NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Data Breach Bill Rejected by New Mexico Senate

The New Mexico Data Breach Notification Act (HB 217) may have been unanimously passed by the house, but the senate has rejected the Act, which would have required businesses to notify customers in the case of a breach of Personally Identifiable Information (PII). The New Mexico description of PII includes Social Security numbers, Government ID numbers, Driver’s license numbers, credit/debit card numbers, bank accounts and information giving access to financial accounts; in cases where that is combined with the person’s full name or last name and initial; although data covered by the Gramm-Leach-Bliley Act of 1999 and the Health Insurance Portability and Accountability Act of 1996 are exempted. The decision not to pass the Act is peculiar. It went before the senate and was unanimously passed by the Corporations Committee; however the Act did not get passed the Judiciary Committee, even though no one voiced concern over the bill. Rep. The rejection however now means that in New Mexico, any individual affected by a data breach involving PII will not be required by law to be notified...

Read More

HIPAA Violation Warning Issued About Medical Record Subpoenas

Law firm, Day Pitney LLP, has issued a warning to healthcare professionals to be cautious about disclosing Protected Health Information, even when asked to provide medical records to attorneys under subpoena. A Connecticut Supreme Court ruling in November 2014 permitted a negligence claim to be filed against a healthcare provider for non-compliance with HIPAA Rules governing the disclosure of PHI to third parties. The court ruled that HIPAA Privacy Rules cover Protected Health Information even when that information is required by attorneys, and requested through proper legal processes. In Connecticut at least, PHI can only be released under subpoena if certain criteria are met. The court cited the Code of Federal Regulations, 45 C.F.R. § 164.512(e)(1)(ii) , which only permits the transfer of Protected Health Information if “satisfactory assurances” have been received that the person whose medical records have been requested to be disclosed has received a notice of the access request. As pointed out by Susan R. Huntington of Day Pitney, in order for PHI to be released under HIPAA...

Read More

10 HIPAA Breach Costs You May not Be Aware of

A data breach is less of a possibility and more of inevitability in 2015. Cyber crime is on the increase and the healthcare industry is under threat, with major attacks already having exposed millions of records – with last year’s tally having already been surpassed by some distance. Determining the data breach financial impact can be difficult as there are variables that cannot be accurately predicted immediately after a breach has occurred. Civil claims for damages will almost certainly be filed, although the number of victims of fraud will not be known for many years, neither the damages which will need to be covered. The Department of Health and Human Services’ Office for Civil Rights investigates data breaches; however it can take time for an assessment to take place. A full compliance audit may be required, the findings assessed and financial penalties considered. Settlements can take a number of years to be reached and there is no telling how many violations will be discovered by its auditors. Each violation category carries a maximum fine of $1.5 million in cases where the...

Read More
Employees Steal 9,000 Patient Records From Florida Hospital
Mar25

Employees Steal 9,000 Patient Records From Florida Hospital

The massive data breaches of Anthem and Premera highlight the real and present danger of HIPAA breaches from hackers, but there is also a major threat from within. Hospital employees may not be responsible for the largest breaches, yet staff snooping on hospital records is a serious problem. Each year employees view and copy the data of tens of thousands of patients, with 9,000 records potentially compromised in the latest case of employee snooping, according to a report in the Daytona Beach News Journal. Two medical professionals working at an unnamed Florida Hospital in Orlando have recently had their employment contracts terminated after the hospital discovered that patient records had been inappropriately accessed. The employees were based in Orlando, and reportedly had access to the patient records at eight Florida hospitals: Florida Hospital Orlando; Florida Hospital Altamonte; Florida Hospital Apopka; Florida Hospital East Orlando; Florida Hospital Kissimmee; Celebration Health; Winter Park Memorial Hospital and Walt Disney Pavilion at Florida Hospital for Children, although...

Read More
Premera HIPAA Breach: Insurer Certified as HIPAA Compliant
Mar24

Premera HIPAA Breach: Insurer Certified as HIPAA Compliant

In the aftermath of a major HIPAA breach, the spotlight is shined on healthcare providers and insurers’ and they investigated to determine whether the breach was preventable, and if it was caused by violations of HIPAA regulations. In the case of Premera, hackers were able to infiltrate the insurer’s computer network and gain free access to patient healthcare records for a period of 10 months. The insurer has been criticized for the breach, in particular for failing to audit its internal computer systems regularly; a measure which could have identified the breach much more quickly and thus would have limited the damage caused. While attention is focused on the insurer and potential HIPAA violations, according to the U.S Office of Personnel Management, the insurer was deemed to be HIPAA-compliant after an audit of its systems last year. The U.S Office of Personnel Management conducted general testing of Premera’s information systems in January 2014, in addition to a full application control audit. While the Office for Civil Rights is tasked with auditing healthcare providers on...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist