NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

PurFoods Sued Over 1.2 Million-Record Mom’s Meal Data Breach

PurFoods LLC is being sued over a cyberattack that exposed the personally identifiable information (PII) and protected health information (PHI) of 1,237,681 individuals who used the services of its subsidiary, Mom’s Meals. Through Mom’s Meals, PurFoods provides a food delivery service for Medicare, Medicaid, and self-pay individuals with chronic health conditions. According to the Mom’s Meals data breach notifications, the company experienced a cyberattack that saw unauthorized individuals access its network between January 16 and February 22, 2023, and deploy software (ransomware) to encrypt files on the network. While data theft was not confirmed, the possibility of data exfiltration could not be ruled out. The review of the affected files was completed on July 10, 2023, and confirmed that names, Social Security numbers, driver’s license numbers, state identification numbers, financial account and payment card information, medical record numbers, health information, treatment information, diagnosis codes, meal categories and costs, health insurance information and patient...

Read More

Health Care Service Corporation Facing Class Action Data Breach Lawsuit

A lawsuit has been filed against the Chicago, IL-based health insurer and Blue Cross Blue Shield licensee, Health Care Service Corporation (HCSC), over a recently disclosed data breach that affected 192,231 of its members. HCSC experienced a cyberattack on or around June 21, 2023, and determined the threat actors had access to member information such as names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, claim numbers, bank account numbers, and medical service information. Notification letters were sent to the affected individuals on August 21, 2023. A lawsuit was recently filed in the Circuit Court of Cook County in Illinois on behalf of plaintiff Elizabeth Slaughter and other similarly situated individuals. The lawsuit alleges HCSC disregarded the rights of the plaintiff and class members by “intentionally, willfully, recklessly, or negligently failing to take and implement adequate and reasonable measures to ensure PHI/PII was safeguarded,” such as encrypting data on its network, and HCSC did not meet its data security obligations under the...

Read More
Is Airdroid Business HIPAA Compliant?
Sep20

Is Airdroid Business HIPAA Compliant?

Airdroid is a HIPAA-compliant all-in-one Android Mobile Device Management (MDM) solution for small businesses and enterprises that can be used by HIPAA-covered entities and their business associates to improve privacy and comply with many provisions of the HIPAA Security Rule.  Managing increasing numbers of mobile devices can be a major challenge for healthcare organizations. Mobile devices can be used to access and store protected health information and if a device is lost or stolen, sensitive data could easily be exposed. Vulnerabilities in mobile devices and mobile applications can easily be missed and can be exploited by malicious actors to gain access to PHI. Compromised devices may also be used as a stepping stone in a broader attack on the organization. The problem for IT teams is they often do not have visibility into mobile devices so ensuring the devices are kept up to date and secured can be a major challenge. An MDM solution makes managing mobile devices much more straightforward. These solutions provide IT teams with full visibility into their mobile devices, no...

Read More
August 2023 Healthcare Data Breach Report
Sep20

August 2023 Healthcare Data Breach Report

There was a 21.4% month-over-month increase in healthcare data breaches in August. 68 data breaches of 500 or more records were reported to the HHS’ Office for Civil Rights, which makes August the second-worst month of the year for data breaches, with reported data breaches reported well above the 2023 monthly average of 58.2 data breaches per month. 463 healthcare data breaches have been reported this year up to August 31, 2023 – a slight increase from the 460 data breaches reported in the corresponding period last year. While there was a 34.3% month-over-month fall in the number of breached records, July’s total was exceptionally high. In August, almost 12 million records were reported as having been exposed or stolen, which is well above the 2023 average of 7.49 million records a month. So far in 2023, the records of 71,479,579 individuals have been exposed or stolen. At this time last year, 29.27 million records had been breached, and 2022 was a bad year for breached healthcare data. If healthcare data breaches continue to occur at the scale seen in the first 8 months of...

Read More
What Does OSHA Stand for in Medical Terms?
Sep19

What Does OSHA Stand for in Medical Terms?

What OSHA stands for in medical terms is the standards adopted by the Occupational Safety and Health Administration to increase the safety and health of employees in the healthcare industry. There can be many benefits of OSHA compliance for medical facilities. These benefits include: A reduction in workplace injuries and illnesses Increased workforce productivity Increased workforce retention Easier workforce recruitment Protection against liability Lower insurance costs Compliance with other standards “Another Set of Standards That Have to be Complied With” You can understand the frustration of a healthcare compliance team who have got everything in place to comply with HIPAA, CMS’ Conditions for Participation in Medicare, ADA, the 21st Century Cures Act, the FD&C Act, and a host of other state and federal healthcare regulations, when a member of the legal team asks the question “What does OSHA stand for in medical terms?”. The appropriate answer to the question is that OSHA stands for the Occupational Safety and Health Administration – an agency of the Department of...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist