NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Bipartisan Senators Reintroduce MATCH IT Act to Streamline Americans’ Health Care
Mar13

Bipartisan Senators Reintroduce MATCH IT Act to Streamline Americans’ Health Care

One of the requirements of the Health Insurance Portability and Accountability Act of 1996 was the introduction of a national patient identifier – A unique identifier for all Americans that would allow medical records to be reliably linked with the right individuals. The mismatching of health records continues to be a problem in healthcare as it was back in 1996 when HIPAA was enacted. The HIPAA Journal has been contacted by a patient who shares the same name and date of birth with another patient at the same hospital and has experienced multiple cases of mismatching her records with the records of the other patient of the same name, resulting in an unauthorized disclosure of her records and has put the safety of both patients at risk. This is far from an isolated example. It is common for medical records to be overlaid, where multiple patients’ records are merged into a single record. This can result in an unauthorized disclosure of health data that is prohibited under HIPAA, and more seriously, can put patient safety at risk. A 2016 report in the Boston Globe identified 14...

Read More
Collaborative Effort Decreases Cobalt Strike Abuse by 80%
Mar13

Collaborative Effort Decreases Cobalt Strike Abuse by 80%

Efforts have been ongoing for several years to crack down on illegal use of Cobalt Strike. Those efforts appear to have paid off, with misuse of the tool down 80% over the past two years.  The Cobalt Strike adversary simulation tool has been designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors. The tool’s post-exploit capabilities cover the full range of ATT&CK tactics, which can be executed within a single, integrated system. The tool is used by red teams to identify vulnerabilities within a company’s network, allowing proactive steps to be taken to improve cybersecurity; however, pirated and unlicensed versions of the tool are sold and shared on cybercriminal marketplaces for use by threat actors in their offensive campaigns. Cobalt Strike has become one of the most widely used tools in cyber attacks, allowing threat actors to deploy ransomware at speed and scale. Unlicensed versions of Cobalt Strike are commonly deployed in spear phishing campaigns that trick users into opening a malicious attachment or otherwise installing...

Read More
Is Airtable HIPAA Compliant?
Mar12

Is Airtable HIPAA Compliant?

Airtable is HIPAA compliant for covered entities and business associates who subscribe to an Enterprise Scale plan and enter into a Business Associate Agreement with Airtable. However, covered entities and business associates are advised that limitations apply to how Airtable can be used in compliance with HIPAA. Airtable is a customizable business management platform with automation capabilities that helps organizations better manage data by enabling connections between siloed databases. The platform can be used – for example – for collaborative project management, inventory management, or data collection and analysis. Airtable can also function as a CRM solution due to numerous integration options. In healthcare, Airtable has many potential uses. It could be used to keep track of appointments and consultant availability, streamline care teams’ workflows, or be used to build relational databases that track patients’ healthcare journeys and automatically trigger actions (i.e., run scripts, send MS Teams notifications, etc.) when specific events occur. However, these uses...

Read More
Columbus Regional Healthcare Agrees to $1,175,000 Data Breach Settlement
Mar12

Columbus Regional Healthcare Agrees to $1,175,000 Data Breach Settlement

Columbus Regional Healthcare has agreed to a $1,175,000 settlement to resolve litigation stemming from a May 2023 data breach. The breach was detected on May 21, 2023, and the forensic investigation confirmed that hackers had access to parts of its network between May 19, 2023, and May 21, 2024, including systems that contained the personal and protected health information of 132,887 individuals. The file review was completed on December 28, 2023, and it was confirmed that the data exposed in the incident included names, addresses, birth dates, Social Security numbers, driver’s license information, passport numbers, financial account information, medical histories, and health insurance information. The affected individuals were notified about the data breach in January 2024, and complimentary credit monitoring services were offered to individuals who had their Social Security numbers compromised. Lawsuits were filed in response to the data breach, which were consolidated into a single lawsuit – In Re: Columbus Regional Healthcare System – in Columbus County, North...

Read More
Is HIPAA Training Required Annually?
Mar12

Is HIPAA Training Required Annually?

Yes, HIPAA training is required annually because it is a best practice to schedule HIPAA annual refresher training. This is required in case additional training has not been necessary due to a change in policies, the outcome of a risk assessment, the enforcement of a sanctions policy, or a corrective action plan following the notification of a data breach. Is HIPAA Training Required Annually? The HIPAA text does not provide a deadline for providing training and incorporates flexibility to make it easier for healthcare organizations to fit training into busy workflows. The HIPAA Privacy Rule states “A covered entity must train all members of its workforce on the policies and procedures with respect to protected health information,” and training should be provided “as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity.” In addition to initial training, a covered entity must provide training when “functions are affected by a material change in the policies or procedures.” That means further training is required when...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist