25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Data Breaches Reported by Three Californian Healthcare Providers
Sep04

Data Breaches Reported by Three Californian Healthcare Providers

Data breaches have recently been reported by Californian healthcare providers Vasinda’s Around the Clock Care, Baker Places, Turning Point of Central California, and Watson Clinic in Florida. Vasinda’s Around the Clock Care / ATC Home Care, California Vasinda’s Around the Clock Care Inc., doing business as ATC Home Care in California, has notified 3,785 individuals about a computer intrusion detected on June 18, 2024. The forensic investigation revealed an unauthorized individual had access to its network for almost 5 months. Its network was first compromised on January 30, 2024, and access remained possible until June 18, 2024. During that time, files were copied from its systems that contained sensitive patient information. The file review confirmed names had been compromised along with addresses, Social Security numbers, health insurance information, billing and claims information, and medical information such as diagnoses, lab results, medications, and other treatment information. The affected individuals were patients or clients of ATC or clients of the payee...

Read More
Security Camera Vendor Fined $2.95 Million for Alleged Violations of FTC Act and CAN-SPAM Act
Sep03

Security Camera Vendor Fined $2.95 Million for Alleged Violations of FTC Act and CAN-SPAM Act

The Federal Trade Commission (FTC) has proposed a $2.95 million financial penalty for the Californian security camera vendor Verkada to resolve allegations the company violated the FTC Act by failing to implement appropriate information security practices and violated the CAN-SPAM Act by bombarding customers with emails without providing a way to unsubscribe. Verkada’s IP-enabled security cameras provide live video feeds and record and store video footage in Amazon Web Services (AWS) storage. The cameras are used in many sensitive locations, including psychiatric hospitals, women’s health clinics, prisons, and schools. Verkada claimed it takes data security and customer privacy seriously and said the company uses best-in-class security tools and best practices to ensure that customer data is kept safe and is prevented from unauthorized access. The FTC alleged that appropriate security measures had not been implemented. For example, the company did not require unique and complex passwords, had not implemented secure network controls, and did not adequately encrypt customer data....

Read More
What is the Administrative Simplification Compliance Act?
Sep03

What is the Administrative Simplification Compliance Act?

The Administrative Simplification Compliance Act is an Act passed in 2001 that requires healthcare providers and medical equipment suppliers to submit claims for payment to Medicare electronically. Noncompliance with the requirement will result in nonpayment and possible exclusion from Medicare unless an exemption applies or the requirement is waived. When Congress passed HIPAA in 1996, one of the changes the Act made to the Public Health and Welfare Code was the “General Requirements for the Adoption of Standards”. The General Requirements led to the publication of the Administrative Simplification Regulations which include the HIPAA Transaction Standards (Part 162), the HIPAA Privacy Rule, and the HIPAA Security Rule. When the first HIPAA Transaction Standards were published in October 2000, the implication was that healthcare providers and medical equipment suppliers only had to apply the standards when submitting electronic claims to Medicare. Indeed, in the preamble to the Part 162 Final Rule, HHS denies any intention to introduce a rumored $1 user fee for each claim submitted...

Read More
CISA Launches New Cyber Incident Reporting Portal
Sep02

CISA Launches New Cyber Incident Reporting Portal

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has launched a new portal to make it easier for organizations to report cyber incidents and data breaches. Use of the portal is voluntary but strongly recommended, as the reporting of cyber incidents benefits the reporting entity as well as the broader community. Cyberattacks can be hugely disruptive for the breached entity; however, CISA and its government partners may be able to offer assistance, as they have unique resources and tools available to help with response and recovery. Prompt reporting will ensure that those resources can be made available when they are needed. “An organization experiencing a cyberattack or incident should report it — for its own benefit, and to help the broader community,” said Jeff Greene, executive assistant director for cybersecurity, CISA. “CISA and our government partners have unique resources and tools to aid with response and recovery, but we can’t help if we don’t know about an incident.” When a threat actor conducts a successful attack, the tactics, techniques, and procedures...

Read More
Specialty Networks Data Breach Affects 411,000 Patients
Aug30

Specialty Networks Data Breach Affects 411,000 Patients

Specialty Networks, Inc., a Chattanooga, TN-based provider of radiology information systems, digital transcription services, and enterprise practice management solutions for healthcare facilities, has recently announced a major data breach involving the protected health information of 411,037 current and former patients. The announcement about the data breach was made on August 15, 2024; however, unauthorized activity within its computer systems was first detected on December 18, 2023. The forensic investigation confirmed there had been unauthorized access to its IT environment from December 11, 2023, to December 18, 2023, and during that time, files were exfiltrated that contained sensitive patient data. The delay in announcing the breach was due to the time taken to review the affected files. On May 31, 2024, Specialty Networks learned that patients’ protected health information had been compromised, then notifications were issued to its covered entity clients, and on or around June 24, 2024, coordinated notification efforts with the affected providers, started verifying...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist