NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

Former South Georgia Medical Center Employee Arrested Over 41K-Record Data Breach

The Hospital Authority of Valdosta and Lowndes County Georgia has recently reported a data breach involving the unauthorized copying of patient data by a former employee of South Georgia Medical Center. On November 12, 2021, security software generated an alert indicating an employee had downloaded data from the hospital’s systems onto a USB drive. The investigation confirmed the downloaded data included patients’ names, dates of birth, and test results. The HIPAA breach was recently reported to the Department of Health and Human Services’ Office for Civil Rights as involving the protected health information of 41,692 individuals. The employee had been provided with access to patient data in order to complete work duties, but no authorization was given to copy patient data and remove it from the hospital. The employee left employment at the hospital on November 11, 2021. South Georgia Medical Center said no data was erased from its systems and the copied files have now been recovered. The data theft incident was reported to law enforcement and the Lowndes County Sheriff’s Office...

Read More

Concerning Healthcare Data Breach Reporting Trend

The HIPAA Breach Notification Rule calls for data breach notifications to be issued to the Secretary of the HHS “without unnecessary delay” and no later than 60 days after the date of discovery of a data breach. The same time frame applies to issuing notification letters to affected individuals. There has been a trend in recent years for HIPAA-regulated entities to wait the full 60 days from the date of discovery of the breach to issue notifications to affected individuals and the HHS, but recently growing numbers have taken the date of discovery as the date when the breach investigation has been completed, or even the date when the full review of impacted documents is finished. In some cases, notifications have been issued many months after the initial system breach was detected. There may be valid reasons for a delay in reporting, such as a request from law enforcement to delay making a cyberattack or data theft incident public to avoid interfering with the law enforcement investigation; however, it is rare for individual notifications to mention these law enforcement requests....

Read More

Cyberattacks and Data Theft Incidents Reported by Medical Healthcare Solutions and Advocates Inc.

Advocates Inc., a Massachusetts-based nonprofit provider of support services for individuals experiencing life challenges such as addiction, autism, brain injury, intellectual disabilities, mental health, and behavioral health, has announced it recently experienced a sophisticated cyberattack and data theft incident. Advocates was informed on October 1, 2021, that an unauthorized individual had gained access to its network and copied files containing the sensitive data of patients and employees. A leading cybersecurity firm was engaged to assist with the investigation, which revealed an unknown individual had accessed its network and copied files over a four-day period between September 14, 2021, and September 18, 2021. The files contained names, addresses, dates of birth, Social Security numbers, health insurance information, client ID numbers, diagnoses, and treatment information. After confirming the individuals affected, Advocate collected up-to-date contact information to allow written notices to be provided, hence the delay in issuing notification letters. The cyberattack was...

Read More

Data Breaches Reported by Houston Area Community Services, County of Kings, and NYU Langone Health

Data breaches have recently been reported by Houston Area Community Services, County of Kings in California, and NYU Langone Health. Avenue 360 Health and Wellness Reports Breach of Employee Email Accounts Houston Area Community Services, Inc., doing business as Avenue 360 Health and Wellness, has discovered an unauthorized individual has gained access to the email accounts of certain employees and may have viewed or obtained the protected health information of 12,186 individuals. Avenue 360 Health and Wellness said its investigation determined the email accounts were compromised between January 15, 2021, and April 2, 2021. A third-party vendor that specializes in the analysis of security incidents such as this was engaged to assist with the investigation. A comprehensive review was conducted of all emails and attachments in the account. On November 9, 2021, Avenue 360 discovered the account contained names, medical record numbers, health insurance information, birthdates, diagnoses, clinical and treatment information, and prescription information. A limited number of individuals...

Read More
Florida County Drug Screening Lab Exposed Sensitive Data Online for 4 Years
Jan28

Florida County Drug Screening Lab Exposed Sensitive Data Online for 4 Years

A misconfiguration of an internal website portal used by a Florida county drug screening lab exposed sensitive information online for a period of more than four years. St. Lucie County’s drug screening lab (SLC Lab) provides drug testing services for employment, court cases, and other purposes. The configuration error was discovered on October 13, 2021, and the issue was immediately corrected. Assisted by third-party cybersecurity professionals, the country determined on December 28, 2021, that the configuration error occurred on June 2, 2017. From June 2, 2017, to October 13, 2021, sensitive data were accessible to certain portal users, including full names, dates of birth, Social Security numbers, and limited information related to the type of drug test performed and the result of the lab test. While sensitive data were exposed via the web portal for 4 years, SLC Lab said it has not been notified about any cases of improper use of any of the exposed information and is unaware of any cases of identity theft or fraud as a result of the portal misconfiguration. SLC Lab did not...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist