NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Lehigh Valley Health Network Data Breach Lawsuit Settled for $65 Million
Sep12

Lehigh Valley Health Network Data Breach Lawsuit Settled for $65 Million

A $65 million settlement has been agreed to resolve a class action data breach lawsuit against Lehigh Valley Health Network (LVHN) that will see plaintiffs compensated for having nude photographs and other sensitive data stolen and published on the dark web. In February 2023, LVHN in Pennsylvania confirmed it had fallen victim to a Blackcat ransomware attack. The attack was detected on February 6, 2023, and affected a network that supported a Lackawanna County physician practice, which included a system used to store clinically appropriate patient images for radiation oncology treatment. The Blackcat ransomware group demanded a ransom payment to prevent the publication of the stolen data on its data leak site, then started to release images of breast cancer patients, naked from the waist up, to increase the pressure on LVHN to pay the ransom. LVHN refused to pay the ransom and Blackcat leaked the stolen data. A lawsuit was filed by Simon B. Paris and Patrick Howard of the law firm Saltz, Mongeluzzi, & Bendesky, P.C. in March 2023 on behalf of plaintiff Jane Doe and other...

Read More
Microsoft & Ivanti Patch Multiple Critical and Actively Exploited Flaws
Sep11

Microsoft & Ivanti Patch Multiple Critical and Actively Exploited Flaws

Microsoft issued patches to fix 79 vulnerabilities on September 2024 Patch Tuesday, including 3 actively exploited vulnerabilities and one that Microsoft considers to be exploited. This month’s updates include fixes for 7 critical flaws, 71 important flaws, and 1 moderate-severity flaw. The actively exploited vulnerabilities affect Windows and Microsoft Publisher CVE-2024-38014 – Windows Installer, Elevation of Privilege – CVSS 7.8 An actively exploited flaw that allows a threat actor to gain SYSTEM privileges on Windows systems. CVE-2024-38226 – Microsoft Publisher, Security Feature Bypass – CVSS 7.3 A flaw allowing an attacker to bypass a security feature that protects against macros embedded in downloaded documents. CVE-2024-38217 – Windows Mark of the Web, Security Feature Bypass – CVSS 5.4 The vulnerability allows an attacker to open specially crafted malicious LNK files and bypass Smart App Control and Mark of the Web security warnings and is thought to have been exploited since 2018. CVE-2024-43491 – Windows Update, Remote Code Execution – CVSS 9.8 Microsoft has not detected...

Read More
Email Accounts Compromised at Welcome Health & United Way of Connecticut
Sep11

Email Accounts Compromised at Welcome Health & United Way of Connecticut

Welcome Health and United Way of Connecticut have reported breaches of employee email accounts and potential unauthorized access to patient data. Welcome Health On July 8, 2024, Welcome Health identified suspicious activity in a user’s email account and immediately terminated access to its systems. The forensic investigation confirmed that the user’s credentials had been compromised and were used by an unauthorized individual to access Welcome Health’s systems between June 11, 2024, and July 8, 2024. The file review was completed on August 12, 2024, and confirmed that patient and contractor information had potentially been viewed or acquired. For patients, the compromised information included first and last name, date of birth, patient number, health plan member number, claim number, date(s) of service, and diagnosis and treatment information. Contractors affected by the incident had their first and last names, Social Security numbers, and tax identification numbers compromised. The affected individuals have now been notified and offered complimentary credit monitoring and...

Read More
HHS-OIG Audit Finds Deficiencies in New Mexico’s Medicaid Personal Care Services Program
Sep11

HHS-OIG Audit Finds Deficiencies in New Mexico’s Medicaid Personal Care Services Program

The Department of Health and Human Services Office of Inspector General (HHS-OIG) conducted an audit of New Mexico’s state Medicaid agency’s personal care services (PCS) program and found that it did not always ensure that PCS were provided by appropriately qualified personnel, which put Medicaid enrollees at risk. The audit of the New Mexico Human Services Department, New Mexico’s state Medicaid agency, covered 2.7 million paid Medicaid PCS encounter claims in calendar year 2019, from which a stratified random sample of 300 claims was selected for the audit. HHS-OIG assessed the qualifications of the attendants who provided services for those claims. HHS-OIG identified 294 unique attendants associated with the 300 sampled claims. The attendants for just over one-third (106) of the sampled claims met federal and state qualification requirements; however, the attendants for almost two-thirds (194) of the claims did not meet one or more of the requirements in areas such as criminal background checks, abuse registry checks, TB testing, written competency tests, annual training, and...

Read More
What is an ABN in Healthcare?
Sep10

What is an ABN in Healthcare?

An ABN in healthcare is an Advanced Beneficiary Notice of Non-Coverage given to a Medicare beneficiary by a healthcare provider when it is possible that Medicare will not cover the cost of a medical service or item. This is usually because the service or item might not be considered medically necessary when Medicare is billed by the healthcare provider. In such cases, the beneficiary (i.e., patient) is asked to pay for the item or service upfront or through an alternative health insurance policy. If Medicare subsequently agrees to pay for the item or service, the healthcare provider will reimburse the beneficiary (or alternative health insurance policy) minus any deductible or copay. Beneficiaries also have the option of paying upfront without a claim for payment being submitted to Medicare, or declining the service or item. Why Might Medicare Consider a Service or Item Unnecessary? Medicare Part A and Part B Fee-For-Service programs generally limit what medical and other health services Medicare will pay for to those listed in §1861 of the Social Security Act. However, there are...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist