25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Extended Data Breach Notification Deadline for California Healthcare Providers

A recent change to the California legislation will extend the time limit for issuing data breach notifications, with certain healthcare providers being allowed up to 15 days to issue notifications to affected persons under Assembly Bill 1755. The current deadline is 5 days. Under AB1755, healthcare providers covered by California Health and Safety Code Section 1280.15 must issue a notice of a breach of medical data to the California Department of Public Health and any individual affected – or their representative. This change affects clinics, health care facilities, hospices and home health agencies. In addition to the 10-day extension to the notification deadline some additional flexibility has been introduced with AB1755 regarding the method of contacting any patient affected by a data breach. The law currently requires that the patient (or his/her representative) is notified by mail to their last known address. The change accommodates HIPAA regulations on confidential communications (45 CFR 164.522(b)) under which a covered healthcare provider may “accommodate reasonable...

Read More

Court Dismisses CMIA Claim for $4 Billion in Damages for HIPAA Breach

Under the California Confidentiality of Medical Information Act (CMIA), companies can be fined billions of dollars for breaches in security leading to the loss of patient medical data. A Californian health care organization has recently escaped a fine of $4 billion after it lost the medical records of over 4 million of its patients. The court case saw plaintiffs filing for $1,000 in damages for the loss of data that occurred when a hard drive containing the unencrypted patient database was stolen from a health care center. The company avoided paying damages because while the laptop – and the data – was clearly stolen; it was not possible to determine if the data had been viewed. Without proof that the data had been accessed by an unauthorized individual, it was not possible to determine on the balance of probabilities that an “injury” had been sustained for which the defendant could be held liable. Because statutory damages of $1,000 can be claimed under CMIA law, any data theft or loss often results in legal action being commenced on the grounds of professional negligence,...

Read More

Malware Potentially Exposes HIPAA Data at North Carolina Dermatology Clinic

Central Dermatology Center & Carolina Medi-Spa is the latest healthcare institution to experience a HIPAA breach as a result of malware. The malicious software was discovered on one of the central servers of its IT network on Sept 25, 2014 according to a statement issued by the facility. The notice, released on Friday, explained that as soon as the problem was discovered, an investigation was launched and forensic IT experts were enlisted to determine the nature of the malware and the data that it could have potentially compromised. The investigation determined that electronic health data had potentially been exposed by the malware, although there was no mention of the number of individuals that were believed to be affected. The data that has been compromised includes Social Security numbers, contact telephone numbers, addresses, dates of birth, age, sex and race information as well as hospital billing and diagnostic codes. The database also includes data such as health insurance policy numbers, provider details, co-payment information, treatment dates, employment details and...

Read More

HIPAA Breach Report: August 2014

August 2014 HIPAA Breach Summary: HIPAA Regulations require all covered entities to submit a report of any breach affecting more than 500 individuals to the Department of Health and Human Services’ Office for Civil Rights. Covered entities only have 60 days in order to make the report or they face a breach notification penalty. This report contains a summary of the breaches reported to the OCR during the month of August, 2014. Major HIPAA Breaches in August 2014 August saw a high number of HIPAA breaches reported in which over 4 million individual records were compromised – more than the total number of individuals affected by data breaches in the first six months of the year. The majority of the victims were created by a huge data breach at Community Health Systems Professional Services Corporation (TN) which exposed the records of 4,500,000 individuals. The CHS HIPAA breach was one of the largest ever recorded, and resulted in hackers obtaining personal identifiers and Social Security numbers, in what was described as “a highly sophisticated attack”. In any other month the...

Read More

How Providence Anesthesiology Leveraged Smartphones to Improve Communication with Field Staff

Healthcare providers have a challenge ahead of them if they are to improve communication with field staff and other mobile workers; how to do so without exposing patient data and violating HIPAA Rules. Providence Anesthesiology Associates opted to use a secure messaging platform to help stay in touch with critical members of the care team, and is now reaping the rewards. Communicating with mobile workers and field staff is convenient, fast and easy via Smartphones; whether they are owned by an employee under a BYOD scheme, or provided by employers. However, ensuring communications remain HIPAA-compliant is difficult. PHI cannot be transmitted via insecure channels, meaning standard communication methods available through mobile devices cannot be used. If PHI is to be transmitted via an insecure channel, HIPAA requires the data to first be encrypted. To ensure remote workers do not inadvertently violate HIPAA Rules by using insecure channels to communicate PHI, HIPAA –covered entities should consider using a HIPAA-compliant text message platform that will allow the transmission of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist