25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Organizations Face Increased Scrutiny of Health Data Breaches

Healthcare hacking incidents are increasing, there are new regulatory requirements and compliance initiatives due to Dobbs and Pixel use, and lawsuits against healthcare organizations over privacy violations are soaring. HIPAA-regulated entities and other organizations that operate in the healthcare space are now facing increased scrutiny of their data security practices and compliance programs, and the coming 12 months will likely see an increase in enforcement actions and lawsuits over privacy violations. The recently published BakerHostetler Data Security Incident Response Report (DSIR) draws attention to these issues and provides insights into the threat landscape to help organizations determine how to prioritize their efforts and investments. The report, now in its 9th year, was based on 1,160 security incidents managed by BakerHostetler’s Digital Assets and Data Management Practice Group in 2022. After a surge in ransomware attacks in 2021, 2022 saw a reduction in attacks; however, there was a surge in ransomware activity toward the end of the year and that surge has...

Read More

Mailing Error at CMS Vendor Affects 10,000 Medicare Beneficiaries

The Centers for Medicare & Medicaid Services (CMS) has started notifying certain Medicaid beneficiaries about an impermissible disclosure of some of their protected health information due to a mailing error at one of its contractors. The incident occurred at Palmetto GBA, which the CMS uses to handle claims. Between January 8 and January 29, 2023, Palmetto GBA mailed Medicare Summary Notices (MSNs) to Medicare recipients; however, a computer programming issue with its print mail services resulted in MSNs for the final quarter of 2022 being mailed to other Medicare beneficiaries within the same zip code. The programming error was discovered by Palmetto GBA on February 7, 2023, and reported the incident to the CMS the same day. The CMS then worked with Palmetto GBA to identify the individuals affected and determined the error had resulted in 10,011 MSNs intended for Medicare beneficiaries in Alabama, Georgia, and Tennessee being sent to incorrect individuals. The MSNs contained the Medicare beneficiary’s name, address, claim number, dates of service, the last four digits of their...

Read More
UHS-Delaware and UHS-Fuller Had Insufficient Workplace Violence Protections
Apr27

UHS-Delaware and UHS-Fuller Had Insufficient Workplace Violence Protections

UHS of Delaware Inc. and UHS of Fuller Inc. have been found to have exposed their employees to unacceptable risks from workplace violence at Fuller Hospital in Attleboro, Massachusetts, and subsequently destroyed evidence and failed to comply with their legal discovery obligations. UHS of Delaware and UHS of Fuller Inc. are subsidiaries of Universal Health Services, which is one of the largest providers of behavioral healthcare services in the United States. Fuller Hospital was inspected by the Occupational Safety and Health Administration (OSHA) in 2019 in response to complaints from UHS-Delaware and UHS-Fuller employees about insufficient safeguards against workplace violence. There were more than 500 incidents of aggression on hospital employees at Fuller Hospital over a 7-month period in 2019 in which employees were bitten, slapped, punched, kicked, and had their hair ripped out. Several employees suffered repeated concussions in those incidents. In December 2019, OSHA cited UHS of Delaware Inc. and UHS of Fuller Inc. for exposing employees to workplace violence. The companies...

Read More
DoE Issues New Guidance on FERPA and Student Health Records
Apr27

DoE Issues New Guidance on FERPA and Student Health Records

The U.S. Department of Education has issued new guidance for schools and postsecondary educational institutions reminding them of their obligations under the Family Educational Rights and Privacy Act (FERPA) to protect student privacy, emphasizing the importance of keeping student health records private. Guidance has also been issued for parents, legal guardians, and students over 18 years of age on their rights under FERPA (Know Your Rights) with respect to student health records. FERPA was enacted to protect the privacy of student records and give parents rights over their children’s educational records. FERPA applies to educational agencies such as school districts, educational institutions (including public elementary and secondary schools), and postsecondary educational institutions (including colleges or universities) that receive funding under any program administered by the U.S. Department of Education. The guidance for FERPA-covered educational institutions reminds them that parents and eligible students have the right to exercise some control over the disclosure of...

Read More

Healthcare Industry Facing Increased Malware and Ransomware Threats

Ransomware actors continue to target the U.S. healthcare sector, cybercriminals are increasingly using malware to steal data and provide persistent access to healthcare networks, and legitimate penetration tools are being used to mask malicious activity amongst genuine use of these tools by red teams. These are some of the findings from the latest Global Threat Intelligence Report from Blackberry, which is based on threats detected by its Cylance Endpoint Security solution over 90 days from December 2022 to February 2023. During that time, Blackberry detected up to 12 cyberattacks per minute and identified a massive increase in unique attacks using new malware samples, which increased by 50% from 1 per minute to 1.5 per minute in the most recent reporting period. The United States remains the most targeted country, although there has been a change in focus elsewhere, with Brazil now the second most targeted country followed by Canada. The same industry sectors are favored, with financial services, healthcare, and food/staples accounting for 60% of all malware-based attacks. The...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist