NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

More Than 50% of Healthcare Employees Fail a HIPAA Assessment, New Data Reveals

Businesses in the healthcare sector have a responsibility to minimise the risks of HIPAA violations, for the sake of their patients, staff and the organization as a whole. One way in which organizations can mitigate internal breaches is by ensuring that staff receive regular HIPAA training. However the number of internal breaches recorded each year would suggest that more needs to be done to ensure employees are HIPAA compliant. To investigate the standards of HIPAA training in the healthcare sector, The HIPAA Journal researchers have examined HIPAA assessment fail rates, the percentage of staff who have witnessed HIPAA violations, and how frequently training is being conducted in 2023. How many employees working with PHI fail a HIPAA assessment? More than half of employees working in the healthcare sector fail a HIPAA assessment. The data suggests that more than 50% of staff working with PHI do not have a comprehensive understanding of HIPAA regulations, and therefore require more training. Which area of HIPAA training sees the highest fail rates? During a HIPAA assessment in...

Read More

HIPAA Compliant Remote Access Software

HIPAA compliant remote access software provides HIPAA-covered entities and their busines associates with a secure way of remotely accessing systems containing electronic protected health information (ePHI) and simplifies the management of remote access. Healthcare organizations can have dozens of vendors who require remote access to servers, applications, and healthcare data, and oftentimes several different methods are used to provide access to vendors. Without a single solution, management of remote access is time consuming, complex, and difficult to carefully control. Healthcare employees also need remote access to applications, files, and ePHI and remote access has become even more important in the COVID-19 era. To reduce the risk of infection and help control the spread of COVID-19, there has been a major expansion of telehealth services. Healthcare professionals are now conducting more visits virtually and need to remotely access applications, EHRs, and files to provide those telehealth services. Windows Remote Desktop Protocol can be used for remote access, but RDP is not...

Read More
Healthcare Data Breaches Reported in New York, Florida, & Arkansas
Oct25

Healthcare Data Breaches Reported in New York, Florida, & Arkansas

Data breaches have recently been reported by Advanced Recovery Equipment & Supplies in New York, We Level Up Treatment in Florida, and Arkansas Blue Cross and Blue Shield. Advanced Recovery Equipment & Supplies, New York Advanced Recovery Equipment & Supplies, a New York-based supplier of medical recovery products, has identified a breach of its network and the theft of files containing customer data. The forensic investigation confirmed that an unauthorized third party accessed its network between June 27, 2023, and July 28, 2023, and removed files from the network. Assisted by third-party specialists, Advanced Recovery Equipment & Supplies conducted a comprehensive review of the affected files, which concluded on September 29, 2024. The files exfiltrated from its network included the protected health information of 56,000 individuals. Data compromised in the incident included names along with one or more of the following: Social Security number, date of birth, driver’s license number/state identification number, credit or debit card information, username and...

Read More
Email Incidents Reported by Survival Flight and Jacksonville Children’s Multispecialty Clinics
Oct25

Email Incidents Reported by Survival Flight and Jacksonville Children’s Multispecialty Clinics

Survival Flight, Inc., an emergency medical transportation company with bases in Alabama, Arkansas, Florida, Georgia, Illinois, Missouri, Oklahoma, and Tennessee, has identified a breach of its email environment. Suspicious activity was detected within its email system on May 22, 2024. Third-party digital forensics specialists were engaged to investigate the breach and confirmed there had been unauthorized access to several employee email accounts. The affected accounts were reviewed, and it was confirmed on August 19, 2024, that they contained sensitive patient information including names, medical histories, treatment information, health insurance information Social Security numbers, and financial information. The breach was recently reported to the HHS’ Office for Civil Rights as affecting 12,342 individuals. While the accounts were subjected to unauthorized access, no evidence has been found to indicate any misuse of patient data; however, the affected individuals have been advised to monitor their accounts and explanation of benefits statements for suspicious activity....

Read More
Henry Schein Confirms 166,000 Individuals Affected By October 2023 Ransomware Attack
Oct25

Henry Schein Confirms 166,000 Individuals Affected By October 2023 Ransomware Attack

Henry Schein, a Melville, NY-based provider of medical and dental supplies and Fortune 500 firm, has continued to investigate a 2023 cyberattack that affected its manufacturing and distribution businesses. The cyber incident was a ransomware attack where files were restored only for them to be encrypted by the ransomware group a second time. Initially, the investigation identified 29,112 individuals who had their data compromised in the attack, and notification letters started to be mailed to those individuals in November 2023. Since then, Henry Schein has been working with an outside expert to review the affected files – a process that has taken a considerable amount of time and resources and continued throughout the first half of the year. In an updated breach notification to the Maine Attorney General, Henry Schein confirmed that 166,432 individuals are now known to have been affected and had their personal and protected health information exposed or stolen. The additional individuals are now being notified and have been offered complimentary credit monitoring and identity...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist