25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

U.S. Vision Subsidiary and Florida Addiction Treatment Center Announce 2021 Data Breaches

USV Optical, a subsidiary of U.S. Vision, has recently confirmed that the information of patients at several entities within its network has been exposed. Suspicious activity was detected within its network on May 12, 2021, with the forensic investigation confirming unauthorized individuals had access to its network for a month between April 20, 2021, and May 17, 2021. During that time, the attackers may have viewed or acquired sensitive patient data. The breach was reported to U.S. Vision shortly after it was detected; however, at the time it was unclear which entities and patients had been affected. Nationwide Optical Group acquired or became affiliated with several U.S. Vision entities in September 2019, including Nationwide Optometry and SightCare. USV Optical started to provide administrative services to those entities around that time. Nationwide Optical Group was informed about the breach and requested U.S. Vision investigate the incident further to find out more information and recommended monitoring the dark web to determine if any sensitive data had been released. No...

Read More

Microsoft Business Associate Agreement

If your organization is a HIPAA Covered Entity, Business Associate, or subcontractor to either, and it creates, receives, maintains, or transmits electronic Protected Health Information (ePHI) via a covered Office 365, Dynamics 365, or Azure service, it will be necessary to enter into a Microsoft Business Associate Agreement. Back in 2016, the Department of Health and Human Services (HHS) published an FAQ about whether a Cloud Service Provider could be considered a “conduit” for ePHI and thereby not qualify as a Business Associate. In the answer to the FAQ, HHS replied that Cloud Service Providers qualify as Business Associates because they have “persistent” access to ePHI (rather than “transient” access), even if ePHI is encrypted and the Cloud Service Provider does not have access to the decryption key. Therefore, before an organization subject to HIPAA uses any cloud service (or any on-premises service that synchronizes via the cloud) to create, receive, maintain, or transmit ePHI, it is necessary to conduct due diligence on the vendor. If the vendor has appropriate measures in...

Read More

St. Luke’s Health Reports Third Party Data Breach

St. Luke’s Health has recently notified 16,906 patients that some of their protected health information has been exposed in a security incident at a vendor that provides consulting services. On November 5, 2021, the email accounts of two employees of Adelanto Healthcare Ventures (AHCV) were accessed by an unauthorized individual. An investigation was launched into the incident, which initially determined no patient information had been exposed; however, a subsequent review determined the information of certain St. Luke’s Health patients was present in the email accounts and could potentially have been accessed or acquired by the attackers. The exposed information included names, addresses, dates of birth, Social Security numbers, dates of service, medical record numbers, Medicaid numbers, and some limited clinical information, such as treatment and diagnosis codes. St. Luke’s Health was notified about the breach on September 1, 2022 St. Luke’s Health explained in its breach notification letters that no reports have been received that suggest there has been any misuse of patient...

Read More

Lawsuits Filed Against OakBend Medical Center and Keystone Health Over Data Breaches

Oakbend Medical Center in Richmond, TX, and Keystone Health in Chambersburg, PA, are facing class action lawsuits over recent hacking incidents that resulted in the exposure and theft of the protected health information of hundreds of thousands of patients. OakBend Medical Center On September 1, 2022, OakBend Medical Center discovered its systems had been compromised and files had been encrypted. The breach was contained and access to its network was terminated, and a forensic investigation was conducted to determine the nature and scope of the attack. The forensic investigation confirmed that the attackers had exfiltrated files containing patient data. OakBend Medical Center said entire medical records do not appear to have been stolen. The stolen data included names, contact information, dates of birth, and Social Security numbers. The threat actors behind the attack – Daixin Team – claim the data they stole included 1 million patient records, although Oakbend Medical Center reported the breach to the HHS Office for Civil Rights as affecting up to 500,000 patients. On October 28,...

Read More
What is OSHA Certified?
Nov07

What is OSHA Certified?

The term OSHA certified has several meanings. It can mean the certificate an individual receives for completing an OSHA-authorized training course, the “card” required by some employers, industries, or states to demonstrate a knowledge of workplace safety, a document proving a trainer is qualified, or a point-in-time record an employer complies with OSHA standards. Getting a straightforward answer to the question what is OSHA certified can be confusing – mostly due to contradictions in OSHA´s literature. For example, in OSHA´s booklet “Training Requirements in OSHA Standards” (PDF), the section relating to OSHA Training Institute Educations Centers states “none of the courses within the Outreach Program is considered a certification”. Yet, within the same section there is a link to a directory of Education Centers offering OSHA-authorized training courses – most of which award a certificate at the completion of the course. Indeed, according to some certificate programs, it is necessary for students to be OSHA certified in one course before they can take a more advanced course in...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist