25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Fort Worth HIPAA Breach Exposes 277K Patient Records

A business associate of the Texas Health Harris Methodist Fort Worth hospital has caused one of the biggest HIPAA breaches to date and the largest exposure of patient PHI to occur this year. This is the third major data security breach to affect Texas Health hospitals. In accordance with HIPAA Breach Notification Rules, the hospital is now in the process of notifying all 277,000 of its patients to inform them of the breach. Victims of data breaches must be allowed the opportunity to take the necessary precautions to prevent losses or damage being suffered as a result of PHI disclosed. The data exposed includes medical health information and personal identifiers such as patient names, dates of birth, telephone numbers, home addresses, medical record IDs, clinical information and health insurance details. Some Social Security numbers were also present in the data. The transfer of Electronic PHI from HIPAA-covered institutions to their business associates is a security risk which should be identified as part of the Risk Analysis which must be undertaken to comply with HIPAA...

Read More

Cedars-Sinai Hospital Fires Six Over Inappropriate Patient PHI Access

Cedars-Sinai Hospital in Los Angeles was chosen by reality TV star Kim Kardashian and Rapper Kayne West as the place to have their daughter delivered. Their baby was born on June 15th, but three days later some members of staff started accessing the medical records of one of the patient from the hospital. The hospital announced that the records were accessed over a period of one week. Six staff gained access to medical records which they were not authorized to view, with one individual accessing 14 patient records and the other five accessing the record of a single patient. The hospital did not confirm the names of the patients affected by this security breach and according to the L.A Times, neither Kardashian nor West was available for comment on the matter. The hospital did confirm that all patients affected by the breach had been contacted and notified of the unauthorized access and the hospital did not believe that any crimes had been committed. Cedars-Sinai operates strict policies to protect confidential medical records and the persons who accessed PHI of patients did not...

Read More
Wellpoint Agrees to $1.7 Million Settlement for HIPAA Violations
Jul10

Wellpoint Agrees to $1.7 Million Settlement for HIPAA Violations

Wellpoint is one of the largest providers of Affiliated Health Plans, with almost 36 million policy holders across the United States. Between October 23, 2009 and March 7, 2010 part of its database of policy holders was accessible to unauthorized individuals. The security breach was brought to the attention of Wellpoint in March 2010 when a lawsuit was filed in California by an applicant who discovered it was possible to access the electronic Protected Health Information of Wellpoint policy holders. Wellpoint took rapid action to restrict access and began an investigation into the data security breach. It determined that the personal health data was accessible to unauthorized third parties although it was limited to 31,700 individuals. Names, addresses and contact details were accessible along with health information and social security numbers. HIPAA demands that breach notifications are sent to all those affected by a security breach to enable them to take action to mitigate any damage caused. The company complied with these regulations and sent notifications informing all those...

Read More

Cloud Service Providers Must Become HIPAA Compliant

On 26th March, 2013 the Omnibus Final Rule of the Health Insurance Portability and Accountability Act came into effect, after a long period of amendments and adjustments. The main purpose of the new legislation is to adjust the HIPAA Privacy and Security Rules and breach notification rules, with this major amendment often referred to as “The HIPAA Mega Rule”. The new rules apply to all HIPAA covered entities and the Department of Health and Human Services will be enforcing the rules; its Office for Civil Rights is due to commence a serious of random audits to check for compliance later this year. The new rules apply not only to healthcare organizations but also their business associates. Under the final rule the definition of business associate has also been changed, and now includes any provider of a service that has contact with electronic protected health information (ePHI). Specifically this means any entity that “creates, receives, maintains, or transmits protected health information (PHI) on behalf of a covered entity”, and they must now agree to abide by the HIPAA Omnibus...

Read More

Programming Error Responsible for Major Indiana HIPAA Breach

A business associate of an Indiana healthcare organization has caused one of the largest HIPAA data breaches to data. The security breach has exposed the ePHI of 187,533 patients of the Indiana Family and Social Services Administration. Not only is this one of the largest data breaches to occur this year, it involves the disclosure of incredibly detailed personal, medical and financial information. Following an investigation into the incident, the Indiana Family and Social Services Administration was able to determine that 3,926 patient Social Security numbers had been disclosed and the patients affected have been notified separately. In addition to names, addresses and other contact information, the records included demographic data, the benefits that clients received, total monthly benefit totals, monthly income and expenses, employment details, bank balances and details of other assets owned. Medical conditions were listed along with health insurance providers and some data relating to members of the patient’s household. Programming Error Responsible for PHI Disclosure The data...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist