NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Security Lapses Could See Majority of Health Practices Fined for HIPAA Non-Compliance

Healthcare organizations face considerable data security risks, yet evidence suggests that while the importance of compliance may be understood, too little is being done to secure ePHI data. A recent survey has highlighted than many healthcare organizations are not paying attention to the warnings being issued by the government. Physicians Practice conducted its annual Technology Survey and discovered that mobile devices are a particular area of concern, with only 31% of the respondents claiming to have implemented the policies and procedures covering the use of mobile devices in the workplace as demanded by HIPAA regulations. Mobile devices are a major security risk due to the ease of theft or loss, yet many healthcare organizations have not taken steps to ensure mobiles are HIPAA compliant. Mobile devices often contain unencrypted patient data and personal mobiles are particularly high risk if used to access, transfer or view patient data. The survey revealed that almost 70% of healthcare organizations have so far failed to implement strategies to deal with the security threat...

Read More
HIPAA Breach Report: April 2014
Jul03

HIPAA Breach Report: April 2014

April 2014 HIPAA Breach Summary: The Breach Notification Rule of the Health Insurance Portability and Accountability Act requires all covered entities, and their Business Associates via their covered entity, to report all data breaches affecting more than 500 individuals to the Department of Health and Human Services’ Office for Civil Rights (OCR). These breaches must be reported with 60 days of the discovery of the breach. This report contains a summary of the breaches which have been reported to the OCR during the month of April, 2014. Major HIPAA Breaches in April 2014 April saw the highest number of monthly HIPAA breaches reported for the year – and the most breaches during the past 6 months – with numerous incidents reported including a major data breach at the Indian Health Service (MD) after a laptop containing unencrypted PHI resulted in the potential disclosure of 214,000 individual records. The second largest breach affected Business Associate, Amerigroup Texas, Inc. (VA), which reported the theft of paper records of 75,026 individuals while the health plan, American...

Read More

OCR Tasks Jocelyn Samuels with HIPAA Enforcement

A new director has been appointed to take over the helm of the Office for Civil Rights of the Department of Health and Human Services following the departure of its director, Leon Rodriguez. An email was recently sent to all staff at the agency confirming that the position has been accepted by Jocelyn Samuels. According to an OCR spokesperson, “Leon is in the process of planning his departure, and we look forward to Jocelyn joining us here at OCR in the near future.” A date has not yet been announced when Samuels will take over at the OCR. Rodriguez has served as Director since September 2011 and has played an important role in the development of the OCR audit program. He was also committed to increasing the scope of the audits and policing HIPAA more rigorously. He was confirmed as having been accepted for the position of U.S. Citizenship and Immigration Services at the Department of Homeland Security on June 24, after the senate agreed to his appointment. Jocelyn Samuels is due to vacate her position as acting assistant attorney general in the civil rights department, where...

Read More
PriceWaterhouseCoopers Report on HIPAA Compliance
Jun30

PriceWaterhouseCoopers Report on HIPAA Compliance

The state of HIPAA compliance in the US has been assessed by PriceWaterhouseCoopers, following a survey conducted this summer. A report on the survey findings has now been issued with the results indicating that HIPAA compliance is often not being given the importance it requires. Healthcare Chief Compliance Officers are often part time positions while 43% of respondents claimed they “are responsible for other functions and those other duties and responsibilities generally took precedence over compliance.” There was also a feeling that more could be done to improve compliance and to raise its perception and profile within organizations. Compliance clearly is not forefront in the minds of all senior leaders and board members when decisions are made relating to day to day operations or even for strategic planning. Since compliance is not a profit making activity, it is essential for CCOs to convince board members of the value to be had from introducing and running a compliance program. One problem raised was the fact that budgetary constraints are hampering compliance efforts. Ten...

Read More

OCR Submits HIPAA PHI Breach Reports To Congress

In accordance with HITECH, the Health and Human Services Office for Civil Rights has submitted its annual reports to congress detailing the Breaches of Unsecured Protected Health Information it was notified of during 2011/2012. The report shows that 98% of victims of PHI data breaches involving over 500 individuals have come from 1% of recorded breaches. The large scale data breaches caused by these security lapses and targeted attacks are affecting millions of Americans. The total count of victims has now risen to 32 million and the total number of recorded HIPAA data breaches is about to reach the 100 mark. The report highlighted the state of HIPAA compliance and clearly showed that healthcare organizations are failing to take the required actions to protect patient data and keep PHI private and confidential. Over the course of the past 12 months there have been record fines issued for security breaches and violations of HIPAA procedures and HHS Chief Regional Civil Rights Counsel Jerome Meites has predicted “a huge spike in the fines from violations” over the coming months. In...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist