NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Healthcare Most Targeted Industry in Mobile Phishing Campaigns
Sep26

Healthcare Most Targeted Industry in Mobile Phishing Campaigns

There has been an alarming increase in phishing attacks targeting enterprise mobile devices, according to the mobile security vendor Zimperium. Mobile phishing (missing) attacks target vulnerabilities in mobile devices, and cybercriminals are increasingly adopting a mobile-first strategy in their phishing campaigns. Targeting mobile devices makes sense, as nearly 67% of employees use personal devices for work, regardless of whether their company has a formal bring-your-own-device policy, and mobile devices often lack the security protections of desktops and laptops – 70% of businesses fail to adequately secure personal devices used for work purposes, according to Zimperium. Further, 71% of employees admitted to engaging in risky activities on their mobile devices. Risky practices include sideloading apps – downloading apps from unofficial stores – Zimperium reports that 1 in 4 Android devices face that issue. Users who download apps from unofficial stores are 200 times as likely to encounter malware. In 8.3% of malware detections on mobile devices, the infection was...

Read More
HHS-OIG Identifies Need for Increased Oversight of Remote Patient Monitoring
Sep25

HHS-OIG Identifies Need for Increased Oversight of Remote Patient Monitoring

Remote patient monitoring allows patients to collect their own health data via connected medical devices that automatically transmit the data to their healthcare provider. Remote patient monitoring is broadly covered by Medicare for both chronic and acute conditions and can be incredibly useful in managing patients’ conditions. The use of remote patient monitoring in Medicare has increased dramatically in recent years. Between 2019 and 2022, the number of Medicare recipients receiving remote patient monitoring increased 10-fold, and billing for remote patient monitoring increased 20-fold. Both the HHS Office of Inspector General (HHS-OIG) and the Centers for Medicare and Medicaid Services (CMS) have voiced concerns about fraud related to remote patient monitoring. In 2023, OIG issued a consumer alert about unscrupulous companies contacting Medicare enrollees to sign them up for remote patient monitoring when there was no medical need for remote monitoring. While the patient is signed up and the company bills Medicare for providing the service, the monitoring never happens. Remote...

Read More
Senator Demands Answers from Hospitals That Denied Emergency Reproductive Health Care
Sep25

Senator Demands Answers from Hospitals That Denied Emergency Reproductive Health Care

Senate Finance Committee Chair Ron Wyden (D-OR) has written to 8 hospitals in states with abortion bans following reports they denied emergency stabilizing care to pregnant women in violation of the Emergency Medical Treatment and Active Labor Act (EMTALA). EMTALA was signed into law in 1986 and requires all patients received at an emergency room or hospital that receives Medicare funding to provide stabilizing care, irrespective of the ability of the patient to pay. Under EMTALA, emergency treatment can include emergency reproductive health care if a pregnant woman’s life is at risk. Around half of U.S. states introduced bans on abortions or severely restricted when abortions can be provided, although many states have exceptions to those abortion bans for emergency care when there is a threat to life. Since the overturning of Roe v. Wade by the Supreme Court, there have been reports of more than 100 women being denied abortion care when they were experiencing a medical emergency such as an ectopic pregnancy or preeclampsia that put their lives at risk. “Across the country, there...

Read More
Texas Attorney General Resolves Investigation of GenAI Healthcare Technology Firm
Sep25

Texas Attorney General Resolves Investigation of GenAI Healthcare Technology Firm

Texas Attorney General Ken Paxton has announced that an agreement has been reached with a Texas-based artificial intelligence healthcare technology firm to resolve allegations the company violated the Texas Deceptive Trade Practices – Consumer Protection Act by making false, misleading, or deceptive statements about the accuracy of its artificial intelligence (AI)-based solution. In June 2024, Attorney General Paxton announced that he had launched a new data privacy and security initiative to protect Texans’ sensitive data from illegal exploitation by technology, AI, and other firms. The initiative was housed within the Consumer Protection Division of the Office of Inspector General and was focused on enforcing compliance with Texas laws such as the Data Privacy and Security Act, Identify Theft Enforcement and Protection Act, Data Broker Law, Biometric Identifier Act, Deceptive Trade Practices Act and federal laws such as the Children’s Online Privacy Protection Act (COPPA) and the Health Insurance Portability and Accountability Act (HIPAA). “Companies that collect and sell...

Read More
CMS Confirms 3.1 Million Individuals Affected by MOVEit Hack on Wisconsin Physicians Service
Sep25

CMS Confirms 3.1 Million Individuals Affected by MOVEit Hack on Wisconsin Physicians Service

The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has reported a data breach to the HHS that has affected 3,112,815 individuals.  The data breach was the same one the CMS and Wisconsin Physicians Service Insurance Corporation (WPS) announced earlier this month – the exploitation of a zero day vulnerability in the MOVEit Transfer solution by the Clop group in a mass exploitation event in May 2023, as detailed in the post below. In the announcement, the CMS and WPS stated that notifications were being issued to 946,801 individuals. The same day the announcement was made (September 6, 2024), the CMS submitted a breach report to the HHS on behalf of its business associate, WPS. That breach portal now shows that more than three times as many individuals were affected than the CMS and WPS said they were notifying. The CMS explained the discrepancy in the figures as being due to WPS holding the data of individuals who had deceased, and also that WPS had collected the data of many individuals as part of its work for the CMS who were...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist