25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Former Pennsylvania Medical Assistant Charged with Stealing Patient Information for Personal Gain

A former employee of Axia Women’s Health in Pennsylvania has been charged in a 39-count indictment for stealing patient information for personal gain. The Upper Moreland Police Department in Montgomery County, PA, uncovered an elaborate scheme involving the theft of the identities of patients, which were used to obtain credit cards and loans, rent high-end apartments, and obtain several thousand dollars worth of furniture. The investigation centered on Gwendolyn Murray of Philadelphia. Text messages were found on Murray’s cellphone that had been sent by Ashley Latimer, 34, of Philadelphia, which appeared to be screenshots of patient records. Ashley was determined to have sent the messages while working at AFC Urgent Care in South Philadelphia. Further investigation revealed Latimer had worked at AFC Urgent Care between September 16, 2021, and December 26, 2021, but was fired when she was suspected of stealing $3,200 from the cash drawer. Latimer then found employment as a medical assistant at Axia Women’s Health, where she was given access to patient records to complete her...

Read More
FDA, MITRE Update Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook
Nov16

FDA, MITRE Update Medical Device Cybersecurity Regional Incident Preparedness and Response Playbook

In the event of a cyberattack that impacts the functionality of medical devices, a rapid and effective response is essential to ensure patient safety and the continuity of clinical operations. While healthcare organizations have practiced protocols that can be implemented immediately in the event of a natural disaster such as a hurricane, they tend to be less well prepared to deal with cybersecurity incidents. Earlier this month, Senator Mark Warner (D-VA), Chairman of the Senate Select Committee on Intelligence, published a white paper – Cybersecurity is Patient Safety – highlighting this problem, which he said is due to an outdated mode of thinking, where cybersecurity is viewed as a secondary or tertiary concern, and that is something that needs to change. The key to a rapid recovery from a cyberattack is preparedness. Healthcare organizations need to treat cyberattacks as a primary concern and ensure they have a tried and tested plan for responding to attacks, and protocols that can be implemented immediately when a cyberattack is detected. Following the WannaCry...

Read More

Update: CorrectCare Integrated Health Data Breach Affects Hundreds of Thousands of Inmates

The medical claims processor, CorrectCare Integrated Health, has recently notified its clients that the protected health information of some of their patients was accidentally exposed over the Internet and may have been accessed by unauthorized individuals. On July 6, 2022, CorrectCare discovered two file directories on its web server had been misconfigured and could be accessed over the Internet without authentication. The breach has affected patients treated by Mediko, Inc. – the largest provider of health care services to individuals in correctional facilities in Virginia. Mediko has reported the HIPAA breach to the HHS’ Office for Civil Rights (OCR) as affecting 2,809 individuals. Sacramento County Adult Correctional Health says 5,372 individuals have been affected, and the Louisiana Department of Public Safety and Corrections says 85,466 individuals incarcerated in facilities in the state have been affected. Health Net Federal Services (HNFS) in California, a business associate of the California Correctional Health Care Services (CCHCS)/ California Department of...

Read More
Pennsylvania Updates Data Breach Notification Law
Nov15

Pennsylvania Updates Data Breach Notification Law

The Governor of Pennsylvania, Tom Wolf, has signed Senate Bill 696 into law, which expands the definition of personal information under the Breach of Personal Information Notification Act that warrants individual notifications to be issued in the event of a data breach. The updated law will take effect on May 2, 2023. The updated definition of personal information now includes medical information, health insurance information, and usernames and passwords. Notifications must be issued if any of that information is breached along with the name of a state resident. Medical information is classed as individually identifiable information related to an individual’s current or past medical condition, diagnosis, or treatment that has been created by a healthcare professional. Health insurance information includes a health insurance policy number or subscriber number, combined with an access code or other information that would allow the misuse of an individual’s insurance benefits. Breaches of usernames also require notifications, if the password is also compromised or any other...

Read More
Five Former Tennessee Hospital Employees Charged with Criminal HIPAA Violations
Nov15

Five Former Tennessee Hospital Employees Charged with Criminal HIPAA Violations

Five former employees of Methodist Hospital in Tennessee have been indicted by a federal grand jury in Memphis for criminal violations of the Health Insurance Portability and Accountability Act (HIPAA) for impermissibly accessing the protected health information of patients and providing that information to another individual for financial gain. According to the indictment, between November 2017 and December 2020, Roderick Harvey, 40, conspired with five former hospital employees and paid them to provide him with the names and telephone numbers of patients who had been involved in motor vehicle accidents. Harvey then sold that information to third parties such as personal injury lawyers and chiropractors. The former Methodist Hospital employees – Kirby Dandridge, 38, Sylvia Taylor, 43, Kara Thompson, 30, Melanie Russell, 41, and Adrianna Taber, 26 – and Harvey were charged with conspiracy to obtain patient information with the intent to sell, transfer or use such information for personal gain, the maximum penalty for which is five years in jail, three years of supervised...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist