NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Most Important Factors for Improving Cyber Resilience

Cyberattacks have increased in volume and sophistication to the point where it is inevitable that a successful attack will be experienced by all healthcare organizations at some point in their lifespan. Healthcare organizations can hope for the best, but it is vital to plan for the worst and take steps to ensure that the damage caused is kept to a minimum. A major focus for security teams, in addition to reducing risks, is improving cyber resilience. Cyber resilience is the ability of an organization to continue to operate in the event of a cyberattack and to recover quickly. A recent survey by Cisco indicates executives are aware of the importance of cyber resilience, with 96% of respondents saying cyber resilience is a high priority, and deservedly so, since 62% of respondents said their organization had experienced a security breach in the past two years – a combination of data breaches (51.5%), network/system outages (51.1%), ransomware attacks (46.7%), and DDoS attacks (46.4%). These attacks had severe repercussions for the breached entities, causing disruption to IT systems,...

Read More
Florida Primary Care Provider Fined $20,000 for HIPAA Right of Access Violation
Dec15

Florida Primary Care Provider Fined $20,000 for HIPAA Right of Access Violation

The Orlando, FL-based primary care provider, Health Specialists of Central Florida Inc. (HSCF), has paid a $20,000 financial penalty to settle a HIPAA Right of Access case with the HHS’ Office for Civil Rights. OCR launched an investigation in response to a November 22, 2019, complaint from a woman who had not been provided with a copy of her deceased father’s medical records. The initial request was made in writing on August 29, 2019, and an Authorization for Release of Medical Record Information form was provided to HSCF along with a copy of the original Letters of Administration. It took multiple requests and almost 5 months for all of the requested medical records to be provided. The complete set of records was received by the woman on January 27, 2020. The HIPAA Right of Access requires healthcare providers to provide a copy of the requested medical records within 30 days of the request being submitted. In certain circumstances, a 30-day extension is applicable. OCR determined that the delay in providing the requested records was a violation of the HIPAA Right of Access. In...

Read More

Nurse Sentenced to 37 Months in Jail for Tampering with and Stealing Medications

A former nurse employed by the Roswell Park Comprehensive Cancer Center in Buffalo, NY, has been sentenced to 37 months in prison for tampering with and stealing controlled medications intended for cancer patients. Kelsey A. Mulvey, 30, of Grand Island, NY, worked as a registered nurse at Roswell Park between February 2018 and June 2018. On June 27, 2018, Mulvey was observed accessing a medication dispensing machine in a room to which she was not assigned and left carrying a backpack. She was placed on administrative leave pending an investigation and later resigned. The investigation concluded Mulvey had stolen hydromorphone, methadone, oxycodone, and lorazepam from the automated medication dispensing systems. In June and July 2018, six patients at Roswell Park became ill with waterborne infections. The investigation concluded that Mulvey had replaced the hydromorphone in the vials with water to hide the theft. Roswell Park has a zero-tolerance policy and immediately notified the New York State Department of Health, the NYS Department of Education, the Bureau of Narcotics and...

Read More

Up to 254,000 Medicare Beneficiaries Affected by Ransomware Attack on CMS Subcontractor

On November 14, 2022, Fairmont, WV-based Health Care Management Solutions (HMS) reported a data breach to the HHS’ Office for Civil Rights that affected up to 500,000 individuals. At the time, few details about the breach were released. It has now been confirmed that HMS suffered a ransomware attack on October 8, 2022. HMS is a subcontractor of ASRC Federal Data Solutions, LLC (ASRC Federal), which is a business associate of the HHS’ Centers for Medicare and Medicaid Services (CMS). The services provided include resolving system errors related to beneficiary entitlement and premium payment records, as well as supporting the collection of Medicare premiums from the direct-paying beneficiary population. The CMS said the HMS does not handle Medicare claims information so no claims data was affected and CMS systems were not breached; however, the cybercriminals behind the attack may have accessed Medicare beneficiaries’ personally identifiable information (PII) and/or protected health information (PHI). The CMS says up to 254,000 Medicare beneficiaries have potentially been affected...

Read More

OCR Fines California Dental Practice for PHI Disclosures on Yelp

The HHS’ Office for Civil Rights (OCR) has announced a settlement has been reached with a Californian dental practice to resolve multiple HIPAA violations that were identified during investigations of a complaint about impermissible disclosures of protected health information on the review platform Yelp. New Vision Dental is a Californian general dental practice with offices in South Pasadena and Glendora. On November 29, 2017, OCR received a complaint alleging Dr. Brandon Au, owner and CEO of New Vision Dental, had posted responses to several reviews by patients on Yelp and frequently disclosed protected health information in the responses. In some of the posts, patients were identified and their full names were disclosed, when they had chosen to only use a moniker on the platform. Other information allegedly posted by Dr. Au included detailed information about the patients’ visits, treatment, and insurance, when that information had not been posted publicly by the patients. The investigation into the impermissible disclosures also included an on-site visit to New Vision Dental....

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist