25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

HIPAA Training for Emergency Room Staff
Oct07

HIPAA Training for Emergency Room Staff

HIPAA training for emergency room staff is mandatory because emergency departments handle high volumes of sensitive patient information in fast paced, high risk environments where privacy and security mistakes can easily occur without proper education. Every member of the emergency room workforce, including clinicians, nurses, technicians, registration staff, and support personnel, must receive standard HIPAA training that explains their responsibilities and prepares them to protect patient information, and must also receive additional HIPAA training about the HIPAA rules while delivering urgent care. Why HIPAA Training is Required in the Emergency Room Emergency rooms routinely collect, use, and disclose protected health information during triage, diagnosis, treatment, and coordination with other providers. HIPAA training ensures staff understand how the Privacy Rule, Security Rule, and Breach Notification Rule apply to everyday emergency department activities. Training reinforces that HIPAA applies even during stressful situations and that compliance supports patient trust,...

Read More
EyeMed Vision Care Agrees to Pay $5 Million to Settle Class Action Data Breach Lawsuit
Oct06

EyeMed Vision Care Agrees to Pay $5 Million to Settle Class Action Data Breach Lawsuit

EyeMed Vision Care has agreed to pay $5 million to settle a class action lawsuit stemming from a June 2020 data breach.  The data breach was identified by EyeMed Vision Care on July 1, 2020, when suspicious activity was observed in an employee’s email account. An employee had responded to a phishing email, allowing their email account to be accessed on June 24, 2020. Between June 24, 2020, and July 1, 2020, the threat actor used the account to send around 2,000 phishing emails. The investigation revealed the account contained emails dating back 6 years. Those emails included the personal and protected health information of 2.1 million individuals. Data compromised in the incident included names, contact information, dates of birth, Social Security numbers, vision insurance account/identification numbers, medical diagnoses and conditions, and treatment information. The first class action lawsuit in response to the data breach was filed in January 2021 by plaintiff Chandra Tate, which was followed by a second class action lawsuit around a week later. The two lawsuits were...

Read More
HIPAA Security Training
Oct04

HIPAA Security Training

HIPAA security training is the structured education healthcare organizations use to ensure all workforce members understand how to safeguard electronic protected health information, reduce cybersecurity risks, and comply with the HIPAA Security Rule in daily operations. What HIPAA Security Training Is Designed to Achieve HIPAA security training focuses on protecting electronic patient information by addressing how data is accessed, stored, transmitted, and monitored. The goal is to reduce the risk of unauthorized access, data loss, and cyber incidents while ensuring staff understand their individual responsibilities. Effective training connects legal requirements to everyday behaviors such as logging into systems, using mobile devices, sharing information electronically, and recognizing suspicious activity. Who Must Receive HIPAA Security Training All staff must receive HIPAA training because every workforce member can impact the security of electronic health information. This includes clinical personnel, administrative teams, billing staff, IT teams, management, contractors, and...

Read More
HIPAA Compliance for Psychiatrists
Oct04

HIPAA Compliance for Psychiatrists

The nature of HIPAA compliance for psychiatrists can vary depending on whether a psychiatrist is a sole practitioner that qualifies as a HIPAA covered entity, a unit within a managed care organization, part of an affiliated entity, a hybrid entity, a business associate, or a member of a HIPAA covered organization’s workforce. There is no one-size-fits-all guide to HIPAA compliance for psychiatrists. This is because some psychiatrists are responsible for all elements of HIPAA compliance, others may subcontract elements of HIPAA compliance to business associates, and others may work in – or for – an organization in which responsibility for HIPAA compliance is assigned to a compliance officer. Due to these factors, some mental health professionals have more autonomy than others with regards to what HIPAA compliance for psychiatrists consists of. In addition, both the HIPAA Privacy Rule and the HIPAA Security Rule allow a flexibility of approach depending on the size, the type of activities that relate to Protected Health Information (PHI), and the capabilities of a...

Read More
Healthcare Cyberattacks Costing $200K+ Rise 400% in a Year
Oct03

Healthcare Cyberattacks Costing $200K+ Rise 400% in a Year

Over the 12 months from March 2024 to March 2025, almost half of healthcare organizations experienced at least one data incident, such as a ransomware attack, hacking incident, or phishing attack, according to the cybersecurity firm Netwrix. For its 2025 Cybersecurity Trends Report, Netwrix surveyed 2,150 IT professionals from 121 countries in March 2025 and compared the findings to previous surveys conducted in 2024, 2023, and 2020. Healthcare has long been targeted by threat actors due to the high value of patient records, and the fact that healthcare organizations cannot tolerate disruption, as it puts patient safety at risk. The sector is extensively targeted by ransomware groups as there is a higher probability that the ransom will be paid to prevent the publication of stolen data and ensure a fast recovery. In the past 12 months, 48% of healthcare organizations experienced at least one security incident that required a dedicated response from the security team. Across all sectors, the number of organizations reporting no impact from security incidents is rapidly reducing. In...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist