25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HIPAA Omnibus Rule Places Further Restrictions on Marketing

The introduction of the Omnibus Final Rule, also known as the HIPAA Mega Rule due to the extent of that it alters the current legislation, tightens up many loose ends that existed from the HIPAA Privacy Rule with regards to marketing. The use of Protected Health Information (PHI) for marketing purposes was restricted by the Privacy Rule, which required patients to provide written consent allowing the use of their health information for marketing purposes. Further restrictions were placed on the use of PHI data with the introduction of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009. This last piece of legislative change prevented further marketing practices that could previously be performed without prior consent being obtained. The introduction of the Omnibus Final Rule in January this year completed the changes concerning marketing, and all organizations are now required to abide by the new rules, with the final date for full adoption being October 23, 2013; the date the Final Rule will be enforced. Marketing has long been a target for the...

Read More
Photocopier Error Costs $1.2 Million in HIPAA Breach Fines
Apr25

Photocopier Error Costs $1.2 Million in HIPAA Breach Fines

Protected Health Information can easily be disclosed to unauthorized personnel if a document is left in a photocopier after copies have been made; however digital photocopiers have potential to expose the personal health data of hundreds of thousands of individuals. When copies of files are made on a digital photocopier the files remain on the machine until they are deleted. Many organizations and individuals forget or do not realize that this is the case and do not delete the data before scrapping the machine. Potentially, every file and document copied on the machine will be available to anyone who accesses the hard drive on the machine. All digital photocopiers sold since 2002 have included hard drive. Under HIPAA regulations, it is mandatory for HIPAA covered organizations to erase all ePHI stored on hard drives before they are scrapped, decommissioned or returned to a leasing company. HIPAA-compliant healthcare organizations must ensure that their PCs, laptops and mobile devices have their data securely erased before they are decommissioned, in addition to photocopiers and all...

Read More

Next Gen Secure Enterprise Messaging App Great News for HIPAA Covered Entities

A next generation secure enterprise messaging app has recently been released, offering HIPAA-covered entities a fast, convenient and secure method of communicating. The real time messaging app has all of the required security features to ensure HIPAA-compliant text messages can be sent quickly, easily, and 100% securely. Communication Problems in the Healthcare Industry   Hackers, malicious insiders, and thieves are trying to obtain healthcare data from HIPAA-Covered entities (CEs); and many are succeeding. The use of Smartphones and other mobile devices has caused concern, as the units are difficult to effectively secure. HIPAA places a number of demands on healthcare providers and other CEs to ensure Protected Health Information (PHI) is kept secure and confidential. There are mandatory data security requirements detailed in the HIPAA Security Rule, and many addressable areas, which ensure that healthcare providers achieve an acceptable standard of data security. Under HIPAA Rules, PHI cannot be sent via insecure networks unless it has been encrypted or deidentified. SMS,...

Read More

Meaningful Use Stage 1 Requirements

The Meaningful Use Stage 1 Requirements are that providers must adopt certified Electronic Health Records (EHRs) and use the EHRs to collect patient data in four categories – core objectives, menu set, clinical quality measures, and additional quality care measures. Not all categories of data collection need to be fully completed in order to qualify for Meaningful Use incentive payments. The Meaningful Use Program The Health Information Technology for Economic and Clinical Health (HITECH) Act was signed into law on February 17, 2009. One of the main aims of the HITECH Act is to encourage healthcare providers to switch from paper records to EHRs. Starting in 2011, two years after the HITECH Act was signed into law, incentive payments could be claimed by eligible professionals under the Meaningful Use program. Those payments could be claimed until 2015, after which, eligible professional taking part in the program that failed to demonstrate meaningful use of EHRs could be fined. While early adoption of EHRs was encouraged, it was possible to adopt EHRs as late as 2014 and still...

Read More
HIPAA Violations Result in Jail Time for New York Identity Thief
Apr11

HIPAA Violations Result in Jail Time for New York Identity Thief

A New York identity thief who stole the medical data of approximately 1000 patients and committed $10.7 million in Medicare fraud has been convicted of HIPAA violations by a New York federal court and sentenced to serve 12 years in a federal penitentiary. Over the course of a four year period, Helene Michel, the owner of Hicksville NY., Medical Solutions Management Inc. (MSM), impersonated a doctor – acting under the name Dr. Elene Allonce – as well as nurses, wound care specialists and other healthcare professionals to gain access to Social Security numbers and medical information of patients in order to make fraudulent medical claims to support her extravagant lifestyle. Michel was able to gain access to nursing facilities in Nassau, Suffolk, Queens, Kings and Dutchess Counties between April 2003 and March 2007. She was able to obtain the information necessary to make bogus Medicare claims for services provided by her company. The proceeds from her crimes were used to purchase a $2.2 million Old Brookville home, set up a personal pension plan as well as an investment brokerage...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist