NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Concern that Drug Company Use of Patient Data Circumvents HIPAA

Pharmaceutical companies are using patient PHI to market their products, even though they are not permitted to have access to this information under HIPAA regulations, according to a recent report on Bloomsberg News. HIPAA covered entities are not permitted to disclose patient information to third parties for the purposes of marketing, yet pharmaceutical companies are obtaining the data from a different source. Drug companies are now seeking assistance from online data agencies that can provide them with the data they require to directly market products to the persons most likely to use their drugs. Marketing data is invaluable to drug companies as it enables them to market their products more effectively. The market for a particular treatment may be very small in terms of penetration so using traditional advertising methods is unlikely to produce the required number of sales. However, if a drug company obtained a list of patients who had been diagnosed with a condition that their drug treats, the volume of sales from its direct marketing efforts would increase substantially....

Read More
Amedisys Hospice to be Investigated for Potential HIPAA Violation
Dec14

Amedisys Hospice to be Investigated for Potential HIPAA Violation

The discovery of documents containing the Protected Health Information of 17 patients of Amedisys Hospice, Tennessee has triggered an investigation over the potential HIPAA violation. Earlier this week, Sandra Rambo was walking with her daughter when she came across paperwork on the side of the highway. The pair noticed that the records contained information on patients, one of whom was the deceased husband of one of her neighbors. The information contained in the paper documents included private patient details such as identification numbers, medical conditions, information about previous hospice visits as well as personal details of patients who had visited the hospice according to a report on local radio station, WHHL. Rachel Seeger, Spokesperson for the US Department of Health and Human Services explained that in cases such as this, the DHHS works with the healthcare provider to resolve HIPAA violations and enters into a resolution agreement to ensure that the entity in question implements an action plan. That action plan must correct any privacy and security issues affecting...

Read More

Laptop Theft Causes HIPAA Breach Exposing Patient Data in Oregon

A new HIPAA breach has been announced affecting patients of an Oregon healthcare facility although the number of patients to be affected is currently unknown. The incident occurred in November when an employee of the Corvallis Clinic left a laptop computer in a vehicle while attending a work conference. The laptop was subsequently stolen from the car. The laptop contained unencrypted data of patients who had visited the clinic during the past two years, although the information was in a spreadsheet and the data it contained was limited and included patient names, dates of birth, name of the healthcare provider and the reason for the visit. The spreadsheet is not believed to have contained any Social Security numbers, driver’s license numbers or credit card details. There is no indication that the thieves have been able to access the data contained in the spreadsheet. The Clinic advised patients that the laptop was protected with a “highly secure” alpha numeric pass code and that it is improbable that the thieves would have been able to access the data. A notice has been posted on...

Read More
Highlands-Cashiers Hospital Reassures 25K Patients After Possible HIPAA Breach
Dec12

Highlands-Cashiers Hospital Reassures 25K Patients After Possible HIPAA Breach

Highlands-Cashiers Hospital of Macon County, North Carolina, has informed 25,000 patients of a security vulnerability that left the PHI of some of its patients unprotected for a period of four months, between May and September, 2014. The healthcare provider employed a business associate, TruBridge, to handle some of its healthcare information however the company made a configuration error which potentially exposed the health records of approximately 25,000 individuals. The vulnerability was discovered during routine security screening procedures on Sept 29. HCH identified information such as patient names, addresses, dates of birth, Social Security numbers, health insurance details, diagnoses and treatments were all potentially accessible and were not protected by the company’s firewall. Immediate action was taken and new firewalls were installed to correct the issue and the data has now been made secure and there is believed to be no further risk of exposure. The hospital hired a forensic investigation company to assess the extent of the data breach and the investigation found no...

Read More

5 Actions to Take to Secure Healthcare IT Systems and Prevent HIPAA Breaches

The publishing of data from the 2013 Survey on Medical Identity Theft by the Ponemon Institute has highlighted the prevalence of medical identity fraud and has shown the crime is becoming much more commonplace. Over the course of past 12 months the number of reported cases of medical identity fraud has risen by 20%. There are now believed to be over 1.84 million Americans now affected by medical identity fraud. The cost is colossal and is a huge drain on the economy, while the victims have had to cover over $12.3 billion in out of pocket expenses. Many of the victims have had their medical records exposed in data breaches at healthcare organizations. If data breaches result from violations of HIPAA regulations, healthcare organizations can be held accountable. The HHS Office for Civil Rights is issuing substantial fines for non-compliance and class action lawyers are keen to sign up victims of data breaches to claim damages. Even in cases where PHI has been accidentally exposed or been deliberately hacked, healthcare organizations can still face hefty fines. In extreme cases it is...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist