25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

How Can You Report a Company to OSHA?
Sep11

How Can You Report a Company to OSHA?

You can report a company to OSHA by phone, mail, email, fax, visiting an OSHA office, or via an online report form. Some channels of communication are more appropriate than others for reporting urgent issues, and these are the things you should consider before you report a company to OSHA: Are you reporting a violation of an OSHA standard? Have you evidence to support your report? Do you have all the detail you need to report a company to OSHA? Which is the most appropriate reporting method? Reporting a Violation of an OSHA Standard When you report a company to OSHA for violating a safety and health standard, your report will be dealt with quicker if you are able to indicate which specific standard(s) your report relates to. OSHA’s website provides a full list of Occupational Safety and Health Standards and the option exists to search the Standards by keyword. If you are uncertain about which standards apply to your report, the website can also be searched by most reported topics (i.e., heat, PPE, hazard communication, etc.) or by most reported industry sector (i.e., agriculture,...

Read More
Kaiser Pays $49 Million to Settle Improper Disposal Investigation
Sep11

Kaiser Pays $49 Million to Settle Improper Disposal Investigation

California Attorney General Rob Bonta has announced a $49 million settlement has been reached with Kaiser Foundation Health Plan Foundation Inc. and Kaiser Foundation Hospitals to resolve allegations of improper disposal of hazardous waste, medical waste, and protected health information. Oakland, CA-based Kaiser is the largest healthcare provider in California with more than 700 healthcare facilities in the state, serving more than 8.8 million patients. An investigation was launched by 6 district attorneys from Alameda, San Bernardino, San Francisco, San Joaquin, San Mateo, and Yolo counties into the unlawful dumping of dangerous items.  Undercover staff from the district attorneys’ offices inspected dumpsters at 16 different Kaiser facilities. The dumpsters were not secured and the contents were destined for disposal in landfill sites. The inspectors found hundreds of items of hazardous and medical waste, including aerosols, cleansers, sanitizers, batteries, syringes, medical tubing containing body fluids, pharmaceuticals, and electronic wastes. The dumpsters also contained...

Read More

Lifeline Systems Company Notifies Patients About August 2022 Cyberattack

Lifeline Systems Company, a Marlborough, MA-based provider of patient alarm systems has recently notified 74,849 individuals about a data breach that occurred more than a year ago. According to the notification letters, unusual network activity was detected on August 6, 2022. Incident response protocols were immediately initiated, and a third-party computer forensic investigation was launched to investigate the nature of the incident. The investigation confirmed that an unauthorized individual had access to its systems from July 27, 2022, to August 6, 2022, and accessed certain documents on its systems during that period. On August 18, 2022, Lifeline determined the documents included information for subscribers, employees, and individuals eligible to receive Lifeline services. The exposed information included names, driver’s license numbers, and Social Security numbers. Due to the length of time taken to perform the document review, notification letters could not be sent until September 7, 2023. Complimentary credit monitoring services have been offered to individuals who had their...

Read More

Cyberattacks Reported by Bienville Orthopaedic Specialists and Just Kids Dental

A round-up of data breaches that have recently been reported to the HHS’ Office for Civil Rights, state Attorneys General, and the media. 242,986 Patients Had PHI Compromised in Cyberattack on Bienville Orthopaedic Specialists Bienville Orthopaedic Specialists in Gautier, MS, has reported a data breach to the Maine Attorney General that has affected up to 242,986 patients. A security breach was detected on March 5, 2023, and systems were immediately taken offline to prevent further unauthorized access. A forensic investigation was initiated to determine the nature and scope of the attack, which confirmed there had been unauthorized access to its systems between February 3, 2023, and March 5, 2023. The threat actor acquired files from its systems on March 4, 2023. The review of the affected files was completed on July 31, 2023, and it was determined that names and Social Security numbers had been compromised. Additional technical safeguards have now been implemented to prevent similar incidents in the future. Credit monitoring services are being offered to the affected individuals...

Read More

IBM Notifies Janssen CarePath Patients About Unauthorized Database Access

IBM has recently announced that the sensitive data of patients of the Johnson & Johnson Health Care Systems subsidiary, Janssen CarePath, has been exposed. IBM is a business associate of Johnson & Johnson and manages the application and database that supports the Janssen CarePath platform. Janssen recently became aware of a method that could be used by unauthorized individuals to gain access to the database and notified IBM, which worked with the database provider and remediated the problem. IBM also conducted an investigation to determine if the database had been accessed by unauthorized individuals and confirmed unauthorized access had occurred on August 2, 2023; however, it was not possible to determine the nature of the access and if patient data had been exfiltrated. Since patient data may have been accessed, IBM has issued notification letters to the affected Janssen CarePath customers. The data exposed included names in combination with one or more of the following data types: contact information, date of birth, health insurance information, medications, and...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist