25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS Urges Health Sector to Improve OT & IoMT Security
Dec27

HHS Urges Health Sector to Improve OT & IoMT Security

The Department of Health and Human Services (HHS) has urged healthcare organizations to take steps to safeguard operational technology (OT) and the Internet of Medical Things (IoMT). Vulnerabilities in OT and IoMT systems could potentially be exploited by malicious actors to access internal healthcare networks, steal data, and cause significant operational disruption. The Food and Drug Administration (FDA) has taken steps to improve medical device security by requiring vendors of medical devices to implement appropriate cybersecurity measures covering the entire lifecycle of their products. Vendors must provide documentation verifying that cybersecurity measures have been implemented in their pre-market submissions. Devices with insufficient cybersecurity will not be approved; however, these requirements only apply to new medical devices that are brought to market, not the large number of medical devices already in use. Devices may be used by healthcare organizations for patient care, product manufacturing, data collection, facility management, and other purposes. Medical devices...

Read More
Decrease in Workplace Fatalities Encouraging – More Must Be Done to Improve Workplace Safety
Dec27

Decrease in Workplace Fatalities Encouraging – More Must Be Done to Improve Workplace Safety

The U.S. Bureau of Labor Statistics has published a summary of the findings of the 2023 National Census of Fatal Occupational Injuries, which shows a 3.7% year-over-year percentage decrease in workplace fatalities. In 2023, there were 5,283 workplace fatalities which occurred at a rate of 3.5 per 100,000 full-time workers, down from 3.7 in 2022. There was one reported fatality every 99 minutes in the United States in 2023. Construction was the sector with the highest number of fatalities (1,075), as has been the case every year since 2011. Slips, trips, and falls were the most common cause of death in this sector (39.2%) followed by transportation incidents. Across all industry sectors, transportation incidents were the most frequent type of fatal event, accounting for 36.8% of all workplace fatalities in 2023. There were 740 fatalities due to violent acts, with homicides accounting for 61.9% of violent acts and 8.7% of all work-related fatalities. 162 workplace fatalities were due to opioid use. The majority of fatalities were men, with women accounting for 8.5% of all workplace...

Read More
American Addiction Centers Ransomware Attack Affects Almost 411,000 Patients
Dec27

American Addiction Centers Ransomware Attack Affects Almost 411,000 Patients

American Addiction Centers, Inc., a Brentwood, TN-based addiction rehabilitation center, has recently confirmed that 410,747 current and former patients have been affected by a cybersecurity incident and may have had their protected health information stolen. A copy of the individual notification letters was sent to the Maine Attorney General confirming that the compromised data included names, addresses, phone numbers, dates of birth, medical record numbers, other identifiers, Social Security numbers, and health insurance information. The unauthorized third party did not obtain any financial or treatment information. The stolen data related to patients of American Addiction Centers as well as its affiliated providers, AdCare (MA & RI), the Greenhouse (TX), Desert Hope Center (NV), Oxford Treatment Center (MS), Recovery First (FL), Sunrise House (NJ), River Oaks Treatment Center (FL), and Laguna Treatment Hospital (CA). The cyberattack was detected on or around September 26, 2024, and third-party cybersecurity experts were engaged to investigate the incident. American Addiction...

Read More
What is the Texas OIG Exclusions Database?
Dec26

What is the Texas OIG Exclusions Database?

The Texas OIG exclusions database is a list of excluded individuals and entities similar to the federal HHS OIG exclusion database. The primary difference between the two databases is that the Texas OIG exclusions database contains the names of individuals and entities that have violated state law as well as those that have violated federal law. Exclusion Databases Explained Exclusion databases are lists of individuals and entities that are prohibited from providing goods or services to federal or state funded programs because they are guilty of some type of misconduct against the federal or state government. Most federal departments and state agencies maintain exclusion databases – usually through an Office of Inspector General (OIG) or equivalent. The most well-known exclusion database in healthcare is the Department of Health and Human Services’ (HHS) OIG List of Excluded Individuals/Entities – also known as the OIG LEIE. This list contains the details of thousands of individuals and entities prohibited from providing goods or services to federal health care programs for...

Read More
Douglas County Department of Health and Human Services Discovers Insider Data Breach
Dec26

Douglas County Department of Health and Human Services Discovers Insider Data Breach

The Douglas County Department of Health and Human Services in Wisconsin has discovered a former employee accessed patient records without authorization over 21 months. Richmond University Medical Center has notified patients affected by a May 2023 data breach, and Premier Healthcare Holdings has discovered a breach of its email system. Douglas County Department of Health and Human Services Discovers Insider Data Breach The Douglas County Department of Health and Human Services in Wisconsin has notified patients whose protected health information was accessed by a former employee without authorization.  On May 13, 2024, an audit of the department records identified unauthorized access to patient information. After verifying the unauthorized access, the employee concerned was terminated and the records were reviewed to determine the types of data potentially viewed or obtained by the former employee. The unauthorized access occurred between August 11, 2022, and May 13, 2024, and the employee may have viewed the following data types: name, address, phone number, email address, date of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist