NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Evergreen Treatment Services Hacking Incident Affects 21K Patients

Evergreen Treatment Services, a Washington-based provider of addiction treatment services, announced on February 13, 2023, that unauthorized individuals gained access to its IT systems and potentially accessed patient information, including names, addresses, birth dates, Social Security numbers, and treatment information. A third-party cybersecurity firm assisted with the investigation but found no instances of fraud or identity theft; however, as a precaution, the 21,325 affected patients have been offered complimentary credit monitoring and identity theft protection services. Evergreen Treatment Services did not state in its breach notice when the incident was detected, for how long the hackers had access to its network, or any information about the nature of the attack. Data security policies have been enhanced in response to the breach to prevent similar incidents in the future. Data Stolen in Cyberattack on Texas Orthopaedics and Sports Medicine Tomball, TX-based Texas Orthopaedics and Sports Medicine (TOSM) has confirmed that an unauthorized third party gained access to its...

Read More

Survey Reveals a Majority of Americans Are Uncomfortable with AI in Healthcare

A recent survey conducted by the Pew Research Center found a majority of Americans are uncomfortable with their healthcare providers using artificial intelligence tools to aid the diagnosis and treatment, indicating a need to improve education on the benefits of AI in healthcare. 60% of respondents expressed discomfort with the use of AI in care settings, with 39% of respondents saying they are comfortable with their care providers relying on AI for medical care. 38% of respondents believe AI will lead to better health outcomes, such as faster diagnosis and treatment, with 33% of respondents believing AI would result in worse health outcomes. 27% of respondents said they didn’t think AI would make much difference to patient outcomes. When probed about the potential benefits of AI in healthcare, 40% of respondents believe AI will reduce the number of mistakes by healthcare providers, such as misdiagnosis or the failure to diagnose a disease, compared to 27% who thought medical mistakes would increase. Out of the respondents who believe there is a problem with racial and ethnic bias...

Read More

True Health New Mexico Proposes Settlement to Resolve Class Action Data Breach Lawsuit

The Albuquerque, NM-based health insurance provider, True Health New Mexico, has proposed a settlement to resolve claims related to a 2021 HIPAA data breach that affected 62,983 members of its health plans. True Health New Mexico identified a security breach on October 5, 2021, with the investigation confirming that an unauthorized third party had gained access to its network and used ransomware to encrypt files. During the period of access, files were potentially viewed and exfiltrated that contained plan member data such as names, dates of birth, ages, home addresses, email addresses, insurance information, medical information, Social Security numbers, health account member IDs, provider information, and date(s) of service. No evidence of misuse of plan member data was identified at the time of issuing notification letters; however, as a precaution against identity theft and fraud, complimentary credit monitoring and identity theft protection services were offered to affected individuals. Several lawsuits were filed soon after notifications were sent alleging the health plan...

Read More

Alvaria Inc. Confirms Hive Ransomware Attack

Alvaria Inc. (formerly Aspect Software, Inc.), a provider of call center and customer experience software technology to large enterprises, has recently confirmed that it fell victim to a ransomware attack on a limited portion of its network. There is a trend for breach notification letters to only contain the bare minimum information to meet regulatory requirements; however, Alvaria breach notifications include comprehensive details about the attack including the name of the ransomware group responsible. The company has also confirmed that sensitive information was stolen, some of which was released on the Hive group’s dark web data leak site, which helps victims of the breach accurately assess the level of risk they face. Alvaria explained that the ransomware attack occurred on November 28, 2022, and steps were immediately taken to contain the attack and prevent further unauthorized access to its network. An investigation was launched and a third-party digital forensics company was engaged to investigate the scope of the attack and determine if protected health information had...

Read More

Judge Approves FTC’s $1.5 Million Settlement with GoodRx to Resolve FTC Act and Health Breach Notification Rule Violations

The GoodRx settlement with the FTC to resolve allegations that the FTC Act and Health Breach Notification Rule have been violated has been approved by a judge and is now in effect. The GoodRx FTC settlement involves a $1.5 million penalty and requires GoodRx to cease the alleged deceptive trading practices. On February 1, 2023, the Department of Justice filed a proposed order on behalf of the Federal Trade Commission prohibiting GoodRx from sharing the health information of its users with third parties for advertising purposes, following an FTC investigation that identified potential violations of the FTC Act and the FTC Health Breach Notification Rule. The FTC alleged that GoodRx – doing business as GoodRx Gold, GoodRx Care, and Hey Doctor (GoodRx) – violated the FTC Act by engaging in unfair and deceptive trade practices by sharing the data of millions of users without their consent and knowledge and violated the FTC Health Breach Notification Rule by failing to notify users about the privacy violation. The information shared with third parties included personally...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist