25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Patient Privacy Violated in Incidents at VCU Health and Cheyenne Regional Medical Center

A lengthy privacy violation has been detected by Virginia Commonwealth University Health System (VCU Health) that potentially started on January 4, 2006. According to the substitute breach notification on the VCU Health website, transplant donor information had been included in the medical records of certain transplant recipients, and transplant recipient information had also been included in the medical records of transplant donors. When donors, recipients of transplants, or their representatives logged into the patient portal to view their medical records, they would have been able to view information about the donor/recipient. It is also possible that the information was provided to individuals who exercised their right under the HIPAA Privacy Rule to obtain a copy of their health information. In each case, the exposed information was not accessible to the public, only to specific transplant donors and recipients. The privacy issue was detected by VCU Health on February 7, 2022, with the subsequent investigation confirming that additional information may also have been viewable,...

Read More

Senators Call for HIPAA Privacy Rule Change to Prohibit Disclosures of Reproductive Health Care Information to Law Enforcement

The HHS’ Office for Civil Rights has recently issued guidance to healthcare organizations following the overturning of Roe v. Wade following the SCOTUS Dobbs v. Jackson Women’s Health Organization ruling, which removed the right to abortion at the federal level and allowed states to set their own laws. The guidance explained how the HIPAA Privacy Rule permits disclosures of protected health information – including reproductive health care information – to law enforcement but does not require such disclosures. OCR explained in the guidance when such disclosures of reproductive health care information would be considered HIPAA violations under the HIPAA Privacy Rule. Two U.S. senators – Michael F. Bennet (D-Co) and Catherine Cortez Masto (D-NV) – recently wrote to the Secretary of the Department of Health and Human Services, Xavier Becerra, calling for the HHS to go further and make an update to the HIPAA Privacy Rule to ensure that the private and confidential health information of patients seeking reproductive healthcare is better protected. “The [SCOTUS} decision has...

Read More

Feds Warn of Threat of Maui Ransomware Attacks By North Korean State-Sponsored Hackers

A joint security alert has been issued to the healthcare and public health sector by the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of the Treasury warning about the threat of Maui ransomware attacks. Since May 2021, North Korean state-sponsored cyber actors have been targeting organizations in the U.S. healthcare and public health sector and have been encrypting servers that support electronic medical record systems and diagnostic, imaging, and intranet services. These attacks have resulted in data encryption which has disrupted the services provided to patients and, in some cases, has resulted in disruption to services for long periods. According to the advisory, initial access is gained to healthcare networks and the ransomware is deployed manually. The threat actors use a command-line interface to control the ransomware payload and launch attacks. Healthcare organizations are an attractive target for ransomware threat actors as they are heavily reliant on data for providing their services. Attacks can cause...

Read More
What Will ADPPA Compliance Entail?
Jul07

What Will ADPPA Compliance Entail?

The American Data Privacy and Protection Act (ADPPA) aims to introduce federal privacy and data security protections for consumer data. Here we explain what ADPPA compliance will entail. The Need for a Federal Consumer Data Privacy Law Despite many U.S. tech firms being among the largest worldwide collectors and processors of consumer data, the U.S. lacks a federal data privacy and protection law, and instead there is a patchwork of privacy laws covering each of the 50 states. National data privacy and protection laws have been introduced in many countries worldwide, yet all attempts to introduce comprehensive consumer data laws in the United States have failed to date. As it stands, the personal data of residents of California, Colorado, Connecticut, Utah, and Virginia is subject to quite stringent laws, but that is far from the case elsewhere. In other states, consumer data privacy and security requirements are far lower or even virtually nonexistent. That means that consumer rights over their personal data can vary considerably, depending on which side of a state border an...

Read More

Google Announces New Measures to Protect User Privacy on Healthcare Matters

Google has announced that it will be taking steps to improve privacy protections for users of its services. Google has long advocated for a comprehensive, national privacy law covering consumer data to ensure there is consistency across the entire country, rather than relying on a patchwork of state-level privacy laws. The American Data Privacy and Protection Act that was recently introduced could see national privacy law introduced, but until ADPPA or equivalent consumer data privacy regulations are signed into law, Google said it has taken additional steps to protect user privacy, especially for health-related issues. Google confirmed that location history is turned off in Google accounts by default, but if users choose to activate location history, they can auto-delete or manually delete parts or all of their location data at any time. However, to further protect privacy, Google has added a new auto-delete feature that will be rolled out in the next few weeks. If Google detects a user has visited certain medical facilities that offer sensitive medical services, the entries will...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist