NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Organizations a Soft Target for Cybercriminals
Dec04

Healthcare Organizations a Soft Target for Cybercriminals

The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 at a time when the internet was still in its infancy. Over the following 18 years the volume of information stored in an electronic format has grown at an extraordinary pace, and with it, so has the threat of theft. Today, ePHI is stored on servers, in the cloud and on mobiles and laptops and according to a recent report by IDC Health Insights, the healthcare industry is seen as a soft target by cybercriminals. The report; titled “Business Strategy: Thwarting Cyber Threats and Attacks against Healthcare Organizations,” suggests that the security issues faced by the healthcare industry are a result of poor investment in IT security infrastructure over the preceeding 18 years. The financial industry is a prime target for cybercriminals, but organizations have invested heavily in security systems to protect the financial details of clients. While no organization is impregnable to attack, they are viewed by criminals as hard targets. Hospitals and healthcare clinics on the other hand are relatively easy...

Read More

HIPAA Settlement Reached for Dumpster PHI Exposure

Under Health Insurance Portability and Accountability Act (HIPAA) data privacy and security rules, Protected Health Information (PHI) must be secured at all times and when data is no longer required it must be destroyed to prevent accidental exposure. In May 2013, Midwest Women’s Healthcare Specialists disposed of a number of medical records of patients; however the files were placed in an open dumpster. While the material was destined to be destroyed, unauthorized individuals could have easily gained access to the information. The HIPAA violation would perhaps not have been identified had it not been a particularly windy day. However, the some of the paper PHI records were blown from the dumpster up the street and the medical records were dispersed over an area of several blocks. The data included in the files and notes included personal identifiable information, addresses, diagnoses, treatment details and test results. Many of the records also detailed the patient’s Social Security numbers. In total, the records of 1,532 female patients from Missouri were potentially exposed by...

Read More

Business Associates Account for 40 Percent of HIPAA Breaches

During the first quarter of 2013, 40% of all HIPAA breaches involving the exposure of PHI that affected more than 500 individuals were the result of the actions of business associates of HIPAA–covered entities. The problem appears to be growing, as over the previous four years BA’s caused 30% of all reported HIPAA security breaches. This fact has not been missed by the Department of Health and Human Services. New legislation has been introduced which makes business associates accountable for their actions – or lack of them – to maintain the security of Protected Health Information. Business associates and their subcontractors are now covered by the latest amendment to HIPAA; the Omnibus Rule. Under the new rule, the Office for Civil Rights has the power to investigate business associates for HIPAA compliance issues and BA’s are expected to be included in the upcoming HIPAA audits. If the OCR discovers HIPAA compliance issues, business associates will be held accountable regardless of whether or not there has been a data breach and fines will be issued directly by the OCR. Before...

Read More

Visionworks Reports Second Server HIPAA Breach in Less Than a Month

Visionworks has announced that it has suffered a second major security breach in less than a month, bringing the total number of patients affected over the past four weeks to 122,627 individuals. Visionworks sent breach notifications to 75,000 patients last month after a computer server was lost following a security upgrade. The missing server was believed to have been inadvertently dumped along with construction debris during the refurbishment of the Visionworks Jennifer Square, Annapolis, MD., facilities. The latest breach affects patients who had received services at its Florida store in the Mall of the Avenues, Jacksonville. The server had been upgraded; however the old server, which contained the Protected Health Information and personal details of approximately 48,000 patients, cannot be located. As with the previous server loss, the incident is being attributed to an employee who may have inadvertently dumped the server, although the breach letter did not confirm that this was definitely the case. The optical care services provider maintains the two incidents are not linked....

Read More
Xerox Reported for 2 Million Record HIPAA Breach by Texas HHSC
Nov26

Xerox Reported for 2 Million Record HIPAA Breach by Texas HHSC

The dispute between Xerox and the Texas Health and Human Services Commission (THHSC) continues with the latter now having reported a 2 million-record HIPAA breach to the Department of Health and Human Services’ Office for Civil Rights for allegedly not returning PHI following the termination of the service provider’s contract. Xerox was a former Business Associate of THHSC and was contracted to provide administrative services for the Texas Medicaid program. However, THHSC took the decision in May to terminate the contract following allegations that Xerox had inappropriately given authorization for orthodontic braces to be given to thousands of Medicaid patients when the devices were not medically necessary. Three months later, once THHSC had replaced Xerox with a new Business Associate, it filed a lawsuit against Xerox claiming that the company had failed to return computer equipment and paper files after its contract was terminated. Stored on those computers and in those files was a large volume of confidential information including personal identifiers, Medicaid numbers and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist