NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OSHA Increases Penalties for Workplace Health and Safety Violations
Jan15

OSHA Increases Penalties for Workplace Health and Safety Violations

The Occupational Safety and Health Administration (OSHA) has increased the minimum and maximum civil monetary penalties (CMPs) for workplace safety violations, as required by the Federal Civil Penalties Inflation Adjustment Act. To maintain the deterrent effect of CMPs and to promote compliance with the law, the Federal Civil Penalties Inflation Adjustment Act requires an annual adjustment of CMPs to account for inflation. Each year, the Office of Management and Budget (OMB) calculates an inflation multiplier, and all federal agencies are required to apply that multiplier to their CMP structures by January 15. For 2024, the OMB has calculated a multiplier of 1.03241 to reflect the cost-of-living increase over the past 12 months. OSHA confirmed the cost-of-living increase in a final rule published in the Federal Register on January 11, 2023. The final rule is effective on January 15, 2024, and will apply to all citations issued by OSHA on or after January 16, 2024. The new penalty structure also applies to open inspections that commenced before January 16, 2024. The new CMP...

Read More
Is Google Hangouts HIPAA Compliant?
Jan15

Is Google Hangouts HIPAA Compliant?

The Google services that were formerly known as Google Hangouts are HIPAA compliant, and can be used to collect, transmit, and share Protected Health Information (PHI) provided they are used as part of a Google Workspaces account that supports HIPAA compliance. It is also necessary for HIPAA-covered customers to agree to Google’s Business Associate Addendum before disclosing PHI on a Google Hangouts service. Google Hangouts was launched in 2013 as a cross-platform messaging service that evolved into a popular chat, voice, and video communication tool. Originally offered free of charge to personal customers, and later as part of the G Suite service to enterprise customers, Hangouts came under increasing competition from rival messaging services such as iMessage, WhatsApp, and Facebook Messenger. To give Hangouts a more meaningful identity, the service was divided into two individual services in 2017 which were renamed Hangouts Chat and Hangouts Meet. The two new services underwent a further rebranding in 2020 – to Google Chat and Google Meet – when the enterprise G Suite...

Read More
Interview: Marc Haskelson, CEO, Compliancy Group
Jan14

Interview: Marc Haskelson, CEO, Compliancy Group

The HIPAA Journal has spoken with Marc Haskelson, CEO of Compliancy Group. Marc explains to readers of The HIPAA Journal why he formed Compliancy Group, what the company offers, the challenges with compliance, and predictions on future regulations in healthcare. Tell the readers about your career in the healthcare industry. My involvement in healthcare started when I was the CEO of a healthcare product business. I founded Compliancy Group after a bad experience trying to satisfy HIPAA. At the time, the options were limited—hire an expensive consultant or combine tools to meet the somewhat confusing law. The real growth came as the Omnibus Rule went into effect, mandating that healthcare vendors had the same obligation to HIPAA law. What was your first position? My earlier career was with Experian and the early days of subscription and continuity billing technology before we all called it SaaS. What is your current position? President and CEO of Compliancy Group What are the main challenges in your position? As risks have increased, we must continually expand our products and...

Read More

ReproSource Fertility Diagnostics Proposes $1.25 Million Class Action Data Breach Settlement

ReproSource Fertility Diagnostics has proposed a settlement to resolve litigation stemming from a 2021 ransomware attack that potentially resulted in the theft of the sensitive health data of up to 350,000 patients. The Marlborough, MA-based fertility testing laboratory, which is owned by Quest Diagnostics, had its network breached on August 8, 2021. The intrusion was detected on August 10 when ransomware was deployed. The forensic investigation confirmed that the parts of the network that the threat actors could access included files that contained sensitive health information. The data exposed included names, addresses, phone numbers, email addresses, dates of birth, billing, and health information, such as CPT codes, diagnosis codes, test requisitions, and results, test reports and/or medical history information, health insurance or group plan identification names and numbers, and other information provided by individuals or by treating physicians, and for a limited number of individuals, Social Security numbers, financial account numbers, driver’s license numbers, passport...

Read More

HMG Healthcare Data Breach Affects 80,000 Individuals

HMG Healthcare, LLC, a Texas-based healthcare services provider, has recently confirmed that the protected health information of up to 80,000 individuals was exposed and potentially stolen in a cyberattack that was detected in November 2023. A forensic investigation was launched after suspicious network activity was detected, which confirmed that unauthorized individuals first gained access to its network in August 2023. The investigation also confirmed that unencrypted files were copied but it “was not feasible” to identify exactly what types of information were obtained by the hackers. It is unclear why that determination was made, such as whether there was insufficient logging or if a comprehensive review would prove too timely and costly. HMG Healthcare said the files that were removed from its network likely contained information such as names, dates of birth, contact information, general health information, medical treatment information, Social Security numbers, and/or employment records. The exact nature of the attack was not disclosed; however, HMG Healthcare did explain...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist