NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

176,200 Ortho Alaska Patients Affected by Data Breach

OrthoAlaska has recently notified the HHS’ Office for Civil Rights (OCR) about a HIPAA data breach that has affected 176,203 patients. At present, little is known about the data breach other than it being a hacking/IT incident in which patient information was exposed or stolen. There is currently no mention of the data breach on the OrthoAlaska website. The data exposure could potentially be linked to a data breach at OrthoAlaska in October 2022 that exposed the information of former employees. In that incident, it was determined on March 3, 2023, that employee data was involved, and notifications were issued on April 3, 2023. This post will be updated when further information is obtained. Physical Therapy Patients in New York Had PHI Exposed in Cyberattack Patients of Physio Logic Chiropractic and Physical Therapy, Physio Logic Medicine, and Dr. Patty DiBlasio have had some of their protected health information exposed in a cyberattack. The cyberattack was detected on July 31, 2023, and a comprehensive investigation was launched to determine the nature and scope of the...

Read More
Big Tech and Health Data: How the Landscape is Changing
Oct09

Big Tech and Health Data: How the Landscape is Changing

The relationship between big tech and health data has been a concern for more than a decade due to fears about the monetization of individuals’ health information and the security of data. Now, federal and state regulators are taking steps to force big tech to be more transparent about what health data is collected, how it is used, and how it is protected. The relationship between big tech and health data started almost a quarter of a century ago when, in 1999, Microsoft invested $250 million into the online health and well-being website WebMD. To ensure the success of the venture, Microsoft also underwrote $150 million in doctor subscriptions and $100 million in commitments to sell advertising and sponsorships. Over the next ten years, Microsoft expanded its interest in the healthcare ecosystem with the acquisition of the integrated hospital information platform Azyxxi (now GE Caradigm), the workflow and patient safety system, Global Care Solutions, and the genetic, genomic, metabolomic, and proteomic data management solution Rosetta Biosoftware. As later-developing tech companies...

Read More

HIPAA Compliant SFTP Server

If FTP is required to transfer protected health information, healthcare providers, health plans, healthcare clearinghouses and business associates of HIPAA-covered entities must ensure their service provider uses a HIPAA compliant sFTP server. FTP is a convenient way of sending/receiving medical transcriptions, transmitting electronic medical records and test results, and for transferring files containing ePHI to cloud storage.  However, FTP communications are not secure and file transfers can easily be intercepted. Consequently, healthcare organizations and their business associates must avoid sending any protected health information over FTP. Doing so would be a violation of the HIPAA Security Rule. HIPAA Security Standard §164.306 requires covered entities to ensure the confidentiality, integrity, and availability of ePHI is safeguarded at rest and in transit. In order to send ePHI securely, HIPAA-covered entities can use a secure FTP server. A secure FTP server uses the Secure File Transfer Protocol rather than the generic file transfer protocol to send and receive files,...

Read More
HIPAA Civil Monetary Penalty Adjustments for 2023
Oct06

HIPAA Civil Monetary Penalty Adjustments for 2023

On October 6, 2023, the U.S. Department of Health and Human Services (HHS) published its long-expected annual inflation adjustments in the Federal Register. The inflation adjustments are effective as of October 6, 2023, and will be applied to all penalties assessed by the Office for Civil Rights (OCR) on or after this date, if the HIPAA violations occurred on or after November 2, 2015. Annual increases in inflation are authorized by the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015, which amended the Federal Civil Penalties Inflation Adjustment Act of 1990. Each year, civil monetary penalties (CMPs) are increased in line with inflation to ensure they remain an effective deterrent against non-compliance. The Office of Management and Budget (OMB) published a cost-of-living multiplier of 1.07745 for 2023 in December 2022 and required all federal agencies to update their CMPs using the multiplier by January 15, 2023. The HHS is often slow to apply the adjustments. OBM is expected to publish its 2024 multiplier in a little over two months, but no later than...

Read More

Best Practices for Creating an Email Archiving Policy

Applying best practices for creating an email archiving policy enable businesses to create a formal email archiving policy that establishes how long emails should be retained before being permanently and securely deleted to ensure compliance with federal, state, and industry regulations. Emails are considered to be just as important as written documents, and regulators and the courts do not take kindly to poor email retention practices and emails that cannot be produced when requested. Read about email retention requirements in our recent HIPAA compliant email retention solution review. If you are requested to provide emails by regulators such as the HHS’ Office for Civil Rights for an audit or compliance investigation, you receive an eDiscovery request, or there is a legal issue, the consequences of not being able to produce emails can be severe. Financial penalties may be imposed, and your organization’s reputation can be damaged. By formalizing an email archiving policy and automating the policy using an email archiving solution, you will be able to eliminate the potential for...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist