NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HHS Updates Civil Monetary Penalty Amounts for HIPAA Violations
Aug08

HHS Updates Civil Monetary Penalty Amounts for HIPAA Violations

The Department of Health and Human Services (HHS) has applied the annual inflation update to its civil monetary penalty (CMP) amounts, per the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015. In December each year, the Office of Management and Budget (OMB) sets the annual inflation multiplier for all government agencies, which is calculated from the Consumer Price Index for all Urban Consumers (CPI-U) for October 2023. OMB requires the adjustment to be applied to each HHS agency’s CMPs by January 15th of each year. The HHS is usually one of the last government departments to apply the updates to its CMP amounts, with the update often applied several months after the January deadline. The HHS has missed the OMB deadline every year since 2017, although was only a few days late in 2020. Last year the update was not applied until October 6, 2024. On August 8, 2024, the HHS published confirmation in the Federal Register that the inflation multiplier has been applied, which will see CMP amounts increased by the OMB’s multiplier of 1.03241 across all HHS...

Read More
CrowdStrike Confirms Root Cause of Falcon Sensor Outage; Healthcare Losses Anticipated to be $1.94B
Aug08

CrowdStrike Confirms Root Cause of Falcon Sensor Outage; Healthcare Losses Anticipated to be $1.94B

As promised, CrowdStrike has published the root cause analysis of the faulty Falcon Sensor software update that caused Windows devices around the world to crash. CrowdStrike had previously published the preliminary findings from its investigation, which confirmed that this was a Channel File 2971 incident caused by a faulty update involving a new Template Type. The purpose of the update was to improve visibility into novel attack types. The new Template Type had previously been used without incident; however, on July 19, 2024, despite passing multiple levels of testing, the update triggered an out-of-bounds memory read issue, causing Windows devices to get caught in a loop and display the Blue Screen of Death. CrowdStrike has now confirmed that several shortcomings have been identified that led to the crash, the most significant of which was a parameter mismatch in its rapid response content update. Falcon Sensor was expecting to receive 20 input fields but instead received 21, triggering an out-of-bounds memory read. The update on July 19, 2024, was the first IPC Template Type to...

Read More
Noncompliance with Performance Standards Contributed to Case Flow Delays at Alaska Medicaid Fraud Control Unit
Aug08

Noncompliance with Performance Standards Contributed to Case Flow Delays at Alaska Medicaid Fraud Control Unit

A performance review of the Alaska Medicaid Fraud Control Unit by the Department of Health and Human Services’ Office of Inspector General (HHS-OIG) has uncovered multiple areas of concern, where the Units’ performance fell short of the requirements of a Medicaid Fraud Control Unit (MFCU) grant award. MFCUs investigate Medicaid provider fraud and patient abuse/neglect and prosecute cases under state law or refer those cases to other prosecuting offices. Unless there is a waiver, each state must have an MFCU. Currently all 50 states, DC, Puerto Rico, and the U.S. Virgin Islands operate MFCUs. Each MFCU receives an annual grant award which covers 90% of expenditures for new units and 75% of expenditures for all other units, with the shortfall made up with collections from their enforcement activities. HHS-OIG has oversight of MFCUs and conducts reviews to assess performance against the requirements of the grant awards and recertify the Units. HHS-OIG conducted a review of the Alaska MFCU in 2016 and identified a number of issues. Case files lacked documentation of periodic...

Read More
What Does DME Stand For in Healthcare?
Aug07

What Does DME Stand For in Healthcare?

DME in healthcare stands for durable medical equipment – defined by CMS as equipment that is used for medical purposes by an individual who is sick or injured and that can withstand at least three years of repeated or frequent use. However, in the context of healthcare compliance, it can be more important to understand the HIPAA status of DME suppliers. One of the reasons it is important to understand what does DME stand for in healthcare is that suppliers of durable medical equipment qualify as healthcare providers under §1395x(s) of the Public Health and Welfare Code. This means that, if a supplier of DME conducts electronic transactions covered by Part 162 of the Administrative Simplification Regulations (i.e., as a Medicare-enrolled DMEPOS supplier), they qualify as a HIPAA covered entity. If a supplier of DME qualifies as a HIPAA covered entity, this has an impact on when it is permissible for a healthcare provider (who also qualifies as a HIPAA covered entity) to disclose Protected Health Information (PHI) to the DME supplier without a HIPAA authorization. It may also have an...

Read More
NHS Software Provider Facing £6M Fine Over Ransomware Attack
Aug07

NHS Software Provider Facing £6M Fine Over Ransomware Attack

An IT and software services provider in the United Kingdom is facing a £6.09 million ($7.74 million) financial penalty over an August 2022 ransomware attack that disrupted the National Health Service (NHS) and other healthcare and social care services in England. The UK’s data watchdog, the Information Commissioners Office (ICO), investigated the attack and has disclosed the provisional findings of the investigation and the proposed financial penalty. Advanced Computer Software Group, which provides IT and software services to the NHS and other organizations in the UK, was determined to have failed to implement sufficient measures to protect the personal information of 82,946 patients, whose data was stolen in the ransomware attack. The stolen data included names, contact information, and medical records. Almost 900 of the affected individuals were receiving healthcare services at home and had given their providers information about how to access their properties, and that information was also stolen in the attack. The attack caused considerable disruption, including to the NHS 111...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist