NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What Does the Acronym OSHA Stand For?
Oct03

What Does the Acronym OSHA Stand For?

The acronym OSHA stands for the Occupational Safety and Health Administration – an agency within the Department of Labor that was created in 1971 following the passage of the Occupation Safety and Health Act (referred to as the OSH Act to avoid confusion about what the acronym OSHA stands for). The agency is responsible for: Reducing the human and economic cost of workplace accidents. Developing workplace safety and health standards in the United States. Providing technical and compliance assistance, education, and training. Establishing recordkeeping requirements for workplace injuries and illnesses. Establishing workplace safety and health rights for employees. Enforcing standards through inspections, citations, and/or penalties. Working in partnership with states that operate their own safety and health programs. Prior to the creation of OSHA, the task of workplace safety and health was the responsibility of the Bureau of Labor Standards. However, as the economy expanded during the 1960s, workplace injury rates started to increase. Congress believed a new agency was necessary to...

Read More

Bienville Orthopaedic Specialists Sued Over March 2023 Data Breach

Bienville Orthopaedic Specialists in Gautier, Mississippi, is being sued by a patient whose protected health information was stolen in a February 2023 cyberattack. Bienville Orthopaedic Specialists identified unauthorized activity within its IT systems on March 5, 2023. The forensic investigation confirmed an unauthorized individual had access to its computer systems between February 3, 2023, and March 5, 2023, and exfiltrated sensitive data including names, Social Security numbers, medical information, health insurance information, usernames and passwords, financial account information, and driver’s license numbers. Complimentary credit monitoring and identity protection services were offered to the affected individuals. The lawsuit was filed by attorney Justin G. Witkin from the law firm Justin G. Witkin in the US District Court for the Southern District of Mississippi on behalf of Bienville patient Robert Harris. The lawsuit alleges Bienville failed to implement reasonable and appropriate security measures to ensure the privacy of its patients, did not follow industry standards...

Read More
AHA Calls for HHS to Drop Website Tracking Technology Rule
Oct02

AHA Calls for HHS to Drop Website Tracking Technology Rule

The American Hospital Association (AHA) has called for Congress to urge the Department of Health and Human Services to withdraw its new rule that prohibits HIPAA-regulated entities from using online tracking technologies on their websites and applications. The AHA represents more than 5,000 member hospitals, health systems, and other healthcare organizations, and its clinician partners include more than 270,000 affiliated physicians and 2 million nurses and other caregivers. The AHA requested the withdrawal of the rule in its response to Sen. Bill Cassidy’s recent request for information on health information privacy and the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Online tracking technologies include Google Analytics and Meta Pixel code, which are used by hospitals for collecting and analyzing information about how individuals interact on their websites. The information collected through these tools helps hospitals to make improvements to their online portals and provide relevant and reliable health information to their communities. A study conducted in...

Read More

Amerita Named in Class Action Lawsuit Over Data Breach at PharMerica

The specialty infusion company Amerita is facing a class action lawsuit over a recent cyberattack and data breach at its parent company, PharMerica. On September 5, 2023, suspicious activity was detected within the computer networks of PharMerica and Amerita. The forensic investigation confirmed that an unauthorized third party gained access to its systems between March 12 and March 13, 2023, and potentially accessed the sensitive data of 5.8 million individuals. PharMerica reported the breach on behalf of itself and its parent company, BrightSpring Health Services. The personal and protected health information of almost 220,000 Amerita patients was also compromised in the attack, including names, addresses, diagnoses, medications, and health insurance information. The Money Message ransomware group claimed responsibility for the attack and claimed on its data leak site to have stolen 4.7 terabytes of data, and then proceeded to leak certain files, some of which contained patient data. Class action lawsuits have already been filed against PharMerica over the data breach, and now a...

Read More
Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors
Oct02

Cybersecurity Awareness Month 2023 Focuses on 4 Key Behaviors

The Cybersecurity and Infrastructure Security Agency (CISA) has launched a new cybersecurity awareness program – Secure Our World – through which the agency will be promoting behavioral change across the nation. The aim of the campaign is to get individuals, families, and small- to medium-sized businesses to take action every day to protect themselves while online and when using connected devices. The new campaign was launched as part of Cybersecurity Awareness Month, which this year focuses on four key behaviors that can greatly improve security when they are consistently adopted across an organization: Using strong passwords and a password manager Implementing multifactor authentication Learning how to recognize phishing and reporting phishing attempts Updating software promptly While organizations should consider transitioning to passwordless authentication, until it can be fully implemented it is vital to ensure that password best practices are followed. Strong, unique passwords should be sent for each account, with passwords consisting of random letters, numbers, and special...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist