25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Mailing Error at CMS Vendor Affects 10,000 Medicare Beneficiaries

The Centers for Medicare & Medicaid Services (CMS) has started notifying certain Medicaid beneficiaries about an impermissible disclosure of some of their protected health information due to a mailing error at one of its contractors. The incident occurred at Palmetto GBA, which the CMS uses to handle claims. Between January 8 and January 29, 2023, Palmetto GBA mailed Medicare Summary Notices (MSNs) to Medicare recipients; however, a computer programming issue with its print mail services resulted in MSNs for the final quarter of 2022 being mailed to other Medicare beneficiaries within the same zip code. The programming error was discovered by Palmetto GBA on February 7, 2023, and reported the incident to the CMS the same day. The CMS then worked with Palmetto GBA to identify the individuals affected and determined the error had resulted in 10,011 MSNs intended for Medicare beneficiaries in Alabama, Georgia, and Tennessee being sent to incorrect individuals. The MSNs contained the Medicare beneficiary’s name, address, claim number, dates of service, the last four digits of their...

Read More
UHS-Delaware and UHS-Fuller Had Insufficient Workplace Violence Protections
Apr27

UHS-Delaware and UHS-Fuller Had Insufficient Workplace Violence Protections

UHS of Delaware Inc. and UHS of Fuller Inc. have been found to have exposed their employees to unacceptable risks from workplace violence at Fuller Hospital in Attleboro, Massachusetts, and subsequently destroyed evidence and failed to comply with their legal discovery obligations. UHS of Delaware and UHS of Fuller Inc. are subsidiaries of Universal Health Services, which is one of the largest providers of behavioral healthcare services in the United States. Fuller Hospital was inspected by the Occupational Safety and Health Administration (OSHA) in 2019 in response to complaints from UHS-Delaware and UHS-Fuller employees about insufficient safeguards against workplace violence. There were more than 500 incidents of aggression on hospital employees at Fuller Hospital over a 7-month period in 2019 in which employees were bitten, slapped, punched, kicked, and had their hair ripped out. Several employees suffered repeated concussions in those incidents. In December 2019, OSHA cited UHS of Delaware Inc. and UHS of Fuller Inc. for exposing employees to workplace violence. The companies...

Read More
DoE Issues New Guidance on FERPA and Student Health Records
Apr27

DoE Issues New Guidance on FERPA and Student Health Records

The U.S. Department of Education has issued new guidance for schools and postsecondary educational institutions reminding them of their obligations under the Family Educational Rights and Privacy Act (FERPA) to protect student privacy, emphasizing the importance of keeping student health records private. Guidance has also been issued for parents, legal guardians, and students over 18 years of age on their rights under FERPA (Know Your Rights) with respect to student health records. FERPA was enacted to protect the privacy of student records and give parents rights over their children’s educational records. FERPA applies to educational agencies such as school districts, educational institutions (including public elementary and secondary schools), and postsecondary educational institutions (including colleges or universities) that receive funding under any program administered by the U.S. Department of Education. The guidance for FERPA-covered educational institutions reminds them that parents and eligible students have the right to exercise some control over the disclosure of...

Read More

Healthcare Industry Facing Increased Malware and Ransomware Threats

Ransomware actors continue to target the U.S. healthcare sector, cybercriminals are increasingly using malware to steal data and provide persistent access to healthcare networks, and legitimate penetration tools are being used to mask malicious activity amongst genuine use of these tools by red teams. These are some of the findings from the latest Global Threat Intelligence Report from Blackberry, which is based on threats detected by its Cylance Endpoint Security solution over 90 days from December 2022 to February 2023. During that time, Blackberry detected up to 12 cyberattacks per minute and identified a massive increase in unique attacks using new malware samples, which increased by 50% from 1 per minute to 1.5 per minute in the most recent reporting period. The United States remains the most targeted country, although there has been a change in focus elsewhere, with Brazil now the second most targeted country followed by Canada. The same industry sectors are favored, with financial services, healthcare, and food/staples accounting for 60% of all malware-based attacks. The...

Read More
NIST Releases Discussion Draft of NIST CSF 2.0 Core
Apr26

NIST Releases Discussion Draft of NIST CSF 2.0 Core

The National Institute of Standards and Technology (NIST) is in the process of updating the NIST Cybersecurity Framework (CSF) 1.1 and plans to release the complete draft version 2.0 in the summer. A discussion draft has been published that includes updates to the Core elements of the Framework and NIST is seeking concrete suggestions on how the Framework can be improved ahead of the publication of the complete draft. The NIST CSF 2.0 Core covers the outcomes across the 6 Functions, 21 Categories, and 112 Subcategories and includes a sample of potential new CSF 2.0 Informative Examples. The discussion draft is not complete and is preliminary, and has been released to improve transparency and inform the development of the complete draft. Modifications have been made to the NIST CSF 1.1 to increase clarity, ensure a consistent level of abstraction, address changes in technologies and risks, and improve alignment with national and international cybersecurity standards and practices. NIST has received comments confirming version 1.1 of the Framework is still effective at addressing...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist