NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2022
Feb22

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2022

The Department of Health and Human Services (HHS) Office for Civil Rights has submitted its annual reports to Congress on HIPAA Privacy, Security, and Breach Notification Rule compliance and breaches of unsecured protected health information (PHI) for calendar year 2022. HIPAA Compliance in 2022 OCR explains in the report that large data breaches have increased by 107% from 2018 to 2022, complaints about potential HIPAA violations have increased by 17% over the same period, and  OCR is now required to assess whether an entity has implemented recognized security practices when determining penalties. As a result, OCR’s workload has significantly increased yet OCR has not received any increase in appropriations. OCR also reassessed the language of the HITECH Act in 2019 and reduced the penalty amounts in three of the four penalty tiers, resulting in smaller penalties. The increase in workload and lowering of the penalty amounts has placed a severe strain on OCR’s limited staff and resources and the lack of funding is hampering its ability to investigate complaints and data breaches at...

Read More

Ransomware Attack on Maryland Psychotherapy Provider Results in HIPAA Penalty

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled alleged violations of the Health Insurance Portability and Accountability Act (HIPAA) with a Maryland behavioral healthcare provider for $40,000. Green Ridge Behavioral Health, LLC (GRBH) is a Gaithersburg, MD-based provider of psychiatric evaluations, medication management, and psychotherapy.  In February 2019, GRBH filed a report with OCR about a breach of the protected health information of 14,000 patients. A malicious actor had accessed its systems and used ransomware to encrypt files. The investigation confirmed that the threat actor stole files containing sensitive patient information. In December 2019, OCR initiated an investigation to establish whether GRBH had complied with the HIPAA Rules. GRBH was unable to provide OCR with evidence to prove that an accurate risk analysis had been conducted to identify risks and vulnerabilities to electronic protected health information (ePHI), as required by 45 C.F.R. § 164.308(a)(l)(ii)(A), and sufficient security measures had not been...

Read More

Medical Management Resource Group (American Vision Partners) Breach Affects 2.26M Patients

Medical Management Resource Group, LLC (MMRG), doing business as American Vision Partners, has recently confirmed in a notification to the HHS’ Office for Civil Rights (OCR) that the protected health information of 2,350,236* individuals was compromised in a HIPAA hacking incident. MMRG detected unauthorized activity within its network on November 14, 2023, and took immediate action to contain the threat. A third-party cybersecurity firm was engaged to investigate the breach and determine the nature and scope of the unauthorized activity, and on or around December 6, 2023, MMRG confirmed that there had been unauthorized access to its network and the removal of files containing patient data. Those files contained information such as names, contact information, dates of birth, medical information such as the services received, clinical records, and medications, and for some individuals, Social Security numbers and health insurance information. MMRG is in the process of notifying the affected individuals and has offered complimentary credit monitoring and identity protection services...

Read More
Greater Cincinnati Behavioral Health Services Reports 62,000-Record Data Breach
Feb21

Greater Cincinnati Behavioral Health Services Reports 62,000-Record Data Breach

Greater Cincinnati Behavioral Health Services (GCBHS) fell victim to a cyberattack on December 10, 2023, that caused network disruption and prevented access to some of its IT systems. Immediate action was taken to contain the incident and third-party cybersecurity experts were engaged to investigate and assist with the breach response. GCBHS said the forensic investigation is ongoing but evidence has been found that indicates an unauthorized third party accessed files containing patient information. The files are still being reviewed and notifications will be issued when that process has been completed. GCBHS said the compromised data includes names, demographic information, dates of birth, Social Security numbers, driver’s license numbers, medical information, and healthcare information. GCBHS said it has implemented additional security tools and will be offering the affected individuals complimentary credit monitoring and identity theft protection services. The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 50,000 patients. UPDATE: September 13,...

Read More
Legislation Proposed to Improve the Accuracy of Patient Matching
Feb21

Legislation Proposed to Improve the Accuracy of Patient Matching

New legislation has been introduced that seeks to establish standards and protocols to improve the matching of patients with their medical records and promote interoperability without increasing the burdens on providers and health systems. Adding patient data to the medical records of incorrect recipients can have serious consequences and it has been a problem that has plagued the healthcare industry for years. There have been many cases where incorrect matching has resulted in denied claims, medical errors, and even patient deaths. Patients with mismatched records often have to undergo unnecessary repeated medical tests, the cost of which can be considerable. Each instance of mismatched records costs an average of $1,950 per patient inpatient stay, and more than $1,700 per emergency department visit, and 35% of all denied claims are due to inaccurate patient identification. The HIPAA Journal was recently contacted by one patient who has been plagued by mismatching problems with her healthcare provider due to her having the same name and date of birth as another patient. The other...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist