NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

New Draft of ADPPA Law Introduced with Bipartisan Support

The American Data Privacy and Protection Act (ADPPA) was introduced in June, was substantially revised within a matter of days, and last month a new draft of ADPPA law was introduced with further revisions. The revised ADPPA has attracted considerable bipartisan support and sailed out of the committee with a vote of 53-2, and there is a reasonable chance that ADPPA will become the first federal privacy and data protection bill to be signed into law in the United States. Why a Federal Data Privacy Law is Desperately Needed ADPPA is far from the only attempt to get a federal data privacy and protection bill signed into law. Many other bills have been introduced that have attempted to introduce minimum standards for privacy and data protection at the federal level, but all attempts so far have failed. What the United States has is a patchwork of privacy and data protection laws at the state level and a handful of industry-specific laws such as HIPAA and FERPA. The problem is that the legal requirements for ensuring privacy and the security of data vary significantly depending on where...

Read More

Ensuring Personal Password Privacy in Shared-Vault Environments

One of the obstacles to the adoption of enterprise password managers is ensuring personal password privacy in shared-vault environments. This article discusses the issue, explains why it is important to address it, and suggests a solution to overcome employee concerns. The number of threats to online security is increasing every day; and, as the majority of threats exploit human error, user susceptibility to phishing, and weak or stolen credentials, many more businesses are implementing vault-based password managers that enable them to securely assign unique, complex passwords for corporate accounts to authorized users. Vault-based password managers help mitigate online security risks universally across platforms – making them ideal for remote workers and businesses operating BYOD policies. Furthermore, they can also be used to store and autofill credit card details, addresses, and other data – increasing productivity by reducing transaction times and further reducing the risk of human error. The Challenge of Changing Users´ Behaviors However, one of the challenges of deploying an...

Read More

Salinas Valley Memorial Healthcare Settles Email Data Breach Lawsuit for $340K

Salinas Valley Memorial Healthcare System in California has agreed to settle a class action lawsuit for $340,000 to resolve claims from patients affected by a breach of its email environment in 2020. Between April 30, 2020, and June 5, 2020, unauthorized individuals gained access to the email accounts of four employees and a contractor following responses to phishing emails. Prompt action was taken to secure its email environment, but during the 5-week period of compromise, the attacker(s) had access to emails containing sensitive patient information including names, hospital account numbers, medical record numbers, dates of service, and other information. Legal action was taken against Salinas Valley by a patient affected by the data breach. The plaintiff alleged that Salinas Valley acted unlawfully by failing to prevent the attack, did not fulfill its legal obligations to safeguard the personal and protected health information of the plaintiff and class members, and violated the California Confidential Medical Information Act, Civil Code §§ 56 et seq. Salinas Valley maintains it...

Read More

HC3 Warns About Risks of IoT in Healthcare

The Health Sector Cybersecurity Coordination Center (HC3) has published a security advisory warning the healthcare and public health sector about the risks associated with Internet of Things (IoT) devices and has made recommendations for improving the security of IoT devices. The Internet of Things (IoT) refers to physical devices that have the capability to exchange data or connect to other devices over the Internet. Currently, there are around 7 billion devices that are connected through IoT, and IoT device use is expected to increase to 20 billion devices worldwide by 2025. These devices use sensors to collect data and communicate over the Internet and include a wide range of “smart” appliances such as TVs and washing machines, doorbell cameras, Amazon Echo devices, voice controllers, and wearable devices. IoT devices are used in industrial settings and many medical devices use IoT. While there have been major advances in IoT technology in recent years to make the technology cheaper and more accessible, the main architectural layers have largely remained unchanged and there is...

Read More

Updates on Cyberattacks on Goodman Campbell Brain and Spine and Behavioral Health Group

Further information has been released on two cyberattacks on healthcare organizations: Goodman Campbell Brain and Spine and Behavioral Health Group. Goodman Campbell Brain and Spine Notifies 363,000 Patients About Public Release of PHI on Dark Web Carmel, IN-based Goodman Campbell Brain and Spine has started notifying 363,000 current and former patients that some of their protected health information was stolen prior to data being encrypted with ransomware and some of the stolen data has been published on the gang’s dark web data leak site. The cyberattack was discovered by Goodman Campbell on May 20, 2022, and a third-party digital forensics firm was engaged to determine the nature and scope of the breach. The investigation confirmed that the electronic medical record system was not affected, but files containing patients’ protected health information had been exfiltrated from its systems. The stolen files contained information such as names, birthdates, addresses, telephone numbers, email addresses, medical record numbers, patient account numbers, diagnosis and treatment...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist