25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Outsourcing IT to HIPAA Compliant Data Centers is a Viable Solution

Healthcare organizations are facing an increasing financial and logistical burden as a result of stricter HIPAA privacy and security rules. Additionally, as the volume of electronic data increases, healthcare organizations must allocate extra resources to their IT departments to ensure that the data is protected and IT systems are made more robust. Most healthcare centers operate with strict budgets and often there are insufficient funds to develop the necessary IT infrastructure to ensure HIPAA compliance; however with audits being conducted by the Office for Civil Rights, doing nothing is not an option. Heavy fines are being issued for each instance of non-compliance found by the OCR which are far in excess of the cost of upgrading current systems. In order to comply with current regulations, healthcare organizations must either invest in their IT departments and upgrade their existing data centers, or if this is not viable, construct new data centers and incorporate the latest technology, hardware and software to ensure the ePHI of patients is properly protected. There is also a...

Read More

Employee Snooping Results in Exposure of 200K HIPAA Covered Records

The Early Learning Coalition of Palm Beach County has announced that a former employee has inappropriately accessed a database containing the medical records of up to 230,000 patients. The database contained personal information of parents and children who have attended centers or received services from the coalition. The affected individuals are believed to be those having received school readiness services or participated in the Voluntary Prekindergarten Education Program according to a statement made by the ELC. The unauthorized access occurred at the Belle Glade office of Family Central Inc. and has been confirmed as having affected 37 patients, although the matter is still under investigation and the final number of victims is not yet known. Data potentially accessed included personal information such as names and contact details, and almost half of the records in the database contained Social Security numbers. The former employee, who was not named in the statement, “accessed the database in an unauthorized manner in order to obtain the personal information, including social...

Read More
Sony Pictures Hack Exposes Sensitive Employee Health Information
Dec05

Sony Pictures Hack Exposes Sensitive Employee Health Information

This week saw Sony Pictures attacked by a group of hackers calling themselves “Guardians of Peace”. The hackers gained access to a number of computers of Sony Pictures employees and obtained files containing highly sensitive information. The group then proceeded to publish some of the stolen documents and spreadsheets online as evidence of their successful hack. Included in the posts was what appeared to be a list of passwords to three machines the hackers claimed to control. The group is claiming to have gained access to hundreds of Sony Pictures computers According to Fusion.net, the files obtained from the computers include a spreadsheet containing the names, birth dates and social security numbers of 3,803 employees of Sony Pictures. The list also includes the details of the company’s top executives, with payroll data also available. Details of employee pay raises and other financial information is in the unprotected data. One document details the staff that had contracts terminated in 2014, with the reasons why their employment was terminated. The data is not limited to...

Read More
Small Healthcare Practices Likely to be Hit with Huge HIPAA Fines
Dec04

Small Healthcare Practices Likely to be Hit with Huge HIPAA Fines

A recent HIPAA compliance survey conducted on small healthcare organizations and billing companies has highlighted major flaws in data security, which in light of the upcoming random audits being conducted by the Office for Civil Rights could see small healthcare institutions hit particularly hard. Fines for HIPAA non-compliance are considerable and all HIPAA-covered entities can potentially be audited, even relatively small healthcare organizations. The survey was conducted by Porter Research on behalf of The Daniel Brown Law Group and NueMD. 1,100 healthcare professionals were asked about the efforts that had been made to secure ePHI and whether they consider their organizations to be fully HIPAA-compliant. The results of the survey show that many small healthcare entities are breaching HIPAA regulations and are struggling to cope with the new rules on data security. It is not just HIPAA that is an issue. Healthcare companies are faced with increased regulations from ICD-10 and Meaningful use and are struggling to keep their policies and procedures compliant with all current...

Read More
Healthcare Organizations a Soft Target for Cybercriminals
Dec04

Healthcare Organizations a Soft Target for Cybercriminals

The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 at a time when the internet was still in its infancy. Over the following 18 years the volume of information stored in an electronic format has grown at an extraordinary pace, and with it, so has the threat of theft. Today, ePHI is stored on servers, in the cloud and on mobiles and laptops and according to a recent report by IDC Health Insights, the healthcare industry is seen as a soft target by cybercriminals. The report; titled “Business Strategy: Thwarting Cyber Threats and Attacks against Healthcare Organizations,” suggests that the security issues faced by the healthcare industry are a result of poor investment in IT security infrastructure over the preceeding 18 years. The financial industry is a prime target for cybercriminals, but organizations have invested heavily in security systems to protect the financial details of clients. While no organization is impregnable to attack, they are viewed by criminals as hard targets. Hospitals and healthcare clinics on the other hand are relatively easy...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist