25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Steve Alder

Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

What is the Cost of HIPAA Certification?
Oct19

What is the Cost of HIPAA Certification?

HIPAA certification for individuals typically costs between $25 to $35, depending on the quality and extent of the HIPAA certification training. Investing in a HIPAA compliance program that provides an Accredited HIPAA Certification at the end of the program can be worthwhile, both for businesses and for individuals. What are HIPAA Compliance Certification Courses? HIPAA compliance certification programs come in many shapes and sizes. Some are designed to help businesses comply with specific elements of HIPAA (i.e. security and awareness training), others cover the evaluation requirements of the Security Rule (§164.308(a)(8)), while the best HIPAA compliance programs are more comprehensive and include Privacy Rule compliance, Business Associate Agreements, and breach notification procedures. HIPAA compliance programs can also be designed to help members of the workforce better understand their compliance obligations by providing foundation training. Foundation training courses do not replace “policy and procedure” training required by the Privacy Rule, but rather explain the basics...

Read More
HIPAA Compliance for Radiology Practices
Oct18

HIPAA Compliance for Radiology Practices

HIPAA compliance for radiology practices requires implementing controls under the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule across scheduling, imaging acquisition, interpretation, reporting, billing, and records release. HIPAA in Radiology Services Radiology centers, radiology clinics, and Radiology Departments create, receive, maintain, and transmit protected health information through patient registration, orders, imaging studies, radiology reports, and revenue cycle processes. A Diagnostic imaging center often exchanges protected health information with ordering providers, hospitals, payers, and external reading services. Each exchange is a regulated disclosure or transmission that requires documented controls. Radiology services also rely on connected systems and vendors that handle protected health information on behalf of the organization. HIPAA compliance depends on governing those relationships, controlling access paths, and maintaining evidence of operational safeguards. Protected Health Information in Imaging Workflows Protected health...

Read More
HIPAA Compliance for Medical Document Shredding Companies
Oct18

HIPAA Compliance for Medical Document Shredding Companies

HIPAA compliance for medical document shredding companies means maintaining a secure, documented chain of custody for Protected Health Information from collection through transport, staging, destruction, and verification, while meeting the obligations that apply to HIPAA Business Associates that handle PHI on behalf of HIPAA Covered Entities. What HIPAA Compliance Looks Like for Shredding Operations Shredding vendors regularly handle printed medical records, billing documents, lab reports, and other materials containing patient identifiers. HIPAA Compliance for Secure shredding and destruction services starts with a clear Business Associate Agreement, written procedures, and reliable controls that prevent loss, theft, or unauthorized access. Practical safeguards include locked collection consoles, tamper resistant containers, controlled access to staging areas, secure vehicles and routes, and standardized destruction processes. HIPAA Training for Business Associates Our training includes specific lessons covering the unique HIPAA-challenges faced by staff at Business Associates....

Read More
HIPAA Compliance for Medical Transcription Services
Oct18

HIPAA Compliance for Medical Transcription Services

HIPAA compliance for medical transcription services means protecting patient health information across every step of the transcription workflow, from receiving audio and documents through processing, quality review, delivery, storage, and secure disposal, while meeting the obligations that apply to HIPAA Business Associates. A key part of that compliance is ensuring all staff receive HIPAA training, supported by annual refresher training as a healthcare best practice, so everyone understands how to handle PHI safely and how to report issues quickly. Why HIPAA Applies to Medical Transcription Services Medical transcription services routinely receive, create, maintain, and transmit Protected Health Information while converting dictated or recorded clinical notes into formal medical records. Because this work is performed on behalf of healthcare providers, transcription companies and independent transcriptionists are HIPAA Business Associates. That status brings clear responsibilities under the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Compliance is not optional...

Read More
Cybersecurity Firm Reports 36% YOY Increase in Ransomware Attacks
Oct17

Cybersecurity Firm Reports 36% YOY Increase in Ransomware Attacks

Cybersecurity firm Black Fog has released its Q3 2025 State of Ransomware Report, which shows ransomware attacks have increased by 36% compared to the same quarter in 2024. Each month in the quarter saw an increase in attacks compared to the corresponding month last year, with July the worst month with a 50% increase. Over the whole quarter, 270 ransomware attacks were reported, although Black Fog notes that the majority of attacks remain in the shadows and go unreported. In Q3, an estimated 1,510 ransomware attacks were not disclosed, which represents a 21% increase from the previous quarter. Healthcare remains a key target for ransomware groups, with the sector experiencing 86 attacks, which represents 32% of all disclosed attacks – more than twice as many ransomware attacks as were disclosed by entities in the next most attacked sectors, government and technology, which each had 28 disclosed incidents. Black Fog reports that 85% of ransomware attacks are not reported, and taking those attacks into account, manufacturing was the hardest hit sector, accounting for 22% of the...

Read More
x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist