NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Countdown to the HIPAA Compliance Audits

The countdown to the HIPAA compliance audits has begun. The HHS’ Office for Civil Rights has now implemented its new breach reporting portal which means the planning of the second round of the audits can begin in earnest. The long-awaited compliance audits look set to take place in 2015 and all covered entities need to be prepared. Background to the HIPAA Compliance Audits The Department of Health and Human Services gave its Office for Civil Rights the role of enforcing the Health Insurance Portability and Accountability Act, with the Enforcement Rule giving the legislation teeth in 2006. Organizations failing to comply with HIPAA Rules have since faced financial consequences if privacy and data security policies are not introduced to the standards demanded by the legislation. Part of the OCR’s role in enforcing HIPAA regulations is to conduct compliance audits. These were conducted between 2011 and 2012 and 115 organizations were audited. The Omnibus Rule and Business Associates The introduction of the HIPAA Omnibus Rule extended the coverage of HIPAA to include Business...

Read More

Malware Responsible for Reeve-Woods Eye Center HIPAA Breach

The Reeve-Woods Eye Center – an eye treatment clinic consisting of two centers in Chico, CA, and Paradise, CA – discovered on Wednesday, September 17, 2014, that malware had been installed on two of its computers. The malware was discovered by an IT consultant used by the clinic who established that the malware was taking screenshots of the computers; essentially making a digital photocopy of the data being viewed on the screen. As patient files were accessed, a snapshot was taken. This means that a wide range of data could potentially have been obtained by criminals responsible for the malicious software. The persons affected are those who have visited the center for treatment or otherwise have had their files accessed on either of the two computers on which the malware had been installed. The data potentially exposed includes names, addresses, contact telephone numbers, Social Security numbers, dates of birth, dates of service, medical insurance details, diagnosis and treatment codes, medical histories, Medi-Cal IDs and Medicare ID numbers, as well as any other data stored...

Read More
HIPAA Breach Report: September 2014
Dec19

HIPAA Breach Report: September 2014

September 2014 HIPAA Breach Summary: The HIPAA Breach Notification Rule requires covered entities to report all data breaches involving HIPAA-covered data to the Department of Health and Human Services’ Office for Civil Rights. Breach reports must be submitted via its website portal, and CEs have 60 days from the discovery of the breach in order to do this. This report contains a summary of the breaches reported to the OCR during the month of September, 2014. Major HIPAA Breaches in September 2014 Large scale data breaches continue to plague the healthcare industry. Last month saw well over 4 million records exposed in hacking incidents, laptop thefts, improper access, disclosure and disposal or records. This month, while there were fewer incidents reported, most of which involved a few thousand records, Xerox State Healthcare, LLC (TX) reported a massive data breach in which approximately 2 million records were exposed. The incident was atypical for a HIPAA breach. Rather than records being exposed by hackers or the theft of computer equipment, this breach was caused following the...

Read More

Watch out for Wearables if you Want to Avoid a HIPAA Violation

Wearable devices are rising in popularity and now Google Glass has been made available to all in the USA and UK, Apple is launching a Smartwatch and other big influential brands are heavily investing in wearables, the next few years could see the devices become the norm and used throughout the healthcare industry. Currently more than 25% of adults in the United States own a fitness tracker or use a Smartphone fitness tracking application and a considerable amount of personal health data is being now recorded. A recent survey conducted by Juniper Research has predicted that the wearables market will grow ten-fold over the next 4-5 years and over 180 million devices will have been sold by 2018. Google Glass is stealing the headlines; however Apps and fitness bands are the most popular method of tracking health and wellness at the present time. The data recorded could revolutionize healthcare allowing preventative steps to be taken to help patients avoid illness and injury. Smart glasses such as Google Glass may not prove so popular for consumers, but the benefits to business are...

Read More
Sony Pictures Confirms Breach Potentially Exposed HIPAA Data
Dec16

Sony Pictures Confirms Breach Potentially Exposed HIPAA Data

Sony Pictures has made an announcement confirming the protected health information of some employees could have been exposed in this month’s security breach. Employees were sent a breach notification letter earlier this week containing details of the data the company believes was exposed. While the written notification letters have only just been mailed, an E-mail was sent to all affected employees earlier this month alerting them to the security breach and stating that computer records had been compromised. In that E-mail Sony Pictures suggested that all affected persons sign up for credit monitoring services with AllClearID; the company being used by Sony Pictures to help mitigate any damage caused. The notification letter reiterated the need to sign up for credit monitoring services and provided additional details about the breach, including more information on the scale of the data exposure. Earlier this month some computers at Sony Pictures were hacked in what appears to be a targeted attempt to steal company and employee data. Some of the data has already been posted on...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist