25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

AHMC Healthcare Omnibus Rule Violation Causes 729K HIPAA Breach
Oct23

AHMC Healthcare Omnibus Rule Violation Causes 729K HIPAA Breach

The HIPAA Omnibus Rule was introduced to improve standards of data security in the healthcare industry and under the new Rule organizations are required to implement a number of additional measures to safeguard the health data of patients. While many organizations have updated procedures and policies to ensure compliance with the new Rule, AHMC Healthcare failed to take action in time to prevent a security breach. Had it have done so, the records of 729,000 patients would not have been exposed. HIPAA regulations require all covered entities to implement the appropriate safeguards to ensure the Protected Health Information of patients is not placed in jeopardy. A risk analysis must be conducted and all potential security risks addressed and eliminated or reduced to a minimal level. Laptop computers carry a particularly high risk of accidental; data exposure; they can store a considerable amount of data; they are portable and are used outside hospitals and clinics. Laptops are frequently stolen as they have a reasonably high monetary value, although thieves are now targeting doctors...

Read More

10 HIPAA Myths Busted by ONC

The Office of the National Coordinator for Health Information Technology (ONC) has many roles, although one of the most important is advising healthcare organizations on how data privacy and security legislation and the best practices that should be adopted to comply with regulations and keep patient and other sensitive data secure. At the HIMSS Privacy and Security Forum last month, Chief Privacy Officer of the ONC, Joy Pritts, spoke about the efforts the ONC have made to assist healthcare organizations achieve compliance and how they have adapted to make it easier to comply. Pritts said, “We were drafting materials that were meant for IT professionals and learned within a year that the content was too technical. We realized that we had to draft materials in plain language that could be distributed in small offices.” The feedback the ONC has gained over recent months suggests that many smaller healthcare organizations are struggling with HIPAA compliance. The problem has been compounded by the number of myths and incorrect assumptions that are circulating within the healthcare...

Read More

Bizarre HIPAA Breach Results in Doctor Having Medical License Suspended

A psychologist in Washington State has recently had his medical license suspended after his personal laptop, containing unencrypted data on his patients, was stolen. Laptop thefts often result in healthcare data being exposed, although what makes this case peculiar is the laptop was stolen by a prostitute the doctor had just visited. Having failed to take sufficient cash, the doctor had to visit an ATM and returned to find no laptop or prostitute. The incident occurred on February 4th, but the theft of the laptop was not reported to the police until February 14th. The Department of Health and Human Services was notified of the incident three days after the laptop had been stolen, according to a Statement of Charges by the Washington State Department of Health. A total of 652 patients were reported to have potentially been affected by the breach. However the psychologist did not was not truthful with the police and failed to inform them of the facts and a false report was also made to the HHS. Eventually the police were informed that a prostitute had stolen the laptop and they were...

Read More

HIPAA Omnibus Final Rule Improves Patient Rights

Healthcare organizations and their business associates are facing fines for non-compliance following the introduction of new regulations which protect the privacy of patients and the security of their data. The Omnibus Final Rule came into effect this year and covered organizations were required to update procedures and policies and comply with the new regulations by September 23, 2013. The new changes have been criticized by some members of the healthcare community; however the changes expand patient rights and allow them to have much greater autonomy and make decisions about how and what is communicated to them and the channels that can be used. If a patient is comfortable receiving information via E-mail, they are allowed to continue to use that medium to communicate with their healthcare providers or care team and information can be sent by healthcare professions to patients provided that they have been made aware of the risks. If it is explained that the medium is not totally secure and there is a chance that their data could be viewed by other people and they accept the...

Read More

Google to Sign BAA to Make its Apps HIPAA Compliant

Many healthcare organizations were unwilling to use Google Apps because under the new HIPAA regulations, Google would be required to sign a Business Associate agreement; something the internet giant has so far failed to do. Google has now agreed to remove this barrier and sign a BAA for the very first time, ensuring its Apps are fully HIPAA-compliant. This is expected to see more healthcare organizations take advantage of the services it offers. The Health Insurance Portability and Accountability Act of 1996 requires healthcare organizations to restrict access to electronic health records and identifiable information. Healthcare organizations are accountable for any data breaches, accidental or deliberate, and the disclosure of individually identifiable health information (IIHI) and protected health information (PHI) to any unauthorized individual. Protected information includes the names and contact details of patients, their health information, financial details relating to services received and medical insurance information. Under HIPAA regulations, if any of this data needs to...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist