25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

The HHS OIG Safe Harbor Regulations
Feb22

The HHS OIG Safe Harbor Regulations

The HHS OIG Safe Harbor Regulations define the circumstances in which the offer, solicitation, payment, or receipt of remuneration in exchange for items or services billable to a Federal healthcare program is not regarded as a violation of the Anti-Kickback Statute. It is important for healthcare providers to be aware of these regulations in order to avoid inadvertent violations of anti-fraud laws. In 1972, Congress added an Anti-Kickback Statute to the Social Security Act §1128B which penalizes individuals found to have intentionally offered, solicited, or received anything of value in return for referrals for goods or services billable to a Federal Healthcare program. At the time, the broad nature of the Statute raised concerns that healthcare providers participating in beneficial commercial arrangements were technically covered by the statute and at risk of criminal prosecution. It was not until the passage of the Medicare and Medicaid Patient and Program Protection Act of 1987 that the law was changed to allow the HHS Office of Inspector General (OIG) to promulgate regulations...

Read More
OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2022
Feb22

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2022

The Department of Health and Human Services (HHS) Office for Civil Rights has submitted its annual reports to Congress on HIPAA Privacy, Security, and Breach Notification Rule compliance and breaches of unsecured protected health information (PHI) for calendar year 2022. HIPAA Compliance in 2022 OCR explains in the report that large data breaches have increased by 107% from 2018 to 2022, complaints about potential HIPAA violations have increased by 17% over the same period, and  OCR is now required to assess whether an entity has implemented recognized security practices when determining penalties. As a result, OCR’s workload has significantly increased yet OCR has not received any increase in appropriations. OCR also reassessed the language of the HITECH Act in 2019 and reduced the penalty amounts in three of the four penalty tiers, resulting in smaller penalties. The increase in workload and lowering of the penalty amounts has placed a severe strain on OCR’s limited staff and resources and the lack of funding is hampering its ability to investigate complaints and data breaches at...

Read More

Ransomware Attack on Maryland Psychotherapy Provider Results in HIPAA Penalty

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) with a Maryland behavioral healthcare provider for $40,000. Green Ridge Behavioral Health, LLC (GRBH) is a Gaithersburg, MD-based provider of psychiatric evaluations, medication management, and psychotherapy.  In February 2019, GRBH filed a report with OCR about a breach of the protected health information of 14,000 patients. A malicious actor had accessed its systems and used ransomware to encrypt files. The investigation confirmed that the threat actor stole files containing sensitive patient information. In December 2019, OCR initiated an investigation to establish whether GRBH had complied with the HIPAA Rules. GRBH was unable to provide OCR with evidence to prove that an accurate risk analysis had been conducted to identify risks and vulnerabilities to electronic protected health information (ePHI), as required by 45 C.F.R. § 164.308(a)(l)(ii)(A), and sufficient security measures had not been...

Read More

Medical Management Resource Group (American Vision Partners) Breach Affects 2.35M Patients

Medical Management Resource Group, LLC (MMRG), doing business as American Vision Partners, has recently confirmed in a notification to the HHS’ Office for Civil Rights that the protected health information of 2,350,236 individuals was compromised in a HIPAA hacking incident. MMRG detected unauthorized activity within its network on November 14, 2023, and took immediate action to contain the threat. A third-party cybersecurity firm was engaged to investigate the breach and determine the nature and scope of the unauthorized activity, and on or around December 6, 2023, MMRG confirmed that there had been unauthorized access to its network, and the removal of files containing patient data. Those files contained information such as names, contact information, dates of birth, medical information such as the services received, clinical records, and medications, and for some individuals, Social Security numbers and health insurance information. MMRG is in the process of notifying the affected individuals and has offered complimentary credit monitoring and identity protection services to the...

Read More
Greater Cincinnati Behavioral Health Services Reports 62,000-Record Data Breach
Feb21

Greater Cincinnati Behavioral Health Services Reports 62,000-Record Data Breach

Greater Cincinnati Behavioral Health Services (GCBHS) fell victim to a cyberattack on December 10, 2023, that caused network disruption and prevented access to some of its IT systems. Immediate action was taken to contain the incident and third-party cybersecurity experts were engaged to investigate and assist with the breach response. GCBHS said the forensic investigation is ongoing but evidence has been found that indicates an unauthorized third party accessed files containing patient information. The files are still being reviewed and notifications will be issued when that process has been completed. GCBHS said the compromised data includes names, demographic information, dates of birth, Social Security numbers, driver’s license numbers, medical information, and healthcare information. GCBHS said it has implemented additional security tools and will be offering the affected individuals complimentary credit monitoring and identity theft protection services. The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 50,000 patients. UPDATE: September 13,...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist