NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Mass General Brigham Terminates Two Employees for Privacy Violations
Jul01

Mass General Brigham Terminates Two Employees for Privacy Violations

Mass General Brigham in Boston, MA, has announced that two employees have been terminated over a privacy breach identified on April 4, 2024. An investigation was launched after the health system learned that the two employees allowed a third individual – who was not employed by Mass General Brigham – to perform some of their job duties that may have resulted in patients’ personal information being viewed. The investigation concluded on May 28, 2024, and confirmed that the alleged offenses occurred between February 26, 2024, and April 4, 2024. The Health Insurance Portability and Accountability Act (HIPAA) requires protected health information (PHI) to be safeguarded at all times and prohibits disclosures of PHI to unauthorized individuals unless a valid authorization has been obtained from the individuals concerned in advance. Mass General Brigham had employment and privacy policies in place and said those policies were violated by the employees resulting in the employees’ immediate termination. Mass General Brigham did not disclose the relationship between the...

Read More
HHS-OIG and Law Enforcement Partners Tackle $2.75 Billion Healthcare Fraud Schemes
Jun28

HHS-OIG and Law Enforcement Partners Tackle $2.75 Billion Healthcare Fraud Schemes

The Department of Health and Human Services Office of Inspector General (HHS-OIG) and its law enforcement partners have tackled nationwide healthcare fraud schemes involving around $2.75 billion in intended losses and $1.6 billion in actual losses. The 2024 National Health Care Fraud Enforcement Action has resulted in criminal charges being filed against 193 defendants, including 76 doctors, nurses, and other licensed medical professionals in 32 federal districts across the country. $231 million in cash, gold, luxury vehicles, and other assets has been seized. One of the actions announced by HHS-OIG Inspector General Christi A. Grimm involved five individuals at a start-up telehealth company that claimed they diagnosed and treated attention deficit hyperactivity disorder (ADHD). The company engaged in deceptive advertising on social media networks to target patients, who were prescribed addictive drugs such as Adderall and other stimulants when they were not medically necessary. Millions of pills were prescribed through the telehealth company, Done Global Inc. and its affiliated...

Read More
Health-ISAC Issues Warning Abuse of TeamViewer Remote Connectivity Software
Jun28

Health-ISAC Issues Warning Abuse of TeamViewer Remote Connectivity Software

The Health Information Sharing and Analysis Center (Health-ISAC) has issued a warning to the healthcare and public health sector about cyber threat actors exploiting TeamViewer remote connectivity software. TeamViewer provides remote access and remote control of devices and is commonly used for remote IT support and maintenance. Health-ISAC has received intelligence from a trusted source that a threat actor tracked as APT29, aka Cozy Bear/Midnight Blizzard, has compromised TeamViewer, and threat actors associated with APT29 are abusing TeamViewer. APT29 is a threat group that has been in operation since at least 2008 and is a Russian hacking group associated with Russia’s intelligence agencies, the Federal Security Service (FSB) and Foreign Intelligence Service (SVR). The United States believes APT29 is led by the SVR. On Thursday, TeamViewer issued a statement confirming it had detected an irregularity in its internal network on June 26, 2024. According to its security update, “A comprehensive taskforce consisting of TeamViewer’s security team together with globally leading cyber...

Read More
January 2024 Cyberattack on Lurie Children’s Hospital Affects 792K Individuals
Jun28

January 2024 Cyberattack on Lurie Children’s Hospital Affects 792K Individuals

On January 31, 2024, Ann & Robert H. Lurie Children’s Hospital of Chicago fell victim to a cyberattack that forced IT systems offline, including its Epic electronic health record systems and its MyChart patient portal. Staff were forced to work under downtime procedures and record patient information manually while its EHR was offline. It took until May 20, 2024, to restore access, and then the lengthy process of transferring all manually recorded data to the EHR commenced. Lurie Children’s said it has taken a considerable amount of time to investigate the incident and restore its systems due to the sophistication of the attack and the complexity of its IT infrastructure. The forensic investigation confirmed that an unauthorized, unnamed third party had access to its systems from January 26, 2024, to January 31, 2024. Lurie Children’s confirmed that the hackers were able to access patient data during those 5 days. “Through our ongoing investigation, Lurie Children’s has determined that certain individuals’ personally identifiable and/or protected health information was...

Read More
OSHA Offers $12.7M in Grants to Support Employee Safety, Health Training & Education
Jun28

OSHA Offers $12.7M in Grants to Support Employee Safety, Health Training & Education

The Occupational Safety and Health Administration (OSHA) is offering $12.7 million in training grants to help create safer workplaces. The grants are administered under OSHA’s Susan Harwood Training Grant Program to support employee safety, health training, and education. The grants are awarded to provide training and education programs for employers and workers on the recognition, avoidance, and prevention of safety and health hazards in their workplaces, and to ensure that workers are aware of their rights under the Occupational Safety and Health (OSH) Act and the responsibilities of their employers to create a safe workplace. The grants are intended to advance job quality by providing instructor-led training for workers, supervisors, and employers in small businesses, industries with high injury, illness, and fatality rates, and vulnerable, underserved workers, such as seasonal workers who often have limited English proficiency. There are three categories of grants available: Targeted Topic Training: To identify and prevent OSHA-designated workplace safety and health hazards....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist