25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Sunglo Home Health Services Suffers HIPAA Breach

A laptop computer containing Social Security numbers and Protected Health Information was stolen from the facilities of Sunglo Home Health Services on January, 26, 2015. While the number of affected individuals was not announced, it was confirmed that personal identifiers and PHI were stored on the laptop making this a HIPAA breach. According to an Action 4 News report the day after the break in, a potential suspect has been arrested. KRGV News reported that the suspect broke into a van that was parked in the Sunglo car park, but instead of driving away he returned and broke into Sunglo’s facilities using a fire extinguisher to smash a window. He then took the laptop computer and made his getaway. The following day the van was recovered and the suspect, Matthew de la Cruz, was apprehended after being caught on CCTV cameras driving the van; however none of the items taken in the break in, including the laptop computer, have been recovered by law enforcement officers. Matthew de la Cruz is currently in jail. Since no equipment has been recovered it is possible that the laptop could...

Read More

Healthcare Technology Trends for 2015

A wealth of new technology is knocking on the door of the healthcare industry and with the current pace of development, 2015 promises to be a very exciting year. Last year we saw health technology develop at a tremendous pace. In 2014 alone, investment in health technology topped $5 million; more than double the investment of the previous year. However, rapidly escalating costs, fast-reducing budgets, and more stringent regulations are putting the industry under more pressure than ever before, and the strain is starting to show. Cost cutting while improving treatment outcomes and complying with HIPAA, HITECH, and Meaningful Use created the biggest challenge for the healthcare industry in 2015. The use of big data, powerful analytics, predictive technologies, the Internet of Things, and 3D printing are all expected to have a major impact in 2015; however, predicting the trends that will have the most significant impact on the healthcare industry – in light of the daily technological advances  – is a tall order. Some of the major issues, innovative technologies, and HIT...

Read More
Sutter Health California Pacific Medical Center HIPAA Breach Announced
Jan23

Sutter Health California Pacific Medical Center HIPAA Breach Announced

Sutter Health, a not-for-profit health system in Northern California, has issued a breach notification alerting the public and patients to a security incident that occurred at its California Pacific Medical Center (CPMC). CPMC reported that it discovered a case of improper access of patient records by an employee during one of its “proactive” audits of electronic medical records on October 10, 2014. That audit showed that one employee had accessed the records of 14 patients. Those patients were mailed breach notification letters on October 21st 2014 and the work contract of the employee in question was terminated. Once the breach had been stopped, CPMC investigated the matter further and discovered a total of 844 patient records had potentially been viewed inappropriately, as there appeared to be no apparent treatment or business purpose that required those records to be viewed. The records were accessed over a period of a year, between October 2013 and October 2014 According to the statement, the information which was potentially accessed by the employee included “patient...

Read More

Government to Help Mobile Health Developers Comply with HIPAA

Mobile health apps have great potential to improve efficiency in healthcare as well as patient outcomes; however, developers of mobile health apps are struggling to attract interest from healthcare providers due to fears that their products would cause violations of the Health Insurance Portability and Accountability Act (HIPAA). HIPAA Privacy and Security Rules serve to protect patient privacy and keep health and personal data secure. Substantial financial penalties are being issued by both the Office for Civil Rights and Attorney General’s Offices for non-compliance, and understandably healthcare providers are being extremely cautious with any new technology or software that could potentially touch the Protected Health Information of their patients. The App Association (ACT) – an advocacy and educational organization representing mobile app developers – wrote to the Office for Civil Rights requesting clarification on HIPAA privacy rules, and how they apply to mobile developers. Developers are keen to incorporate the required privacy controls to ensure HIPAA compliance;...

Read More
Mass. Marijuana Program HIPAA Breach Reported
Jan20

Mass. Marijuana Program HIPAA Breach Reported

A violation of the HIPAA Privacy Rule has been reported after the Massachusetts Health Department sent a mailing to patients enrolled in its medical marijuana program. The violation involves a bizarre oversight, which should have been detected prior to the email being sent. Over a period of three months, more than 6,800 emails were sent to patients advising them that they had been approved to join the medical marijuana program run by the state. This information is sensitive and should have been communicated to the patients via a secure medium. The mailing the patients received included a subject line of “Confirmation of Patient Certification in the Medical Use of Marijuana Online System.” Also contained in the emails was the intended recipient’s full name and registration number. Since the emails contained personal identifiers and the choice of subject line, this incident is considered to be a breach of HIPAA Privacy Rule as the enrollment in the program can be classed as medical information. Also of concern is the incident involved a unique code and the patient’s email address,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist