NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Sheds Light on Phase 2 HIPAA Audits

The Office for Civil Rights (OCR) has announced that it is to recommence its HIPAA compliance audit program this fall. Phase 2 will consist of 350 compliance audits which will be conducted on healthcare providers, healthcare clearing houses and health plans, along with 50 further audits which, in accordance with the HIPAA Omnibus Rule, will be conducted on business associates. The OCR conducted a round of pilot audits in 2011/2012 which looked closely at a wide range of areas of compliance in order to allow it to ascertain the level of compliance across different sectors of the healthcare industry. The pilot round involved 115 covered entities, which were subjected to a full compliance audit including a site inspection. The audits uncovered numerous areas in which healthcare organizations were violating HIPAA regulations. The majority of organizations that were audited were to have found to have violated HIPAA with only 11% of covered entities found to be fully compliant. 80% of healthcare providers found to have violated HIPAA did so by failing to conduct a full risk analysis,...

Read More

New HHS Tool Released to Assist with HIPAA Risk Assessments

Conducting a thorough risk assessment is a requirement under the HIPAA Security Rule; however it can be a complex process requiring all potential security risks to be identified. The process can be a daunting task for any organization, especially when the risks of non-compliance are so severe. Under the Security Rule, HIPAA-covered entities are required to conduct a risk assessment to determine any potential vulnerabilities and take the appropriate actions to reduce and, as far as is possible, eliminate data security risks. Incorporating the necessary safeguards, software systems and data encryption services is essential under HIPAA regulations in order to keep electronic health records private and confidential. The HHS understands the issues faced by healthcare organizations and has developed a tool to help organizations conduct thorough risk analyses and ensure they are fully HIPAA-compliant. Any organization about to conduct a risk analyses under HIPAA should use the new tool provided by the HHS on its website. The tool takes the user through a series of questions which need to...

Read More

Nurses Find a Replacement for Hospital Pagers

A survey has recently been conducted by Spyglass Consulting Group that indicates nurses are violating HIPAA regulations by using personal Smartphones in hospitals. The survey indicated that 67% of nurses were taking their iPhones and android phones to work and using them, even though 89% of hospitals do not permit the devices to be used at work. The Spyglass survey indicates that nurses are not being given a pager alternative, as only 4% of hospitals currently reported having a Smartphone system installed for nurses. Furthermore, out of the 53% of hospitals that did have a Bring Your Own Device (BYOD) scheme in place, only 11% included nurses in that scheme. The situation does appear to be improving as more than half of the organizations taking part in the survey claimed to be about to extend coverage to nurses. The use of mobile phones for hospital communications is forbidden, as the devices are insecure and lack the necessary controls to keep confidential data secure. The sending of any PHI via text message is an immediate HIPAA violation, unless the text is sent via a secure...

Read More

Los Angeles County Doubles Estimate of HIPAA Breach Victims

The victim count from the Sutherland Healthcare data breach has more than doubled from the initial estimate of 168,500 as announced last month. This week the Los Angeles County Department of Health Services (DHS) has announced that an additional 170,200 patients are believed to have been affected by the HIPAA breach. Thieves gained access to one of the offices of Sutherland Healthcare in Torrance on February 5th and stole 8 computers, which has now been confirmed to have included the protected health information and other personal data of 338,700 individuals. Sutherland Healthcare has used a public relations firm to release a description of the suspect they believe was responsible for the theft and a reward of $25,000 is being offered for information that leads to the apprehension of perpetrators and retrieval of the stolen equipment and data. The suspect has been described as a black male of indeterminate age and height and was heavy set. At the time of the theft he was wearing gloves and a dark hat with white insignias, a dark sweatshirt, blue jeans and bright blue athletic...

Read More
HIPAA Breach Report: January 2014
Apr03

HIPAA Breach Report: January 2014

January 2014 HIPAA Breach Summary: The HIPAA Breach Notification Rule demands that Healthcare providers, health plans healthcare clearing houses and BAs report data breaches involving more than 500 individuals to the Office for Civil Rights of the HHS within sixty days of the discovery of the breach. This report contains a summary of the breaches which have been reported to the OCR during the month of .January, 2014 Major HIPAA Breaches in January 2014 After two relatively quiet months, January saw a high volume of data breaches, including two massive data breaches that exposed hundreds of thousands of patient records. The theft of a laptop computer from Horizon Healthcare Services, Inc. (As Horizon Blue Cross Blue Shield of New Jersey) resulted in 839,711 potentially being exposed, while a network server incident at Triple-C, Inc. (PR) was reported to the OCR as exposing 398,000 and 8,000 patient-records. The large breach at the North Carolina Department of Health and Human Services (NC) appears small by comparison, although the unauthorized disclosure affected 48,752 individuals....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist