NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Rady Children’s Hospital Reports 14,000-Record HIPAA Breach
Jun18

Rady Children’s Hospital Reports 14,000-Record HIPAA Breach

Despite major efforts to secure its healthcare data from hackers and external threats, Rady Children’s Hospital has suffered a 14,121-record HIPAA breach after a member of staff made a simple error which resulted in six job applicants being provided with real data from its patients. As part of an internal evaluation, job applicants were provided with data that had not been de-identified, which is a breach of the HIPAA Privacy Rule. The data included the patients’ names, dates of birth, medical records, insurance claim information and primary diagnoses, although no financial information or Social Security numbers were divulged and neither were patient addresses. The names of parents or legal guardians were not present in the data set. The breach affects patients who had visited the hospital for treatment between July 1, 2012 and June 30, 2013. The data – in the form of a spreadsheet – was sent to the applicants via email; an insecure medium for transmitting PHI. The spreadsheet was emailed to four potential members of staff who had applied for data management positions...

Read More
Community Health Center Investigated for 130K-Patient HIPAA Breach
Jun16

Community Health Center Investigated for 130K-Patient HIPAA Breach

A former IT Director of Community Health Center, Connecticut has alleged that the healthcare provider failed to address a number of security vulnerabilities and believes his employment was terminated as a result of highlighting those problems to the upper management. Furthermore, when he was sent his personal belongings the package he received is alleged to have contained a computer hard drive on which there were approximately 130,000 medical records of current and former patients of the Middletown clinic. The hard drive has been provided to the state and the Attorney General’s Office is conducting an investigation into the matter. Community Health Center operates 13 clinics in the Middletown area including medical and dental centers, behavioral health clinics and specialized care services for HIV/AIDS patients. Ali Eslami was employed by CHC as its IT Director and had held the position for 14 years. He claims to have spoken to the top management about the poor state of the IT security and provided information on a potential hacking incident; one that could have exposed the credit...

Read More
Staff Error Exposes 33K HIPAA Records at St. Joseph Health
Jun13

Staff Error Exposes 33K HIPAA Records at St. Joseph Health

Even with the best defenses in place, HIPAA violations can occur, as the Santa Rosa Memorial Hospital in Northern California recently discovered. The hospital, operated by the St. Joseph Health system, recently reported that an error made by a member of staff at the hospital resulted in the data of 33,702 patients being obtained by a thief. The theft occurred during a burglary at the hospital’s Redwood Regional Medical Group offices. The facilities were broken into and the thief – or thieves – managed to find a thumb drive on which the unencrypted records of almost 34,000 patients were being temporarily stored. The unencrypted thumb drive had been put in an unlocked staff locker overnight. In the morning, when the break in was discovered, the member of staff concerned realized that the thumb drive was missing. The theft was reported to law enforcement officers, although the perpetrators have not been identified and the thumb drive has not been recovered, although the investigation is continuing. The thumb drive was being used to temporarily store backed up data from the radiology...

Read More
Salina Family Healthcare Center Reports HIPAA Email Breach
Jun05

Salina Family Healthcare Center Reports HIPAA Email Breach

The Salina Health Education Foundation, doing business as the Salina Family Healthcare Center, has caused a breach of 9,640 patient records after a member of staff submitted a database to the National Commission for Quality Assurance as part of a care coordination research study. The database was sent via email, and since the medium is insecure and the data was not encrypted, this potentially could lead to PHI falling into the hands of individuals unauthorized to view the information. According to a statement released by the medical center in response to the breach, the incident occurred on April 8, 2014. The data that was exposed contained sensitive information which could potentially be used to commit fraud, although no Social Security numbers or financial information was present in the database. Information included patient names and dates of birth, chart numbers and medical codes, which should have been removed prior to the data being sent. The lack of data de-identification was immediately spotted by NCQA staff, which alerted the medical center and immediately deleted the...

Read More
HIPAA Breach Report: March 2014
Jun05

HIPAA Breach Report: March 2014

March 2014 HIPAA Breach Summary: The HIPAA Breach Notification Rule requires covered entities to report all data breaches involving HIPAA-covered data to the Department of Health and Human Services’ Office for Civil Rights. Breach reports must be submitted via its website portal, and CEs have 60 days from the discovery of the breach in order to do this. This report contains a summary of the breaches which have been reported to the OCR during the month of March, 2014. Major HIPAA Breaches in March 2014 The number of individuals affected by data breaches in March 2014 was substantially lower, with 68% fewer victims compared to last month, although there were 7 more breaches reported in March. Phoenix-based not-for-profit health system, Banner Health (AZ), reported the largest HIPAA breach after 55,207 individuals had their Social Security numbers or Medicare numbers printed on magazine labels in a marketing error when sending its quarterly magazine to patients. HealthPartners, Inc. (MN) reported a 27,839-record accidental disclosure data breach, in addition to three data breaches...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist