NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HIPAA Notice of Privacy Practices
Jan15

HIPAA Notice of Privacy Practices

A HIPAA Notice of Privacy Practices is a document provided to patients on first contact, and to health plan members on enrollment, that outlines how a HIPAA covered entity can use or disclose Protected Health Information (PHI) and the rights individuals have to obtain copies of their PHI. The Notice must also include the contact details for an individual who can answer questions or to whom complaints can be made. However, although the core elements of a HIPAA Notice of Privacy Practices have to follow the Privacy Rule standards in §164.520, the content can differ depending on whether a covered entity is a healthcare provider or a group health plan, or – for example – whether the covered entity is part of a Health Maintenance Organization (HMO) or Organized Health Care Arrangement (OHCA). In addition, there are different rules for distributing HIPAA Notices of Privacy Practices depending on whether a covered healthcare provider has a direct treatment relationship with the individual (i.e., this rule would not apply to pharmacies), and different rules for reminding individuals...

Read More
How to Secure Patient Information (PHI)
Jan15

How to Secure Patient Information (PHI)

To best explain how to secure patient information and PHI, it is necessary to distinguish between what is patient information and what is PHI because although HIPAA requires PHI to be secured, it does not require all patient information to be secured. The easiest way to distinguish between PHI and other patient information is to define PHI first, because any remaining patient information does not need to be secured under HIPAA – although other privacy and security laws may apply. What is PHI? And What is Not PHI? The Administrative Simplification Regulations defines PHI as individually identifiable health information “transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium”. To understand why some patient information might not be PHI, it is necessary to review the definition of individually identifiable health information: “Information […] collected from an individual […] that relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an...

Read More
HIPAA Compliance for Dentists
Jan15

HIPAA Compliance for Dentists

HIPAA compliance for dentists consists of complying with the applicable standards of the HIPAA Administrative Simplifications Regulations, state regulations with stronger protections than HIPAA, and any compliance requirements attributable to the operational setup. It is important for dentists to be aware of their HIPAA “status”, understand who within the organization is responsible for HIPAA compliance, and ensure all dental practice workers comply with HIPAA privacy and security policies and procedures. HIPAA compliance for dentists and dental practices can be particularly complicated. This may be because some dentists do not qualify as covered entities and are not required to comply with the HIPAA Privacy and Security Rules, it may be because state privacy laws pre-empt HIPAA, or because a dental practice is part of a Dental Service Organization which itself may be part of an Affiliated Covered Entity or Organized Health Care Arrangement. The Administrative Simplification Regulations of HIPAA can be difficult to understand for any type of covered entity or business associate....

Read More
Is Zoom HIPAA Compliant?
Jan15

Is Zoom HIPAA Compliant?

Zoom is HIPAA compliant provided organizations subscribe to a Zoom business account with the appropriate security controls, enter into a Business Associate Agreement with Zoom, configure the platform correctly, and ensure it is used compliantly. Zoom is a popular video and web conferencing platform that has been adopted by more than 150,000 businesses but is the service suitable for use by healthcare organizations for sharing PHI. Is Zoom HIPAA compliant? What is Zoom? Zoom is a cloud-based video and web conferencing platform that allows workers across multiple locations to take part in meetings, share files, and collaborate. The platform supports webinars and includes a business IM service. Zoom has already been adopted by many healthcare organizations around the globe who use the platform to consult with other providers and communicate with patients. However, in the United States, healthcare providers, health plans, and healthcare clearinghouses (collectively “HIPAA-covered entities”) using the platform must comply with HIPAA. Any software solution used to share...

Read More
Why is HIPAA Important?
Jan15

Why is HIPAA Important?

HIPAA is important because, due to the passage of the Health Insurance Portability and Accountability Act, the Department of Health and Human Services was able to develop standards that protect the privacy of individually identifiable health information and the confidentiality, integrity, and availability of electronic Protected Health Information. HIPAA was introduced in 1996, primarily to address one particular issue: Insurance coverage for individuals between jobs and with pre-existing conditions. Without HIPAA, employees faced a potential loss of insurance coverage between jobs. Because of the cost of HIPAA’s primary objective to health insurance companies – and the risk that the cost would be passed onto employers and individuals as higher premiums – Congress instructed the Secretary for Health and Human Services to develop standards that would reduce healthcare insurance fraud and simplify the administration of healthcare transaction. Due to the increased number of transactions being conducted electronically, standards were also developed to protect the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist