NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024
May26

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has submitted its annual reports to Congress on compliance with the Health Insurance Portability and Accountability Act (HIPAA) and breaches of unsecured protected health information for calendar year 2024. The reports are a requirement of the Health Information Technology for Economic and Clinical Health (HITECH) Act and provide a snapshot of the state of compliance in healthcare, the actions taken by OCR in response to potential noncompliance, and the extent to which sensitive health information is being exposed or stolen. The reports to Congress are based on the number of data breaches that occurred in each calendar year, not the year in which the data breach was reported. In calendar year 2024, OCR received 742 reports of data breaches affecting 500 or more individuals; however, only 663 reports related to breaches that occurred in 2024. 2023 was a particularly bad year for large healthcare data breaches. In its previous reports to Congress, OCR reported that 732 large data breaches occurred in...

Read More
Mission Community Hospital Pays $1.55M to Settle Data Breach Lawsuit
May26

Mission Community Hospital Pays $1.55M to Settle Data Breach Lawsuit

Deanco Healthcare, LLC, the operator of Mission Community Hospital, an acute care hospital serving patients in the San Fernando Valley in California, has agreed to a settlement to resolve claims stemming from a cyberattack that was discovered by the hospital on May 1, 2023. According to the forensic investigation, the unauthorized access started the same day, and while the attack was quickly identified and contained, the threat actor exfiltrated files containing patient data such as names, addresses, dates of birth, Social Security numbers, driver’s license numbers, and financial account information. The Ransomhouse ransomware group took responsibility for the attack and claimed to have exfiltrated around 2.5 terabytes of data. The data breach was reported to the HHS’ Office for Civil Rights as affecting 269,547 individuals. Two class action lawsuits were filed in response to the data breach in the Superior Court of California for the County of Los Angeles, which were consolidated into a single action – Concepcion et al. v. Deanco Healthcare – as they had overlapping claims....

Read More

45 CFR 164.308(a)(5) Security Awareness and Training

45 CFR 164.308(a)(5) is the administrative safeguard provision of the HIPAA Security Rule that mandates security awareness and training for all workforce members of covered entities and business associates, establishing that organizations must “implement a security awareness and training program for all members of its workforce (including management)” and must address protection from malicious software, log-in monitoring, and password management as addressable implementation specifications within that program. The provision sits within the administrative safeguards category of the HIPAA Security Rule, which governs the policies, procedures, and workforce management activities that protect electronic Protected Health Information. Its placement in the administrative safeguards framework means that security awareness training is not a supplementary activity or a compliance courtesy. It is one of the required mechanisms through which an organization demonstrates that it manages its workforce’s relationship with electronic Protected Health Information in a controlled...

Read More
Home Healthcare Agency Owner Facing Decades in Jail for $1.6M Medicare Fraud Scheme
May22

Home Healthcare Agency Owner Facing Decades in Jail for $1.6M Medicare Fraud Scheme

The owner and operator of a Michigan home health care company has been convicted of five counts of healthcare fraud and four counts of paying illegal healthcare kickbacks and now faces decades in jail. Ruby Scott, 55, of Farmington Hills, Michigan, the owner and operator of Delta Home Health Care LLC, was alleged to have operated a fraud scheme that caused more than $1.6 million in losses to the Medicare program. From 2018 to 2021, Scott was alleged to have fraudulently billed Medicare for home health services using stolen patient records. Scott bribed a discharge nurse at a Detroit hospital to identify Medicare patients and fax their medical records to Delta Home Health Care. Scott developed a kickback relationship with the nurse, paying approximately $300 for each set of patient records that were successfully used to bill Medicare. The discharge nurse was paid more than $130,000 via PayPal, CashApp, cash, and check for providing the records. Scott used confidential diagnostic and personal information to bill Medicare for home healthcare services for the patients, falsely...

Read More
Datavant Group to Pay $900,000 to Settle Class Action Data Breach Lawsuit
May22

Datavant Group to Pay $900,000 to Settle Class Action Data Breach Lawsuit

A settlement has been agreed to resolve a class action lawsuit against Ciox Health, which does business as Datavant Group, an Arizona-based health IT company, over a May 2024 email-related data breach. Suspicious activity was identified within an employee’s email account on May 9, 2024. The forensic investigation confirmed that an unauthorized individual had access to the account between May 8 and May 9, 2024. Access to the account was gained after an employee responded to a phishing email. The breach was reported to the HHS’ Office for Civil Rights as affecting 320,702 individuals. Data potentially compromised in the incident included names, dates of birth, addresses, contact information, Social Security numbers, financial account information, driver’s license numbers, passport numbers, and health information. A lawsuit was filed in response to the data breach – Jackson v. Ciox Health, LLC d/b/a Datavant Group – in the United States District Court for the District of Arizona. The lawsuit alleged that the defendant failed to implement sufficient security measures to protect...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist