25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Texas Women Pleads Guilty to HIPAA Violations

U.S. Attorney John M. Bales has announced that Joneshia Cranford, a 33-year-old resident of Lufkin in the Eastern District of Texas, has pleaded guilty to violations of the Health Insurance Portability and Accountability Act of 1996. Cranford was accused of inappropriately accessing the Protected Health Information of patients at the healthcare facility where she worked and disclosing that information for financial reward, with the woman pleading guilty to the wrongful disclosure of individually identifiable health information. The two individuals to whom the information was disclosed – Shavator Albro, 35, and Francis “Frank” Ibiok, 28 from Houston – have both pleaded guilty to healthcare and identity fraud charges. The willful disclosure of individually identifiable health information carries a maximum jail sentence of 10 years, while the use of that information to commit Medicare, Medicaid or Insurance fraud carries a maximum penalty of 15 years imprisonment. A sentencing date for the offenses has yet to be set. HIPAA is policed by the Office of Civil Rights of...

Read More

HIPAA Audit Protocol Published by Office for Civil Rights

The introduction of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009 updated HIPAA, and as such it required the Department of Health & Human Services’ Office for Civil Rights (OCR) to conduct a program of compliance audits to ensure the new rules had been applied. Following a series of 20 preliminary pilot audits the OCR has devised an HIPAA compliance audit protocol which will be used to assess compliance at a total of 155 HIPAA-covered entities, with the audits concluding in December 2012. Since any entity can be audited – not just large healthcare providers – it is important that all organizations check their procedures and revised them as appropriate to take the new Security Rule requirements into account. The OCR has now published the long awaited details of the audit program on its website detailing the specific aspects of HIPAA, the Privacy Rule, Security Rule and Breach Notification Rules that will be assessed. OCR Pilot Audit Protocol 2012 There are three main aspects of the legislation which are being specifically tested...

Read More
Alaska DHSS Reaches $1.7M Settlement with OCR for HIPAA Security Rule Violations
Jun26

Alaska DHSS Reaches $1.7M Settlement with OCR for HIPAA Security Rule Violations

The theft of a portable hard drive from an employee of the Alaska Department of Health and Social Services (DHSS) potentially exposed the ePHI of an estimated 2,000 individuals. Following an investigation by the HHS Office for Civil Rights (OCR), a settlement has been reached and the DHHS must pay the HHS $1.7 million for the HIPAA Security Rule violations. The U.S. Department of Health and Human Services’ Office for Civil Rights was alerted to the breach when the Alaska DHSS reported the hard drive theft. All healthcare organizations must submit a report of data security breaches affecting more than 500 individuals to the HHS Secretary Sebelius under Health Information Technology for Economic and Clinical Health (HITECH) regulations (Smaller breaches need only to be reported annually). A media announcement must also be made to alert potential victims and Breach Notification Rules require all individuals to be contacted and advised of the security breach to allow them to take action to protect their identities and finances. The investigation unearthed a number of non-compliance...

Read More

Office for Civil Rights Releases HIPAA Audit Results

The introduction of the Security Rule has warranted a round of compliance audits by the Office for Civil Rights of the Department of Health and Human Services. The results of its first round of preliminary HIPAA compliance audits – conducted in March this year – have now been announced. The OCR conducted 20 audits to assess organizations for compliance with new HIPAA regulations, in particular those relating to the Privacy and Security Rules. Only a small number of audits were conducted but the results have given the OCR important insights into the general state of compliance in the healthcare industry. Some of the key findings were announced at the recent OCR and National Institute of Standards and Technology conference. OCR Compliance Audit Findings (March 2012) The results of the audits indicate that while large organizations have by and large made the appropriate updates to their data privacy and security policies, there is a discrepancy between the government’s high expectations of data privacy and security compliance and what the OCR has observed in practice. Healthcare...

Read More
Attorney General’s Office Confirms HIPAA Settlement Reached with South Shore Hospital
May27

Attorney General’s Office Confirms HIPAA Settlement Reached with South Shore Hospital

An announcement has been made by the Office of the Massachusetts Attorney General that a settlement has now been reached with South Shore Hospital. The healthcare provider will be required to pay a fine of $750,000 for violations of the state Consumer Protection Act (Massachusetts General Law Chapter 93A) and also violating the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The settlement was reached for the accidental exposure of Protected Health Information and for failing to securely erase ePHI. The violation occurring when three backup tapes containing unencrypted ePHI were accidentally sent to a data archiving company to be erased and resold; however that company was not informed of the contents of the tapes. Two of those tapes were subsequently lost and have not been recovered. The Attorney General’s investigation revealed that a number of errors had been made by the hospital. The hospital had failed to obtain a signed business agreement and did not determine whether its choice of data company complied with HIPAA regulations. The passing of the Health...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist