NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Community First Medical Center Suffers 216K-Record Data Breach

Community First Medical Center in Chicago, IL, has started notifying 216,047 patients about a cyberattack that saw an unauthorized third party gain access to its computer systems on July 12, 2023. According to the September 26, 2023, breach notifications, a forensic investigation was launched that determined on July 28, 2023, that the third party had accessed files that contained patients’ protected health information. The types of information compromised in the incident varied from individual to individual and may have included full names, telephone numbers, email addresses, Social Security numbers, medical record numbers, and Medicare numbers. Community First Medical Center said it is unaware of actual or attempted misuse of patient information; however, as a precaution, individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring services. Community First Medical Center said many precautions had been taken prior to the cyberattack to secure patient data and that it will evaluate and modify its security practices to prevent...

Read More

CareSource Facing Multiple Class Action Lawsuits Over MOVEit Data Breach

The Dayton, OH-based Medicaid and Medicare plan provider, CareSource, is facing multiple class action lawsuits over a recent cyberattack and data breach. The Clop threat group exploited a zero-day vulnerability in the MOVEit Transfer file transfer solution and obtained the protected health information of 3,180,537 individuals, including names, addresses, date of birth, Social Security Numbers, health plan information, medications, and other health information. CareSource was notified by Progress Software about the vulnerability on May 31, 2023, and patched the flaw on June 1, 2023; however, the vulnerability had already been exploited. CareSource confirmed the breach on June 27, 2023, and notified the affected individuals on August 24, 2023. 2 years of complimentary credit monitoring and identity theft protection services were offered to the affected individuals. Several lawsuits have now been filed against CareSource in response to the data breach. On September 13, 2023, a lawsuit was filed in the U.S. District Court for the Southern District of Ohio Western Division on behalf of...

Read More

Oak Valley Hospital District Cyberattack Impacts 284K Patients

Oak Valley Hospital District in Oakdale, CA, has recently notified 283,629 patients about a cybersecurity incident that exposed their sensitive information. Suspicious activity was detected within its IT systems on July 18, 2023, and the subsequent forensic investigation confirmed that an unauthorized third party had access to its systems from April 21, 2023, to July 18, 2023. During that time, files used for billing and treatment purposes may have been viewed or stolen. The files contained protected health information such as names, health insurance information, Social Security numbers, and information related to the care provided. Individuals who had their Social Security numbers exposed have been offered complimentary credit monitoring and identity theft protection services. Oak Valley Hospital District said it has strengthened system security and will continue to assess and enhance its security protocols to prevent further data breaches. Mountrail County Medical Center Affected by Cyberattack on DMS Health Technologies Mountrail County Medical Center in Stanley, ND, has been...

Read More

IBM and Johnson & Johnson Health Care Systems Sued Over August 2023 Data Breach

A lawsuit has been filed against IBM Corp. and Johnson & Johnson Health Care Systems Inc. over an August 2023 data breach that exposed the protected health information of thousands of people who used the Janssen CarePath patient assistance program. IBM is a business associate of Johnson & Johnson and manages the application and database that supports the Janssen CarePath platform. After being notified about a technical issue within the platform that could be exploited to gain access to sensitive data, IBM investigated and discovered there had been unauthorized access on August 2, 2023. The information accessed by an unauthorized third party included names, contact information, dates of birth, health insurance information, medications, and healthcare conditions. Affected individuals were offered complimentary credit monitoring services for 12 months. It is currently unclear how many patients were affected. Last year 1,16 million patients used the Janssen CarePath patient assistance program. On September 22, 2023, a class action lawsuit was filed in the US District Court for...

Read More

HITECH Act and Meaningful Use

When the HITECH ACT and Meaningful Use incentive program was enacted in 2009, it was described as “the most important piece of healthcare legislation to be passed in the last 20 to 30 years” and “the foundation for health care reform”. Not only did the HITECH Act and Meaningful Use incentive program aim to have every US citizen´s health information electronically accessible within five years, it also introduced new measures to protect the integrity of electronic Protected Health Information (ePHI). One of the key measures introduced by the HITECH Act and Meaningful Use incentive program was to make Business Associates and subcontractors liable for any unauthorized disclosures of ePHI attributable to their own negligence. Previously, Business Associates and subcontractors could avoid liability for breaches of ePHI by claiming they were unaware of the requirement to be HIPAA compliant. HITECH closed that loophole. Other Measures Introduced in the HITECH Act and Meaningful Use Program Several other measures were introduced in the HITECH ACT and Meaningful Use incentive...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist