25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Massachusetts Healthcare Provider to pay $1.5M HIPAA Settlement to HHS
Dec17

Massachusetts Healthcare Provider to pay $1.5M HIPAA Settlement to HHS

The theft of a laptop computer from a healthcare center belonging to Massachusetts Eye and Ear Infirmary and Massachusetts Eye and Ear Associates, Inc. (MEEI) has resulted in a settlement of $1.5 million with the HHS Office for Civil Rights for HIPAA violations. The U.S. Department of Health and Human Services is enforcing Health Insurance Portability and Accountability Act compliance, and MEEI was deemed to have violated the Security Rule by failing to take adequate precautions to protect the health information of its patients and research subjects. The laptop contained unencrypted data which could be accessed by the person in possession of the laptop. The data includes patient prescription details, clinical information and other protected data that could potentially be used to commit medical and identity fraud. Under the Health Information Technology for Economic and Clinical Health Act (HITECH) Breach Notification Rule, the HHS must be notified of security breaches involving the exposure of PHI of patients. When MEEI issued the notification it triggered the OCR investigation....

Read More

Healthcare Data Breaches Exceed 500

In September 2009, following the incorporation of the requirements of the HITECH Act into HIPAA legislation, the Department of Health and Human Services started monitoring healthcare data breaches. Since that date all data breaches affecting over 500 individuals must be reported within 60 days of the breach being discovered. Over 21.2 million individuals have been affected by healthcare data breaches since records started being kept, and the tally of data braches has now exceeded the 500 milestone. The Health Insurance Portability and Accountability Act was introduced with a number of aims, one of which was to ensure Protected Health Information is safeguarded and protected from unauthorized access, disclosure, hacking, loss and theft. The legislation also covers patient privacy and restricts the information that can be disclosed without authorization. HIPAA is supposed to ensure that all covered entities implement administrative, technical and physical safeguards to protect PHI and meet a minimum national standard of data security. The problem is that covered entities are not...

Read More

Pediatricians Risking HIPAA Violations Sending SMS Messages

The pager has served doctors and medical professionals well since the 1940s and an estimated 90% of hospitals are still using the devices for communication between members of the care team. However an increasing number of medical professionals are turning to Smartphones to communicate, according to a recent survey conducted by the University of Kansas School of Medicine in Wichita. The data even suggests that phone text messaging is about to take over as the primary mode of communication in U.S hospitals. Smartphones allow doctors to communicate quickly with other members of the healthcare team, but while modern mobile devices offer convenience, the use of SMS in hospitals could result in HIPAA Privacy and Security Rule violations. Text messages are not secure, and any unencrypted PHI sent via the SMS network could potentially be read by any number of people. Uptake of Smartphones has not been quick in healthcare due to the cost of purchasing the units and making them secure. However, since the majority of medical professionals have a personal phone, Bring Your Own Device (BOYD)...

Read More

Kentucky E-mail Hack Highlights Importance of HIPAA Compliance

A healthcare provider in Kentucky has notified 2,500 patients that a hacker had gained access to an email account which contained some Protected Health Information and personal identifiers, and that their data could potentially have been viewed by that individual. The incident occurred when an employee of Cabinet for Health and Family Services responded to a phishing email he had been sent by a hacker and his response allowed the hacker to gain access to his email account. Controls were in place to identify any suspicious email activity which allowed the breach to be identified quickly. Within 30 minutes of access being gained the account was closed, severely limiting the opportunity for health information to be viewed. The breach was investigated by Cabinet for Health and Family Services which determined that the motivation for the hack was to gain access to government servers to send spam emails, and was not a targeted attack to gain access to Protected Health Information. The healthcare provider believes Protected Health Information and personally identifiable information has...

Read More

Data Loss and HIPAA Breaches Biggest Fear of Health Professionals

A new report released by CDW indicates the biggest fear of healthcare IT professionals is data loss, and in the case of healthcare, the accompanying HIPAA violation penalty. It is not only the health industry that worries about data loss. The survey suggest the same fear is shared by IT professionals in all industries. Healthcare, business, finance and higher education sectors had over 50% of respondents listing data loss as their biggest concern. For healthcare providers the data includes Protected Health Information and Social Security numbers, the consequences of loss of that data can be very severe. Malicious attacks were rated as the biggest fear by 18% of respondents, 14% said evolved forms of current threats were the biggest worry and 13% believed social engineering would be the main problem. Bots and mobile threats were rated at 9% and 8% respectively, and 6% had no idea where the main threat was coming from. Perhaps that is the most worrying statistic of all. 50% of respondents believed customer, student, employee and patient records would be the most likely data to be...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist