NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is EDI in Healthcare?
Jul26

What is EDI in Healthcare?

EDI in healthcare stands for Electronic Data Interchange – a system for securely transmitting information between healthcare providers, health care clearinghouses, and payers about a patient’s condition, treatment for the condition, and payment for the treatment. Since 2000, the standards used in EDI healthcare transactions have been governed by Part 162 of the HIPAA Administrative Simplification Regulations. To help explain what EDI in healthcare is, it can be useful to start with the scenario of a patient attending a checkup appointment with a doctor. The doctor examines the patient and identifies a problem that requires treatment. Before providing the treatment, the doctor sends an eligibility enquiry to the patient’s insurance company (or Medicare, etc.), and the insurance company replies to inform the doctor whether the patient is eligible for the treatment. In this case, the patient is eligible for the treatment without any further authorizations required. The doctor provides the treatment and submits a claim for payment supported by details of the patient/doctor encounter....

Read More
North Korean Hacker Indicted for Ransomware Attacks on U.S. Hospitals and Healthcare Orgs
Jul26

North Korean Hacker Indicted for Ransomware Attacks on U.S. Hospitals and Healthcare Orgs

A North Korean government hacker has been indicted for his involvement in Maui ransomware attacks on U.S. hospitals and healthcare organizations. The U.S. State Department is offering a reward of up to $10 million for information that leads to his capture. Rim Jong Hyok is a member of the Andariel (APT45), a North Korean hacking group that has been in operation since at least 2009. The hacking group conducts activities as part of North Korea’s cyber defensive operations, primarily targeting military and government personnel. The group’s primary aims are espionage and data theft, especially the theft of sensitive defense and technology data. The hacking group also conducts financially motivated ransomware attacks to obtain funds to support its cyber campaigns, including ransomware attacks on U.S. hospitals and healthcare providers. Hyok was indicted by a grand jury in the U.S. District Court, District of Kansas on Wednesday and has been charged with one count of conspiracy to knowingly cause the transmission of a program, information, code, and command to intentionally cause damage...

Read More
Healthcare Organizations Are Exposing PII Through Incorrect File Sharing
Jul26

Healthcare Organizations Are Exposing PII Through Incorrect File Sharing

A report published this week has warned about gaps in data security and compliance at healthcare organizations, where files containing personally identifiable information (PII) are being shared using nonsecure methods. The report was published by Metomic, a data security software company from the UK that helps companies protect sensitive data in SaaS, GenAI, and cloud apps. The company’s research has revealed many healthcare organizations are exposing large amounts of sensitive data through incorrect filesharing. While employees may be aware of the importance of protecting HIPAA-covered protected health information, PII is often shared insecurely. According to Metomic, 25% of publicly shared files contain PII, such as names, addresses, and Social Security numbers which, if intercepted, could be used for identity theft, fraud, phishing, and social engineering attempts. Metomic’s research revealed that 77% of private files that are shared internally contained PII, and 68% of private files shared externally included PII. Sensitive data is typically exposed as a result of errors by...

Read More
New Jersey Oral & Maxillofacial Surgery Notifies 74,400 Patients About PHI Exposure
Jul26

New Jersey Oral & Maxillofacial Surgery Notifies 74,400 Patients About PHI Exposure

New Jersey Oral & Maxillofacial Surgery has confirmed that the PHI of 74,413 individuals has been exposed in a cyberattack. The Kansas Fire Department is investigating a security incident and has confirmed that sensitive data was exfiltrated from its network. New Jersey Oral & Maxillofacial Surgery Notifies Patients About April 2024 Cyberattack New Jersey Oral & Maxillofacial Surgery has notified 74,413 patients that some of their protected health information has been stolen in a cyberattack. A security incident was detected on May 14, 2024, and the investigation confirmed that there had been unauthorized access to its computer systems starting on or around April 19, 2024. The practice immediately initiated its incident response procedures and worked quickly to secure its systems to prevent further unauthorized access. The investigation confirmed that an unauthorized third party accessed the network and acquired certain files from its computer systems. The review of the exposed files confirmed that they contained patient information including names, addresses, dates of...

Read More
Survey Highlights Challenges in Healthcare with Managing Sensitive Content in Communications
Jul25

Survey Highlights Challenges in Healthcare with Managing Sensitive Content in Communications

Kiteworks (formerly Accellion, Inc.) has published the findings of a 2024 survey of professionals in the IT, security, and compliance sectors that has identified some of the challenges faced with managing sensitive content in communications. In healthcare, 53% of surveyed healthcare organizations said they used 5 or more communications tools for sharing sensitive content, comparable with other industry sectors, and while the same percentage of healthcare organizations believe they could track and control sensitive data when sent internally, only 44% shared that confidence about tracking and controlling sensitive data when sent externally. When asked about the most important privacy and compliance priorities regarding the communication of sensitive data, 61% of respondents said the prevention of leakage of confidential IP and corporate secrets. Interestingly, that ranked more important than the avoidance of regulatory violations, which was a top priority for 56% of healthcare respondents. Those figures were 56% and 48% across all industry sectors. There has been an increase in the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist