25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Western Washington Medical Group Reports 350,000-Record Data Breach

Western Washington Medical Group, a team of more than 100 providers serving patients in Snohomish, Skagit, Island, and Whatcom counties in Washington state, has recently reported a data breach to the HHS’ Office for Civil Rights (OCR) that has affected up to 350,863 patients. Western Washington Medical Group identified a security breach on August 26, 2023, and immediately shut off access to the network. A third-party cybersecurity firm was engaged to investigate the breach and determined that patient data had been exposed. The exposed data varied from individual to individual and may have included first and last name, address, Social Security number, date of birth, medical record number, health insurance policy number, medical history, mental/physical condition, medical diagnosis, and/or treatment information. The breach was reported to OCR on October 26, 2023, and individuals were notified on November 6, 2023. Western Washington Medical Group said that at the time of issuing notifications, no evidence had been found to indicate any actual or attempted misuse of patient data;...

Read More

Doctors’ Management Services Settles OCR HIPAA Probe for $100,000

The HHS’ Office for Civil (OCR) has agreed to a $100,000 settlement with Doctors’ Management Services to resolve an investigation of a ransomware attack and data breach that uncovered multiple potential violations of the HIPAA Security Rule. Doctors’ Management Services (DMS) is a Massachusetts-based medical management company whose services include medical billing and payor credentialing. DMS identified an intrusion on December 24, 2018, when GandCrab ransomware was used to encrypt files on its network. The forensic investigation confirmed the attackers first gained access to its network on April 1, 2017. According to DMS, the threat actor gained access to its network via Remote Desktop Protocol (RDP) on one of its workstations and potentially obtained names, addresses, dates of birth, Social Security numbers, insurance information, Medicare/Medicaid ID numbers, driver’s license numbers, and diagnostic information. The breach was reported to OCR on April 22, 2019, as affecting up to 206,695 individuals. OCR opened an investigation of the breach to determine whether DMS had...

Read More
OCR Video Explains How to Improve Cybersecurity Defenses Through HIPAA Security Rule Compliance
Oct31

OCR Video Explains How to Improve Cybersecurity Defenses Through HIPAA Security Rule Compliance

The HHS’ Office for Civil Rights has released a video in recognition of National Cybersecurity Awareness Month that explains how compliance with the HIPAA Security Rule can help HIPAA-regulated entities defend against cyberattacks. The video features Nick Heesters, Senior Advisor for Cybersecurity for the Health Information Privacy, Data, and Cybersecurity Division of the HHS’ Office for Civil Rights, who discusses some of the real-world cyberattack trends identified by OCR from breach reports. There has been a massive increase in healthcare data breaches since the HIPAA Breach Notification Rule was enacted. In 2010, the first full year of breach report data, OCR received 199 reports of healthcare data breaches of 500 or more records. More than 700 data breaches were reported in both 2021 and 2022, and 2023 looks set to become the third successive year with more than 700 reported data breaches. In the year to September 30, 2023, hacking and other IT incidents accounted for 77% of all large data breaches, compared to just 49% of incidents in 2009, and as of September 30, 2023, more...

Read More
AAFP Shares Views on State of MACRA and Makes Policy Recommendations
Oct31

AAFP Shares Views on State of MACRA and Makes Policy Recommendations

The American Academy of Family Physicians (AAFP) has responded to a request for information from Congress on a potential solution to address financial uncertainties in the healthcare system associated with Medicare that have been getting progressively worse for years and were exacerbated by the COVID-19 pandemic. In 2015, the Medicare Access and CHIP Reauthorization Act (MACRA) was signed into law and replaced the sustainable growth rate (SGR) formula with the Quality Payment Program (QPP). MACRA changed Medicare’s approach to physician payment to paying providers based on quality, value, and the results of care delivered, instead of the old system that was based on the number of services provided. While the United States invests more in healthcare than many other Western countries, the United States faces poorer healthcare outcomes and has a critical shortage of healthcare providers. One of the problems that has contributed to this is the Medicare Payment System, which has failed to maintain levels of provider reimbursement that adequately incentivize high-quality care. Congress...

Read More
OSHA’s Mission is to Ensure Safe Workplaces
Oct31

OSHA’s Mission is to Ensure Safe Workplaces

OSHA’s mission is to ensure safe workplaces and, to help fulfil this mission, OSHA has the authority to develop and enforce standards that ensure safe and healthy working conditions. OSHA’s mission to ensure safe workplaces is supported by multiple initiatives. For example: OSHA provides training programs for members of the public. OSHA provides tools and resources for in-house safety training. OSHA provides on-site compliance assistance to employers. OSHA responds to safety complaints made by employees. OSHA investigates all workplace fatalities and catastrophes. OSHA receives reports of workplace injuries and illnesses. OSHA provides training grants to non-profit organizations. OSHA publishes safety and health posters, fact sheets, and advice. OSHA organizes workplace safety programs with labor groups. The Occupational Safety and Health Administration (OSHA) was created in 1971 following the passage of the Occupational Safety and Health Act (OSH Act) a year earlier. OSHA’s mission is to ensure safe workplaces in order to reduce the human and economic costs of avoidable injuries...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist