requires advanced defenses to be deployed to keep networks and data secure. The recent high-profile attacks have prompted many firms to commit more funds to cybersecurity. MarketsandMarkets has estimated there will be an increase of $60 billion in cybersecurity spending over the next four years, and Raytheon is poised to take advantage. Websense has developed Internet security technology for enterprises and governments to protect against web-based threats and block data theft and keep systems and endpoints free from malware. Those solutions will be...

Read More
HIPAA Privacy Violation Reason for Whistle-Blower Testimony Erasure
Apr19

HIPAA Privacy Violation Reason for Whistle-Blower Testimony Erasure

The Florida Department of Corrections has scrubbed the name of an inmate from a video testimony provided by Doug Glisson; an inspector of the Department of Corrections’ Office of Inspector General, due to a HIPAA Privacy Rule violation, according to a news report in the Miami Herald. Glisson is a DOC whistle-blower who has testified under oath of potentially negligent medical care, sabotaged investigations and criminal activity. He alleges that a number of HIPAA violation cases, which he give four specific examples in his video testimony; investigations have been sabotaged in order to protect the organization’s top officials. In his testimony at the Senate Criminal Justice Committee’s March 10 meeting, he cited the name of an inmate in one the examples he provided in his testimony. The case in question concerned an inmate who died in hospital under “suspicious” circumstances. Glisson claims that the patient was “undergoing medical care” at Jefferson Correctional Institution, but no information relating to his medical condition was provided. He “started having seizures” and “wound...

Read More
EEOC Releases New Rules for Wellness Programs
Apr18

EEOC Releases New Rules for Wellness Programs

The Equal Employment Opportunity Commission (the EEOC) has proposed some long awaited rules for wellness programs, which in many cases fall outside of current regulations with regards to data privacy and security. The new regulations are intended to work alongside those already laid down in the Health Insurance Portability and Accountability Act (HIPAA) and the Americans with Disabilities Act (ADA). The Rules will help to make sure appropriate security measures are implemented to protect any medical data that is collected on employees, and also ensure that privacy safeguards are put in place to restrict access to that data. Regulations for HIPAA-Covered and Non-HIPAA-Covered Wellness Programs The new rules proposed by the EEOC apply to wellness programs that involve medical examinations being conducted, in addition to any that make inquiries about disabilities. Wellness programs that are offered to employees as part of a group health plan are already covered under HIPAA regulations, and any data collected on the employees would be classed as Protected Health Information (PHI). That...

Read More

New HIPAA Breach Report Confirms Healthcare Hacking Increase

The cybersecurity threat faced by the healthcare industry has been widely reported as being at a critical level, yet data on the actual threat level is in short supply. A survey was recently commissioned by HITRUST – to investigate the actual threat level and this week a review of reported data breaches has been published on the matter. The latest study was performed by staff at Kaiser Permanente, an integrated managed care consortium, based in Oakland, California. The study looked at the hacking incidents which occurred between 2010 and 2013, with the findings recently having been published in The Journal of the American Medical Association – JAMA . The study shows that over the course of four years, hacking incidents involving Protected Health Information had almost doubled. In 2010, close to 5% of all data breaches involving HIPAA-covered data – and involving more than 500 individuals – were attributed to the actions of hackers or malicious software called malware. By the end of 2013 that percentage had risen to 9%. Dr. Vincent Liu was the lead author on the report. He...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist